File name:

0cbaebd8ef911a3e1e6e832c611ec2ba.exe

Full analysis: https://app.any.run/tasks/02a899fb-f8a7-4939-99d3-41387235bace
Verdict: Malicious activity
Analysis date: July 01, 2025, 02:10:47
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

0CBAEBD8EF911A3E1E6E832C611EC2BA

SHA1:

D78FBA8DA5EBD7BB4A7D1C1F7B7EB9B0B6F61205

SHA256:

94E9F7BB98601DB3F67E1EB0A67254E0E2766826B9F4291F168E172B74C35FB2

SSDEEP:

98304:iCQK0hqgxtl5Yn/Dt2tSCQiQtwLnOUQ+btCQj9+HtK3ltbr0brr//6Oy63ku21/U:hpQdmGdvDxDc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Create files in the Startup directory

      • KeepMove.exe (PID: 4832)
  • SUSPICIOUS

    • Drops 7-zip archiver for unpacking

      • 0cbaebd8ef911a3e1e6e832c611ec2ba.exe (PID: 320)
    • Creates a software uninstall entry

      • 0cbaebd8ef911a3e1e6e832c611ec2ba.exe (PID: 320)
    • Executable content was dropped or overwritten

      • 0cbaebd8ef911a3e1e6e832c611ec2ba.exe (PID: 320)
      • KeepMove.exe (PID: 4832)
    • Reads security settings of Internet Explorer

      • 0cbaebd8ef911a3e1e6e832c611ec2ba.exe (PID: 320)
      • SanXiaServer.exe (PID: 5504)
    • Creates or modifies Windows services

      • SanXiaServer.exe (PID: 436)
    • Executes as Windows Service

      • SanXiaServer.exe (PID: 5504)
    • Searches for installed software

      • SheelEverything.exe (PID: 6216)
      • SanXiaServer.exe (PID: 5504)
      • SheelEverything.exe (PID: 856)
    • Connects to unusual port

      • SheelEverything.exe (PID: 6216)
      • SheelEverything.exe (PID: 856)
      • NNBrowser.exe (PID: 7120)
      • upgrade.exe (PID: 316)
    • There is functionality for taking screenshot (YARA)

      • NNBrowser.exe (PID: 7120)
  • INFO

    • Creates files in the program directory

      • 0cbaebd8ef911a3e1e6e832c611ec2ba.exe (PID: 320)
      • ReMove.exe (PID: 2192)
      • KeepMove.exe (PID: 4832)
      • upgrade.exe (PID: 316)
    • Checks supported languages

      • 0cbaebd8ef911a3e1e6e832c611ec2ba.exe (PID: 320)
      • ReMove.exe (PID: 2192)
      • SanXiaServer.exe (PID: 304)
      • SanXiaServer.exe (PID: 436)
      • KeepMove.exe (PID: 4832)
      • SanXiaServer.exe (PID: 5504)
      • SheelEverything.exe (PID: 6216)
      • launcher.exe (PID: 6104)
      • SheelEverything.exe (PID: 856)
      • upgrade.exe (PID: 316)
      • launcher.exe (PID: 4864)
      • SXNoThing.exe (PID: 1080)
      • NNBrowser.exe (PID: 7120)
    • The sample compiled with chinese language support

      • 0cbaebd8ef911a3e1e6e832c611ec2ba.exe (PID: 320)
    • The sample compiled with english language support

      • 0cbaebd8ef911a3e1e6e832c611ec2ba.exe (PID: 320)
    • Reads the computer name

      • KeepMove.exe (PID: 4832)
      • SanXiaServer.exe (PID: 304)
      • SanXiaServer.exe (PID: 5504)
      • SheelEverything.exe (PID: 6216)
      • SheelEverything.exe (PID: 856)
      • NNBrowser.exe (PID: 7120)
      • upgrade.exe (PID: 316)
      • SanXiaServer.exe (PID: 436)
      • ReMove.exe (PID: 2192)
      • 0cbaebd8ef911a3e1e6e832c611ec2ba.exe (PID: 320)
    • Process checks computer location settings

      • 0cbaebd8ef911a3e1e6e832c611ec2ba.exe (PID: 320)
    • Launching a file from the Startup directory

      • KeepMove.exe (PID: 4832)
    • Creates files or folders in the user directory

      • KeepMove.exe (PID: 4832)
      • NNBrowser.exe (PID: 7120)
    • Reads the machine GUID from the registry

      • SanXiaServer.exe (PID: 5504)
    • Checks proxy server information

      • upgrade.exe (PID: 316)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:12:15 22:24:22+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 24576
InitializedDataSize: 118784
UninitializedDataSize: 1024
EntryPoint: 0x31d6
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
152
Monitored processes
15
Malicious processes
1
Suspicious processes
3

Behavior graph

Click at the process to see the details
start 0cbaebd8ef911a3e1e6e832c611ec2ba.exe remove.exe no specs sanxiaserver.exe no specs keepmove.exe sanxiaserver.exe no specs sanxiaserver.exe sheeleverything.exe launcher.exe no specs sheeleverything.exe launcher.exe no specs upgrade.exe sxnothing.exe no specs nnbrowser.exe slui.exe no specs 0cbaebd8ef911a3e1e6e832c611ec2ba.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
304"C:\Program Files (x86)\SanXiaWorkSafe\SanXiaServer.exe" -uninstallC:\Program Files (x86)\SanXiaWorkSafe\SanXiaServer.exeReMove.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files (x86)\sanxiaworksafe\sanxiaserver.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
316"C:\Program Files (x86)\SanXiaWorkSafe\1.0.0.7\upgrade.exe"C:\Program Files (x86)\SanXiaWorkSafe\1.0.0.7\upgrade.exe
launcher.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\program files (x86)\sanxiaworksafe\1.0.0.7\upgrade.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
320"C:\Users\admin\AppData\Local\Temp\0cbaebd8ef911a3e1e6e832c611ec2ba.exe" C:\Users\admin\AppData\Local\Temp\0cbaebd8ef911a3e1e6e832c611ec2ba.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\0cbaebd8ef911a3e1e6e832c611ec2ba.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
436"C:\Program Files (x86)\SanXiaWorkSafe\SanXiaServer.exe" -installC:\Program Files (x86)\SanXiaWorkSafe\SanXiaServer.exe0cbaebd8ef911a3e1e6e832c611ec2ba.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files (x86)\sanxiaworksafe\sanxiaserver.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
856"C:\Program Files (x86)\SanXiaWorkSafe\SheelEverything.exe" -SERC:\Program Files (x86)\SanXiaWorkSafe\SheelEverything.exe
SanXiaServer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files (x86)\sanxiaworksafe\sheeleverything.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
1080"C:\Program Files (x86)\SanXiaWorkSafe\1.0.0.7\SXNoThing.exe"C:\Program Files (x86)\SanXiaWorkSafe\1.0.0.7\SXNoThing.exelauncher.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\program files (x86)\sanxiaworksafe\1.0.0.7\sxnothing.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2192"C:\Program Files (x86)\SanXiaWorkSafe\ReMove.exe"C:\Program Files (x86)\SanXiaWorkSafe\ReMove.exe0cbaebd8ef911a3e1e6e832c611ec2ba.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files (x86)\sanxiaworksafe\remove.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
3780"C:\Users\admin\AppData\Local\Temp\0cbaebd8ef911a3e1e6e832c611ec2ba.exe" C:\Users\admin\AppData\Local\Temp\0cbaebd8ef911a3e1e6e832c611ec2ba.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\0cbaebd8ef911a3e1e6e832c611ec2ba.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
4832"C:\Program Files (x86)\SanXiaWorkSafe\KeepMove.exe" SW_SHOWNORMALC:\Program Files (x86)\SanXiaWorkSafe\KeepMove.exe
0cbaebd8ef911a3e1e6e832c611ec2ba.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files (x86)\sanxiaworksafe\keepmove.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4864"C:\Program Files (x86)\SanXiaWorkSafe\launcher.exe"C:\Program Files (x86)\SanXiaWorkSafe\launcher.exeSheelEverything.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files (x86)\sanxiaworksafe\launcher.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
Total events
2 335
Read events
2 322
Write events
13
Delete events
0

Modification events

(PID) Process:(436) SanXiaServer.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Keep NetWork Safe Service.
Operation:writeName:Description
Value:
安全守护服务,请保持运行状态
(PID) Process:(436) SanXiaServer.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\Application\Keep NetWork Safe Service.
Operation:writeName:EventMessageFile
Value:
C:\Program Files (x86)\SanXiaWorkSafe\SanXiaServer.exe
(PID) Process:(436) SanXiaServer.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\Application\Keep NetWork Safe Service.
Operation:writeName:TypesSupported
Value:
7
(PID) Process:(320) 0cbaebd8ef911a3e1e6e832c611ec2ba.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SanXiaWorkSafe
Operation:writeName:DisplayName
Value:
SanXiaWorkSafe 1.0.0.7
(PID) Process:(320) 0cbaebd8ef911a3e1e6e832c611ec2ba.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SanXiaWorkSafe
Operation:writeName:UninstallString
Value:
C:\Program Files (x86)\SanXiaWorkSafe\uninst.exe
(PID) Process:(320) 0cbaebd8ef911a3e1e6e832c611ec2ba.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SanXiaWorkSafe
Operation:writeName:DisplayIcon
Value:
C:\Program Files (x86)\SanXiaWorkSafe\SheelEverything.exe
(PID) Process:(320) 0cbaebd8ef911a3e1e6e832c611ec2ba.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SanXiaWorkSafe
Operation:writeName:DisplayVersion
Value:
1.0.0.7
(PID) Process:(320) 0cbaebd8ef911a3e1e6e832c611ec2ba.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SanXiaWorkSafe
Operation:writeName:Publisher
Value:
My company, Inc.
(PID) Process:(5504) SanXiaServer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SanXiaWorkSafe.exe
Operation:writeName:SPath
Value:
C:\Program Files (x86)\SanXiaWorkSafe\SanXiaServer.exe
(PID) Process:(5504) SanXiaServer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SanXiaWorkSafe.exe
Operation:writeName:InstallTime
Value:
Executable files
15
Suspicious files
2
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
3200cbaebd8ef911a3e1e6e832c611ec2ba.exeC:\Program Files (x86)\SanXiaWorkSafe\1.0.0.7\7z.exeexecutable
MD5:A51D90F2F9394F5EA0A3ACAE3BD2B219
SHA256:AC9674FEB8F2FAD20C1E046DE67F899419276AE79A60E8CC021A4BF472AE044F
3200cbaebd8ef911a3e1e6e832c611ec2ba.exeC:\Program Files (x86)\SanXiaWorkSafe\1.0.0.7\7z.dllexecutable
MD5:04AD4B80880B32C94BE8D0886482C774
SHA256:A1E1D1F0FFF4FCCCFBDFA313F3BDFEA4D3DFE2C2D9174A615BBC39A0A6929338
3200cbaebd8ef911a3e1e6e832c611ec2ba.exeC:\Program Files (x86)\SanXiaWorkSafe\1.0.0.7\upgrade.exeexecutable
MD5:719F7E12CF000E62B99DA44AA794E129
SHA256:005AC88C2301D699BEA9FDE35BA8E2363840DD6E82EDA42B9EF953DE803E601E
3200cbaebd8ef911a3e1e6e832c611ec2ba.exeC:\Program Files (x86)\SanXiaWorkSafe\uninst.exeexecutable
MD5:1754E6E0CFA9E6AC6893F38ED4667DC9
SHA256:3B35824A0EE6D160416B4B9A77EE8903341B186904E850DD3FAC20756408D56B
4832KeepMove.exeC:\Program Files (x86)\SanXiaWorkSafe\supersx.lnkbinary
MD5:C2F1917BB736C06980B8304F1A3D2276
SHA256:FA1041993DF58D4784E87A0417AC4F7BAC01DE888E9196E924F368FB7713BC62
3200cbaebd8ef911a3e1e6e832c611ec2ba.exeC:\Program Files (x86)\SanXiaWorkSafe\ReMove.exeexecutable
MD5:17D9D6D386F08B9FA2649B0E020EDC00
SHA256:24BBC27CE96C3BBD9050C13ADEC5A3CF075A736C040EFD21EDFDAC998B29EEC1
3200cbaebd8ef911a3e1e6e832c611ec2ba.exeC:\Program Files (x86)\SanXiaWorkSafe\1.0.0.7\config.initext
MD5:90D5A47978E68088C20AE8CF4BEFDC08
SHA256:00409DB3CA0C9043F2F3290CAE17CB9E531CD19FB461713BE456908802212288
2192ReMove.exeC:\Program Files (x86)\SanXiaWorkSafe\log\20250701.dbtext
MD5:2635B0AB3548881996FDF174B111E7B1
SHA256:DD720D8D4AA904812FBC54020A4B5FB08F342FA67E7EF4CAF047D152DC2A08B9
316upgrade.exeC:\Program Files (x86)\SanXiaWorkSafe\1.0.0.7\flag.txttext
MD5:DC1D71BBB5C4D2A5E936DB79EF10C19F
SHA256:836FF184E7B41B1E13CB5FD89FA1DE98DBBAB99E9D2918913FF43B86A5C7C213
3200cbaebd8ef911a3e1e6e832c611ec2ba.exeC:\Program Files (x86)\SanXiaWorkSafe\1.0.0.7\NNBrowser.exeexecutable
MD5:6900B856FC0E0EEA9444ECFC83DBA321
SHA256:0C8CD260A8D115542EE536649E3211EC465E63E2F389C27C95AE1EC755F77B9F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
31
DNS requests
20
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6216
SheelEverything.exe
POST
200
121.36.23.37:8803
http://client.baiwang.com:8803/v2/statistic/doClick/web
unknown
whitelisted
7120
NNBrowser.exe
POST
200
121.36.23.37:8803
http://client.baiwang.com:8803/v2/statistic/doClick/web
unknown
whitelisted
856
SheelEverything.exe
POST
200
121.36.23.37:8803
http://client.baiwang.com:8803/v2/statistic/doClick/web
unknown
whitelisted
316
upgrade.exe
POST
200
121.36.23.37:8802
http://client.baiwang.com:8802/get/updateProgram
unknown
whitelisted
2524
svchost.exe
GET
200
2.22.98.7:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1268
svchost.exe
GET
200
2.20.245.139:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6656
SIHClient.exe
GET
200
104.123.41.162:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6656
SIHClient.exe
GET
200
104.123.41.162:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
316
upgrade.exe
POST
200
121.36.23.37:8802
http://client.baiwang.com:8802/get/updateProgram
unknown
whitelisted
316
upgrade.exe
POST
200
121.36.23.37:8802
http://client.baiwang.com:8802/get/updateProgram
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5944
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3936
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
5504
SanXiaServer.exe
103.235.46.115:80
www.baidu.com
Beijing Baidu Netcom Science and Technology Co., Ltd.
HK
whitelisted
6216
SheelEverything.exe
121.36.23.37:8803
client.baiwang.com
Huawei Cloud Service data center
CN
whitelisted
5504
SanXiaServer.exe
8.152.207.223:443
sanxia-smb-drhutkfygg.cn-beijing.fcapp.run
SG
unknown
856
SheelEverything.exe
121.36.23.37:8803
client.baiwang.com
Huawei Cloud Service data center
CN
whitelisted
7120
NNBrowser.exe
121.36.23.37:8803
client.baiwang.com
Huawei Cloud Service data center
CN
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.124.78.146
  • 40.127.240.158
whitelisted
google.com
  • 142.250.186.46
whitelisted
www.baidu.com
  • 103.235.46.115
  • 103.235.46.102
whitelisted
client.baiwang.com
  • 121.36.23.37
whitelisted
sanxia-smb-drhutkfygg.cn-beijing.fcapp.run
  • 8.152.207.223
unknown
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 20.190.159.4
  • 40.126.31.128
  • 20.190.159.131
  • 40.126.31.73
  • 40.126.31.71
  • 20.190.159.23
  • 20.190.159.0
  • 20.190.159.64
whitelisted
ocsp.digicert.com
  • 2.22.98.7
whitelisted
crl.microsoft.com
  • 2.20.245.139
  • 2.20.245.137
whitelisted
www.microsoft.com
  • 104.123.41.162
whitelisted

Threats

PID
Process
Class
Message
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info