File name:

DupeToolkit.jar

Full analysis: https://app.any.run/tasks/65eae0a2-05dd-496c-84cf-ab5ba42f80f5
Verdict: Malicious activity
Analysis date: August 01, 2025, 02:13:07
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
java
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

EE31E658AB9026A155B2023063315002

SHA1:

B8C1DB6C7C30A9C93ED9C3D654EAF702011E20D6

SHA256:

E57B45B9F3631FD9F6F9451D8AA436B1C7B56B75F8928F2A974C32E84C481A6B

SSDEEP:

1536:k7/sySaNn0uP474r32jkGvmARWDk/iQICnfeg2:i0yd2uP4USjkrAcDLQICfeg2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • OneDriveSetup.exe (PID: 620)
  • SUSPICIOUS

    • Creates/Modifies COM task schedule object

      • OneDrive.exe (PID: 6312)
      • OneDriveSetup.exe (PID: 620)
    • Reads security settings of Internet Explorer

      • OneDrive.exe (PID: 6312)
      • OneDriveSetup.exe (PID: 3392)
      • OneDriveSetup.exe (PID: 620)
    • Application launched itself

      • OneDriveSetup.exe (PID: 3392)
    • Process drops legitimate windows executable

      • OneDriveSetup.exe (PID: 620)
    • The process creates files with name similar to system file names

      • OneDriveSetup.exe (PID: 620)
    • Executable content was dropped or overwritten

      • OneDriveSetup.exe (PID: 620)
    • The process drops C-runtime libraries

      • OneDriveSetup.exe (PID: 620)
    • Creates a software uninstall entry

      • OneDriveSetup.exe (PID: 620)
  • INFO

    • Checks supported languages

      • javaw.exe (PID: 3788)
      • OneDrive.exe (PID: 6312)
      • OneDriveSetup.exe (PID: 3392)
      • OneDriveSetup.exe (PID: 620)
      • OneDrive.exe (PID: 3028)
      • FileSyncConfig.exe (PID: 7060)
    • Application based on Java

      • javaw.exe (PID: 3788)
    • Create files in a temporary directory

      • javaw.exe (PID: 3788)
      • OneDrive.exe (PID: 6312)
      • svchost.exe (PID: 5988)
      • OneDriveSetup.exe (PID: 620)
    • Manual execution by a user

      • OneDrive.exe (PID: 6312)
    • Creates files in the program directory

      • javaw.exe (PID: 3788)
      • SearchIndexer.exe (PID: 3880)
    • Creates files or folders in the user directory

      • OneDrive.exe (PID: 6312)
      • OneDriveSetup.exe (PID: 3392)
      • OneDriveSetup.exe (PID: 620)
      • OneDrive.exe (PID: 3028)
    • Reads the machine GUID from the registry

      • OneDrive.exe (PID: 6312)
      • OneDriveSetup.exe (PID: 620)
      • OneDriveSetup.exe (PID: 3392)
      • OneDrive.exe (PID: 3028)
    • Reads the time zone

      • OneDrive.exe (PID: 6312)
    • Reads CPU info

      • OneDrive.exe (PID: 6312)
    • Reads the computer name

      • OneDrive.exe (PID: 6312)
      • OneDriveSetup.exe (PID: 3392)
      • OneDriveSetup.exe (PID: 620)
      • OneDrive.exe (PID: 3028)
    • Checks proxy server information

      • OneDrive.exe (PID: 6312)
      • slui.exe (PID: 2140)
    • Process checks computer location settings

      • OneDrive.exe (PID: 6312)
      • OneDriveSetup.exe (PID: 620)
    • Reads the software policy settings

      • OneDrive.exe (PID: 6312)
      • OneDriveSetup.exe (PID: 620)
      • OneDriveSetup.exe (PID: 3392)
      • slui.exe (PID: 2140)
    • The sample compiled with portuguese language support

      • OneDriveSetup.exe (PID: 620)
    • The sample compiled with english language support

      • OneDriveSetup.exe (PID: 620)
    • The sample compiled with chinese language support

      • OneDriveSetup.exe (PID: 620)
    • Reads Environment values

      • OneDrive.exe (PID: 3028)
    • Launching a file from a Registry key

      • OneDriveSetup.exe (PID: 620)
    • Executes as Windows Service

      • SearchIndexer.exe (PID: 3880)
    • Reads security settings of Internet Explorer

      • SearchProtocolHost.exe (PID: 5576)
    • Reads Microsoft Office registry keys

      • OpenWith.exe (PID: 5744)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.jar | Java Archive (78.3)
.zip | ZIP compressed archive (21.6)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 1980:01:01 00:00:00
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: assets/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
160
Monitored processes
17
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start javaw.exe no specs icacls.exe no specs conhost.exe no specs slui.exe rundll32.exe no specs onedrive.exe svchost.exe onedrivesetup.exe no specs onedrivesetup.exe filesyncconfig.exe no specs onedrive.exe no specs filecoauth.exe no specs Indexer Status Update Object no specs searchindexer.exe no specs searchprotocolhost.exe no specs searchfilterhost.exe no specs openwith.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
472"C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\FileCoAuth.exe" -EmbeddingC:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\FileCoAuth.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneDriveFile Co-Authoring Executable
Exit code:
0
Version:
21.220.1024.0005
Modules
Images
c:\users\admin\appdata\local\microsoft\onedrive\21.220.1024.0005\filecoauth.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
620C:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe /update /restart /updateSource:ODU /peruser /childprocess C:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe
OneDriveSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneDrive (32 bit) Setup
Exit code:
0
Version:
21.220.1024.0005
Modules
Images
c:\users\admin\appdata\local\microsoft\onedrive\update\onedrivesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
2120\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeicacls.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2140C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2716C:\WINDOWS\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)MC:\Windows\System32\icacls.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
3028 /updateInstalled /backgroundC:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exeOneDriveSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneDrive
Exit code:
2147943660
Version:
21.220.1024.0005
Modules
Images
c:\users\admin\appdata\local\microsoft\onedrive\onedrive.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
3108C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
3392"C:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" /update /restart /updateSource:ODU C:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exeOneDrive.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneDrive (32 bit) Setup
Exit code:
0
Version:
21.220.1024.0005
Modules
Images
c:\users\admin\appdata\local\microsoft\onedrive\update\onedrivesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
3788"C:\Program Files\Java\jre1.8.0_271\bin\javaw.exe" -jar C:\Users\admin\AppData\Local\Temp\DupeToolkit.jarC:\Program Files\Java\jre1.8.0_271\bin\javaw.exeexplorer.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java(TM) Platform SE binary
Exit code:
1
Version:
8.0.2710.9
Modules
Images
c:\program files\java\jre1.8.0_271\bin\javaw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
3880C:\WINDOWS\system32\SearchIndexer.exe /EmbeddingC:\Windows\System32\SearchIndexer.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Indexer
Version:
7.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\searchindexer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
Total events
23 311
Read events
22 360
Write events
379
Delete events
572

Modification events

(PID) Process:(6312) OneDrive.exeKey:HKEY_CLASSES_ROOT\WOW6432Node\Interface\{466F31F7-9892-477E-B189-FA5C59DE3603}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(6312) OneDrive.exeKey:HKEY_CLASSES_ROOT\Interface\{869BDA08-7ACF-42B8-91AE-4D8D597C0B33}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(6312) OneDrive.exeKey:HKEY_CLASSES_ROOT\WOW6432Node\Interface\{869BDA08-7ACF-42B8-91AE-4D8D597C0B33}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(6312) OneDrive.exeKey:HKEY_CLASSES_ROOT\Interface\{679EC955-75AA-4FB2-A7ED-8C0152ECF409}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(6312) OneDrive.exeKey:HKEY_CLASSES_ROOT\WOW6432Node\Interface\{679EC955-75AA-4FB2-A7ED-8C0152ECF409}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(6312) OneDrive.exeKey:HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\InProcServer32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(6312) OneDrive.exeKey:HKEY_CLASSES_ROOT\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\InProcServer32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(6312) OneDrive.exeKey:HKEY_CLASSES_ROOT\odopen\DefaultIcon
Operation:delete keyName:(default)
Value:
(PID) Process:(6312) OneDrive.exeKey:HKEY_CLASSES_ROOT\odopen\shell\open\command
Operation:delete keyName:(default)
Value:
(PID) Process:(6312) OneDrive.exeKey:HKEY_CLASSES_ROOT\odopen\shell\open
Operation:delete keyName:(default)
Value:
Executable files
221
Suspicious files
75
Text files
407
Unknown types
11

Dropped files

PID
Process
Filename
Type
5988svchost.exeC:\Users\admin\AppData\Local\Temp\BIT54A9.tmp
MD5:
SHA256:
5988svchost.exeC:\Users\admin\AppData\Local\Temp\wct548A.tmp
MD5:
SHA256:
6312OneDrive.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe
MD5:
SHA256:
620OneDriveSetup.exeC:\Users\admin\AppData\Local\Temp\tmp61F7.tmp
MD5:
SHA256:
6312OneDrive.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Personal\telemetryCache.otc.sessionsqlite
MD5:580BD824DEBBA908591408D7A5A3D01F
SHA256:B3218FF93047231A34C6962C758A36D412C2EB928C33F7EE537023EB6E489974
6312OneDrive.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Personal\TraceArchive.0304.0013-36.etlabr
MD5:97596EEBD1886A7637AEC1F4739959FC
SHA256:43A342C94BDA9B236D3D1F45711C0B2FB9FA179CF7E0C9252E6DB0EE1930811F
6312OneDrive.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Personal\telemetryCache.otc.session-journalbinary
MD5:52072F19C559D0E9DF2D2E8975EF9CBA
SHA256:6418F8B2B06C1041783CE4EBCB0A756B588A55523A661BC598088D236ED61A52
6312OneDrive.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9der
MD5:FA762B161F45FF06C65404A6A36252D6
SHA256:0099EDFE2F9DA7770FF749D177DB9D7C982F7C4A95FFC3D749FDC87AB5EE7451
6312OneDrive.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:F2E9EF839FA69FC43B547824F1352F5F
SHA256:B20A97C0E1B56CF722C42188BFC8ECC33D0CEFAD5D52FD3401F7E221570717DB
6312OneDrive.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9binary
MD5:A3ED9C811C543EA6F5B36A0AF26649AD
SHA256:9A8991432A5121D5B828D6F8F0972E0520D04F37C893A4280A11F0B7FDA24912
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
31
DNS requests
25
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.216.77.42:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6312
OneDrive.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1868
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
6312
OneDrive.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
2528
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2940
svchost.exe
GET
200
23.3.109.48:80
http://x1.c.lencr.org/
unknown
whitelisted
1036
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1036
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6292
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
23.216.77.42:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
1268
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5944
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2528
svchost.exe
20.190.160.131:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.124.78.146
  • 51.104.136.2
whitelisted
google.com
  • 216.58.206.78
whitelisted
crl.microsoft.com
  • 23.216.77.42
  • 23.216.77.28
  • 23.216.77.6
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 95.101.149.131
whitelisted
login.live.com
  • 20.190.160.131
  • 20.190.160.67
  • 20.190.160.4
  • 20.190.160.64
  • 40.126.32.74
  • 40.126.32.134
  • 40.126.32.133
  • 40.126.32.68
  • 40.126.32.72
  • 20.190.160.17
  • 20.190.160.2
  • 40.126.32.136
  • 20.190.160.132
whitelisted
ocsp.digicert.com
  • 2.17.190.73
  • 184.30.131.245
whitelisted
slscr.update.microsoft.com
  • 74.178.240.61
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted
self.events.data.microsoft.com
  • 13.89.178.26
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted

Threats

No threats detected
No debug info