| URL: | https://urldefense.proofpoint.com/v2/url?u=https-3A__us-2Deast-2D2.protection.sophos.com_-3Fd-3Dcisco.com-26u-3DaHR0cHM6Ly9zZWN1cmUtd2ViLmNpc2NvLmNvbS8xdEt6U1JTSUNXZW5hOVhRZlhjQlNQQkFhdHFxbEliZVFvbUo5TXV2ZGxlbGFVZlJtSy1wb2l4b0lHT3lMeDU3YVBOc0tGb0w3V0tua3NPbm5PT1pSeGdwWkJ3dW1KZWU2R1hsdzRnYldqNWRwMV96elZoZFJQZU5CbzhWdzJxTjZZaGFid3A0UFB1V1J6R05xZHJlSGx1LU5SbmJTN3ZXcHp0dndHRXRaNF9TU2FrTlJzUnZJQXhJaXlib3QwOVNnQkdnZFRwa3lDMWJVQnAwVG1rUjViOW9nNW1IaEZCUy1yR1JMdDh5M1gzUDNVWllxdXV1YnBWLXdzOGt3UnV0YVhjUkZwMUlYbzJfM0JPYVNyanpWVm5pdEIxVDZUTGdkbDZKcGdyMGNaUFVBbGw0X0hCdk5UVFVLNlIzQ0trdUhhMDI5cjJuYk9fUEdQbkVSb1NTR1ZMZHFiRnAxdGlhblFSazE5TUo3YmJmblI3V0NQRTJTd3JjeWMtWkFUUTZXZENJS2Rid25kMzhMckhNbV9YdWlQZU9UTm9VYngwX3dMM1J0bnZsZ3ZNby9odHRwcyUzQSUyRiUyRnVsdHJhZ3VhcmQuY29tLmF1JTJGbmV3Q2FsY3VsYXRvciUyRm1hdGhz-26i-3DNWVhMGI5Y2FiMDIzNGIxMTk2NTJhNWE4-26t-3DSkduWWR0VVZtT0NqSEtyUTR4azg4TDBYWlV5aUg0QStYUlRtUE9XNmtZOD0-3D-26h-3Dc6111619739f4c1cb223cff9ea159e57-26s-3DAVNPUEhUT0NFTkNSWVBUSVYnUwwXV5mw6hjsIyeS9RVCs2KNYuukYR-5FQDER7UMXcrQ&d=DwMFAw&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=BVqwgystsg0YCERq8Eiqf2y54jWy9bfIIQQjAiiGXuA&m=6EI7ZzcxhaAqHmCQsoPcgstuREkvMa1PWKRU22SdpnlJ2Jb70gdXRDw9FEJBN0l_&s=bXV3wnPqkutCPLlQnEOxtOnkzMgm66XHR3JK-sl47dM&e=#carmen.wilson@sanlam.co.za/w4bv16nohbv2hnxl99h902b4qoj715k3cd9lv2h9yfxl1uh3d7jysw6lph4tbr1aax6ypmcg7xfizy3lcujl13l9n3q1uasvnsy7/fc05dd618fc962be67985aa619677e5187605ab62fbdb9658d1b53203e7faed8/hq3fbb1aeo0wv3f4h58hmd8ce /w4bv16nohbv2hnxl99h902b4qoj715k3cd9lv2h9yfxl1uh3d7jysw6lph4tbr1aax6ypmcg7xfizy3lcujl13l9n3q1uasvnsy7/hq3fbb1aeo0wv3f4h58hmd8ce/w4bv16nohbv2hnxl99h902b4qoj715k3cd9lv2h9yfxl1uh3d7jysw6lph4tbr1aax6ypmcg7xfizy3lcujl13l9n3q1uasvnsy7/EWGDL3YFQ86fc05dd618fc962be67985aa619677e5187605ab62fbdb9658d1b53203e7faed8.cdxcf |
| Full analysis: | https://app.any.run/tasks/0f62d4a3-e2d8-440e-8a4e-4ac45b8548d1 |
| Verdict: | Malicious activity |
| Analysis date: | May 15, 2026, 10:50:38 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | B96AC141A4211C02EFBEBD58A07BBC2B |
| SHA1: | 1DF0FE814201DFA699925411ED34C36E35156249 |
| SHA256: | E03F53EC990F828E4EA1A530D2CD534A422ECFD0EC489DD664A6EEA59E4AB8B0 |
| SSDEEP: | 48:5/tTRl9hQ/aCf30UooaC5CxDr1zgZ1Mj1Jv:5/tTRo3zoQ45zgbMRJv |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 572 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --field-trial-handle=5844,i,6481636775096099605,1717020918888745758,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=6096 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 133.0.6943.127 Modules
| |||||||||||||||
| 1296 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --field-trial-handle=6008,i,6481636775096099605,1717020918888745758,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=3360 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 133.0.6943.127 Modules
| |||||||||||||||
| 1352 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --field-trial-handle=6116,i,6481636775096099605,1717020918888745758,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=5784 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 133.0.6943.127 Modules
| |||||||||||||||
| 2156 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --string-annotations --enable-dinosaur-easter-egg-alt-images --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=5 --field-trial-handle=3244,i,6481636775096099605,1717020918888745758,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=3296 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 133.0.6943.127 Modules
| |||||||||||||||
| 2328 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --string-annotations --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=9 --field-trial-handle=5732,i,6481636775096099605,1717020918888745758,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=5508 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 133.0.6943.127 Modules
| |||||||||||||||
| 2364 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --field-trial-handle=3460,i,6481636775096099605,1717020918888745758,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=3520 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 133.0.6943.127 Modules
| |||||||||||||||
| 2532 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --field-trial-handle=3512,i,6481636775096099605,1717020918888745758,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=5580 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 133.0.6943.127 Modules
| |||||||||||||||
| 2648 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --string-annotations --extension-process --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=7 --field-trial-handle=2996,i,6481636775096099605,1717020918888745758,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=4452 /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 133.0.6943.127 Modules
| |||||||||||||||
| 2652 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --field-trial-handle=5308,i,6481636775096099605,1717020918888745758,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=3516 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 133.0.6943.127 Modules
| |||||||||||||||
| 2680 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --field-trial-handle=3476,i,6481636775096099605,1717020918888745758,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=5952 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 133.0.6943.127 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3580 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\ClientCertificates\LOG.old~RFdfd0e.TMP | — | |
MD5:— | SHA256:— | |||
| 3580 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\ClientCertificates\LOG.old | — | |
MD5:— | SHA256:— | |||
| 3580 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old~RFdfd0e.TMP | — | |
MD5:— | SHA256:— | |||
| 3580 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 3580 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old~RFdfd0e.TMP | — | |
MD5:— | SHA256:— | |||
| 3580 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old | — | |
MD5:— | SHA256:— | |||
| 3580 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old~RFdfd1d.TMP | — | |
MD5:— | SHA256:— | |||
| 3580 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 3580 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RFdfd1d.TMP | — | |
MD5:— | SHA256:— | |||
| 3580 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old~RFdfd1d.TMP | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
7684 | chrome.exe | GET | 302 | 52.71.28.102:443 | https://urldefense.proofpoint.com/v2/url?u=https-3A__us-2Deast-2D2.protection.sophos.com_-3Fd-3Dcisco.com-26u-3DaHR0cHM6Ly9zZWN1cmUtd2ViLmNpc2NvLmNvbS8xdEt6U1JTSUNXZW5hOVhRZlhjQlNQQkFhdHFxbEliZVFvbUo5TXV2ZGxlbGFVZlJtSy1wb2l4b0lHT3lMeDU3YVBOc0tGb0w3V0tua3NPbm5PT1pSeGdwWkJ3dW1KZWU2R1hsdzRnYldqNWRwMV96elZoZFJQZU5CbzhWdzJxTjZZaGFid3A0UFB1V1J6R05xZHJlSGx1LU5SbmJTN3ZXcHp0dndHRXRaNF9TU2FrTlJzUnZJQXhJaXlib3QwOVNnQkdnZFRwa3lDMWJVQnAwVG1rUjViOW9nNW1IaEZCUy1yR1JMdDh5M1gzUDNVWllxdXV1YnBWLXdzOGt3UnV0YVhjUkZwMUlYbzJfM0JPYVNyanpWVm5pdEIxVDZUTGdkbDZKcGdyMGNaUFVBbGw0X0hCdk5UVFVLNlIzQ0trdUhhMDI5cjJuYk9fUEdQbkVSb1NTR1ZMZHFiRnAxdGlhblFSazE5TUo3YmJmblI3V0NQRTJTd3JjeWMtWkFUUTZXZENJS2Rid25kMzhMckhNbV9YdWlQZU9UTm9VYngwX3dMM1J0bnZsZ3ZNby9odHRwcyUzQSUyRiUyRnVsdHJhZ3VhcmQuY29tLmF1JTJGbmV3Q2FsY3VsYXRvciUyRm1hdGhz-26i-3DNWVhMGI5Y2FiMDIzNGIxMTk2NTJhNWE4-26t-3DSkduWWR0VVZtT0NqSEtyUTR4azg4TDBYWlV5aUg0QStYUlRtUE9XNmtZOD0-3D-26h-3Dc6111619739f4c1cb223cff9ea159e57-26s-3DAVNPUEhUT0NFTkNSWVBUSVYnUwwXV5mw6hjsIyeS9RVCs2KNYuukYR-5FQDER7UMXcrQ&d=DwMFAw&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=BVqwgystsg0YCERq8Eiqf2y54jWy9bfIIQQjAiiGXuA&m=6EI7ZzcxhaAqHmCQsoPcgstuREkvMa1PWKRU22SdpnlJ2Jb70gdXRDw9FEJBN0l_&s=bXV3wnPqkutCPLlQnEOxtOnkzMgm66XHR3JK-sl47dM&e= | US | — | — | unknown |
7684 | chrome.exe | GET | 302 | 13.33.187.57:443 | https://us-east-2.protection.sophos.com/?d=cisco.com&u=aHR0cHM6Ly9zZWN1cmUtd2ViLmNpc2NvLmNvbS8xdEt6U1JTSUNXZW5hOVhRZlhjQlNQQkFhdHFxbEliZVFvbUo5TXV2ZGxlbGFVZlJtSy1wb2l4b0lHT3lMeDU3YVBOc0tGb0w3V0tua3NPbm5PT1pSeGdwWkJ3dW1KZWU2R1hsdzRnYldqNWRwMV96elZoZFJQZU5CbzhWdzJxTjZZaGFid3A0UFB1V1J6R05xZHJlSGx1LU5SbmJTN3ZXcHp0dndHRXRaNF9TU2FrTlJzUnZJQXhJaXlib3QwOVNnQkdnZFRwa3lDMWJVQnAwVG1rUjViOW9nNW1IaEZCUy1yR1JMdDh5M1gzUDNVWllxdXV1YnBWLXdzOGt3UnV0YVhjUkZwMUlYbzJfM0JPYVNyanpWVm5pdEIxVDZUTGdkbDZKcGdyMGNaUFVBbGw0X0hCdk5UVFVLNlIzQ0trdUhhMDI5cjJuYk9fUEdQbkVSb1NTR1ZMZHFiRnAxdGlhblFSazE5TUo3YmJmblI3V0NQRTJTd3JjeWMtWkFUUTZXZENJS2Rid25kMzhMckhNbV9YdWlQZU9UTm9VYngwX3dMM1J0bnZsZ3ZNby9odHRwcyUzQSUyRiUyRnVsdHJhZ3VhcmQuY29tLmF1JTJGbmV3Q2FsY3VsYXRvciUyRm1hdGhz&i=NWVhMGI5Y2FiMDIzNGIxMTk2NTJhNWE4&t=SkduWWR0VVZtT0NqSEtyUTR4azg4TDBYWlV5aUg0QStYUlRtUE9XNmtZOD0=&h=c6111619739f4c1cb223cff9ea159e57&s=AVNPUEhUT0NFTkNSWVBUSVYnUwwXV5mw6hjsIyeS9RVCs2KNYuukYR_QDER7UMXcrQ | US | — | — | unknown |
7684 | chrome.exe | GET | 302 | 146.112.255.69:443 | https://secure-web.cisco.com/1tKzSRSICWena9XQfXcBSPBAatqqlIbeQomJ9MuvdlelaUfRmK-poixoIGOyLx57aPNsKFoL7WKnksOnnOOZRxgpZBwumJee6GXlw4gbWj5dp1_zzVhdRPeNBo8Vw2qN6Yhabwp4PPuWRzGNqdreHlu-NRnbS7vWpztvwGEtZ4_SSakNRsRvIAxIiybot09SgBGgdTpkyC1bUBp0TmkR5b9og5mHhFBS-rGRLt8y3X3P3UZYquuubpV-ws8kwRutaXcRFp1IXo2_3BOaSrjzVVnitB1T6TLgdl6Jpgr0cZPUAll4_HBvNTTUK6R3CKkuHa029r2nbO_PGPnERoSSGVLdqbFp1tianQRk19MJ7bbfnR7WCPE2Swrcyc-ZATQ6WdCIKdbwnd38LrHMm_XuiPeOTNoUbx0_wL3RtnvlgvMo/https%3A%2F%2Fultraguard.com.au%2FnewCalculator%2Fmaths | US | — | — | whitelisted |
— | — | GET | 200 | 23.11.40.157:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAjTxtAB8my1oj8MfWpz%2F7Y%3D | NL | binary | 313 b | whitelisted |
5276 | MoUsoCoreWorker.exe | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | US | binary | 814 b | whitelisted |
7684 | chrome.exe | GET | 200 | 142.251.20.139:80 | http://clients2.google.com/time/1/current?cup2key=8:fItOaJDmxp8j63DcyJFuKHzGH6kZip8HqLMV5_xewvg&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 | US | text | 106 b | whitelisted |
— | — | GET | 200 | 204.79.197.203:80 | http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQ3L3%2F%2Fa6ADK8NraY2GXzVaYrHG4AQUb6t%2B2v%2BXQ3LsO2d33oJhNYhHQoUCEzMAAAAGb6JMMcOVb6sAAAAAAAY%3D | US | binary | 960 b | whitelisted |
7684 | chrome.exe | GET | 200 | 142.251.14.95:443 | https://safebrowsingohttpgateway.googleapis.com/v1/ohttp/hpkekeyconfig?key=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE | US | binary | 41 b | whitelisted |
7684 | chrome.exe | GET | 200 | 192.178.183.101:443 | https://clientservices.googleapis.com/chrome-variations/seed?osname=win&channel=stable&milestone=133 | US | compressed | 92.0 Kb | whitelisted |
7684 | chrome.exe | POST | 200 | 142.251.127.84:443 | https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard | US | text | 17 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 48.209.138.168:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4 | System | 192.168.100.255:137 | — | Not routed | — | whitelisted |
— | — | 128.24.231.64:443 | activation-v2.sls.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
5276 | MoUsoCoreWorker.exe | 23.216.77.9:80 | crl.microsoft.com | AKAMAI-ASN1 | NL | whitelisted |
5276 | MoUsoCoreWorker.exe | 88.221.169.152:80 | www.microsoft.com | AKAMAI-AS | US | whitelisted |
7984 | svchost.exe | 48.209.138.168:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
5532 | SearchApp.exe | 2.16.241.219:443 | www.bing.com | AKAMAI-ASN1 | NL | whitelisted |
— | — | 23.11.40.157:80 | ocsp.digicert.com | AKAMAI-AMS | NL | whitelisted |
— | — | 204.79.197.203:80 | oneocsp.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4 | System | 192.168.100.255:138 | — | Not routed | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
activation-v2.sls.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
oneocsp.microsoft.com |
| whitelisted |
clients2.google.com |
| whitelisted |
safebrowsingohttpgateway.googleapis.com |
| whitelisted |
clientservices.googleapis.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
7984 | svchost.exe | Unknown Traffic | ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW) |