File name:

0cbaebd8ef911a3e1e6e832c611ec2ba.exe

Full analysis: https://app.any.run/tasks/02a899fb-f8a7-4939-99d3-41387235bace
Verdict: Malicious activity
Analysis date: July 01, 2025, 02:10:47
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

0CBAEBD8EF911A3E1E6E832C611EC2BA

SHA1:

D78FBA8DA5EBD7BB4A7D1C1F7B7EB9B0B6F61205

SHA256:

94E9F7BB98601DB3F67E1EB0A67254E0E2766826B9F4291F168E172B74C35FB2

SSDEEP:

98304:iCQK0hqgxtl5Yn/Dt2tSCQiQtwLnOUQ+btCQj9+HtK3ltbr0brr//6Oy63ku21/U:hpQdmGdvDxDc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Create files in the Startup directory

      • KeepMove.exe (PID: 4832)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 0cbaebd8ef911a3e1e6e832c611ec2ba.exe (PID: 320)
      • KeepMove.exe (PID: 4832)
    • Creates a software uninstall entry

      • 0cbaebd8ef911a3e1e6e832c611ec2ba.exe (PID: 320)
    • Drops 7-zip archiver for unpacking

      • 0cbaebd8ef911a3e1e6e832c611ec2ba.exe (PID: 320)
    • Creates or modifies Windows services

      • SanXiaServer.exe (PID: 436)
    • Reads security settings of Internet Explorer

      • 0cbaebd8ef911a3e1e6e832c611ec2ba.exe (PID: 320)
      • SanXiaServer.exe (PID: 5504)
    • Executes as Windows Service

      • SanXiaServer.exe (PID: 5504)
    • Searches for installed software

      • SanXiaServer.exe (PID: 5504)
      • SheelEverything.exe (PID: 6216)
      • SheelEverything.exe (PID: 856)
    • Connects to unusual port

      • SheelEverything.exe (PID: 6216)
      • SheelEverything.exe (PID: 856)
      • NNBrowser.exe (PID: 7120)
      • upgrade.exe (PID: 316)
    • There is functionality for taking screenshot (YARA)

      • NNBrowser.exe (PID: 7120)
  • INFO

    • Checks supported languages

      • 0cbaebd8ef911a3e1e6e832c611ec2ba.exe (PID: 320)
      • ReMove.exe (PID: 2192)
      • SanXiaServer.exe (PID: 304)
      • KeepMove.exe (PID: 4832)
      • SanXiaServer.exe (PID: 436)
      • SanXiaServer.exe (PID: 5504)
      • SheelEverything.exe (PID: 6216)
      • SheelEverything.exe (PID: 856)
      • launcher.exe (PID: 6104)
      • launcher.exe (PID: 4864)
      • upgrade.exe (PID: 316)
      • SXNoThing.exe (PID: 1080)
      • NNBrowser.exe (PID: 7120)
    • Creates files in the program directory

      • 0cbaebd8ef911a3e1e6e832c611ec2ba.exe (PID: 320)
      • ReMove.exe (PID: 2192)
      • KeepMove.exe (PID: 4832)
      • upgrade.exe (PID: 316)
    • The sample compiled with chinese language support

      • 0cbaebd8ef911a3e1e6e832c611ec2ba.exe (PID: 320)
    • The sample compiled with english language support

      • 0cbaebd8ef911a3e1e6e832c611ec2ba.exe (PID: 320)
    • Reads the computer name

      • ReMove.exe (PID: 2192)
      • 0cbaebd8ef911a3e1e6e832c611ec2ba.exe (PID: 320)
      • SanXiaServer.exe (PID: 304)
      • KeepMove.exe (PID: 4832)
      • SanXiaServer.exe (PID: 436)
      • SanXiaServer.exe (PID: 5504)
      • SheelEverything.exe (PID: 6216)
      • SheelEverything.exe (PID: 856)
      • NNBrowser.exe (PID: 7120)
      • upgrade.exe (PID: 316)
    • Process checks computer location settings

      • 0cbaebd8ef911a3e1e6e832c611ec2ba.exe (PID: 320)
    • Launching a file from the Startup directory

      • KeepMove.exe (PID: 4832)
    • Creates files or folders in the user directory

      • KeepMove.exe (PID: 4832)
      • NNBrowser.exe (PID: 7120)
    • Reads the machine GUID from the registry

      • SanXiaServer.exe (PID: 5504)
    • Checks proxy server information

      • upgrade.exe (PID: 316)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:12:15 22:24:22+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 24576
InitializedDataSize: 118784
UninitializedDataSize: 1024
EntryPoint: 0x31d6
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
152
Monitored processes
15
Malicious processes
1
Suspicious processes
3

Behavior graph

Click at the process to see the details
start 0cbaebd8ef911a3e1e6e832c611ec2ba.exe remove.exe no specs sanxiaserver.exe no specs keepmove.exe sanxiaserver.exe no specs sanxiaserver.exe sheeleverything.exe launcher.exe no specs sheeleverything.exe launcher.exe no specs upgrade.exe sxnothing.exe no specs nnbrowser.exe slui.exe no specs 0cbaebd8ef911a3e1e6e832c611ec2ba.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
304"C:\Program Files (x86)\SanXiaWorkSafe\SanXiaServer.exe" -uninstallC:\Program Files (x86)\SanXiaWorkSafe\SanXiaServer.exeReMove.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files (x86)\sanxiaworksafe\sanxiaserver.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
316"C:\Program Files (x86)\SanXiaWorkSafe\1.0.0.7\upgrade.exe"C:\Program Files (x86)\SanXiaWorkSafe\1.0.0.7\upgrade.exe
launcher.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\program files (x86)\sanxiaworksafe\1.0.0.7\upgrade.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
320"C:\Users\admin\AppData\Local\Temp\0cbaebd8ef911a3e1e6e832c611ec2ba.exe" C:\Users\admin\AppData\Local\Temp\0cbaebd8ef911a3e1e6e832c611ec2ba.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\0cbaebd8ef911a3e1e6e832c611ec2ba.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
436"C:\Program Files (x86)\SanXiaWorkSafe\SanXiaServer.exe" -installC:\Program Files (x86)\SanXiaWorkSafe\SanXiaServer.exe0cbaebd8ef911a3e1e6e832c611ec2ba.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files (x86)\sanxiaworksafe\sanxiaserver.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
856"C:\Program Files (x86)\SanXiaWorkSafe\SheelEverything.exe" -SERC:\Program Files (x86)\SanXiaWorkSafe\SheelEverything.exe
SanXiaServer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files (x86)\sanxiaworksafe\sheeleverything.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
1080"C:\Program Files (x86)\SanXiaWorkSafe\1.0.0.7\SXNoThing.exe"C:\Program Files (x86)\SanXiaWorkSafe\1.0.0.7\SXNoThing.exelauncher.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\program files (x86)\sanxiaworksafe\1.0.0.7\sxnothing.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2192"C:\Program Files (x86)\SanXiaWorkSafe\ReMove.exe"C:\Program Files (x86)\SanXiaWorkSafe\ReMove.exe0cbaebd8ef911a3e1e6e832c611ec2ba.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files (x86)\sanxiaworksafe\remove.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
3780"C:\Users\admin\AppData\Local\Temp\0cbaebd8ef911a3e1e6e832c611ec2ba.exe" C:\Users\admin\AppData\Local\Temp\0cbaebd8ef911a3e1e6e832c611ec2ba.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\0cbaebd8ef911a3e1e6e832c611ec2ba.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
4832"C:\Program Files (x86)\SanXiaWorkSafe\KeepMove.exe" SW_SHOWNORMALC:\Program Files (x86)\SanXiaWorkSafe\KeepMove.exe
0cbaebd8ef911a3e1e6e832c611ec2ba.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files (x86)\sanxiaworksafe\keepmove.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4864"C:\Program Files (x86)\SanXiaWorkSafe\launcher.exe"C:\Program Files (x86)\SanXiaWorkSafe\launcher.exeSheelEverything.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files (x86)\sanxiaworksafe\launcher.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
Total events
2 335
Read events
2 322
Write events
13
Delete events
0

Modification events

(PID) Process:(436) SanXiaServer.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Keep NetWork Safe Service.
Operation:writeName:Description
Value:
安全守护服务,请保持运行状态
(PID) Process:(436) SanXiaServer.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\Application\Keep NetWork Safe Service.
Operation:writeName:EventMessageFile
Value:
C:\Program Files (x86)\SanXiaWorkSafe\SanXiaServer.exe
(PID) Process:(436) SanXiaServer.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\Application\Keep NetWork Safe Service.
Operation:writeName:TypesSupported
Value:
7
(PID) Process:(320) 0cbaebd8ef911a3e1e6e832c611ec2ba.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SanXiaWorkSafe
Operation:writeName:DisplayName
Value:
SanXiaWorkSafe 1.0.0.7
(PID) Process:(320) 0cbaebd8ef911a3e1e6e832c611ec2ba.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SanXiaWorkSafe
Operation:writeName:UninstallString
Value:
C:\Program Files (x86)\SanXiaWorkSafe\uninst.exe
(PID) Process:(320) 0cbaebd8ef911a3e1e6e832c611ec2ba.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SanXiaWorkSafe
Operation:writeName:DisplayIcon
Value:
C:\Program Files (x86)\SanXiaWorkSafe\SheelEverything.exe
(PID) Process:(320) 0cbaebd8ef911a3e1e6e832c611ec2ba.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SanXiaWorkSafe
Operation:writeName:DisplayVersion
Value:
1.0.0.7
(PID) Process:(320) 0cbaebd8ef911a3e1e6e832c611ec2ba.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SanXiaWorkSafe
Operation:writeName:Publisher
Value:
My company, Inc.
(PID) Process:(5504) SanXiaServer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SanXiaWorkSafe.exe
Operation:writeName:SPath
Value:
C:\Program Files (x86)\SanXiaWorkSafe\SanXiaServer.exe
(PID) Process:(5504) SanXiaServer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SanXiaWorkSafe.exe
Operation:writeName:InstallTime
Value:
Executable files
15
Suspicious files
2
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
3200cbaebd8ef911a3e1e6e832c611ec2ba.exeC:\Program Files (x86)\SanXiaWorkSafe\launcher.exeexecutable
MD5:EEBACAAE58D530556295AFC4AC37E4A7
SHA256:CB84162F7ED87296E260D8C950311F50B563E573378BD7939C46B8EBE9FF0C6F
3200cbaebd8ef911a3e1e6e832c611ec2ba.exeC:\Program Files (x86)\SanXiaWorkSafe\Launcher.initext
MD5:C47B3843738E32326F9FF8E6C3BC3909
SHA256:84D95844763D58D5A45D31D139EAFF2EFCBE98E99BD4AEF1A47D303BD97F8950
3200cbaebd8ef911a3e1e6e832c611ec2ba.exeC:\Program Files (x86)\SanXiaWorkSafe\SheelEverything.exeexecutable
MD5:657EE8DBC7AD4B13B3CE82351C3E127C
SHA256:5A2C20D20D88C952B684B737FD06F8659E328555EAC585E967B4D6C04572C5F6
3200cbaebd8ef911a3e1e6e832c611ec2ba.exeC:\Program Files (x86)\SanXiaWorkSafe\ReMove.exeexecutable
MD5:17D9D6D386F08B9FA2649B0E020EDC00
SHA256:24BBC27CE96C3BBD9050C13ADEC5A3CF075A736C040EFD21EDFDAC998B29EEC1
3200cbaebd8ef911a3e1e6e832c611ec2ba.exeC:\Program Files (x86)\SanXiaWorkSafe\1.0.0.7\upgrade.exeexecutable
MD5:719F7E12CF000E62B99DA44AA794E129
SHA256:005AC88C2301D699BEA9FDE35BA8E2363840DD6E82EDA42B9EF953DE803E601E
3200cbaebd8ef911a3e1e6e832c611ec2ba.exeC:\Program Files (x86)\SanXiaWorkSafe\SanXiaServer.exeexecutable
MD5:D7CC0C3A523727D2E099C2DCAA5EEE00
SHA256:5E488F69583FE1FD858B41859195CE9C4F739CF03B217C172B68CE88415555C4
4832KeepMove.exeC:\Program Files (x86)\SanXiaWorkSafe\SheelEverything.exe.bakexecutable
MD5:657EE8DBC7AD4B13B3CE82351C3E127C
SHA256:5A2C20D20D88C952B684B737FD06F8659E328555EAC585E967B4D6C04572C5F6
3200cbaebd8ef911a3e1e6e832c611ec2ba.exeC:\Program Files (x86)\SanXiaWorkSafe\KeepMove.exeexecutable
MD5:016885913C2DC2658141DDAB1FF300F6
SHA256:13A1A73BC61551D963A0B636CA781F6767CFD395303CBE5BA1F94ACFF25E687E
2192ReMove.exeC:\Program Files (x86)\SanXiaWorkSafe\log\20250701.dbtext
MD5:2635B0AB3548881996FDF174B111E7B1
SHA256:DD720D8D4AA904812FBC54020A4B5FB08F342FA67E7EF4CAF047D152DC2A08B9
3200cbaebd8ef911a3e1e6e832c611ec2ba.exeC:\Program Files (x86)\SanXiaWorkSafe\KeepMoveYL.dllexecutable
MD5:E6108E73E9559AB72B39F34155EF1B95
SHA256:82F39BCAA670F49B4DCCFBC9362F75BBC359400A141DA09B532A63F9038AF9CF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
31
DNS requests
20
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6656
SIHClient.exe
GET
200
104.123.41.162:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6656
SIHClient.exe
GET
200
104.123.41.162:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6216
SheelEverything.exe
POST
200
121.36.23.37:8803
http://client.baiwang.com:8803/v2/statistic/doClick/web
unknown
whitelisted
7120
NNBrowser.exe
POST
200
121.36.23.37:8803
http://client.baiwang.com:8803/v2/statistic/doClick/web
unknown
whitelisted
316
upgrade.exe
POST
200
121.36.23.37:8802
http://client.baiwang.com:8802/get/updateProgram
unknown
whitelisted
2524
svchost.exe
GET
200
2.22.98.7:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
856
SheelEverything.exe
POST
200
121.36.23.37:8803
http://client.baiwang.com:8803/v2/statistic/doClick/web
unknown
whitelisted
316
upgrade.exe
POST
200
121.36.23.37:8802
http://client.baiwang.com:8802/get/updateProgram
unknown
whitelisted
1268
svchost.exe
GET
200
2.20.245.139:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
104.123.41.162:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5944
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3936
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
5504
SanXiaServer.exe
103.235.46.115:80
www.baidu.com
Beijing Baidu Netcom Science and Technology Co., Ltd.
HK
whitelisted
6216
SheelEverything.exe
121.36.23.37:8803
client.baiwang.com
Huawei Cloud Service data center
CN
whitelisted
5504
SanXiaServer.exe
8.152.207.223:443
sanxia-smb-drhutkfygg.cn-beijing.fcapp.run
SG
unknown
856
SheelEverything.exe
121.36.23.37:8803
client.baiwang.com
Huawei Cloud Service data center
CN
whitelisted
7120
NNBrowser.exe
121.36.23.37:8803
client.baiwang.com
Huawei Cloud Service data center
CN
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.124.78.146
  • 40.127.240.158
whitelisted
google.com
  • 142.250.186.46
whitelisted
www.baidu.com
  • 103.235.46.115
  • 103.235.46.102
whitelisted
client.baiwang.com
  • 121.36.23.37
whitelisted
sanxia-smb-drhutkfygg.cn-beijing.fcapp.run
  • 8.152.207.223
unknown
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 20.190.159.4
  • 40.126.31.128
  • 20.190.159.131
  • 40.126.31.73
  • 40.126.31.71
  • 20.190.159.23
  • 20.190.159.0
  • 20.190.159.64
whitelisted
ocsp.digicert.com
  • 2.22.98.7
whitelisted
crl.microsoft.com
  • 2.20.245.139
  • 2.20.245.137
whitelisted
www.microsoft.com
  • 104.123.41.162
whitelisted

Threats

PID
Process
Class
Message
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info