File name:

styx-client-install-4.0.3.zip

Full analysis: https://app.any.run/tasks/9e692881-1ce1-4399-8923-c51a2f1534ec
Verdict: Malicious activity
Analysis date: July 04, 2025, 09:40:04
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
ms-smartcard
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

90C9AF20DA7A2A4F2F78F331CD07A712

SHA1:

DE4E3408C9C0EB6599F8479B7A6112BCB10D0A49

SHA256:

3908665F5A195C5ECB9B0D7E7F2EFF12B9A100830292C5F50CDE257451C19F2B

SSDEEP:

98304:NDxyMbqb5VG53KHjcXgtcRTw9kp7G84IEAxgKpHFVMOLLxBWG7nOQQtheI9qUQyM:wxCziiAiwYOCrOAdsRC7IEr

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 6860)
    • Changes the autorun value in the registry

      • StyxClient-install-4.0.3.exe (PID: 2368)
      • ePass2003-Setup.exe (PID: 1328)
    • Executing a file with an untrusted certificate

      • ePass2003-Setup.exe (PID: 1328)
      • ePassCertd_2003.exe (PID: 3392)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • StyxClient-install-4.0.3.exe (PID: 2368)
      • ePass2003-Setup.exe (PID: 1328)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • StyxClient-install-4.0.3.exe (PID: 2368)
      • ePass2003-Setup.exe (PID: 1328)
    • Executable content was dropped or overwritten

      • StyxClient-install-4.0.3.exe (PID: 2368)
      • ePass2003-Setup.exe (PID: 1328)
    • Reads security settings of Internet Explorer

      • StyxClient-install-4.0.3.exe (PID: 2368)
      • RegAsm.exe (PID: 4724)
      • RegAsm.exe (PID: 3876)
      • RegAsm.exe (PID: 2388)
      • RegAsm.exe (PID: 3624)
      • ePass2003-Setup.exe (PID: 1328)
    • Process drops legitimate windows executable

      • StyxClient-install-4.0.3.exe (PID: 2368)
    • Creates/Modifies COM task schedule object

      • RegAsm.exe (PID: 3876)
      • RegAsm.exe (PID: 3624)
      • RegAsm.exe (PID: 4724)
    • There is functionality for taking screenshot (YARA)

      • StyxClient-install-4.0.3.exe (PID: 2368)
      • ePass2003-Setup.exe (PID: 1328)
      • ePassCertd_2003.exe (PID: 3392)
    • Reads the BIOS version

      • SxRegCNG.exe (PID: 4132)
      • SxRegCNG.exe (PID: 7000)
    • Creates a software uninstall entry

      • StyxClient-install-4.0.3.exe (PID: 2368)
      • ePass2003-Setup.exe (PID: 1328)
    • Smart Card resource manager service initialization

      • ePassCertd_2003.exe (PID: 3392)
  • INFO

    • Manual execution by a user

      • StyxClient-install-4.0.3.exe (PID: 1508)
      • StyxClient-install-4.0.3.exe (PID: 2368)
    • Reads the computer name

      • StyxClient-install-4.0.3.exe (PID: 2368)
      • RegAsm.exe (PID: 4724)
      • RegAsm.exe (PID: 2388)
      • RegAsm.exe (PID: 3876)
      • RegAsm.exe (PID: 3624)
      • ePass2003-Setup.exe (PID: 1328)
      • ePassCertd_2003.exe (PID: 3392)
    • Create files in a temporary directory

      • StyxClient-install-4.0.3.exe (PID: 2368)
      • ePass2003-Setup.exe (PID: 1328)
    • Creates files in the program directory

      • StyxClient-install-4.0.3.exe (PID: 2368)
      • ePass2003-Setup.exe (PID: 1328)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6860)
    • Checks supported languages

      • StyxClient-install-4.0.3.exe (PID: 2368)
      • RegAsm.exe (PID: 4724)
      • RegAsm.exe (PID: 2388)
      • RegAsm.exe (PID: 3876)
      • RegAsm.exe (PID: 3624)
      • SxRegCNG.exe (PID: 7000)
      • SxRegCNG.exe (PID: 1700)
      • ePass2003-Setup.exe (PID: 1328)
      • SxRegCNG.exe (PID: 4132)
      • SxRegCNG.exe (PID: 3588)
      • ePassCertd_2003.exe (PID: 3392)
    • Creates files or folders in the user directory

      • StyxClient-install-4.0.3.exe (PID: 2368)
    • The sample compiled with english language support

      • StyxClient-install-4.0.3.exe (PID: 2368)
      • ePass2003-Setup.exe (PID: 1328)
    • Process checks computer location settings

      • StyxClient-install-4.0.3.exe (PID: 2368)
    • Reads the machine GUID from the registry

      • RegAsm.exe (PID: 4724)
      • RegAsm.exe (PID: 2388)
      • RegAsm.exe (PID: 3876)
      • RegAsm.exe (PID: 3624)
    • Process checks whether UAC notifications are on

      • SxRegCNG.exe (PID: 7000)
      • SxRegCNG.exe (PID: 4132)
    • Launching a file from a Registry key

      • StyxClient-install-4.0.3.exe (PID: 2368)
      • ePass2003-Setup.exe (PID: 1328)
    • The sample compiled with chinese language support

      • ePass2003-Setup.exe (PID: 1328)
    • Checks proxy server information

      • slui.exe (PID: 6176)
    • Reads the software policy settings

      • slui.exe (PID: 6176)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2024:11:20 18:12:42
ZipCRC: 0x325c31b5
ZipCompressedSize: 10708108
ZipUncompressedSize: 10734979
ZipFileName: StyxClient-install-4.0.3.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
160
Monitored processes
22
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe styxclient-install-4.0.3.exe no specs styxclient-install-4.0.3.exe regasm.exe no specs conhost.exe no specs regasm.exe no specs conhost.exe no specs regasm.exe no specs conhost.exe no specs regasm.exe no specs conhost.exe no specs sxregcng.exe conhost.exe no specs sxregcng.exe conhost.exe no specs sxregcng.exe no specs conhost.exe no specs sxregcng.exe no specs conhost.exe no specs epass2003-setup.exe slui.exe epasscertd_2003.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1328"C:\Program Files\StyxClient\ePass2003-Setup.exe"C:\Program Files\StyxClient\ePass2003-Setup.exe
StyxClient-install-4.0.3.exe
User:
admin
Company:
EnterSafe
Integrity Level:
HIGH
Description:
EnterSafe Middleware (For ePass2003)
Exit code:
0
Version:
1.1.15.1104
Modules
Images
c:\program files\styxclient\epass2003-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1508"C:\Users\admin\Desktop\StyxClient-install-4.0.3.exe" C:\Users\admin\Desktop\StyxClient-install-4.0.3.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\styxclient-install-4.0.3.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
1700"C:\Program Files\StyxClient\x64\SxRegCNG.exe" -unregisterC:\Program Files\StyxClient\x64\SxRegCNG.exeStyxClient-install-4.0.3.exe
User:
admin
Company:
BrightSoftTech
Integrity Level:
HIGH
Description:
StyxCNG System Registration
Exit code:
1
Version:
1.0.0.16
Modules
Images
c:\program files\styxclient\x64\sxregcng.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
2368"C:\Users\admin\Desktop\StyxClient-install-4.0.3.exe" C:\Users\admin\Desktop\StyxClient-install-4.0.3.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\styxclient-install-4.0.3.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2388"C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\regasm.exe" C:\WINDOWS\SysWOW64\StyxCryptoCB.dllC:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeStyxClient-install-4.0.3.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Assembly Registration Utility
Exit code:
100
Version:
4.8.9037.0 built by: NET481REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\regasm.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
2536\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeRegAsm.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2804\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeRegAsm.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3392"C:\Program Files (x86)\EnterSafe\ePass2003\ePassCertd_2003.exe"C:\Program Files (x86)\EnterSafe\ePass2003\ePassCertd_2003.exeePass2003-Setup.exe
User:
admin
Company:
EnterSafe
Integrity Level:
HIGH
Description:
certreg MFC Application
Version:
1, 1, 15, 1104
Modules
Images
c:\program files (x86)\entersafe\epass2003\epasscertd_2003.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
3588"C:\Program Files\StyxClient\x64\SxRegCNG.exe" -registerC:\Program Files\StyxClient\x64\SxRegCNG.exeStyxClient-install-4.0.3.exe
User:
admin
Company:
BrightSoftTech
Integrity Level:
HIGH
Description:
StyxCNG System Registration
Exit code:
1
Version:
1.0.0.16
Modules
Images
c:\program files\styxclient\x64\sxregcng.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
3620\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeRegAsm.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
4 998
Read events
4 043
Write events
943
Delete events
12

Modification events

(PID) Process:(6860) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6860) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6860) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6860) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\styx-client-install-4.0.3.zip
(PID) Process:(6860) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6860) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6860) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6860) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(4724) RegAsm.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{49F13D23-2140-3A06-BDB0-28C23661ECBD}\InprocServer32\2.6.2.0
Operation:writeName:Assembly
Value:
StyxCrypto, Version=2.6.2.0, Culture=neutral, PublicKeyToken=f0ee695cb39ebd9f
(PID) Process:(4724) RegAsm.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{49F13D23-2140-3A06-BDB0-28C23661ECBD}\InprocServer32\2.6.2.0
Operation:writeName:RuntimeVersion
Value:
v4.0.30319
Executable files
90
Suspicious files
7
Text files
41
Unknown types
8

Dropped files

PID
Process
Filename
Type
2368StyxClient-install-4.0.3.exeC:\Users\admin\AppData\Local\Temp\nsv8435.tmp\UserInfo.dllexecutable
MD5:F8B6DD1F9620BE4EF2AD1E81FB6B79FA
SHA256:A921CC9CC4AF332BE96186D60D2539CB413DFA44CFD73E85687F9338505FF85E
2368StyxClient-install-4.0.3.exeC:\Program Files\StyxClient\Win32\StyxCpB.dllexecutable
MD5:45D1FDCD7E1542C3D58085D6E1E5E0DD
SHA256:A742E8F44536FA0614CF7B62ED75CE5A620082617F24BE0264EE87EA8DB8BC90
2368StyxClient-install-4.0.3.exeC:\Users\admin\AppData\Local\Temp\nsv8435.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
2368StyxClient-install-4.0.3.exeC:\Users\admin\AppData\Local\Temp\nsv8435.tmp\nsDialogs.dllexecutable
MD5:B7D61F3F56ABF7B7FF0D4E7DA3AD783D
SHA256:89A82C4849C21DFE765052681E1FAD02D2D7B13C8B5075880C52423DCA72A912
2368StyxClient-install-4.0.3.exeC:\Users\admin\AppData\Local\Temp\nsv8435.tmp\modern-header.bmpimage
MD5:3DEBE6FB3464CE77A0BD9503A750DAD1
SHA256:E333642230C5023737360917864E66597D5F33DFCD2DBD28DCCAEC4197180B0A
6860WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6860.33036\StyxClient-install-4.0.3.exeexecutable
MD5:63170F3CEB94EA799DCA1F61359A0D0E
SHA256:91308204098A866B84D86D530BBE3170174953085419A5FE1A6E483AD161E1F5
2368StyxClient-install-4.0.3.exeC:\Program Files\StyxClient\Win32\StyxCpN.dllexecutable
MD5:3042613007F9B5A11D0FB89A57EC406C
SHA256:2487823A843CE2703B14D480ADEAE8CE4FF3DDAA4C377867921E1DA579F00889
2368StyxClient-install-4.0.3.exeC:\Users\admin\AppData\Local\Temp\nsv8435.tmp\System.dllexecutable
MD5:192639861E3DC2DC5C08BB8F8C7260D5
SHA256:23D618A0293C78CE00F7C6E6DD8B8923621DA7DD1F63A070163EF4C0EC3033D6
2368StyxClient-install-4.0.3.exeC:\Program Files\StyxClient\Win32\SxRegCNG.exeexecutable
MD5:57EC4017EA6F53C954B74E08C124677B
SHA256:B6797240C7F109F9721838713529DF5AE19583B57F5454F8F07066111DA803A3
2368StyxClient-install-4.0.3.exeC:\Program Files\StyxClient\Win32\StyxExt.dllexecutable
MD5:DFCAB8DDCEDF5667B6457D8EC3E3F027
SHA256:71D2C7B41F1F38345010A2FFBAF67DF164DA7D6FA9BCE6ABC45E730641CBE0A2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
24
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.48.23.176:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6344
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4880
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5328
SearchApp.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
2940
svchost.exe
GET
200
2.23.197.184:80
http://x1.c.lencr.org/
unknown
whitelisted
4880
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5944
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6732
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
23.48.23.176:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
6344
svchost.exe
20.190.160.66:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6344
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
5944
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
whitelisted
google.com
  • 142.250.185.238
whitelisted
crl.microsoft.com
  • 23.48.23.176
  • 23.48.23.177
  • 23.48.23.194
  • 23.48.23.164
  • 23.48.23.173
  • 23.48.23.147
  • 23.48.23.145
  • 23.48.23.166
  • 23.48.23.180
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
login.live.com
  • 20.190.160.66
  • 20.190.160.65
  • 20.190.160.64
  • 40.126.32.76
  • 40.126.32.74
  • 40.126.32.140
  • 20.190.160.131
  • 20.190.160.3
whitelisted
ocsp.digicert.com
  • 2.17.190.73
  • 2.23.77.188
whitelisted
nexusrules.officeapps.live.com
  • 52.111.229.19
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

No threats detected
Process
Message
SxRegCNG.exe
%s------------------------------------------------ --- WinLicense Professional --- --- (c)2012 Oreans Technologies --- ------------------------------------------------
SxRegCNG.exe
%s------------------------------------------------ --- WinLicense Professional --- --- (c)2012 Oreans Technologies --- ------------------------------------------------