Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
InstallDriver.exe

Overview

General Information

Sample name:InstallDriver.exe
Analysis ID:1428974
MD5:f25a0a82ad1eefd4becd6f034c078dbc
SHA1:75c1063c318bd528b90e8a29bfc419beb1d35654
SHA256:2f6cef951a937f898ff24bc6adcdffb321b55fd3d21769ca9580e0233bbeed5a
Infos:

Detection

Score:2
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
May sleep (evasive loops) to hinder dynamic analysis
Queries disk information (often used to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Uses 32bit PE files

Classification

Analysis Advice

Sample monitors window changes (e.g. starting applications), analyze the sample with the 'Simulates keyboard and window changes' cookbook
Sample tries to load a library which is not present or installed on the analysis machine, adding the library might reveal more behavior
  • System is w10x64_ra
  • InstallDriver.exe (PID: 7016 cmdline: "C:\Users\user\Desktop\InstallDriver.exe" MD5: F25A0A82AD1EEFD4BECD6F034C078DBC)
  • Music.UI.exe (PID: 2196 cmdline: "C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe" -ServerName:Microsoft.ZuneMusic.AppX48dcrcgzqqdshm3kf61t0cm5e9pyd6h6.mca MD5: F963F75C0AD152437E10D656A00793A3)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: InstallDriver.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: Binary string: e:\My Documents\Visual Studio 2005\Projects\inpout32_source_and_bins\Inpout32_dll_source\Win32\Release\InstallDriver.pdb source: InstallDriver.exe
Source: Binary string: e:\My Documents\Visual Studio 2005\Projects\inpout32_source_and_bins\Inpout32_dll_source\Win32\Release\InstallDriver.pdb),TXi source: InstallDriver.exe
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownDNS traffic detected: queries for: settings-ssl.xboxlive.com
Source: Music.UI.exe, 00000011.00000002.2382048622.0000018F37413000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ns.a.0
Source: Music.UI.exe, 00000011.00000002.2382048622.0000018F37413000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ns.adobe.ho
Source: Music.UI.exe, 00000011.00000002.2398245124.0000018F38579000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://activity.windows.com/UserActivity.ReadWrite.CreatedByApp82hN
Source: Music.UI.exe, 00000011.00000002.2399528212.0000018F38600000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://android.notify.windows.com/iOS
Source: Music.UI.exe, 00000011.00000002.2399528212.0000018F38600000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://android.notify.windows.com/iOShttps://android.notify.windows.com/iOS
Source: Music.UI.exe, 00000011.00000002.2403976447.0000018F38824000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.live.com
Source: Music.UI.exe, 00000011.00000002.2403976447.0000018F38824000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.live.com/
Source: Music.UI.exe, 00000011.00000002.2398059478.0000018F38568000.00000004.00000020.00020000.00000000.sdmp, Music.UI.exe, 00000011.00000002.2393104911.0000018F37D86000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.windows.local
Source: Music.UI.exe, 00000011.00000002.2393104911.0000018F37D86000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.windows.local/
Source: Music.UI.exe, 00000011.00000002.2401689816.0000018F386CD000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.windows.net
Source: Music.UI.exe, 00000011.00000002.2401689816.0000018F386CD000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.windows.net/n
Source: Music.UI.exe, 00000011.00000002.2401689816.0000018F386CD000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.windows.net8AHSM
Source: Music.UI.exe, 00000011.00000002.2389150141.0000018F37C00000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://musicart.xboxlive.com/9/5c6a4700-0000-0000-0000-000000000002/504/image.jpg
Source: Music.UI.exe, 00000011.00000002.2389150141.0000018F37C00000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://musicart.xboxlive.com/9/e74d4600-0000-0000-0000-000000000002/504/image.jpg
Source: Music.UI.exe, 00000011.00000003.1913149954.0000018F3775F000.00000004.00000020.00020000.00000000.sdmp, Music.UI.exe, 00000011.00000002.2387013615.0000018F3776E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://musicimage.xboxlive.comtXBLWinClient/v10_music/configuration.xml
Source: Music.UI.exe, 00000011.00000002.2379989061.0000018F36F38000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://settings-ssl.xboxlive.com
Source: Music.UI.exe, 00000011.00000003.1913149954.0000018F3775F000.00000004.00000020.00020000.00000000.sdmp, Music.UI.exe, 00000011.00000002.2387013615.0000018F37780000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://settings-ssl.xboxlive.com/
Source: Music.UI.exe, 00000011.00000003.1913149954.0000018F3775F000.00000004.00000020.00020000.00000000.sdmp, Music.UI.exe, 00000011.00000002.2387013615.0000018F3776E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://settings-ssl.xboxlive.com/XBLWinClient/v10_music/configuration.xml
Source: Music.UI.exe, 00000011.00000003.1913149954.0000018F3775F000.00000004.00000020.00020000.00000000.sdmp, Music.UI.exe, 00000011.00000002.2387013615.0000018F3776E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://settings-ssl.xboxlive.com/XBLWinClient/v10_music/configuration.xmlAC
Source: Music.UI.exe, 00000011.00000002.2386766345.0000018F37700000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://wns.windows.com/
Source: Music.UI.exe, 00000011.00000002.2401689816.0000018F386CD000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://xsts.auth.xboxlive.com
Source: Music.UI.exe, 00000011.00000002.2401689816.0000018F386CD000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://xsts.auth.xboxlive.com/
Source: Music.UI.exe, 00000011.00000002.2389150141.0000018F37C00000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://xsts.auth.xboxlive.comngpng(
Source: InstallDriver.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: classification engineClassification label: clean2.winEXE@2/14@1/0
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\Jump to behavior
Source: InstallDriver.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\InstallDriver.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: unknownProcess created: C:\Users\user\Desktop\InstallDriver.exe "C:\Users\user\Desktop\InstallDriver.exe"
Source: unknownProcess created: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe "C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe" -ServerName:Microsoft.ZuneMusic.AppX48dcrcgzqqdshm3kf61t0cm5e9pyd6h6.mca
Source: C:\Users\user\Desktop\InstallDriver.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\InstallDriver.exeSection loaded: inpout32.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: d3d11.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: sharedui.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: vccorlib140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: msvcp140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: concrt140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: vcruntime140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: vcruntime140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: msvcp140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: vcruntime140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: dxgi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.ui.xaml.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: bcp47langs.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: dcomp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: twinapi.appcore.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.staterepositorycore.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.ui.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windowmanagementapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: inputhost.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: propsys.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: netutils.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: resourcepolicyclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: dxcore.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: d2d1.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: dwrite.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: rometadata.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.applicationmodel.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: esent.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.storage.applicationdata.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: wldp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: logoncli.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mrmcorer.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.staterepositoryclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: profapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: appxdeploymentclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: bcp47mrm.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.ui.xaml.controls.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.shell.servicehostbuilder.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: execmodelproxy.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: rmclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: uiamanager.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.ui.core.textinput.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.ui.immersive.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: dataexchange.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: threadpoolwinrt.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.globalization.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.system.profile.retailinfo.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.media.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.applicationmodel.lockscreen.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: wincorlib.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: lockappbroker.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.graphics.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.ui.xaml.phone.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: twinapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.networking.connectivity.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.media.playback.mediaplayer.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mfplat.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: rtworkq.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.media.mediacontrol.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mmdevapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: devobj.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mfmediaengine.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: xmllite.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: audioses.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.media.devices.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.media.playback.proxystub.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: comppkgsup.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.devices.enumeration.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: devdispitemprovider.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: ddores.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: defaultdevicemanager.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: directmanipulation.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: msftedit.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: globinputhost.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: msxml6.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.web.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: wpnapps.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windowscodecs.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: photometadatahandler.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: wuceffects.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: wininet.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.networking.backgroundtransfer.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: systemeventsbrokerclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: userenv.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: profext.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: winnsi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: biwinrt.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: dnsapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: rasadhlp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: fwpuclnt.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: schannel.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.security.authentication.web.core.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: onecorecommonproxystub.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: vaultcli.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.staterepositoryps.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: microsoftaccountwamextension.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mskeyprotect.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: ncryptsslp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: dpapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: gpapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mfsrcsnk.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: appcontracts.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: usermgrproxy.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: cdprt.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: cdp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: dsreg.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mfps.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mfmp4srcsnk.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: msamrnbsource.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mfasfsrcsnk.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mfds.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: gnsdk_fp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: msflacdecoder.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: avrt.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mfmpeg2srcsnk.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mfmkvsrcsnk.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mfnetsrc.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mfnetcore.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: dwmapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32Jump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeFile opened: C:\Windows\SYSTEM32\msftedit.dllJump to behavior
Source: InstallDriver.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: e:\My Documents\Visual Studio 2005\Projects\inpout32_source_and_bins\Inpout32_dll_source\Win32\Release\InstallDriver.pdb source: InstallDriver.exe
Source: Binary string: e:\My Documents\Visual Studio 2005\Projects\inpout32_source_and_bins\Inpout32_dll_source\Win32\Release\InstallDriver.pdb),TXi source: InstallDriver.exe
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeWindow / User API: threadDelayed 381Jump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe TID: 3640Thread sleep count: 381 > 30Jump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe TID: 3640Thread sleep time: -32918400000s >= -30000sJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe TID: 3640Thread sleep time: -86400000s >= -30000sJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeFile opened: PhysicalDrive0Jump to behavior
Source: Music.UI.exe, 00000011.00000002.2389688641.0000018F37C57000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\edbtmp.log VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\edbtmp.log VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\edbres00001.jrs VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\edb.log VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\edb.log VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\edb.log VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\edb.chk VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\EntClientDb.jfm VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\EntClientDb.edb VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\EntClientDb.edb VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\tmp.edb VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\edb.chk VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Resources\Fonts\SegMVR2.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Resources\Fonts\SegMVR2.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Resources\Fonts\SegMVR2.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Resources\Fonts\SegMVR2.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Resources\Fonts\SegMVR2.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Windows\Fonts\segoeuisl.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\SRPData.xml VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\DiagOutputDir VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\DiagOutputDir\CriticalError_playbackTrace_1715897156.txt VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Windows\Fonts\segoeuil.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Windows\Fonts\segmdl2.ttf VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
DLL Side-Loading
1
Process Injection
1
Masquerading
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Application Layer Protocol
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
2
Virtualization/Sandbox Evasion
LSASS Memory2
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Process Injection
Security Account Manager1
Application Window Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
DLL Side-Loading
NTDS21
System Information Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1428974 Sample: InstallDriver.exe Startdate: 20/04/2024 Architecture: WINDOWS Score: 2 9 settings-ssl.xboxlive.com 2->9 5 Music.UI.exe 63 40 2->5         started        7 InstallDriver.exe 2->7         started        process3

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
InstallDriver.exe0%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://login.windows.local0%URL Reputationsafe
https://login.windows.local/0%URL Reputationsafe
NameIPActiveMaliciousAntivirus DetectionReputation
settings-ssl.xboxlive.com
unknown
unknownfalse
    high
    NameSourceMaliciousAntivirus DetectionReputation
    https://login.windows.localMusic.UI.exe, 00000011.00000002.2398059478.0000018F38568000.00000004.00000020.00020000.00000000.sdmp, Music.UI.exe, 00000011.00000002.2393104911.0000018F37D86000.00000004.00000020.00020000.00000000.sdmpfalse
    • URL Reputation: safe
    unknown
    https://login.windows.netMusic.UI.exe, 00000011.00000002.2401689816.0000018F386CD000.00000004.00000020.00020000.00000000.sdmpfalse
      high
      https://settings-ssl.xboxlive.com/XBLWinClient/v10_music/configuration.xmlMusic.UI.exe, 00000011.00000003.1913149954.0000018F3775F000.00000004.00000020.00020000.00000000.sdmp, Music.UI.exe, 00000011.00000002.2387013615.0000018F3776E000.00000004.00000020.00020000.00000000.sdmpfalse
        high
        https://settings-ssl.xboxlive.comMusic.UI.exe, 00000011.00000002.2379989061.0000018F36F38000.00000004.00000020.00020000.00000000.sdmpfalse
          high
          https://login.windows.net8AHSMMusic.UI.exe, 00000011.00000002.2401689816.0000018F386CD000.00000004.00000020.00020000.00000000.sdmpfalse
            unknown
            https://musicimage.xboxlive.comtXBLWinClient/v10_music/configuration.xmlMusic.UI.exe, 00000011.00000003.1913149954.0000018F3775F000.00000004.00000020.00020000.00000000.sdmp, Music.UI.exe, 00000011.00000002.2387013615.0000018F3776E000.00000004.00000020.00020000.00000000.sdmpfalse
              unknown
              https://android.notify.windows.com/iOSMusic.UI.exe, 00000011.00000002.2399528212.0000018F38600000.00000004.00000020.00020000.00000000.sdmpfalse
                high
                https://xsts.auth.xboxlive.comMusic.UI.exe, 00000011.00000002.2401689816.0000018F386CD000.00000004.00000020.00020000.00000000.sdmpfalse
                  high
                  https://android.notify.windows.com/iOShttps://android.notify.windows.com/iOSMusic.UI.exe, 00000011.00000002.2399528212.0000018F38600000.00000004.00000020.00020000.00000000.sdmpfalse
                    high
                    https://musicart.xboxlive.com/9/e74d4600-0000-0000-0000-000000000002/504/image.jpgMusic.UI.exe, 00000011.00000002.2389150141.0000018F37C00000.00000004.00000020.00020000.00000000.sdmpfalse
                      high
                      https://xsts.auth.xboxlive.comngpng(Music.UI.exe, 00000011.00000002.2389150141.0000018F37C00000.00000004.00000020.00020000.00000000.sdmpfalse
                        low
                        https://settings-ssl.xboxlive.com/Music.UI.exe, 00000011.00000003.1913149954.0000018F3775F000.00000004.00000020.00020000.00000000.sdmp, Music.UI.exe, 00000011.00000002.2387013615.0000018F37780000.00000004.00000020.00020000.00000000.sdmpfalse
                          high
                          https://musicart.xboxlive.com/9/5c6a4700-0000-0000-0000-000000000002/504/image.jpgMusic.UI.exe, 00000011.00000002.2389150141.0000018F37C00000.00000004.00000020.00020000.00000000.sdmpfalse
                            high
                            http://ns.a.0Music.UI.exe, 00000011.00000002.2382048622.0000018F37413000.00000004.00000020.00020000.00000000.sdmpfalse
                              low
                              https://wns.windows.com/Music.UI.exe, 00000011.00000002.2386766345.0000018F37700000.00000004.00000020.00020000.00000000.sdmpfalse
                                high
                                http://ns.adobe.hoMusic.UI.exe, 00000011.00000002.2382048622.0000018F37413000.00000004.00000020.00020000.00000000.sdmpfalse
                                  unknown
                                  https://activity.windows.com/UserActivity.ReadWrite.CreatedByApp82hNMusic.UI.exe, 00000011.00000002.2398245124.0000018F38579000.00000004.00000020.00020000.00000000.sdmpfalse
                                    high
                                    https://login.windows.net/nMusic.UI.exe, 00000011.00000002.2401689816.0000018F386CD000.00000004.00000020.00020000.00000000.sdmpfalse
                                      high
                                      https://login.windows.local/Music.UI.exe, 00000011.00000002.2393104911.0000018F37D86000.00000004.00000020.00020000.00000000.sdmpfalse
                                      • URL Reputation: safe
                                      unknown
                                      https://settings-ssl.xboxlive.com/XBLWinClient/v10_music/configuration.xmlACMusic.UI.exe, 00000011.00000003.1913149954.0000018F3775F000.00000004.00000020.00020000.00000000.sdmp, Music.UI.exe, 00000011.00000002.2387013615.0000018F3776E000.00000004.00000020.00020000.00000000.sdmpfalse
                                        high
                                        https://xsts.auth.xboxlive.com/Music.UI.exe, 00000011.00000002.2401689816.0000018F386CD000.00000004.00000020.00020000.00000000.sdmpfalse
                                          high
                                          No contacted IP infos
                                          Joe Sandbox version:40.0.0 Tourmaline
                                          Analysis ID:1428974
                                          Start date and time:2024-04-20 00:04:13 +02:00
                                          Joe Sandbox product:CloudBasic
                                          Overall analysis duration:0h 4m 19s
                                          Hypervisor based Inspection enabled:false
                                          Report type:full
                                          Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                          Number of analysed new started processes analysed:25
                                          Number of new started drivers analysed:0
                                          Number of existing processes analysed:0
                                          Number of existing drivers analysed:0
                                          Number of injected processes analysed:0
                                          Technologies:
                                          • HCA enabled
                                          • EGA enabled
                                          • AMSI enabled
                                          Analysis Mode:default
                                          Analysis stop reason:Timeout
                                          Sample name:InstallDriver.exe
                                          Detection:CLEAN
                                          Classification:clean2.winEXE@2/14@1/0
                                          EGA Information:Failed
                                          HCA Information:
                                          • Successful, ratio: 100%
                                          • Number of executed functions: 0
                                          • Number of non-executed functions: 0
                                          Cookbook Comments:
                                          • Found application associated with file extension: .exe
                                          • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, BackgroundTransferHost.exe, RuntimeBroker.exe, SIHClient.exe, Microsoft.Photos.exe, SgrmBroker.exe, MoUsoCoreWorker.exe, conhost.exe, backgroundTaskHost.exe, svchost.exe
                                          • Excluded IPs from analysis (whitelisted): 23.63.156.44
                                          • Excluded domains from analysis (whitelisted): fs.microsoft.com, slscr.update.microsoft.com, login.live.com, ctldl.windowsupdate.com, settings-ssl.xboxlive.com.edgekey.net, e87.dspb.akamaiedge.net, fe3cr.delivery.mp.microsoft.com
                                          • Not all processes where analyzed, report is missing behavior information
                                          • Report size getting too big, too many NtOpenKey calls found.
                                          • Report size getting too big, too many NtOpenKeyEx calls found.
                                          • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                          • Report size getting too big, too many NtQueryValueKey calls found.
                                          • VT rate limit hit for: InstallDriver.exe
                                          TimeTypeDescription
                                          00:05:56API Interceptor451x Sleep call for process: Music.UI.exe modified
                                          No context
                                          No context
                                          No context
                                          No context
                                          No context
                                          Process:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                          File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                          Category:dropped
                                          Size (bytes):2659
                                          Entropy (8bit):4.926959150875136
                                          Encrypted:false
                                          SSDEEP:48:cK88z2Dxfo++T4Vu5Hj2oJ//QBfM9ifr9jf2dBfUyrAf0dPfUytCfN4wc/+:n88z2DxueBQipjQB8BWP8pc+
                                          MD5:69415BBB2113097CE28402C78AAB8A1D
                                          SHA1:3CC52AA27D635F22434CFEAD93C27D3B5287BF2E
                                          SHA-256:95458051B4940AA84E142A19F4F775901CBFADC6BDEC409FC7C9DAC854FC8910
                                          SHA-512:03C62FF862F73046C45D6495D6E5E821ACBD228A230E6761DEE9E8A4E48F157CE3566E6E06FE8CACA73D4736B6AC78A4914855CDE4037574D8DBF86B2B2A0B54
                                          Malicious:false
                                          Reputation:moderate, very likely benign file
                                          Preview:<?xml version="1.0" encoding="utf-8"?>..<clientConfiguration xmlns="http://schemas.microsoft.com/XblWinClient/2012/03" version="1">.. <targetedClient>XblWinClient</targetedClient > .. <rights>Copyright (c) Microsoft Corporation. All rights reserved.</rights> .... <configuration name="Features">.. <property name="EditorialPlaylistsEnabled" type="string" value="AU,CA,DE,FR,GB,MX,NZ,US" />.. <property name="ExploreWithGenreDetailsEnabled" type="string" value="AU,CA,DE,FR,GB,MX,NZ,US" />.. <property name="GenreRadioEnabled" type="string" value="AU,CA,DE,FR,GB,MX,NZ,US" />.. <property name="MusicPassUpsell" type="string" value="" />.. <property name="MusicPassUpsellForCollectionPDP" type="string" value="" />.. <property name="MusicPassUpsellInMixtapes" type="string" value="" />.. <property name="MusicPassInAppPurchase" type="string" value="" />.. <property name="MusicSubscription" type="stri
                                          Process:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                          File Type:Extensible storage engine DataBase, version 0x620, checksum 0xde9a0322, page size 8192, DirtyShutdown, Windows version 10.0
                                          Category:dropped
                                          Size (bytes):3670016
                                          Entropy (8bit):0.2950584082208883
                                          Encrypted:false
                                          SSDEEP:1536:BdSh2d9KY8k/fnbfgTC0/k63bBu7fhWxM/46USh29KY8k2xyDFqfaLgTC0/k63bm:P6wLFNA6U6SLEQR6
                                          MD5:A0B429093F220DEF05533F67BAB23331
                                          SHA1:6EFBBF43068F56AE977B8D944A3098722960FCEF
                                          SHA-256:DD6518682C19E13A2CEB6BB686135F73B76D571D6940CCD4D048E1D3F4718A2E
                                          SHA-512:E7B1ED025F12227469EA4DF8F2C3B01EA36D9DFD86A505D449B819233D398149A6DA9C85E20E9DC983A737B251BC72E30094CD95701674AD4740895E61728AE6
                                          Malicious:false
                                          Reputation:low
                                          Preview:.."... .......-........e..8....|m.....................................8....|..h.............................\8....|?.........................................................................................................eJ........... ...................................................................................................... .......8....|?.................................................8....|......................................................................................................................................8....|....................................|58....|E.....................8....|..........................................................................................................................................................................................................................................................................................................................................................................................
                                          Process:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                          File Type:data
                                          Category:dropped
                                          Size (bytes):16384
                                          Entropy (8bit):0.08390289220277451
                                          Encrypted:false
                                          SSDEEP:3:GJXYtvgQ2Xlll1lVgzSH3qiQR4izSHall7WWtXnl2n+9s9k/q/Qs9aclQ1Hl/l:yXYtvgXl/1+wniHSF/Icy
                                          MD5:48369515BB495C6A07619ACB1AC3C831
                                          SHA1:1B6E17215BA5BFF29C53826955F96C61BBB61534
                                          SHA-256:708B0718373D1AD0190773A2BF743B26F5465820E275161A78FAEEFB79A34FCC
                                          SHA-512:4FE7153809212230ED16E2A35ED1DFE85B9E877B979863BA9F9243B9F054D051A10C6544620D49DECF759F2677313BFBB85B8CC7FD9D280B143BBD44B1298C90
                                          Malicious:false
                                          Reputation:low
                                          Preview:../5....................................8....|m.8....|m.................8....|...........'.z8....|......................8....|..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                          Process:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                          File Type:data
                                          Category:dropped
                                          Size (bytes):8192
                                          Entropy (8bit):0.6123381902501969
                                          Encrypted:false
                                          SSDEEP:12:Ku1wUIPxJ1qwUIPxJ1GQelR2u1wUIPxJ1qwUIPxJ1GQelR:71wUCx/qwUCx/Gd1wUCx/qwUCx/G
                                          MD5:EB9670F79E9DF79C958FF3A7DBB52DB0
                                          SHA1:78ABE1EB6018F116129315251C2E65CE76C3ED99
                                          SHA-256:6DBFD3AE36DBD30B5D22079795CDECB844C470472A28C9D745F6B1E9CDDDC2F3
                                          SHA-512:DEE6057903806EA864CD13547E2D515F6D1571BC4B2F57A2F1D9E228022414E41B37F8BE5B5EB6EC7CB76D424406B87739A28ED25E552DD4CD55A20918D7D4FC
                                          Malicious:false
                                          Reputation:low
                                          Preview:.bE...................\8....|?.................C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\................................................................................................................................................................C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\.................................................................................................................................................................0u..,.....................5w.................................................................................................................................................................................................................................................................................................................................................................................................................
                                          Process:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                          File Type:data
                                          Category:dropped
                                          Size (bytes):2097152
                                          Entropy (8bit):0.7400993880126588
                                          Encrypted:false
                                          SSDEEP:1536:TLf6R1dtEBmHltDulBuuia+ciy+zW8baf4lBiNO8WfO4odiFY1Z38AZ5yeh0G32l:TLf6R7DhXOhz9hCQlsNqKs3v
                                          MD5:A2319084E6965D19091DA9A82C86823A
                                          SHA1:78A796FD9766F96508838FBCC7709D6FBBC4C468
                                          SHA-256:E331D6D729497C3F5089745B454B931FFE4792FF4C222AF4279B90D125EF3B21
                                          SHA-512:C49B52CC59F244F22D43E1D57A1BF6C20C6E2155B9C9D8CB2BAF4CEB4FFED32A0E9D99907695F67E5793AA0CE54CC45E768C3174DA1CA40E70F16E26BD1C3C5C
                                          Malicious:false
                                          Reputation:low
                                          Preview:3.^............ 8....|?.......................\8....|?.................C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\................................................................................................................................................................C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\.................................................................................................................................................................0u..,.....................5w.......................................#.................................................................................................................................................................................................................................................................................................................................................
                                          Process:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                          File Type:data
                                          Category:dropped
                                          Size (bytes):2097152
                                          Entropy (8bit):0.0
                                          Encrypted:false
                                          SSDEEP:3::
                                          MD5:B2D1236C286A3C0704224FE4105ECA49
                                          SHA1:7D76D48D64D7AC5411D714A4BB83F37E3E5B8DF6
                                          SHA-256:5647F05EC18958947D32874EEB788FA396A05D0BAB7C1B71F112CEB7E9B31EEE
                                          SHA-512:731859029215873FDAC1C9F2F8BD25A334ABF0F3A9E1B057CF2CACC2826D86B0C26A3FA920A936421401C0471F38857CB53BA905489EA46B185209FDFF65B3B6
                                          Malicious:false
                                          Reputation:moderate, very likely benign file
                                          Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                          Process:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                          File Type:data
                                          Category:dropped
                                          Size (bytes):2097152
                                          Entropy (8bit):0.0
                                          Encrypted:false
                                          SSDEEP:3::
                                          MD5:B2D1236C286A3C0704224FE4105ECA49
                                          SHA1:7D76D48D64D7AC5411D714A4BB83F37E3E5B8DF6
                                          SHA-256:5647F05EC18958947D32874EEB788FA396A05D0BAB7C1B71F112CEB7E9B31EEE
                                          SHA-512:731859029215873FDAC1C9F2F8BD25A334ABF0F3A9E1B057CF2CACC2826D86B0C26A3FA920A936421401C0471F38857CB53BA905489EA46B185209FDFF65B3B6
                                          Malicious:false
                                          Reputation:moderate, very likely benign file
                                          Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                          Process:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                          File Type:data
                                          Category:dropped
                                          Size (bytes):2097152
                                          Entropy (8bit):0.0
                                          Encrypted:false
                                          SSDEEP:3::
                                          MD5:B2D1236C286A3C0704224FE4105ECA49
                                          SHA1:7D76D48D64D7AC5411D714A4BB83F37E3E5B8DF6
                                          SHA-256:5647F05EC18958947D32874EEB788FA396A05D0BAB7C1B71F112CEB7E9B31EEE
                                          SHA-512:731859029215873FDAC1C9F2F8BD25A334ABF0F3A9E1B057CF2CACC2826D86B0C26A3FA920A936421401C0471F38857CB53BA905489EA46B185209FDFF65B3B6
                                          Malicious:false
                                          Reputation:moderate, very likely benign file
                                          Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                          Process:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                          File Type:Extensible storage engine DataBase, version 0x620, checksum 0xf2644874, page size 8192, JustCreated, Windows version 0.0
                                          Category:dropped
                                          Size (bytes):262144
                                          Entropy (8bit):0.14192384005184558
                                          Encrypted:false
                                          SSDEEP:768:E2gAhY+VxEyVjqaytqxUSYQHDmit8UPcim:bhY+VxEyVjqaytqxUSYQHDmit8UPcim
                                          MD5:2EF4BC0B2AF8FF7F5F43BA44CF90858C
                                          SHA1:0D74ECD75C321FC9C2F53F61B2C18EAA5F30649D
                                          SHA-256:E2AC2E2855FACFBA1967DE727ADFECF64F03A51C9CC3F1B2405D2EC6B46F7A60
                                          SHA-512:F82363F47B36D0CC2B9F56E34F4E7EC815354A34EEC6FC93EC707480490D2BE1C10132B7F482308B41B6767BB2CBCB06EFE20F12723FB203DFF66380AD185033
                                          Malicious:false
                                          Reputation:low
                                          Preview:.dHt... .......@...........8....|........................................................................................................................................................................................................... ...................................................................................................... ...................................................................................................................................................................................................................................................$...8....|.9....................................................................................................................................................................................................................................................................................................................................................................................................................
                                          Process:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                          File Type:ASCII text
                                          Category:dropped
                                          Size (bytes):40866
                                          Entropy (8bit):5.3162149368399225
                                          Encrypted:false
                                          SSDEEP:768:mBBBRX5y7OJEDws21uP+cYWblAyLsrpppSGrVsWsXOFOogPgqg6gOOGsWgitDGne:mBBdZs21uP+cYWblAyLsrpppSGraTeMh
                                          MD5:64D891F22EE6F5AB2B1E2C1A7D4A0295
                                          SHA1:E8E48872A4C4F3DEF76134E322F2C71225593833
                                          SHA-256:2D65BFAE05385E4DB00F0FF9C8C94ECFC49178CB1E9C1F23267E6BC67C75D8A5
                                          SHA-512:0EBCD485EC0BC980E33A002E952360B1CF26557762C424389153C29E2AEA10774E7AAF53909817908D5365BF14C9C49D97C93085BF3274F62713C11927037B3E
                                          Malicious:false
                                          Reputation:low
                                          Preview:1.04/22/24 01:57:50.2228.MS::Entertainment::Music::Playback::PlaybackProperties::AppActivationKind::set - value = File.2.04/26/24 01:57:50.4372.MS::Entertainment::Core::Services::MemoryLimitsInformationService::OnAppMemoryUsageLimitChanging - Memory Usage Limit Changed to 18446744073709551615 from 18446744073709551615, our current usage is 19480576.3.04/26/24 01:57:50.2228.MS::Entertainment::Music::Playback::PlaylistPlaybackService::PlaylistPlaybackService.4.04/26/24 01:57:50.4636.MS::Entertainment::Core::Services::MemoryLimitsInformationService::OnAppMemoryUsageIncreased - App memory usage level increased to Low, Total commit is 19480576 .5.04/26/24 01:57:50.2228.MS::Entertainment::Music::Playback::PlaylistPlaybackService::PlaylistPlaybackService - userCid = .6.04/28/24 01:57:50.2228.MS::Entertainment::Music::Playback::MetadataProviderEventWrapper::MetadataProviderEventWrapper.7.04/28/24 01:57:50.2228.MS::Entertainment::Music::Playback::SharedEvent::GetHandle - Event EnterpriseDataPro
                                          Process:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                          File Type:ASCII text
                                          Category:dropped
                                          Size (bytes):40866
                                          Entropy (8bit):5.3162149368399225
                                          Encrypted:false
                                          SSDEEP:768:mBBBRX5y7OJEDws21uP+cYWblAyLsrpppSGrVsWsXOFOogPgqg6gOOGsWgitDGne:mBBdZs21uP+cYWblAyLsrpppSGraTeMh
                                          MD5:64D891F22EE6F5AB2B1E2C1A7D4A0295
                                          SHA1:E8E48872A4C4F3DEF76134E322F2C71225593833
                                          SHA-256:2D65BFAE05385E4DB00F0FF9C8C94ECFC49178CB1E9C1F23267E6BC67C75D8A5
                                          SHA-512:0EBCD485EC0BC980E33A002E952360B1CF26557762C424389153C29E2AEA10774E7AAF53909817908D5365BF14C9C49D97C93085BF3274F62713C11927037B3E
                                          Malicious:false
                                          Reputation:low
                                          Preview:1.04/22/24 01:57:50.2228.MS::Entertainment::Music::Playback::PlaybackProperties::AppActivationKind::set - value = File.2.04/26/24 01:57:50.4372.MS::Entertainment::Core::Services::MemoryLimitsInformationService::OnAppMemoryUsageLimitChanging - Memory Usage Limit Changed to 18446744073709551615 from 18446744073709551615, our current usage is 19480576.3.04/26/24 01:57:50.2228.MS::Entertainment::Music::Playback::PlaylistPlaybackService::PlaylistPlaybackService.4.04/26/24 01:57:50.4636.MS::Entertainment::Core::Services::MemoryLimitsInformationService::OnAppMemoryUsageIncreased - App memory usage level increased to Low, Total commit is 19480576 .5.04/26/24 01:57:50.2228.MS::Entertainment::Music::Playback::PlaylistPlaybackService::PlaylistPlaybackService - userCid = .6.04/28/24 01:57:50.2228.MS::Entertainment::Music::Playback::MetadataProviderEventWrapper::MetadataProviderEventWrapper.7.04/28/24 01:57:50.2228.MS::Entertainment::Music::Playback::SharedEvent::GetHandle - Event EnterpriseDataPro
                                          Process:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                          File Type:ASCII text, with no line terminators
                                          Category:dropped
                                          Size (bytes):215
                                          Entropy (8bit):4.840898391480387
                                          Encrypted:false
                                          SSDEEP:3:uncHUTIqUHek8KIfFhKP4SfHUyLGewqcV3otRslUERrRD+EGmNrOVgNnb:e28IqUHeksNhy5mOw1SEGmNrDnb
                                          MD5:8E932FED9060096F7A1C355B1DD37B20
                                          SHA1:9EC80804A023F801409B30E196101EA1BBC5FCA8
                                          SHA-256:9AA87AC87F0B234F977AE2EF4D4F853065182E7E4BC47D9B1901FB2C28A0324F
                                          SHA-512:BCF405DAE69F73B4F8961E7DB6BBDA4679D8714813A27181CBB803A408C24A2C0DC9569D1897277CDE635904DF83DD2C80C660E5E2FD03D2720F9F778A98C146
                                          Malicious:false
                                          Preview:<SRPData version="1" sessionId="1"><Outcomes></Outcomes><Threshold launches="1" daysLaunched="1" dayOfLastLaunch="22" monthOfLastLaunch="5" yearOfLastLaunch="2024" userHasAccepted="false" timesPolled="0"/></SRPData>
                                          Process:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                          File Type:ASCII text, with no line terminators
                                          Category:dropped
                                          Size (bytes):215
                                          Entropy (8bit):4.840898391480387
                                          Encrypted:false
                                          SSDEEP:3:uncHUTIqUHek8KIfFhKP4SfHUyLGewqcV3otRslUERrRD+EGmNrOVgNnb:e28IqUHeksNhy5mOw1SEGmNrDnb
                                          MD5:8E932FED9060096F7A1C355B1DD37B20
                                          SHA1:9EC80804A023F801409B30E196101EA1BBC5FCA8
                                          SHA-256:9AA87AC87F0B234F977AE2EF4D4F853065182E7E4BC47D9B1901FB2C28A0324F
                                          SHA-512:BCF405DAE69F73B4F8961E7DB6BBDA4679D8714813A27181CBB803A408C24A2C0DC9569D1897277CDE635904DF83DD2C80C660E5E2FD03D2720F9F778A98C146
                                          Malicious:false
                                          Preview:<SRPData version="1" sessionId="1"><Outcomes></Outcomes><Threshold launches="1" daysLaunched="1" dayOfLastLaunch="22" monthOfLastLaunch="5" yearOfLastLaunch="2024" userHasAccepted="false" timesPolled="0"/></SRPData>
                                          Process:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                          File Type:MS Windows registry file, NT/2000 or above
                                          Category:dropped
                                          Size (bytes):16384
                                          Entropy (8bit):0.3734170645836998
                                          Encrypted:false
                                          SSDEEP:24:6E1+/r4WlVnQlDuUbwB7d82/+wB7svTnl/wZPo:TMJlVM87d37J
                                          MD5:4899D54A8778500AE2788774C9894643
                                          SHA1:158459B3FBC6498098411A075761B94E08D54A2F
                                          SHA-256:5DE7EA3AD3F174FB5CABC4D78C5CDA8F3B285709D8FE8D5E342739F9E1B38FF2
                                          SHA-512:4599DEA9A709C9FAC96A4749D9E039B8960C76C25C34FBD838754AF8FDAE0EE91125D011C3299008EEB26CF5F429A7651BF5321AEC088450A465474CCE16AA17
                                          Malicious:false
                                          Preview:regf........b.Q.7.................. ...........:.\.W.i.n.d.o.w.s.\.S.y.s.t.e.m.3.2.\.s.e.t.t.i.n.g.s...d.a.t...y..j.....J.....y..j.....J.........z..j.....J.....rmtmr.P.7..............................................................................................................................................................................................................................................................................................................................................@Q.G........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                          File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                          Entropy (8bit):5.657316217386607
                                          TrID:
                                          • Win32 Executable (generic) a (10002005/4) 99.96%
                                          • Generic Win/DOS Executable (2004/3) 0.02%
                                          • DOS Executable Generic (2002/1) 0.02%
                                          • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                          File name:InstallDriver.exe
                                          File size:49'152 bytes
                                          MD5:f25a0a82ad1eefd4becd6f034c078dbc
                                          SHA1:75c1063c318bd528b90e8a29bfc419beb1d35654
                                          SHA256:2f6cef951a937f898ff24bc6adcdffb321b55fd3d21769ca9580e0233bbeed5a
                                          SHA512:5d16a06664a22d95b4a9c553608456e1e9499c72db3fa76e429e3e3da83c9af589fa76f0b66c867976d71b26c4c6d5cc67afb1d0861af3751852368e5d7c7e3b
                                          SSDEEP:768:zsfqbtPnPlt0RBNxamrr1A081ZadarUq3XEOgbtwg:FbFP/0D3DriT18w1etwg
                                          TLSH:3523180A3893C033E41649B586E58AC15FFF7C133AF3A06FEF84454E1AA129899797F5
                                          File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........cK.............np......nc......n`.......P......nv..............n.......nq......nu.....Rich............................PE..L..
                                          Icon Hash:90cececece8e8eb0
                                          Entrypoint:0x4012cb
                                          Entrypoint Section:.text
                                          Digitally signed:false
                                          Imagebase:0x400000
                                          Subsystem:windows gui
                                          Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
                                          DLL Characteristics:
                                          Time Stamp:0x4D2F5F91 [Thu Jan 13 20:24:49 2011 UTC]
                                          TLS Callbacks:
                                          CLR (.Net) Version:
                                          OS Version Major:4
                                          OS Version Minor:0
                                          File Version Major:4
                                          File Version Minor:0
                                          Subsystem Version Major:4
                                          Subsystem Version Minor:0
                                          Import Hash:87cea554f9cb4b282bb296a63949bda0
                                          Instruction
                                          call 00007F5CAC9BBC3Bh
                                          jmp 00007F5CAC9BA28Ch
                                          push ebp
                                          mov ebp, esp
                                          sub esp, 00000328h
                                          mov dword ptr [0040ADD8h], eax
                                          mov dword ptr [0040ADD4h], ecx
                                          mov dword ptr [0040ADD0h], edx
                                          mov dword ptr [0040ADCCh], ebx
                                          mov dword ptr [0040ADC8h], esi
                                          mov dword ptr [0040ADC4h], edi
                                          mov word ptr [0040ADF0h], ss
                                          mov word ptr [0040ADE4h], cs
                                          mov word ptr [0040ADC0h], ds
                                          mov word ptr [0040ADBCh], es
                                          mov word ptr [0040ADB8h], fs
                                          mov word ptr [0040ADB4h], gs
                                          pushfd
                                          pop dword ptr [0040ADE8h]
                                          mov eax, dword ptr [ebp+00h]
                                          mov dword ptr [0040ADDCh], eax
                                          mov eax, dword ptr [ebp+04h]
                                          mov dword ptr [0040ADE0h], eax
                                          lea eax, dword ptr [ebp+08h]
                                          mov dword ptr [0040ADECh], eax
                                          mov eax, dword ptr [ebp-00000320h]
                                          mov dword ptr [0040AD28h], 00010001h
                                          mov eax, dword ptr [0040ADE0h]
                                          mov dword ptr [0040ACDCh], eax
                                          mov dword ptr [0040ACD0h], C0000409h
                                          mov dword ptr [0040ACD4h], 00000001h
                                          mov eax, dword ptr [0040A004h]
                                          mov dword ptr [ebp-00000328h], eax
                                          mov eax, dword ptr [0040A008h]
                                          mov dword ptr [ebp-00000324h], eax
                                          call dword ptr [00408024h]
                                          Programming Language:
                                          • [ASM] VS2005 build 50727
                                          • [C++] VS2005 build 50727
                                          • [ C ] VS2005 build 50727
                                          • [IMP] VS2005 build 50727
                                          • [RES] VS2005 build 50727
                                          • [LNK] VS2005 build 50727
                                          NameVirtual AddressVirtual Size Is in Section
                                          IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                          IMAGE_DIRECTORY_ENTRY_IMPORT0x98cc0x50.rdata
                                          IMAGE_DIRECTORY_ENTRY_RESOURCE0xc0000x608.rsrc
                                          IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                          IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                          IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                                          IMAGE_DIRECTORY_ENTRY_DEBUG0x81500x1c.rdata
                                          IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                          IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                          IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                          IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x95400x40.rdata
                                          IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                          IMAGE_DIRECTORY_ENTRY_IAT0x80000x114.rdata
                                          IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                          IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                          IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                          NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                          .text0x10000x63e40x70005eda842b76912c93face23b0e6da1c81False0.5626743861607143MPEG-4 LOAS6.227527587523542IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                          .rdata0x80000x1ee40x20009f22aadfb5847aa841f5a12f656e6ecaFalse0.335693359375data5.293548469075136IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                          .data0xa0000x199c0x1000afbe25c12caab7ca2f123e94e0f0eba0False0.20361328125firmware 1200 v0 (revision 1350909952) N\346@\273\261\031\277D\ \224\206@ V2, version 8704.0.55425 (region 318767104), 209993728 bytes or less, UNKNOWN1 0x13000000, UNKNOWN2 0xc4844000, UNKNOWN3 0x1c000000, at 0x1f000000 2827173888 bytes , at 0x20000000 1887649792 bytes , at 0x21000000 2021801984 bytes2.120795269175888IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                          .rsrc0xc0000x6080x10008366c09c7f65b861036e291728a92229False0.1689453125data4.095901447806458IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                          NameRVASizeTypeLanguageCountryZLIB Complexity
                                          RT_STRING0xc0e80x3adataEnglishGreat Britain0.6551724137931034
                                          RT_VERSION0xc1240x39cdataEnglishGreat Britain0.4296536796536797
                                          RT_MANIFEST0xc4c00x147ASCII text, with CRLF line terminatorsEnglishUnited States0.5749235474006116
                                          DLLImport
                                          inpout32.dll
                                          USER32.dllMessageBoxW
                                          KERNEL32.dllHeapFree, GetVersionExA, HeapAlloc, GetProcessHeap, GetStartupInfoW, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetProcAddress, GetModuleHandleA, ExitProcess, WriteFile, GetStdHandle, GetModuleFileNameA, GetModuleFileNameW, FreeEnvironmentStringsA, MultiByteToWideChar, GetEnvironmentStrings, FreeEnvironmentStringsW, GetLastError, GetEnvironmentStringsW, GetCommandLineA, GetCommandLineW, SetHandleCount, GetFileType, GetStartupInfoA, DeleteCriticalSection, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, SetLastError, GetCurrentThreadId, InterlockedDecrement, HeapDestroy, HeapCreate, VirtualFree, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, LeaveCriticalSection, EnterCriticalSection, LoadLibraryA, InitializeCriticalSection, Sleep, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, VirtualAlloc, HeapReAlloc, RtlUnwind, HeapSize, GetLocaleInfoA, WideCharToMultiByte, GetStringTypeA, GetStringTypeW, LCMapStringA, LCMapStringW
                                          Language of compilation systemCountry where language is spokenMap
                                          EnglishGreat Britain
                                          EnglishUnited States
                                          TimestampSource PortDest PortSource IPDest IP
                                          Apr 20, 2024 00:05:59.566011906 CEST5976153192.168.2.161.1.1.1
                                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                          Apr 20, 2024 00:05:59.566011906 CEST192.168.2.161.1.1.10x75a9Standard query (0)settings-ssl.xboxlive.comA (IP address)IN (0x0001)false
                                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                          Apr 20, 2024 00:05:59.673691988 CEST1.1.1.1192.168.2.160x75a9No error (0)settings-ssl.xboxlive.comsettings-ssl.xboxlive.com.edgekey.netCNAME (Canonical name)IN (0x0001)false

                                          Click to jump to process

                                          Click to jump to process

                                          Click to jump to process

                                          Target ID:0
                                          Start time:00:04:37
                                          Start date:20/04/2024
                                          Path:C:\Users\user\Desktop\InstallDriver.exe
                                          Wow64 process (32bit):true
                                          Commandline:"C:\Users\user\Desktop\InstallDriver.exe"
                                          Imagebase:0x400000
                                          File size:49'152 bytes
                                          MD5 hash:F25A0A82AD1EEFD4BECD6F034C078DBC
                                          Has elevated privileges:true
                                          Has administrator privileges:true
                                          Programmed in:C, C++ or other language
                                          Reputation:low
                                          Has exited:false

                                          Target ID:17
                                          Start time:00:05:56
                                          Start date:20/04/2024
                                          Path:C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe
                                          Wow64 process (32bit):false
                                          Commandline:"C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe" -ServerName:Microsoft.ZuneMusic.AppX48dcrcgzqqdshm3kf61t0cm5e9pyd6h6.mca
                                          Imagebase:0x7ff77a460000
                                          File size:23'140'864 bytes
                                          MD5 hash:F963F75C0AD152437E10D656A00793A3
                                          Has elevated privileges:false
                                          Has administrator privileges:false
                                          Programmed in:C, C++ or other language
                                          Reputation:moderate
                                          Has exited:false

                                          No disassembly