File name:

DirLister.v2.beta4.zip

Full analysis: https://app.any.run/tasks/2b77d2df-b0ba-4b01-a021-efa986cd5600
Verdict: Malicious activity
Analysis date: October 10, 2024, 18:15:38
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

A8DDF9CD19C4290D7F8254130B9C2A06

SHA1:

5A2126C9C1742B7D8C5D6934338D552D630CD04C

SHA256:

E3FA43635F1A8C1AD6E6222D2F2F16821CEB606D6C2CE1A157DA7E57BAC074E3

SSDEEP:

3072:IxTguSBa0b3fsV4VNRDvDgnrQxrJh+F/6HZjYRKGGBANtoOa2wmQHJ:Ilx0jsVaNRzEnw1wF/6iKGdyh2op

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 608)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • DirLister.exe (PID: 4088)
      • DirLister.exe (PID: 7044)
      • DirLister.exe (PID: 6360)
      • DirLister33.exe (PID: 1580)
    • Sets XML DOM element text (SCRIPT)

      • splwow64.exe (PID: 2796)
    • Opens a file (MACROS)

      • EXCEL.EXE (PID: 6100)
    • Reads data from a file (MACROS)

      • EXCEL.EXE (PID: 6100)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 7112)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 7112)
      • DirLister.exe (PID: 4088)
      • DirLister.exe (PID: 7044)
      • DirLister.exe (PID: 6360)
      • DirLister33.exe (PID: 1580)
      • EXCEL.EXE (PID: 6100)
    • Manual execution by a user

      • DirLister.exe (PID: 4088)
      • WinRAR.exe (PID: 7112)
      • DirLister.exe (PID: 7044)
      • DirLister33.exe (PID: 1580)
      • DirLister.exe (PID: 6360)
    • Checks supported languages

      • DirLister.exe (PID: 4088)
      • DirLister.exe (PID: 7044)
      • DirLister.exe (PID: 6360)
      • DirLister33.exe (PID: 1580)
    • Reads the computer name

      • DirLister.exe (PID: 4088)
      • DirLister.exe (PID: 7044)
      • DirLister.exe (PID: 6360)
      • DirLister33.exe (PID: 1580)
    • Reads the machine GUID from the registry

      • DirLister.exe (PID: 4088)
      • DirLister.exe (PID: 7044)
      • DirLister33.exe (PID: 1580)
      • DirLister.exe (PID: 6360)
    • Creates files or folders in the user directory

      • DirLister.exe (PID: 4088)
      • DirLister.exe (PID: 7044)
      • DirLister.exe (PID: 6360)
      • DirLister33.exe (PID: 1580)
    • Reads the software policy settings

      • slui.exe (PID: 7020)
      • slui.exe (PID: 3912)
    • Process checks computer location settings

      • DirLister33.exe (PID: 1580)
    • Checks proxy server information

      • slui.exe (PID: 3912)
    • Reads security settings of Internet Explorer

      • splwow64.exe (PID: 2796)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2020:03:18 19:15:58
ZipCRC: 0x87a55c19
ZipCompressedSize: 93203
ZipUncompressedSize: 238592
ZipFileName: DirLister.Core.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
154
Monitored processes
12
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs sppextcomobj.exe no specs slui.exe winrar.exe rundll32.exe no specs dirlister.exe no specs slui.exe dirlister.exe no specs dirlister.exe no specs dirlister33.exe no specs excel.exe splwow64.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
608"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\DirLister.v2.beta4.zipC:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1580"C:\Users\admin\Desktop\DirLister.v2.beta4\DirLister33.exe" C:\Users\admin\Desktop\DirLister.v2.beta4\DirLister33.exeexplorer.exe
User:
admin
Company:
DirLister
Integrity Level:
MEDIUM
Description:
DirLister.UI
Version:
2.0.0.0
Modules
Images
c:\users\admin\desktop\dirlister.v2.beta4\dirlister33.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
2796C:\WINDOWS\splwow64.exe 8192C:\Windows\splwow64.exeEXCEL.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Print driver host for applications
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\splwow64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
3912C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4088"C:\Users\admin\Desktop\DirLister.v2.beta4\DirLister.exe" C:\Users\admin\Desktop\DirLister.v2.beta4\DirLister.exeexplorer.exe
User:
admin
Company:
DirLister
Integrity Level:
MEDIUM
Description:
DirLister.UI
Exit code:
1
Version:
2.0.0.0
Modules
Images
c:\users\admin\desktop\dirlister.v2.beta4\dirlister.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
4568C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
6100"C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\admin\Documents\DirLister.2024-10-10_18-18-20.C_Users_admin_Desktop.csv"C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
DirLister33.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Excel
Version:
16.0.16026.20146
Modules
Images
c:\program files\microsoft office\root\office16\excel.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ole32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\program files\common files\microsoft shared\clicktorun\appvisvsubsystems64.dll
c:\windows\system32\combase.dll
6360"C:\Users\admin\Desktop\DirLister.v2.beta4\DirLister.exe" C:\Users\admin\Desktop\DirLister.v2.beta4\DirLister.exeexplorer.exe
User:
admin
Company:
DirLister
Integrity Level:
MEDIUM
Description:
DirLister.UI
Exit code:
0
Version:
2.0.0.0
Modules
Images
c:\users\admin\desktop\dirlister.v2.beta4\dirlister.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
6912C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
7020"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
12 353
Read events
12 055
Write events
271
Delete events
27

Modification events

(PID) Process:(608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\DirLister.v2.beta4.zip
(PID) Process:(608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
(PID) Process:(608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
(PID) Process:(608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:psize
Value:
80
Executable files
3
Suspicious files
16
Text files
15
Unknown types
1

Dropped files

PID
Process
Filename
Type
7112WinRAR.exeC:\Users\admin\Desktop\DirLister.v2.beta4\DirLister.exe.configxml
MD5:D15212B3041B7C394439B4BA7FD12E20
SHA256:C16C9A1685C64A9C6955FB09CD41B9073F303889A3A202DC02BD18B13E8CC628
6360DirLister.exeC:\Users\admin\AppData\Local\DirLister\DirLister.exe_Url_wmzfuvc0iaxaknx4kid4bjumx3y3u4np\2.0.0.0\t5tkr2kv.newcfgxml
MD5:DD50D7AB919485471FE5CCE338B90F54
SHA256:17CAD6D96E6AF0BDA797331A1AFFA411F5A9C57B10CB50CC6AE13AE64A4D2010
6100EXCEL.EXEC:\Users\admin\AppData\Local\Microsoft\TokenBroker\Cache\56a61aeb75d8f5be186c26607f4bb213abe7c5ec.tbresbinary
MD5:C44434747EB32CBB8A171107239C0A7F
SHA256:98074B74BAE631C6121B74D42E6760FC1C638ED5C3F85E72EB12BD556461F1DF
1580DirLister33.exeC:\Users\admin\AppData\Local\DirLister\DirLister33.exe_Url_b2ow4vmdjgurvo5pzponsp23f4n3tj52\2.0.0.0\5k3i31ln.newcfgxml
MD5:6731D019515186268456B7D396F6E35E
SHA256:1350B04E3C950280139C3CCE69850021F4D03CB60142A6327E5B34B9095D15CE
6360DirLister.exeC:\Users\admin\AppData\Local\DirLister\DirLister.exe_Url_wmzfuvc0iaxaknx4kid4bjumx3y3u4np\2.0.0.0\user.configxml
MD5:DD50D7AB919485471FE5CCE338B90F54
SHA256:17CAD6D96E6AF0BDA797331A1AFFA411F5A9C57B10CB50CC6AE13AE64A4D2010
6100EXCEL.EXEC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9binary
MD5:E15FED65BAE6F9CC89446C8CA620F215
SHA256:5393AABF67FF2B7FB5332650D2E0F51B79ED31711E82A2D01E1DCB56B09CFA46
1580DirLister33.exeC:\Users\admin\AppData\Local\DirLister\DirLister33.exe_Url_b2ow4vmdjgurvo5pzponsp23f4n3tj52\2.0.0.0\itil5whq.newcfgxml
MD5:6731D019515186268456B7D396F6E35E
SHA256:1350B04E3C950280139C3CCE69850021F4D03CB60142A6327E5B34B9095D15CE
1580DirLister33.exeC:\Users\admin\AppData\Local\DirLister\DirLister33.exe_Url_b2ow4vmdjgurvo5pzponsp23f4n3tj52\2.0.0.0\user.configxml
MD5:6731D019515186268456B7D396F6E35E
SHA256:1350B04E3C950280139C3CCE69850021F4D03CB60142A6327E5B34B9095D15CE
1580DirLister33.exeC:\Users\admin\Documents\DirLister.2024-10-10_18-18-20.C_Users_admin_Desktop.csvcsv
MD5:C605654D6CC44A3FBE6AFB41519AB18E
SHA256:845E881FB15AC9C0C010BA33CEFC5B67E1B98EFDE23C53DC9DAACF25BAB4630C
1580DirLister33.exeC:\Users\admin\AppData\Local\DirLister\DirLister33.exe_Url_b2ow4vmdjgurvo5pzponsp23f4n3tj52\2.0.0.0\igwkpvxs.newcfgxml
MD5:FA2BF03A9AC2E706224A9F99142537F7
SHA256:7A3E9FC9CB5EEC325F54097DC0DB18EC338EF58C9B635833CC724FE6A500C4C3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
72
DNS requests
33
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.48.23.147:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
2776
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4032
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6024
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6024
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6100
EXCEL.EXE
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6944
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5488
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.48.23.147:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4360
SearchApp.exe
104.126.37.153:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4360
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
6944
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 23.48.23.147
  • 23.48.23.156
  • 23.48.23.143
  • 23.48.23.177
  • 23.48.23.166
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
www.bing.com
  • 104.126.37.153
  • 104.126.37.152
  • 104.126.37.162
  • 104.126.37.163
  • 104.126.37.155
  • 104.126.37.168
  • 104.126.37.171
  • 104.126.37.154
  • 104.126.37.137
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
google.com
  • 142.250.185.110
whitelisted
login.live.com
  • 40.126.32.133
  • 40.126.32.74
  • 40.126.32.76
  • 40.126.32.140
  • 20.190.160.17
  • 40.126.32.72
  • 40.126.32.134
  • 20.190.160.22
whitelisted
th.bing.com
  • 104.126.37.184
  • 104.126.37.131
  • 104.126.37.128
  • 104.126.37.178
  • 104.126.37.146
  • 104.126.37.145
  • 104.126.37.144
  • 104.126.37.137
  • 104.126.37.130
whitelisted
go.microsoft.com
  • 104.96.142.203
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted

Threats

No threats detected
No debug info