File name:

MDE_File_Sample_e247901083648ee7f4e8e85652e90604851c7d4f.zip

Full analysis: https://app.any.run/tasks/c7a0a338-a424-41f1-a488-d5bff3b4c1f3
Verdict: Malicious activity
Analysis date: March 13, 2026, 13:45:21
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

22926B1D7BFF987D790043229FC365FA

SHA1:

2325C74C43086159762A52EEBDF404804977C510

SHA256:

C39275CA11A57ACA30D3D08B7F8949AF8D7726FED6514A594F60960B1F83DB39

SSDEEP:

98304:/dZY+Zdh6BX/hoUPW1/LlQiHitmfq95AEfEnIT1/iKqLHKINg3KTLe2iysE8/Yxb:eMDpDP7MygNQOpyesMhq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • SamFwTool.exe (PID: 7884)
      • SamFwTool.exe (PID: 8712)
      • SamFwTool.exe (PID: 4756)
      • SamFwTool.exe (PID: 9020)
      • SamFwTool.exe (PID: 1324)
      • SamFwTool.exe (PID: 772)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 7636)
      • WinRAR.exe (PID: 7980)
    • Reads the computer name

      • SamFwTool.exe (PID: 7884)
      • SamFwTool.exe (PID: 9020)
      • SamFwTool.exe (PID: 1324)
    • Reads the machine GUID from the registry

      • SamFwTool.exe (PID: 7884)
      • SamFwTool.exe (PID: 9020)
      • SamFwTool.exe (PID: 1324)
    • Checks supported languages

      • SamFwTool.exe (PID: 7884)
      • SamFwTool.exe (PID: 9020)
      • SamFwTool.exe (PID: 1324)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 7636)
      • WinRAR.exe (PID: 7980)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 3944)
      • WerFault.exe (PID: 2360)
      • WerFault.exe (PID: 7244)
    • Manual execution by a user

      • WinRAR.exe (PID: 7980)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0001
ZipCompression: Deflated
ZipModifyDate: 2026:03:13 13:44:48
ZipCRC: 0xc34f6e25
ZipCompressedSize: 5735203
ZipUncompressedSize: 7821568
ZipFileName: SamFwTool.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
165
Monitored processes
12
Malicious processes
1
Suspicious processes
7

Behavior graph

Click at the process to see the details
start winrar.exe samfwtool.exe no specs samfwtool.exe werfault.exe samfwtool.exe no specs samfwtool.exe werfault.exe winrar.exe slui.exe samfwtool.exe no specs samfwtool.exe werfault.exe

Process information

PID
CMD
Path
Indicators
Parent process
772"C:\Users\admin\AppData\Local\Temp\Rar$EXb7980.21380\SamFwTool.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb7980.21380\SamFwTool.exeWinRAR.exe
User:
admin
Company:
SamFw.com
Integrity Level:
MEDIUM
Description:
SamFwTool
Exit code:
3221226540
Version:
5.4.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb7980.21380\samfwtool.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
1324"C:\Users\admin\AppData\Local\Temp\Rar$EXb7980.21380\SamFwTool.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb7980.21380\SamFwTool.exe
WinRAR.exe
User:
admin
Company:
SamFw.com
Integrity Level:
HIGH
Description:
SamFwTool
Exit code:
3762504530
Version:
5.4.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb7980.21380\samfwtool.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
2360C:\WINDOWS\SysWOW64\WerFault.exe -u -p 9020 -s 1368C:\Windows\SysWOW64\WerFault.exe
SamFwTool.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
3944C:\WINDOWS\SysWOW64\WerFault.exe -u -p 7884 -s 1396C:\Windows\SysWOW64\WerFault.exe
SamFwTool.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
4756"C:\Users\admin\AppData\Local\Temp\Rar$EXb7636.19119\SamFwTool.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb7636.19119\SamFwTool.exeWinRAR.exe
User:
admin
Company:
SamFw.com
Integrity Level:
MEDIUM
Description:
SamFwTool
Exit code:
3221226540
Version:
5.4.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb7636.19119\samfwtool.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
5548C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7244C:\WINDOWS\SysWOW64\WerFault.exe -u -p 1324 -s 1388C:\Windows\SysWOW64\WerFault.exe
SamFwTool.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
7636"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\MDE_File_Sample_e247901083648ee7f4e8e85652e90604851c7d4f.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
7884"C:\Users\admin\AppData\Local\Temp\Rar$EXb7636.17283\SamFwTool.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb7636.17283\SamFwTool.exe
WinRAR.exe
User:
admin
Company:
SamFw.com
Integrity Level:
HIGH
Description:
SamFwTool
Exit code:
3762504530
Version:
5.4.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb7636.17283\samfwtool.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
7980"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\MDE_File_Sample_e247901083648ee7f4e8e85652e90604851c7d4f.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
13 477
Read events
13 420
Write events
48
Delete events
9

Modification events

(PID) Process:(7636) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(7636) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(7636) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(7636) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(7636) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Downloads\chromium_build 1.zip
(PID) Process:(7636) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\MDE_File_Sample_e247901083648ee7f4e8e85652e90604851c7d4f.zip
(PID) Process:(7636) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(7636) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(7636) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(7636) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
3
Suspicious files
7
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
3944WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_SamFwTool.exe_6246c8a85aad34f2e2284427f47a0f1a8ad9f0_cff04333_ccf1ce4d-9978-44ff-8394-f9774461cb1e\Report.wer
MD5:
SHA256:
3944WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\SamFwTool.exe.7884.dmp
MD5:
SHA256:
2360WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_SamFwTool.exe_6246c8a85aad34f2e2284427f47a0f1a8ad9f0_cff04333_95cf75ed-07c7-43cb-9819-a64c08e5d3d8\Report.wer
MD5:
SHA256:
2360WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\SamFwTool.exe.9020.dmp
MD5:
SHA256:
7244WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_SamFwTool.exe_6246c8a85aad34f2e2284427f47a0f1a8ad9f0_cff04333_81a5200e-cb4b-4e79-8f0e-aeef4fa565cc\Report.wer
MD5:
SHA256:
7244WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\SamFwTool.exe.1324.dmp
MD5:
SHA256:
3944WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\37C951188967C8EB88D99893D9D191FEbinary
MD5:05DDF56FC804F432398703E32AF90A79
SHA256:7193D01CF9580401784B76B581FABC0D63B97D49977EDD15370DF6967EF2F443
3944WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\21253908F3CB05D51B1C2DA8B681A785binary
MD5:1A3A08F5EC73273F18F9F94289DDA6B7
SHA256:2E306230AA41D2C40649BBB57E2F1EB54E6ACF15C6206B0AAABBDBA47A387462
7636WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb7636.17283\SamFwTool.exeexecutable
MD5:B61F634ACA0B1C6C17DD9F2674F56FC4
SHA256:7BD9223FCE3C81EB751D34AE8489F1C3669E31C3DBAF7520E14B04AD4DFAD925
3944WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERB0FF.tmp.WERInternalMetadata.xmlxml
MD5:DD66953415FBE5ECA2E3D6D23E4611B6
SHA256:E532CA384FF109FB22FC209C7D2C0439E2BF1B76860E370D239A97735260F4AE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
46
TCP/UDP connections
33
DNS requests
25
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6768
MoUsoCoreWorker.exe
GET
304
51.104.136.2:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
US
whitelisted
5900
svchost.exe
GET
304
51.124.78.146:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/UpdateHealthTools?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&sampleId=s:95271487&appVer=10.0.19041.3626&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=SedimentPack&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
whitelisted
356
svchost.exe
POST
200
20.190.159.130:443
https://login.live.com/RST2.srf
US
xml
1.24 Kb
whitelisted
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQ3L3%2F%2Fa6ADK8NraY2GXzVaYrHG4AQUb6t%2B2v%2BXQ3LsO2d33oJhNYhHQoUCEzMAAAAGb6JMMcOVb6sAAAAAAAY%3D
US
binary
959 b
whitelisted
GET
200
23.11.40.157:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAjTxtAB8my1oj8MfWpz%2F7Y%3D
NL
binary
314 b
whitelisted
356
svchost.exe
POST
400
20.190.159.130:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
356
svchost.exe
POST
400
20.190.159.130:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
356
svchost.exe
POST
400
20.190.159.130:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
356
svchost.exe
GET
200
23.11.40.157:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
NL
binary
471 b
whitelisted
356
svchost.exe
POST
400
20.190.159.130:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
5900
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
8176
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5568
SearchApp.exe
2.16.204.141:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
23.11.40.157:80
ocsp.digicert.com
AKAMAI-AMS
NL
whitelisted
204.79.197.203:80
oneocsp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
356
svchost.exe
20.190.159.130:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 51.104.136.2
whitelisted
self.events.data.microsoft.com
  • 52.182.143.210
whitelisted
google.com
  • 142.251.208.14
whitelisted
www.bing.com
  • 2.16.204.141
  • 2.16.204.143
  • 2.16.204.150
  • 2.16.204.149
  • 2.16.204.146
  • 2.16.204.147
  • 2.16.204.145
  • 2.16.204.151
  • 2.16.204.139
whitelisted
ocsp.digicert.com
  • 23.11.40.157
whitelisted
oneocsp.microsoft.com
  • 204.79.197.203
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 20.190.159.130
  • 40.126.31.0
  • 20.190.159.68
  • 40.126.31.129
  • 40.126.31.3
  • 40.126.31.67
  • 20.190.159.0
  • 40.126.31.2
  • 40.126.31.71
  • 20.190.159.2
  • 20.190.159.131
  • 20.190.159.23
  • 40.126.31.128
  • 20.190.159.75
whitelisted
crl.microsoft.com
  • 23.53.41.90
  • 23.53.40.178
  • 23.216.77.15
  • 23.216.77.21
  • 23.216.77.20
  • 23.216.77.42
  • 23.216.77.6
  • 23.216.77.38
  • 23.216.77.41
  • 23.216.77.5
  • 23.216.77.7
whitelisted
www.microsoft.com
  • 23.59.18.102
  • 23.209.214.100
whitelisted

Threats

PID
Process
Class
Message
5900
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info