File name:

pdf24-creator-installer.exe

Full analysis: https://app.any.run/tasks/1abd9ef1-0688-4ae5-b600-573443b34421
Verdict: Malicious activity
Analysis date: February 21, 2025, 12:46:29
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-doc
delphi
inno
installer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

9AC8560D27B0FFC0DAF6F54974B059D1

SHA1:

A6805E50710D54E952532BF43E0A50AE55A049C6

SHA256:

F62FBA626DADF2B4DF26E92A8E1D358F680BF13B567112A7066F68D91D07D4EC

SSDEEP:

12288:B0mnEV/OX5bWqVVX7pV7JYpopr+wCarSMadLVAy3Cy8RuH6DLcywRBflHuN5DU:B0mnEVsbrchwady8UM9uN5DU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • pdf24-creator-installer.exe (PID: 3840)
      • pdf24-creator.exe (PID: 2928)
      • pdf24-creator.exe (PID: 1400)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • pdf24-creator-installer.exe (PID: 3840)
      • pdf24-creator.tmp (PID: 4804)
      • pdf24-creator.tmp (PID: 1916)
    • Checks Windows Trust Settings

      • pdf24-creator-installer.exe (PID: 3840)
    • There is functionality for taking screenshot (YARA)

      • pdf24-creator-installer.exe (PID: 3840)
    • Executable content was dropped or overwritten

      • pdf24-creator.exe (PID: 2928)
      • pdf24-creator.exe (PID: 1400)
      • pdf24-creator.tmp (PID: 1916)
    • Uses WMIC.EXE to obtain data on processes

      • pdf24-creator.tmp (PID: 1916)
    • Stops a currently running service

      • sc.exe (PID: 6056)
    • Reads the Windows owner or organization settings

      • pdf24-creator.tmp (PID: 1916)
    • The process drops C-runtime libraries

      • pdf24-creator.tmp (PID: 1916)
    • Process drops legitimate windows executable

      • pdf24-creator.tmp (PID: 1916)
  • INFO

    • Checks supported languages

      • pdf24-creator-installer.exe (PID: 3840)
      • pdf24-creator.exe (PID: 2928)
      • pdf24-creator.tmp (PID: 4804)
      • pdf24-creator.tmp (PID: 1916)
      • pdf24-creator.exe (PID: 1400)
    • The sample compiled with english language support

      • pdf24-creator-installer.exe (PID: 3840)
      • pdf24-creator.tmp (PID: 1916)
    • Reads the machine GUID from the registry

      • pdf24-creator-installer.exe (PID: 3840)
    • Checks proxy server information

      • pdf24-creator-installer.exe (PID: 3840)
    • Reads the computer name

      • pdf24-creator-installer.exe (PID: 3840)
      • pdf24-creator.tmp (PID: 4804)
      • pdf24-creator.exe (PID: 1400)
      • pdf24-creator.tmp (PID: 1916)
    • Creates files or folders in the user directory

      • pdf24-creator-installer.exe (PID: 3840)
    • Reads the software policy settings

      • pdf24-creator-installer.exe (PID: 3840)
    • Create files in a temporary directory

      • pdf24-creator-installer.exe (PID: 3840)
      • pdf24-creator.exe (PID: 2928)
      • pdf24-creator.exe (PID: 1400)
      • pdf24-creator.tmp (PID: 1916)
    • Process checks computer location settings

      • pdf24-creator-installer.exe (PID: 3840)
      • pdf24-creator.tmp (PID: 4804)
      • pdf24-creator.tmp (PID: 1916)
    • Detects InnoSetup installer (YARA)

      • pdf24-creator.exe (PID: 2928)
      • pdf24-creator.tmp (PID: 4804)
      • pdf24-creator.tmp (PID: 1916)
      • pdf24-creator.exe (PID: 1400)
    • Reads security settings of Internet Explorer

      • WMIC.exe (PID: 2624)
      • WMIC.exe (PID: 1292)
      • WMIC.exe (PID: 2084)
    • Compiled with Borland Delphi (YARA)

      • pdf24-creator.exe (PID: 2928)
      • pdf24-creator.exe (PID: 1400)
      • pdf24-creator.tmp (PID: 4804)
      • pdf24-creator.tmp (PID: 1916)
    • Creates files in the program directory

      • pdf24-creator.tmp (PID: 1916)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:01:15 11:46:15+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 14.42
CodeSize: 348160
InitializedDataSize: 306688
UninitializedDataSize: -
EntryPoint: 0x2e1c4
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileVersion: 1.0.0
ProductVersion: 1.0.0
CompanyName: geek software GmbH
ProductName: PDF24 Creator Installer
LegalCopyright: geek software GmbH
InternalName: PDF24 Creator Installer
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
141
Monitored processes
13
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start pdf24-creator-installer.exe pdf24-creator.exe pdf24-creator.tmp no specs pdf24-creator.exe pdf24-creator.tmp sc.exe no specs conhost.exe no specs wmic.exe no specs conhost.exe no specs wmic.exe no specs conhost.exe no specs wmic.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1292"C:\Windows\System32\wbem\WMIC.exe" PROCESS WHERE "Name='pdf24.exe'" CALL TERMINATEC:\Windows\SysWOW64\wbem\WMIC.exepdf24-creator.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
WMI Commandline Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\wbem\wmic.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
1400"C:\Users\admin\AppData\Local\Temp\pdf24-creator.exe" /SPAWNWND=$5035A /NOTIFYWND=$6034E /FromSmallInstaller /SkipLicensePage /SILENTC:\Users\admin\AppData\Local\Temp\pdf24-creator.exe
pdf24-creator.tmp
User:
admin
Company:
geek software GmbH
Integrity Level:
HIGH
Description:
PDF24 Creator
Version:
11.23.0
Modules
Images
c:\users\admin\appdata\local\temp\pdf24-creator.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
1760\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1916"C:\Users\admin\AppData\Local\Temp\is-UUDQ0.tmp\pdf24-creator.tmp" /SL5="$702D6,365614836,835072,C:\Users\admin\AppData\Local\Temp\pdf24-creator.exe" /SPAWNWND=$5035A /NOTIFYWND=$6034E /FromSmallInstaller /SkipLicensePage /SILENTC:\Users\admin\AppData\Local\Temp\is-UUDQ0.tmp\pdf24-creator.tmp
pdf24-creator.exe
User:
admin
Company:
geek software GmbH
Integrity Level:
HIGH
Description:
Setup/Uninstall
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-uudq0.tmp\pdf24-creator.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
2084"C:\Windows\System32\wbem\WMIC.exe" PROCESS WHERE "Name='pdf24-Reader.exe' AND CommandLine LIKE '%/shellPreview%'" CALL TERMINATEC:\Windows\SysWOW64\wbem\WMIC.exepdf24-creator.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
WMI Commandline Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\wbem\wmic.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
2624"C:\Windows\System32\wbem\WMIC.exe" PROCESS WHERE "Name='prevhost.exe' AND CommandLine LIKE '%{09E6D117-5330-4A29-8C20-0C3AF9F90A1C}%'" CALL TERMINATEC:\Windows\SysWOW64\wbem\WMIC.exepdf24-creator.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
WMI Commandline Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\wbem\wmic.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
2792\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeWMIC.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2904\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeWMIC.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2928"C:\Users\admin\AppData\Local\Temp\pdf24-creator.exe" /FromSmallInstaller /SkipLicensePage /SILENTC:\Users\admin\AppData\Local\Temp\pdf24-creator.exe
pdf24-creator-installer.exe
User:
admin
Company:
geek software GmbH
Integrity Level:
MEDIUM
Description:
PDF24 Creator
Version:
11.23.0
Modules
Images
c:\users\admin\appdata\local\temp\pdf24-creator.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
3840"C:\Users\admin\AppData\Local\Temp\pdf24-creator-installer.exe" C:\Users\admin\AppData\Local\Temp\pdf24-creator-installer.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\pdf24-creator-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
1 980
Read events
1 977
Write events
3
Delete events
0

Modification events

(PID) Process:(3840) pdf24-creator-installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3840) pdf24-creator-installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3840) pdf24-creator-installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
Executable files
202
Suspicious files
1 287
Text files
1 393
Unknown types
1

Dropped files

PID
Process
Filename
Type
3840pdf24-creator-installer.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\KCV3KQBA\pdf24-creator-11.23.0-x64[1].exe
MD5:
SHA256:
3840pdf24-creator-installer.exeC:\Users\admin\AppData\Local\Temp\pdf24-creator.exe
MD5:
SHA256:
1916pdf24-creator.tmpC:\Users\admin\AppData\Local\Temp\is-HSHEU.tmp\SetupSupport.dllexecutable
MD5:5378FCC67A1BDDC8DDED34292B9CCFA1
SHA256:9798B2D81CB860978FE67129E67AF2BBCCC08F0A349A6A448A8062D15BFDE1A1
1916pdf24-creator.tmpC:\Program Files\PDF24\is-LAIEH.tmpexecutable
MD5:CFDF6EAF5328FECBDEC268B7F9E21F3A
SHA256:9057D39B36B6C7D054865EE2BF9CDE7A490FE3B01EC4E82514687E24F576269F
3840pdf24-creator-installer.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\pdf24-creator-latest-x64[1].htmhtml
MD5:FC2A1A5880025C2D294C3D7030F59B05
SHA256:4796011BF77495529013046ED013469B54177800FB37082A164AF1A7E970BC59
2928pdf24-creator.exeC:\Users\admin\AppData\Local\Temp\is-AATKJ.tmp\pdf24-creator.tmpexecutable
MD5:429ED1D6CE36D693E97CF64E40735EC7
SHA256:5E0B351CED501E497B8F0C10250A66DBEDFE9252BD61B24BE912DF6870D8AFC2
1916pdf24-creator.tmpC:\Program Files\PDF24\is-324SD.tmpexecutable
MD5:6DD04C14A17CAAE50D068FC89D7D01F0
SHA256:A65249861238E1C18B84AE5D112617C438D83A76B67EDDC170AD82DBC2338665
1916pdf24-creator.tmpC:\Program Files\PDF24\unins000.exeexecutable
MD5:7E224C05C0CDC41F8EC184ADD6D9DD64
SHA256:434342629B982A9B467914ED26826B31E723E1F33F5B0C62434A0B3EBCFDB949
1916pdf24-creator.tmpC:\Program Files\PDF24\is-2OVOU.tmpexecutable
MD5:DDC38BB34DE28E1F42B6DEA9770D4D65
SHA256:89E2E9A163165E20C540F9ADEA081E927DDFE4A556547B0F45F11586D4CCE165
1916pdf24-creator.tmpC:\Program Files\PDF24\is-QQ451.tmpexecutable
MD5:8FC1C2F2EBB7E46DF30ECD772622B0BC
SHA256:E2E4609C569C69F7B1686F6D0E81CE62187AC5DF05E0247954500053B3C3DE3F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
36
DNS requests
23
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
3840
pdf24-creator-installer.exe
GET
200
69.192.161.44:80
http://x1.c.lencr.org/
unknown
whitelisted
3840
pdf24-creator-installer.exe
GET
200
184.24.77.52:80
http://e6.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBTUejiAQejpjQc4fOz2ttjyD6VkMQQUDcXM%2FZvuFAWhTDCCpT5eisNYCdICEgPBARXEJ%2BQ9ut0iVd81jHBWpg%3D%3D
unknown
whitelisted
1176
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5064
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5880
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4444
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
5880
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
92.123.104.30:443
Akamai International B.V.
DE
unknown
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4712
MoUsoCoreWorker.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
92.123.104.30:443
Akamai International B.V.
DE
unknown
3840
pdf24-creator-installer.exe
88.198.205.206:443
download.pdf24.org
Hetzner Online GmbH
DE
unknown
3840
pdf24-creator-installer.exe
69.192.161.44:80
x1.c.lencr.org
AKAMAI-AS
DE
whitelisted
3840
pdf24-creator-installer.exe
184.24.77.52:80
e6.o.lencr.org
Akamai International B.V.
DE
whitelisted
1076
svchost.exe
23.35.238.131:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
1176
svchost.exe
40.126.31.2:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.162
  • 23.48.23.190
  • 23.48.23.161
  • 23.48.23.183
  • 23.48.23.194
  • 23.48.23.180
  • 23.48.23.158
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 23.219.150.101
whitelisted
google.com
  • 142.250.186.174
whitelisted
download.pdf24.org
  • 88.198.205.206
  • 128.140.92.59
  • 91.107.177.140
  • 195.201.227.97
  • 128.140.108.66
  • 5.75.227.95
  • 157.90.231.214
  • 157.90.115.179
  • 116.203.147.5
unknown
x1.c.lencr.org
  • 69.192.161.44
whitelisted
e6.o.lencr.org
  • 184.24.77.52
  • 184.24.77.67
  • 184.24.77.54
  • 184.24.77.80
  • 184.24.77.46
  • 184.24.77.48
  • 184.24.77.53
  • 184.24.77.83
  • 184.24.77.45
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
login.live.com
  • 40.126.31.2
  • 20.190.159.75
  • 20.190.159.73
  • 40.126.31.128
  • 40.126.31.131
  • 20.190.159.0
  • 20.190.159.68
  • 20.190.159.4
whitelisted
ocsp.digicert.com
  • 2.23.77.188
  • 2.17.190.73
whitelisted

Threats

No threats detected
No debug info