File name:

styx-client-install-4.0.3.zip

Full analysis: https://app.any.run/tasks/9e692881-1ce1-4399-8923-c51a2f1534ec
Verdict: Malicious activity
Analysis date: July 04, 2025, 09:40:04
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
ms-smartcard
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

90C9AF20DA7A2A4F2F78F331CD07A712

SHA1:

DE4E3408C9C0EB6599F8479B7A6112BCB10D0A49

SHA256:

3908665F5A195C5ECB9B0D7E7F2EFF12B9A100830292C5F50CDE257451C19F2B

SSDEEP:

98304:NDxyMbqb5VG53KHjcXgtcRTw9kp7G84IEAxgKpHFVMOLLxBWG7nOQQtheI9qUQyM:wxCziiAiwYOCrOAdsRC7IEr

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 6860)
    • Executing a file with an untrusted certificate

      • ePass2003-Setup.exe (PID: 1328)
      • ePassCertd_2003.exe (PID: 3392)
    • Changes the autorun value in the registry

      • StyxClient-install-4.0.3.exe (PID: 2368)
      • ePass2003-Setup.exe (PID: 1328)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • StyxClient-install-4.0.3.exe (PID: 2368)
      • ePass2003-Setup.exe (PID: 1328)
    • Executable content was dropped or overwritten

      • StyxClient-install-4.0.3.exe (PID: 2368)
      • ePass2003-Setup.exe (PID: 1328)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • StyxClient-install-4.0.3.exe (PID: 2368)
      • ePass2003-Setup.exe (PID: 1328)
    • Process drops legitimate windows executable

      • StyxClient-install-4.0.3.exe (PID: 2368)
    • Reads security settings of Internet Explorer

      • StyxClient-install-4.0.3.exe (PID: 2368)
      • RegAsm.exe (PID: 4724)
      • RegAsm.exe (PID: 2388)
      • RegAsm.exe (PID: 3876)
      • RegAsm.exe (PID: 3624)
      • ePass2003-Setup.exe (PID: 1328)
    • Creates/Modifies COM task schedule object

      • RegAsm.exe (PID: 4724)
      • RegAsm.exe (PID: 3624)
      • RegAsm.exe (PID: 3876)
    • There is functionality for taking screenshot (YARA)

      • StyxClient-install-4.0.3.exe (PID: 2368)
      • ePass2003-Setup.exe (PID: 1328)
      • ePassCertd_2003.exe (PID: 3392)
    • Reads the BIOS version

      • SxRegCNG.exe (PID: 7000)
      • SxRegCNG.exe (PID: 4132)
    • Creates a software uninstall entry

      • StyxClient-install-4.0.3.exe (PID: 2368)
      • ePass2003-Setup.exe (PID: 1328)
    • Smart Card resource manager service initialization

      • ePassCertd_2003.exe (PID: 3392)
  • INFO

    • Manual execution by a user

      • StyxClient-install-4.0.3.exe (PID: 2368)
      • StyxClient-install-4.0.3.exe (PID: 1508)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6860)
    • Create files in a temporary directory

      • StyxClient-install-4.0.3.exe (PID: 2368)
      • ePass2003-Setup.exe (PID: 1328)
    • Reads the computer name

      • StyxClient-install-4.0.3.exe (PID: 2368)
      • RegAsm.exe (PID: 4724)
      • RegAsm.exe (PID: 2388)
      • RegAsm.exe (PID: 3876)
      • RegAsm.exe (PID: 3624)
      • ePass2003-Setup.exe (PID: 1328)
      • ePassCertd_2003.exe (PID: 3392)
    • Checks supported languages

      • StyxClient-install-4.0.3.exe (PID: 2368)
      • RegAsm.exe (PID: 4724)
      • RegAsm.exe (PID: 2388)
      • RegAsm.exe (PID: 3876)
      • RegAsm.exe (PID: 3624)
      • SxRegCNG.exe (PID: 7000)
      • SxRegCNG.exe (PID: 4132)
      • SxRegCNG.exe (PID: 3588)
      • ePass2003-Setup.exe (PID: 1328)
      • SxRegCNG.exe (PID: 1700)
      • ePassCertd_2003.exe (PID: 3392)
    • Creates files in the program directory

      • StyxClient-install-4.0.3.exe (PID: 2368)
      • ePass2003-Setup.exe (PID: 1328)
    • Creates files or folders in the user directory

      • StyxClient-install-4.0.3.exe (PID: 2368)
    • The sample compiled with english language support

      • StyxClient-install-4.0.3.exe (PID: 2368)
      • ePass2003-Setup.exe (PID: 1328)
    • Process checks computer location settings

      • StyxClient-install-4.0.3.exe (PID: 2368)
    • Reads the machine GUID from the registry

      • RegAsm.exe (PID: 4724)
      • RegAsm.exe (PID: 2388)
      • RegAsm.exe (PID: 3876)
      • RegAsm.exe (PID: 3624)
    • Process checks whether UAC notifications are on

      • SxRegCNG.exe (PID: 7000)
      • SxRegCNG.exe (PID: 4132)
    • The sample compiled with chinese language support

      • ePass2003-Setup.exe (PID: 1328)
    • Launching a file from a Registry key

      • StyxClient-install-4.0.3.exe (PID: 2368)
      • ePass2003-Setup.exe (PID: 1328)
    • Reads the software policy settings

      • slui.exe (PID: 6176)
    • Checks proxy server information

      • slui.exe (PID: 6176)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2024:11:20 18:12:42
ZipCRC: 0x325c31b5
ZipCompressedSize: 10708108
ZipUncompressedSize: 10734979
ZipFileName: StyxClient-install-4.0.3.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
160
Monitored processes
22
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe styxclient-install-4.0.3.exe no specs styxclient-install-4.0.3.exe regasm.exe no specs conhost.exe no specs regasm.exe no specs conhost.exe no specs regasm.exe no specs conhost.exe no specs regasm.exe no specs conhost.exe no specs sxregcng.exe conhost.exe no specs sxregcng.exe conhost.exe no specs sxregcng.exe no specs conhost.exe no specs sxregcng.exe no specs conhost.exe no specs epass2003-setup.exe slui.exe epasscertd_2003.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1328"C:\Program Files\StyxClient\ePass2003-Setup.exe"C:\Program Files\StyxClient\ePass2003-Setup.exe
StyxClient-install-4.0.3.exe
User:
admin
Company:
EnterSafe
Integrity Level:
HIGH
Description:
EnterSafe Middleware (For ePass2003)
Exit code:
0
Version:
1.1.15.1104
Modules
Images
c:\program files\styxclient\epass2003-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1508"C:\Users\admin\Desktop\StyxClient-install-4.0.3.exe" C:\Users\admin\Desktop\StyxClient-install-4.0.3.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\styxclient-install-4.0.3.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
1700"C:\Program Files\StyxClient\x64\SxRegCNG.exe" -unregisterC:\Program Files\StyxClient\x64\SxRegCNG.exeStyxClient-install-4.0.3.exe
User:
admin
Company:
BrightSoftTech
Integrity Level:
HIGH
Description:
StyxCNG System Registration
Exit code:
1
Version:
1.0.0.16
Modules
Images
c:\program files\styxclient\x64\sxregcng.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
2368"C:\Users\admin\Desktop\StyxClient-install-4.0.3.exe" C:\Users\admin\Desktop\StyxClient-install-4.0.3.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\styxclient-install-4.0.3.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2388"C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\regasm.exe" C:\WINDOWS\SysWOW64\StyxCryptoCB.dllC:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeStyxClient-install-4.0.3.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Assembly Registration Utility
Exit code:
100
Version:
4.8.9037.0 built by: NET481REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\regasm.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
2536\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeRegAsm.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2804\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeRegAsm.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3392"C:\Program Files (x86)\EnterSafe\ePass2003\ePassCertd_2003.exe"C:\Program Files (x86)\EnterSafe\ePass2003\ePassCertd_2003.exeePass2003-Setup.exe
User:
admin
Company:
EnterSafe
Integrity Level:
HIGH
Description:
certreg MFC Application
Version:
1, 1, 15, 1104
Modules
Images
c:\program files (x86)\entersafe\epass2003\epasscertd_2003.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
3588"C:\Program Files\StyxClient\x64\SxRegCNG.exe" -registerC:\Program Files\StyxClient\x64\SxRegCNG.exeStyxClient-install-4.0.3.exe
User:
admin
Company:
BrightSoftTech
Integrity Level:
HIGH
Description:
StyxCNG System Registration
Exit code:
1
Version:
1.0.0.16
Modules
Images
c:\program files\styxclient\x64\sxregcng.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
3620\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeRegAsm.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
4 998
Read events
4 043
Write events
943
Delete events
12

Modification events

(PID) Process:(6860) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6860) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6860) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6860) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\styx-client-install-4.0.3.zip
(PID) Process:(6860) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6860) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6860) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6860) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(4724) RegAsm.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{49F13D23-2140-3A06-BDB0-28C23661ECBD}\InprocServer32\2.6.2.0
Operation:writeName:Assembly
Value:
StyxCrypto, Version=2.6.2.0, Culture=neutral, PublicKeyToken=f0ee695cb39ebd9f
(PID) Process:(4724) RegAsm.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{49F13D23-2140-3A06-BDB0-28C23661ECBD}\InprocServer32\2.6.2.0
Operation:writeName:RuntimeVersion
Value:
v4.0.30319
Executable files
90
Suspicious files
7
Text files
41
Unknown types
8

Dropped files

PID
Process
Filename
Type
2368StyxClient-install-4.0.3.exeC:\Users\admin\AppData\Local\Temp\nsv8435.tmp\System.dllexecutable
MD5:192639861E3DC2DC5C08BB8F8C7260D5
SHA256:23D618A0293C78CE00F7C6E6DD8B8923621DA7DD1F63A070163EF4C0EC3033D6
2368StyxClient-install-4.0.3.exeC:\Program Files\StyxClient\x64\StyxCpB.dllexecutable
MD5:2433049B492A254685F069BD308B0B72
SHA256:FEE54DE22BA07D1702F02A715D853AAC09C7C14D5C425E81F795527D64E489B7
2368StyxClient-install-4.0.3.exeC:\Program Files\StyxClient\Win32\StyxCpN.dllexecutable
MD5:3042613007F9B5A11D0FB89A57EC406C
SHA256:2487823A843CE2703B14D480ADEAE8CE4FF3DDAA4C377867921E1DA579F00889
2368StyxClient-install-4.0.3.exeC:\Users\admin\AppData\Local\Temp\nsv8435.tmp\modern-header.bmpimage
MD5:3DEBE6FB3464CE77A0BD9503A750DAD1
SHA256:E333642230C5023737360917864E66597D5F33DFCD2DBD28DCCAEC4197180B0A
2368StyxClient-install-4.0.3.exeC:\Users\admin\AppData\Local\Temp\nsv8435.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
2368StyxClient-install-4.0.3.exeC:\Program Files\StyxClient\Win32\StyxCpB.dllexecutable
MD5:45D1FDCD7E1542C3D58085D6E1E5E0DD
SHA256:A742E8F44536FA0614CF7B62ED75CE5A620082617F24BE0264EE87EA8DB8BC90
2368StyxClient-install-4.0.3.exeC:\Users\admin\AppData\Local\Temp\nsv8435.tmp\nsDialogs.dllexecutable
MD5:B7D61F3F56ABF7B7FF0D4E7DA3AD783D
SHA256:89A82C4849C21DFE765052681E1FAD02D2D7B13C8B5075880C52423DCA72A912
2368StyxClient-install-4.0.3.exeC:\Program Files\StyxClient\x64\SxRegCNG.exeexecutable
MD5:767D4D2E40D8D087E9364196AEF139D0
SHA256:3E1380FF3D510677DA920C67DAB056285931FD07C5489B14C4B7E6220D7B93CF
2368StyxClient-install-4.0.3.exeC:\Program Files\StyxClient\x64\StyxCpN.dllexecutable
MD5:17348C7541D4A9EDCC00A9E59E16B9B3
SHA256:0F723278C425171ED7251911CBFE085211CC7E0AEFF06B7019B71D19DF98A7CF
2368StyxClient-install-4.0.3.exeC:\Program Files\StyxClient\ePass2003-Setup.exeexecutable
MD5:AF3CC5C1F93E46BA881CEBD793027692
SHA256:AF52771DCB118FDD0F26123F1A5A37431EDEE9DBFD3410302D0E337D0A127109
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
24
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.48.23.176:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6344
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4880
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4880
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2940
svchost.exe
GET
200
2.23.197.184:80
http://x1.c.lencr.org/
unknown
whitelisted
5328
SearchApp.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5944
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6732
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
23.48.23.176:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
6344
svchost.exe
20.190.160.66:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6344
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
5944
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
whitelisted
google.com
  • 142.250.185.238
whitelisted
crl.microsoft.com
  • 23.48.23.176
  • 23.48.23.177
  • 23.48.23.194
  • 23.48.23.164
  • 23.48.23.173
  • 23.48.23.147
  • 23.48.23.145
  • 23.48.23.166
  • 23.48.23.180
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
login.live.com
  • 20.190.160.66
  • 20.190.160.65
  • 20.190.160.64
  • 40.126.32.76
  • 40.126.32.74
  • 40.126.32.140
  • 20.190.160.131
  • 20.190.160.3
whitelisted
ocsp.digicert.com
  • 2.17.190.73
  • 2.23.77.188
whitelisted
nexusrules.officeapps.live.com
  • 52.111.229.19
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

No threats detected
Process
Message
SxRegCNG.exe
%s------------------------------------------------ --- WinLicense Professional --- --- (c)2012 Oreans Technologies --- ------------------------------------------------
SxRegCNG.exe
%s------------------------------------------------ --- WinLicense Professional --- --- (c)2012 Oreans Technologies --- ------------------------------------------------