G
gihan bhawantha
Hi,I have been observing that there are suspicious network connections established with the following Microsoft domains from werfault.exe. These results have been generated from the EDR. umwatson.events.data.microsoft.com, kmwatson.events.data.microsoft.com :- 20.189.173.21:443watson.microsoft.com :- 20.42.73.29:443ctldl.windowsupdate.com, au.download.windowsupdate.com :- 125.214.166.82:80I want to know whether these, IP addresses are the correct ones or not. Is there a way to verify that? instead of just searching about the IP address. Thank you.
Continue reading...
Continue reading...