File name:

DupeToolkit.jar

Full analysis: https://app.any.run/tasks/65eae0a2-05dd-496c-84cf-ab5ba42f80f5
Verdict: Malicious activity
Analysis date: August 01, 2025, 02:13:07
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
java
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

EE31E658AB9026A155B2023063315002

SHA1:

B8C1DB6C7C30A9C93ED9C3D654EAF702011E20D6

SHA256:

E57B45B9F3631FD9F6F9451D8AA436B1C7B56B75F8928F2A974C32E84C481A6B

SSDEEP:

1536:k7/sySaNn0uP474r32jkGvmARWDk/iQICnfeg2:i0yd2uP4USjkrAcDLQICfeg2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • OneDriveSetup.exe (PID: 620)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • OneDrive.exe (PID: 6312)
      • OneDriveSetup.exe (PID: 620)
      • OneDriveSetup.exe (PID: 3392)
    • Creates/Modifies COM task schedule object

      • OneDrive.exe (PID: 6312)
      • OneDriveSetup.exe (PID: 620)
    • Application launched itself

      • OneDriveSetup.exe (PID: 3392)
    • Process drops legitimate windows executable

      • OneDriveSetup.exe (PID: 620)
    • Executable content was dropped or overwritten

      • OneDriveSetup.exe (PID: 620)
    • The process creates files with name similar to system file names

      • OneDriveSetup.exe (PID: 620)
    • The process drops C-runtime libraries

      • OneDriveSetup.exe (PID: 620)
    • Creates a software uninstall entry

      • OneDriveSetup.exe (PID: 620)
  • INFO

    • Create files in a temporary directory

      • javaw.exe (PID: 3788)
      • OneDrive.exe (PID: 6312)
      • svchost.exe (PID: 5988)
      • OneDriveSetup.exe (PID: 620)
    • Checks supported languages

      • javaw.exe (PID: 3788)
      • OneDrive.exe (PID: 6312)
      • OneDriveSetup.exe (PID: 3392)
      • OneDriveSetup.exe (PID: 620)
      • FileSyncConfig.exe (PID: 7060)
      • OneDrive.exe (PID: 3028)
    • Manual execution by a user

      • OneDrive.exe (PID: 6312)
    • Reads the machine GUID from the registry

      • OneDrive.exe (PID: 6312)
      • OneDriveSetup.exe (PID: 620)
      • OneDriveSetup.exe (PID: 3392)
      • OneDrive.exe (PID: 3028)
    • Reads the computer name

      • OneDrive.exe (PID: 6312)
      • OneDriveSetup.exe (PID: 3392)
      • OneDriveSetup.exe (PID: 620)
      • OneDrive.exe (PID: 3028)
    • Application based on Java

      • javaw.exe (PID: 3788)
    • Reads the time zone

      • OneDrive.exe (PID: 6312)
    • Creates files or folders in the user directory

      • OneDrive.exe (PID: 6312)
      • OneDriveSetup.exe (PID: 3392)
      • OneDriveSetup.exe (PID: 620)
      • OneDrive.exe (PID: 3028)
    • Checks proxy server information

      • OneDrive.exe (PID: 6312)
      • slui.exe (PID: 2140)
    • Reads CPU info

      • OneDrive.exe (PID: 6312)
    • Process checks computer location settings

      • OneDrive.exe (PID: 6312)
      • OneDriveSetup.exe (PID: 620)
    • Reads the software policy settings

      • OneDrive.exe (PID: 6312)
      • OneDriveSetup.exe (PID: 620)
      • OneDriveSetup.exe (PID: 3392)
      • slui.exe (PID: 2140)
    • Creates files in the program directory

      • javaw.exe (PID: 3788)
      • SearchIndexer.exe (PID: 3880)
    • The sample compiled with portuguese language support

      • OneDriveSetup.exe (PID: 620)
    • The sample compiled with english language support

      • OneDriveSetup.exe (PID: 620)
    • The sample compiled with chinese language support

      • OneDriveSetup.exe (PID: 620)
    • Reads Environment values

      • OneDrive.exe (PID: 3028)
    • Launching a file from a Registry key

      • OneDriveSetup.exe (PID: 620)
    • Reads security settings of Internet Explorer

      • SearchProtocolHost.exe (PID: 5576)
    • Executes as Windows Service

      • SearchIndexer.exe (PID: 3880)
    • Reads Microsoft Office registry keys

      • OpenWith.exe (PID: 5744)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.jar | Java Archive (78.3)
.zip | ZIP compressed archive (21.6)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 1980:01:01 00:00:00
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: assets/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
160
Monitored processes
17
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start javaw.exe no specs icacls.exe no specs conhost.exe no specs slui.exe rundll32.exe no specs onedrive.exe svchost.exe onedrivesetup.exe no specs onedrivesetup.exe filesyncconfig.exe no specs onedrive.exe no specs filecoauth.exe no specs Indexer Status Update Object no specs searchindexer.exe no specs searchprotocolhost.exe no specs searchfilterhost.exe no specs openwith.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
472"C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\FileCoAuth.exe" -EmbeddingC:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\FileCoAuth.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneDriveFile Co-Authoring Executable
Exit code:
0
Version:
21.220.1024.0005
Modules
Images
c:\users\admin\appdata\local\microsoft\onedrive\21.220.1024.0005\filecoauth.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
620C:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe /update /restart /updateSource:ODU /peruser /childprocess C:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe
OneDriveSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneDrive (32 bit) Setup
Exit code:
0
Version:
21.220.1024.0005
Modules
Images
c:\users\admin\appdata\local\microsoft\onedrive\update\onedrivesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
2120\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeicacls.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2140C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2716C:\WINDOWS\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)MC:\Windows\System32\icacls.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
3028 /updateInstalled /backgroundC:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exeOneDriveSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneDrive
Exit code:
2147943660
Version:
21.220.1024.0005
Modules
Images
c:\users\admin\appdata\local\microsoft\onedrive\onedrive.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
3108C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
3392"C:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" /update /restart /updateSource:ODU C:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exeOneDrive.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneDrive (32 bit) Setup
Exit code:
0
Version:
21.220.1024.0005
Modules
Images
c:\users\admin\appdata\local\microsoft\onedrive\update\onedrivesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
3788"C:\Program Files\Java\jre1.8.0_271\bin\javaw.exe" -jar C:\Users\admin\AppData\Local\Temp\DupeToolkit.jarC:\Program Files\Java\jre1.8.0_271\bin\javaw.exeexplorer.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java(TM) Platform SE binary
Exit code:
1
Version:
8.0.2710.9
Modules
Images
c:\program files\java\jre1.8.0_271\bin\javaw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
3880C:\WINDOWS\system32\SearchIndexer.exe /EmbeddingC:\Windows\System32\SearchIndexer.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Indexer
Version:
7.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\searchindexer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
Total events
23 311
Read events
22 360
Write events
379
Delete events
572

Modification events

(PID) Process:(6312) OneDrive.exeKey:HKEY_CLASSES_ROOT\WOW6432Node\Interface\{466F31F7-9892-477E-B189-FA5C59DE3603}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(6312) OneDrive.exeKey:HKEY_CLASSES_ROOT\Interface\{869BDA08-7ACF-42B8-91AE-4D8D597C0B33}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(6312) OneDrive.exeKey:HKEY_CLASSES_ROOT\WOW6432Node\Interface\{869BDA08-7ACF-42B8-91AE-4D8D597C0B33}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(6312) OneDrive.exeKey:HKEY_CLASSES_ROOT\Interface\{679EC955-75AA-4FB2-A7ED-8C0152ECF409}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(6312) OneDrive.exeKey:HKEY_CLASSES_ROOT\WOW6432Node\Interface\{679EC955-75AA-4FB2-A7ED-8C0152ECF409}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(6312) OneDrive.exeKey:HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\InProcServer32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(6312) OneDrive.exeKey:HKEY_CLASSES_ROOT\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\InProcServer32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(6312) OneDrive.exeKey:HKEY_CLASSES_ROOT\odopen\DefaultIcon
Operation:delete keyName:(default)
Value:
(PID) Process:(6312) OneDrive.exeKey:HKEY_CLASSES_ROOT\odopen\shell\open\command
Operation:delete keyName:(default)
Value:
(PID) Process:(6312) OneDrive.exeKey:HKEY_CLASSES_ROOT\odopen\shell\open
Operation:delete keyName:(default)
Value:
Executable files
221
Suspicious files
75
Text files
407
Unknown types
11

Dropped files

PID
Process
Filename
Type
5988svchost.exeC:\Users\admin\AppData\Local\Temp\BIT54A9.tmp
MD5:
SHA256:
5988svchost.exeC:\Users\admin\AppData\Local\Temp\wct548A.tmp
MD5:
SHA256:
6312OneDrive.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe
MD5:
SHA256:
620OneDriveSetup.exeC:\Users\admin\AppData\Local\Temp\tmp61F7.tmp
MD5:
SHA256:
6312OneDrive.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Personal\telemetryCache.otc.session-journalbinary
MD5:52072F19C559D0E9DF2D2E8975EF9CBA
SHA256:6418F8B2B06C1041783CE4EBCB0A756B588A55523A661BC598088D236ED61A52
6312OneDrive.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Personal\TraceArchive.0304.0013-36.etlabr
MD5:97596EEBD1886A7637AEC1F4739959FC
SHA256:43A342C94BDA9B236D3D1F45711C0B2FB9FA179CF7E0C9252E6DB0EE1930811F
6312OneDrive.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9binary
MD5:A3ED9C811C543EA6F5B36A0AF26649AD
SHA256:9A8991432A5121D5B828D6F8F0972E0520D04F37C893A4280A11F0B7FDA24912
6312OneDrive.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\E4DJRUXW\PreSignInSettingsConfig[1].jsonbinary
MD5:E516A60BC980095E8D156B1A99AB5EEE
SHA256:543796A1B343B4EBC0285D89CB8EB70667AC7B513DA37495E38003704E9D88D7
6312OneDrive.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9der
MD5:FA762B161F45FF06C65404A6A36252D6
SHA256:0099EDFE2F9DA7770FF749D177DB9D7C982F7C4A95FFC3D749FDC87AB5EE7451
6312OneDrive.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Personal\SyncEngine-2025-08-01.0214.6312.1.aodlbinary
MD5:28DCA2FF4B34B5A52A2E59DF202A6ED3
SHA256:33BACCB7296F1ED1F995FC77A23049F261CF391AC0388F9E8DD161F8C17B7F94
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
31
DNS requests
25
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2940
svchost.exe
GET
200
23.3.109.48:80
http://x1.c.lencr.org/
unknown
whitelisted
6312
OneDrive.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6312
OneDrive.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
1868
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
1268
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1036
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
1036
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1268
svchost.exe
GET
200
23.216.77.42:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2528
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6292
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
23.216.77.42:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
1268
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5944
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2528
svchost.exe
20.190.160.131:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.124.78.146
  • 51.104.136.2
whitelisted
google.com
  • 216.58.206.78
whitelisted
crl.microsoft.com
  • 23.216.77.42
  • 23.216.77.28
  • 23.216.77.6
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 95.101.149.131
whitelisted
login.live.com
  • 20.190.160.131
  • 20.190.160.67
  • 20.190.160.4
  • 20.190.160.64
  • 40.126.32.74
  • 40.126.32.134
  • 40.126.32.133
  • 40.126.32.68
  • 40.126.32.72
  • 20.190.160.17
  • 20.190.160.2
  • 40.126.32.136
  • 20.190.160.132
whitelisted
ocsp.digicert.com
  • 2.17.190.73
  • 184.30.131.245
whitelisted
slscr.update.microsoft.com
  • 74.178.240.61
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted
self.events.data.microsoft.com
  • 13.89.178.26
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted

Threats

No threats detected
No debug info