Source: backgroundTaskHost.exe, 00000009.00000002.2040751054.000002AFE81C7000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertGlobalRootG2.crt0 |
Source: LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004CCF000.00000004.00000800.00020000.00000000.sdmp, LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004C36000.00000004.00000800.00020000.00000000.sdmp, LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004CBE000.00000004.00000800.00020000.00000000.sdmp, douyin.exe.0.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDCodeSigningCA.crt0 |
Source: LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004C16000.00000004.00000800.00020000.00000000.sdmp, LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004D03000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://cd.file.myqcloud.com |
Source: LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004CCF000.00000004.00000800.00020000.00000000.sdmp, douyin.exe.0.dr | String found in binary or memory: http://crl.thawte.com/ThawteTimestampingCA.crl0 |
Source: backgroundTaskHost.exe, 00000009.00000002.2040751054.000002AFE81C7000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootG2.crl07 |
Source: backgroundTaskHost.exe, 00000009.00000002.2084007233.000002AFE8611000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/Omniroot2025.crl0 |
Source: LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004CCF000.00000004.00000800.00020000.00000000.sdmp, LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004C36000.00000004.00000800.00020000.00000000.sdmp, LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004CBE000.00000004.00000800.00020000.00000000.sdmp, douyin.exe.0.dr | String found in binary or memory: http://crl3.digicert.com/sha2-assured-cs-g1.crl05 |
Source: backgroundTaskHost.exe, 00000009.00000002.2040751054.000002AFE81C7000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertGlobalRootG2.crl0 |
Source: LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004CCF000.00000004.00000800.00020000.00000000.sdmp, LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004C36000.00000004.00000800.00020000.00000000.sdmp, LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004CBE000.00000004.00000800.00020000.00000000.sdmp, douyin.exe.0.dr | String found in binary or memory: http://crl4.digicert.com/sha2-assured-cs-g1.crl0K |
Source: LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004C16000.00000004.00000800.00020000.00000000.sdmp, LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004D03000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://get22222222asfas-1328031368.cos.ap-chengdu.myqcloud.com |
Source: LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004CCF000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://gz.file.myqcloud.com |
Source: Music.UI.exe, 00000011.00000002.2126897118.0000011FD1413000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ns.a.0 |
Source: Music.UI.exe, 00000011.00000002.2126897118.0000011FD1413000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ns.adobe.c.0 |
Source: Music.UI.exe, 00000011.00000002.2126897118.0000011FD1413000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ns.adobe.ho |
Source: Music.UI.exe, 00000011.00000002.2126897118.0000011FD1413000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ns.adora |
Source: Music.UI.exe, 00000011.00000002.2126897118.0000011FD1413000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ns.phX |
Source: backgroundTaskHost.exe, 00000009.00000002.2040751054.000002AFE81C7000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com0 |
Source: backgroundTaskHost.exe, 00000009.00000002.2084007233.000002AFE8611000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com0: |
Source: LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004CCF000.00000004.00000800.00020000.00000000.sdmp, LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004C36000.00000004.00000800.00020000.00000000.sdmp, LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004CBE000.00000004.00000800.00020000.00000000.sdmp, douyin.exe.0.dr | String found in binary or memory: http://ocsp.digicert.com0N |
Source: backgroundTaskHost.exe, 00000009.00000002.2084007233.000002AFE8611000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.msocsp.com0 |
Source: LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004C36000.00000004.00000800.00020000.00000000.sdmp, LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004CBE000.00000004.00000800.00020000.00000000.sdmp, douyin.exe.0.dr | String found in binary or memory: http://ocsp.thawte.com0 |
Source: LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004B71000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004CCF000.00000004.00000800.00020000.00000000.sdmp, LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004C36000.00000004.00000800.00020000.00000000.sdmp, LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004CBE000.00000004.00000800.00020000.00000000.sdmp, douyin.exe.0.dr | String found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca-g2.cer0 |
Source: LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004CCF000.00000004.00000800.00020000.00000000.sdmp, LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004C36000.00000004.00000800.00020000.00000000.sdmp, LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004CBE000.00000004.00000800.00020000.00000000.sdmp, douyin.exe.0.dr | String found in binary or memory: http://ts-crl.ws.symantec.com/tss-ca-g2.crl0( |
Source: LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004CCF000.00000004.00000800.00020000.00000000.sdmp, LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004C36000.00000004.00000800.00020000.00000000.sdmp, LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004CBE000.00000004.00000800.00020000.00000000.sdmp, douyin.exe.0.dr | String found in binary or memory: http://ts-ocsp.ws.symantec.com07 |
Source: LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004CCF000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www40sada-1328031368.cos.ap-guangzhou.myqcloud.com |
Source: backgroundTaskHost.exe, 00000016.00000002.2242590137.000001E860E59000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://activity.windows.com/UserActivity.ReadWrite.CreatedByApp |
Source: Music.UI.exe, 00000011.00000002.2286210205.0000011FD2043000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://activity.windows.com/UserActivity.ReadWrite.CreatedByApp82hN |
Source: BackgroundTransferHost.exe, 00000018.00000002.2062449931.0000023E34D1D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://aefd.nelreports.net/ap |
Source: backgroundTaskHost.exe, 0000001C.00000002.2485881161.0000014F5D8D2000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000001C.00000002.2485881161.0000014F5D891000.00000004.00000020.00020000.00000000.sdmp, 445325b3-79d8-41ea-9a13-3a2fd7d61b0b.ce662765-b572-49a6-8221-6746c6b640b0.down_meta.24.dr, fde2eb7a-b40f-4413-ad59-475540b113df.25646938-9d2d-4437-9657-ab96b3d6c07e.down_meta.24.dr, f03c4bb8-c2a4-4b95-aac4-eabe74c1e366.64da9497-d4db-4bd1-901f-0e309daaef56.down_meta.24.dr, f7b99221-ce7f-4946-80e2-73b3785700eb.25646938-9d2d-4437-9657-ab96b3d6c07e.down_meta.24.dr, a23c2c9d-d930-4807-a925-63a026f47282.1c016d01-c842-4d55-b8f0-b0178463c806.down_meta.24.dr, 916c5f0a-c83b-4d58-9aa5-6a91a2379cae.dd3c0f53-88e9-41d2-b11b-91f31ed13136.down_meta.24.dr, 0de711ec-2171-4413-8966-ee185340f175.64da9497-d4db-4bd1-901f-0e309daaef56.down_meta.24.dr, 2ceada02-9b08-4c99-ba7b-88e5fedcc013.ce662765-b572-49a6-8221-6746c6b640b0.down_meta.24.dr, e579ca37-681f-451c-9c22-4fc74e3cc243.49fe1c41-aee4-4f3c-9d8d-46c18d80229c.down_meta.24.dr, 1b5c1a31-1e08-4ecf-9fd0-c80a83dd3ac3.49fe1c41-aee4-4f3c-9d8d-46c18d80229c.down_meta.24.dr, 2b4cb80d-ffb6-49d2-90fd-cd33e40d7abb.1c016d01-c842-4d55-b8f0-b0178463c806.down_meta.24.dr, dd9f7a7c-dcba-4a13-bf03-402628bd88f7.dd3c0f53-88e9-41d2-b11b-91f31ed13136.down_meta.24.dr, dd9f7a7c-dcba-4a13-bf03-402628bd88f7.a4890f9a-6686-4ea5-882d-71683b903fec.down_meta.24.dr | String found in binary or memory: https://aefd.nelreports.net/api/report?cat=bingth&ndcParam=QUZE |
Source: Music.UI.exe, 00000011.00000002.2079156617.0000011FCF0E8000.00000004.00000020.00020000.00000000.sdmp, Music.UI.exe, 00000011.00000002.2182020311.0000011FD1CA6000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000016.00000002.2242590137.000001E860E59000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://android.notify.windows.com/iOS |
Source: Music.UI.exe, 00000011.00000002.2079156617.0000011FCF0E8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://android.notify.windows.com/iOS. |
Source: backgroundTaskHost.exe, 00000009.00000002.2150496375.000002AFE8CA9000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000001C.00000002.2516086227.0000014F5FC4D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://arc.msn.com/ |
Source: backgroundTaskHost.exe, 00000009.00000002.2053210175.000002AFE8291000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000003.1741073885.000002AFE8291000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000003.1782869999.000002AFE8291000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000003.1504609231.000002AFE826C000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000003.1508747636.000002AFE8291000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000002.1993733380.000002AFE609F000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000003.1474460958.000002AFE61F4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://arc.msn.com/v3/Delivery/Events/Impression=&PID=400084281&TID=700117803&CID=11600000000027065 |
Source: backgroundTaskHost.exe, 00000009.00000002.2165992925.000002AFE8DCE000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000001C.00000003.2173802378.0000014F5D98F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://arc.msn.com/v3/Delivery/Events/Impression=&PID=425 |
Source: backgroundTaskHost.exe, 00000009.00000002.2024561341.000002AFE812D000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000003.1504609231.000002AFE826C000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000002.2007905031.000002AFE6113000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000003.1470226638.000002AFE811C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://arc.msn.com/v3/Delivery/Events/Impression=&PID=425115820&TID=700333385&CID=12800000000162740 |
Source: backgroundTaskHost.exe, 00000009.00000003.1504609231.000002AFE826C000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000002.2024561341.000002AFE8100000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000002.2007905031.000002AFE6113000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000003.1470226638.000002AFE811C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://arc.msn.com/v3/Delivery/Events/Impression=&PID=425116118&TID=700333392&CID=12800000000162740 |
Source: backgroundTaskHost.exe, 00000009.00000003.1470226638.000002AFE811C000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000002.2053210175.000002AFE8273000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000002.2066751828.000002AFE832C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://arc.msn.com/v3/Delivery/Events/Impression=&PID=425116119&TID=700333391&CID=12800000000162740 |
Source: backgroundTaskHost.exe, 00000009.00000002.1998194573.000002AFE60A4000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000002.2007905031.000002AFE6113000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://arc.msn.com/v3/Delivery/Events/Impression=&PID=425116120&TID=700333386&CID=12800000000162740 |
Source: backgroundTaskHost.exe, 00000009.00000003.1474460958.000002AFE61F4000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000002.1998194573.000002AFE60A4000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000002.2053210175.000002AFE828B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://arc.msn.com/v3/Delivery/Events/Impression=&PID=425116121&TID=700333389&CID=12800000000162740 |
Source: backgroundTaskHost.exe, 0000001C.00000003.2277680972.0000014F5D9A2000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000001C.00000003.2419792349.0000014F5D929000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://arc.msn.com/v3/Delivery/Events/Impression=&PID=425116123&TID=1&CID=128000000001627409&BID=18 |
Source: backgroundTaskHost.exe, 00000009.00000003.1508747636.000002AFE828B000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000003.1504609231.000002AFE826C000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000003.1741073885.000002AFE8277000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000002.2024561341.000002AFE8100000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000003.1470226638.000002AFE811C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://arc.msn.com/v3/Delivery/Events/Impression=&PID=425116215&TID=700333445&CID=12800000000162740 |
Source: backgroundTaskHost.exe, 0000001C.00000002.2502636903.0000014F5F85D000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000001C.00000002.2493497059.0000014F5D926000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://arc.msn.com/v3/Delivery/Events/Impression=&PID=425116216&TID=1&CID=128000000001627409&BID=20 |
Source: backgroundTaskHost.exe, 00000009.00000003.1504609231.000002AFE826C000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000003.1741073885.000002AFE8277000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000002.2024561341.000002AFE8100000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000003.1470226638.000002AFE811C000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000002.2053210175.000002AFE8273000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000001C.00000002.2492479166.0000014F5D913000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000001C.00000002.2500306988.0000014F5F81C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://arc.msn.com/v3/Delivery/Events/Impression=&PID=425116219&TID=700333446&CID=12800000000162740 |
Source: backgroundTaskHost.exe, 00000009.00000003.1787589604.000002AFE8D6F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://arc.msn.com/v3/Delivery/Events/Impression=&PID=4251_imp00000001627409 |
Source: backgroundTaskHost.exe, 00000009.00000003.1470226638.000002AFE811C000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000002.2053210175.000002AFE8273000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000003.1504609231.000002AFE8298000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://arc.msn.com/v3/Delivery/Events/Impression=&PID=425681886&TID=700341298&CID=12800000000437620 |
Source: backgroundTaskHost.exe, 00000009.00000003.1536081613.000002AFE8299000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://arc.msn.com/v3/Delivery/Events/Impression=&PID=425681888&TID=700342084&CID=1280000000 |
Source: backgroundTaskHost.exe, 00000009.00000003.1470226638.000002AFE811C000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000002.2053210175.000002AFE8273000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://arc.msn.com/v3/Delivery/Events/Impression=&PID=425681888&TID=700342084&CID=12800000000437618 |
Source: backgroundTaskHost.exe, 00000009.00000002.2154420920.000002AFE8CFC000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://arc.msn.com/v3/Delivery/Placement?pubid=da63df93-3dbc-42ae-a505-b34988683ac7&pid=280815& |
Source: backgroundTaskHost.exe, 00000009.00000002.2012948752.000002AFE6163000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://arc.msn.com/v3/Delivery/Placement?pubid=da63df93-3dbc-42ae-a505-b34988683ac7&pid=280815&adm= |
Source: backgroundTaskHost.exe, 00000009.00000002.2130753526.000002AFE8913000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://arc.msn.com/v3/Delivery/Placement?pubid=da63df93-3dbc-42ae-a505-b34988683ac7&pid=338387&adm= |
Source: backgroundTaskHost.exe, 00000009.00000003.1743827560.000002AFE83FF000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000003.1776228245.000002AFE8D03000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000002.1998194573.000002AFE60A4000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000002.2024561341.000002AFE8138000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://arc.msn.com/v3/Delivery/Placement?pubid=da63df93-3dbc-42ae-a505-b34988683ac7&pid=338388&adm= |
Source: backgroundTaskHost.exe, 00000009.00000003.1743827560.000002AFE83FF000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000002.2024561341.000002AFE8156000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000002.2088570749.000002AFE8670000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000003.1885618793.000002AFE6163000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000003.1776228245.000002AFE8D03000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000002.2019946009.000002AFE61BB000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000002.2130753526.000002AFE8913000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000002.2012948752.000002AFE6163000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://arc.msn.com/v3/Delivery/Placement?pubid=da63df93-3dbc-42ae-a505-b34988683ac7&pid=338389&adm= |
Source: backgroundTaskHost.exe, 0000001C.00000003.2258001465.0000014F5D922000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000001C.00000002.2517329275.0000014F5FC79000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://arc.msn.com/v3/Delivery/Placement?pubid=da63df93-3dbc-42ae-a505-b34988683ac7&pid=88000045&ad |
Source: backgroundTaskHost.exe, 0000000B.00000002.1391654894.0000023FD0E41000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000000B.00000002.1392226258.0000023FD0E82000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000000B.00000002.1391475447.0000023FD0E28000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://arc.msn.com/v4 |
Source: svchost.exe, 00000008.00000002.2621112531.000001E71FC7B000.00000004.00000001.00020000.00000000.sdmp, svchost.exe, 00000008.00000000.1366177627.000001E71FCC2000.00000004.00000001.00020000.00000000.sdmp, svchost.exe, 00000008.00000000.1365979203.000001E71FC69000.00000004.00000001.00020000.00000000.sdmp, svchost.exe, 00000008.00000002.2626192614.000001E71FCC8000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://cdn.onenote.net/livetile/?Language= |
Source: backgroundTaskHost.exe, 00000009.00000003.1485299474.000002AFE8834000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000002.2115016135.000002AFE8800000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://excel.office.com |
Source: backgroundTaskHost.exe, 00000009.00000002.2163753464.000002AFE8D8B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://g..com/ne |
Source: backgroundTaskHost.exe, 00000009.00000002.2163753464.000002AFE8D8B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://g.bi |
Source: backgroundTaskHost.exe, 0000001C.00000003.2440031840.0000014F60121000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://g.bin |
Source: backgroundTaskHost.exe, 0000001C.00000003.2440031840.0000014F60121000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://g.bing.c |
Source: LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004C52000.00000004.00000800.00020000.00000000.sdmp, LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004C0C000.00000004.00000800.00020000.00000000.sdmp, LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004BF7000.00000004.00000800.00020000.00000000.sdmp, LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004D03000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://get22222222asfas-1328031368.cos.ap-chengdu.myqcloud.com |
Source: LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004C52000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://get22222222asfas-1328031368.cos.ap-chengdu.myqcloud.com/douyin.exe |
Source: LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004B71000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://get22222222asfas-1328031368.cos.ap-chengdu.myqcloud.com/sscronet.dll |
Source: LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004D03000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://get22222222asfas-1328031368.cos.ap-chengdu.myqcloud.com/tier0.dll |
Source: backgroundTaskHost.exe, 00000009.00000002.2031758797.000002AFE8164000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000002.2115016135.000002AFE8847000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://img-prod-cms-rt-microsoft-com.akamaized.net/cms/api/am/imageFileData/RW18NZO?ver=7c98 |
Source: backgroundTaskHost.exe, 00000009.00000003.1506638174.000002AFE8275000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000003.1509395087.000002AFE8278000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000003.1504609231.000002AFE826C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://img-prod-cms-rt-microsoft-com.akamaized.net/cms/api/am/imageFileData/RW18NZO?ver=7c98Ti |
Source: backgroundTaskHost.exe, 00000009.00000002.2115016135.000002AFE8847000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://img-prod-cms-rt-microsoft-com.akamaized.net/cms/api/am/imageFileData/RW18NZO?ver=7c98at |
Source: backgroundTaskHost.exe, 00000009.00000003.1472351511.000002AFE8703000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://img-prod-cms-rt-microsoft-com.akamaized.net/cms/api/am/imageFileData/RW18NZO?ver=7c98b5https |
Source: backgroundTaskHost.exe, 00000009.00000003.1506638174.000002AFE8275000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000003.1509395087.000002AFE8278000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000003.1504609231.000002AFE826C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://img-prod-cms-rt-microsoft-com.akamaized.net/cms/api/am/imageFileData/RW18NZO?ver=7c98et |
Source: backgroundTaskHost.exe, 00000009.00000003.1506638174.000002AFE8275000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000003.1504609231.000002AFE826C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://img-prod-cms-rt-microsoft-com.akamaized.net/cms/api/am/imageFileData/RW18NZO?ver=7c98g=https |
Source: backgroundTaskHost.exe, 00000009.00000003.1539666820.000002AFE83C5000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000003.1886858639.000002AFE83CD000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://img-prod-cms-rt-microsoft-com.akamaized.net/cms/api/am/imageFileData/RW18NZO?ver=7c98https:/ |
Source: backgroundTaskHost.exe, 00000009.00000002.2024561341.000002AFE8100000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000002.1998194573.000002AFE60A4000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000002.2115016135.000002AFE8847000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://img-prod-cms-rt-microsoft-com.akamaized.net/cms/api/am/imageFileData/RW18NZP?ver=5e78 |
Source: backgroundTaskHost.exe, 00000009.00000002.2115016135.000002AFE8847000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://img-prod-cms-rt-microsoft-com.akamaized.net/cms/api/am/imageFileData/RW18NZP?ver=5e78at |
Source: backgroundTaskHost.exe, 00000009.00000003.1886858639.000002AFE83CD000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://img-prod-cms-rt-microsoft-com.akamaized.net/cms/api/am/imageFileData/RW18NZP?ver=5e78https:/ |
Source: backgroundTaskHost.exe, 00000009.00000002.2031758797.000002AFE8164000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000002.2115016135.000002AFE8847000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://img-prod-cms-rt-microsoft-com.akamaized.net/cms/api/am/imageFileData/RW18SZK?ver=2175 |
Source: backgroundTaskHost.exe, 00000009.00000003.1506638174.000002AFE8275000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000003.1504609231.000002AFE826C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://img-prod-cms-rt-microsoft-com.akamaized.net/cms/api/am/imageFileData/RW18SZK?ver=2175WDhttps |
Source: backgroundTaskHost.exe, 00000009.00000002.2115016135.000002AFE8847000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://img-prod-cms-rt-microsoft-com.akamaized.net/cms/api/am/imageFileData/RW18SZK?ver=2175at |
Source: backgroundTaskHost.exe, 00000009.00000003.1506638174.000002AFE8275000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000003.1504609231.000002AFE826C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://img-prod-cms-rt-microsoft-com.akamaized.net/cms/api/am/imageFileData/RW18SZK?ver=2175cohttps |
Source: backgroundTaskHost.exe, 00000009.00000003.1472351511.000002AFE8703000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://img-prod-cms-rt-microsoft-com.akamaized.net/cms/api/am/imageFileData/RW18SZK?ver=2175https:/ |
Source: backgroundTaskHost.exe, 00000009.00000003.1539666820.000002AFE83C5000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000003.1655233140.000002AFE87BA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://img-prod-cms-rt-microsoft-com.akamaized.net/cms/api/am/imageFileData/RW18SZK?ver=2175ms-appd |
Source: backgroundTaskHost.exe, 00000009.00000003.1886858639.000002AFE83B5000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000003.1477045606.000002AFE8362000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://img-prod-cms-rt-microsoft-com.akamaized.net/cms/api/am/imageFileData/RW18VF4?ver=f0b5 |
Source: backgroundTaskHost.exe, 00000009.00000003.1655233140.000002AFE87BA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://img-prod-cms-rt-microsoft-com.akamaized.net/cms/api/am/imageFileData/RW18VF4?ver=f0b59b |
Source: backgroundTaskHost.exe, 00000009.00000003.1539666820.000002AFE83C5000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000003.1472351511.000002AFE8703000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000003.1886858639.000002AFE83B5000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000003.1477045606.000002AFE8362000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://img-prod-cms-rt-microsoft-com.akamaized.net/cms/api/am/imageFileData/RW18VF4?ver=f0b5https:/ |
Source: backgroundTaskHost.exe, 00000009.00000003.1477045606.000002AFE8362000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://img-prod-cms-rt-microsoft-com.akamaized.net/cms/api/am/imageFileData/RW18VF5?ver=8d01 |
Source: backgroundTaskHost.exe, 00000009.00000002.2088570749.000002AFE8670000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://img-prod-cms-rt-microsoft-com.akamaized.net/cms/api/am/imageFileData/RW18VF5?ver=8d01001 |
Source: backgroundTaskHost.exe, 00000009.00000003.1655233140.000002AFE87BA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://img-prod-cms-rt-microsoft-com.akamaized.net/cms/api/am/imageFileData/RW18VF5?ver=8d011696583 |
Source: backgroundTaskHost.exe, 0000001C.00000002.2485881161.0000014F5D891000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com |
Source: backgroundTaskHost.exe, 0000001C.00000002.2485881161.0000014F5D891000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com/ |
Source: Music.UI.exe, 00000011.00000002.2351955837.0000011FD25D9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com/xsts.auth.xboxlive.com |
Source: backgroundTaskHost.exe, 0000000B.00000002.1392226258.0000023FD0E82000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.microsoftonline.com |
Source: backgroundTaskHost.exe, 0000000B.00000002.1392226258.0000023FD0E82000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.microsoftonline.com/ |
Source: backgroundTaskHost.exe, 0000000B.00000002.1391909552.0000023FD0E57000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.microsoftonline.com/common |
Source: backgroundTaskHost.exe, 0000000B.00000002.1392226258.0000023FD0E82000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.microsoftonline.com/common/oauth2/authorize |
Source: backgroundTaskHost.exe, 0000000B.00000002.1392226258.0000023FD0E82000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.microsoftonline.com/common/oauth2/authorize03 |
Source: backgroundTaskHost.exe, 0000000B.00000002.1391909552.0000023FD0E57000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.microsoftonline.com/common1003 |
Source: backgroundTaskHost.exe, 0000000B.00000002.1392226258.0000023FD0E82000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.microsoftonline.com/commonoauth2/authorizeager |
Source: backgroundTaskHost.exe, 0000000B.00000002.1392226258.0000023FD0E82000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.windows-ppe.net |
Source: backgroundTaskHost.exe, 0000000B.00000002.1392226258.0000023FD0E82000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.windows-ppe.net/ |
Source: backgroundTaskHost.exe, 0000001C.00000002.2485881161.0000014F5D8D2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.windows.local |
Source: backgroundTaskHost.exe, 00000009.00000002.2151718274.000002AFE8CC0000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000002.1998194573.000002AFE60A4000.00000004.00000020.00020000.00000000.sdmp, Music.UI.exe, 00000011.00000002.2246904183.0000011FD1F00000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000001C.00000002.2485881161.0000014F5D8D2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.windows.local/ |
Source: backgroundTaskHost.exe, 00000009.00000002.2151718274.000002AFE8CC0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.windows.local6https://login.windows.local |
Source: backgroundTaskHost.exe, 0000000B.00000002.1392226258.0000023FD0E82000.00000004.00000020.00020000.00000000.sdmp, Music.UI.exe, 00000011.00000003.1947252502.0000011FD1DA4000.00000004.00000020.00020000.00000000.sdmp, Music.UI.exe, 00000011.00000002.2169308717.0000011FD1C00000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000001C.00000002.2485881161.0000014F5D8D2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.windows.net |
Source: backgroundTaskHost.exe, 00000009.00000002.1998194573.000002AFE60A4000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000000B.00000002.1392226258.0000023FD0E82000.00000004.00000020.00020000.00000000.sdmp, Music.UI.exe, 00000011.00000002.2169308717.0000011FD1C00000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000001C.00000002.2485881161.0000014F5D8D2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.windows.net/ |
Source: backgroundTaskHost.exe, 00000009.00000002.1998194573.000002AFE60A4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.windows.nethttps://xsts.auth.xboxlive.com |
Source: Music.UI.exe, 00000011.00000002.2188835156.0000011FD1D00000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://musicart.xboxlive.com/9/5c6a4700-0000-0000-0000-000000000002/504/image.jpg |
Source: Music.UI.exe, 00000011.00000002.2188835156.0000011FD1D00000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://musicart.xboxlive.com/9/e74d4600-0000-0000-0000-000000000002/504/image.jpg |
Source: svchost.exe, 00000008.00000000.1369339698.000001E720543000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://officeapps.live.com |
Source: backgroundTaskHost.exe, 00000009.00000002.2115016135.000002AFE8847000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://outlook.comx |
Source: backgroundTaskHost.exe, 00000009.00000002.2115016135.000002AFE8800000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://powerpoint.office.comcember |
Source: backgroundTaskHost.exe, 00000009.00000002.2138567159.000002AFE8C00000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000003.1553025254.000002AFE892F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ris.ap |
Source: backgroundTaskHost.exe, 0000001C.00000003.2172530579.0000014F5D95F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ris.api |
Source: backgroundTaskHost.exe, 00000009.00000003.1523078262.000002AFE816C000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000002.2031758797.000002AFE818F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ris.api.ir |
Source: backgroundTaskHost.exe, 00000009.00000003.1523078262.000002AFE816C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ris.api.ir0$ |
Source: backgroundTaskHost.exe, 00000009.00000003.1411364307.000002AFE810C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ris.api.iris.micros |
Source: Music.UI.exe, 00000011.00000003.1608080445.0000011FD1C89000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://settings-ssl.xboxlive.com |
Source: Music.UI.exe, 00000011.00000003.1608080445.0000011FD1C89000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://settings-ssl.xboxlive.com/ |
Source: Music.UI.exe, 00000011.00000003.1608080445.0000011FD1C89000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://settings-ssl.xboxlive.com/XBLWinClient/v10_music/configuration.xml |
Source: backgroundTaskHost.exe, 00000009.00000002.2163753464.000002AFE8D8B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://tse1.mm.0 |
Source: backgroundTaskHost.exe, 00000009.00000002.2165209591.000002AFE8DAC000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://tse1.mm.bi1696583420 |
Source: BackgroundTransferHost.exe, 00000018.00000002.2052868120.0000023E32CB5000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://tse1.mm.bing.net/ |
Source: backgroundTaskHost.exe, 00000009.00000003.1779648120.000002AFE87A8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://tse1.mm.bing.net/th?id=OADD2.102393 |
Source: backgroundTaskHost.exe, 0000001C.00000002.2517865099.0000014F5FC90000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://tse1.mm.bing.net/th?id=OADD2.10239339388230_1GCYE192JMK1GRK5F |
Source: backgroundTaskHost.exe, 00000009.00000002.2053210175.000002AFE8273000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://tse1.mm.bing.net/th?id=OADD2.10239339388230_1GCYE192JMK1GRK5F&pi |
Source: backgroundTaskHost.exe, 0000001C.00000002.2485881161.0000014F5D8D2000.00000004.00000020.00020000.00000000.sdmp, f03c4bb8-c2a4-4b95-aac4-eabe74c1e366.64da9497-d4db-4bd1-901f-0e309daaef56.down_meta.24.dr, 0de711ec-2171-4413-8966-ee185340f175.64da9497-d4db-4bd1-901f-0e309daaef56.down_meta.24.dr | String found in binary or memory: https://tse1.mm.bing.net/th?id=OADD2.10239339388230_1GCYE192JMK1GRK5F&pid=21.2&c=16&roil=0&roit=0&ro |
Source: backgroundTaskHost.exe, 0000001C.00000002.2517865099.0000014F5FC90000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://tse1.mm.bing.net/th?id=OADD2.10239339388231_1UY1F8SP8NFGIRB6T |
Source: backgroundTaskHost.exe, 0000001C.00000002.2503621029.0000014F5F87F000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000001C.00000003.2247408139.0000014F5F974000.00000004.00000020.00020000.00000000.sdmp, a23c2c9d-d930-4807-a925-63a026f47282.1c016d01-c842-4d55-b8f0-b0178463c806.down_meta.24.dr, 2b4cb80d-ffb6-49d2-90fd-cd33e40d7abb.1c016d01-c842-4d55-b8f0-b0178463c806.down_meta.24.dr | String found in binary or memory: https://tse1.mm.bing.net/th?id=OADD2.10239339388231_1UY1F8SP8NFGIRB6T&pid=21.2&c=3&w=1080&h=1920&dyn |
Source: backgroundTaskHost.exe, 00000009.00000003.1820918262.000002AFE8E02000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000001C.00000003.2443431005.0000014F5FD02000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000001C.00000003.2437586038.0000014F60131000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000001C.00000003.2435243510.0000014F60120000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://tse1.mm.bing.net/th?id=OADD2.10239340418581_1PW4UWMX6DVDU64ZR |
Source: BackgroundTransferHost.exe, 00000018.00000002.2052868120.0000023E32CB5000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://tse1.mm.bing.net/th?id=OADD2.10239340418581_1PW4UWMX6DVDU64ZR&pid=21.2& |
Source: backgroundTaskHost.exe, 0000001C.00000002.2494213404.0000014F5D937000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000001C.00000003.2429888850.0000014F5FCC3000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000001C.00000002.2503621029.0000014F5F87F000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000001C.00000003.2247408139.0000014F5F974000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000001C.00000002.2485881161.0000014F5D8C0000.00000004.00000020.00020000.00000000.sdmp, 916c5f0a-c83b-4d58-9aa5-6a91a2379cae.dd3c0f53-88e9-41d2-b11b-91f31ed13136.down_meta.24.dr, dd9f7a7c-dcba-4a13-bf03-402628bd88f7.dd3c0f53-88e9-41d2-b11b-91f31ed13136.down_meta.24.dr, dd9f7a7c-dcba-4a13-bf03-402628bd88f7.a4890f9a-6686-4ea5-882d-71683b903fec.down_meta.24.dr | String found in binary or memory: https://tse1.mm.bing.net/th?id=OADD2.10239340418581_1PW4UWMX6DVDU64ZR&pid=21.2&c=3&w=1080&h=1920&dyn |
Source: backgroundTaskHost.exe, 00000009.00000003.1820918262.000002AFE8E02000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000001C.00000003.2443431005.0000014F5FD02000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000001C.00000003.2437586038.0000014F60131000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000001C.00000003.2435243510.0000014F60120000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://tse1.mm.bing.net/th?id=OADD2.10239340418582_18ZLZW09JZ7BHXRKX |
Source: backgroundTaskHost.exe, 00000009.00000002.2053210175.000002AFE8273000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://tse1.mm.bing.net/th?id=OADD2.10239340418582_18ZLZW09JZ7BHXRKX&pi |
Source: backgroundTaskHost.exe, 0000001C.00000002.2485881161.0000014F5D8D2000.00000004.00000020.00020000.00000000.sdmp, 445325b3-79d8-41ea-9a13-3a2fd7d61b0b.ce662765-b572-49a6-8221-6746c6b640b0.down_meta.24.dr, 2ceada02-9b08-4c99-ba7b-88e5fedcc013.ce662765-b572-49a6-8221-6746c6b640b0.down_meta.24.dr | String found in binary or memory: https://tse1.mm.bing.net/th?id=OADD2.10239340418582_18ZLZW09JZ7BHXRKX&pid=21.2&c=16&roil=0&roit=0&ro |
Source: backgroundTaskHost.exe, 00000009.00000003.1782869999.000002AFE8291000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000001C.00000002.2493497059.0000014F5D926000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000001C.00000003.2437586038.0000014F6013C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://tse1.mm.bing.net/th?id=OADD2.10239400907839_1ZQL244JEBB0HCE6J |
Source: backgroundTaskHost.exe, 0000001C.00000002.2500306988.0000014F5F800000.00000004.00000020.00020000.00000000.sdmp, e579ca37-681f-451c-9c22-4fc74e3cc243.49fe1c41-aee4-4f3c-9d8d-46c18d80229c.down_meta.24.dr, 1b5c1a31-1e08-4ecf-9fd0-c80a83dd3ac3.49fe1c41-aee4-4f3c-9d8d-46c18d80229c.down_meta.24.dr | String found in binary or memory: https://tse1.mm.bing.net/th?id=OADD2.10239400907839_1ZQL244JEBB0HCE6J&pid=21.2&c=3&w=1080&h=1920&dyn |
Source: backgroundTaskHost.exe, 00000009.00000003.1782869999.000002AFE8291000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000001C.00000002.2493497059.0000014F5D926000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000001C.00000003.2437586038.0000014F6013C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://tse1.mm.bing.net/th?id=OADD2.10239400907840_1FPLTEXP4VV24MYRE |
Source: BackgroundTransferHost.exe, 00000018.00000002.2052868120.0000023E32CB5000.00000004.00000020.00020000.00000000.sdmp, BackgroundTransferHost.exe, 00000018.00000002.2074312284.0000023E34DF9000.00000004.00000020.00020000.00000000.sdmp, BackgroundTransferHost.exe, 00000018.00000002.2065521589.0000023E34D5B000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000001C.00000002.2494213404.0000014F5D937000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000001C.00000002.2514176700.0000014F5FC0C000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000001C.00000002.2492479166.0000014F5D913000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000001C.00000002.2485881161.0000014F5D8D2000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000001C.00000002.2521537238.0000014F6011B000.00000004.00000020.00020000.00000000.sdmp, fde2eb7a-b40f-4413-ad59-475540b113df.25646938-9d2d-4437-9657-ab96b3d6c07e.down_meta.24.dr, f7b99221-ce7f-4946-80e2-73b3785700eb.25646938-9d2d-4437-9657-ab96b3d6c07e.down_meta.24.dr | String found in binary or memory: https://tse1.mm.bing.net/th?id=OADD2.10239400907840_1FPLTEXP4VV24MYRE&pid=21.2&c=16&roil=0&roit=0&ro |
Source: backgroundTaskHost.exe, 00000009.00000002.2165209591.000002AFE8DAC000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://tse1.mm.bing.net/th?id=OADz |
Source: Music.UI.exe, 00000011.00000002.2340628917.0000011FD2524000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000016.00000002.2247318330.000001E860E89000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://wns.windows.com/ |
Source: backgroundTaskHost.exe, 00000009.00000003.1485299474.000002AFE8834000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 00000009.00000002.2115016135.000002AFE8800000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://word.office.com |
Source: LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004CCF000.00000004.00000800.00020000.00000000.sdmp, LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004C36000.00000004.00000800.00020000.00000000.sdmp, LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004CBE000.00000004.00000800.00020000.00000000.sdmp, douyin.exe.0.dr | String found in binary or memory: https://www.digicert.com/CPS0 |
Source: LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004CCF000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www40sada-1328031368.cos.ap-guangzhou.myqcloud.com |
Source: LEC3KQZZqZ.exe, 00000000.00000002.1421776629.0000000004CCF000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www40sada-1328031368.cos.ap-guangzhou.myqcloud.com/mpclient.dat |
Source: Music.UI.exe, 00000011.00000003.1947252502.0000011FD1DA4000.00000004.00000020.00020000.00000000.sdmp, Music.UI.exe, 00000011.00000002.2169308717.0000011FD1C00000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000001C.00000002.2485881161.0000014F5D8D2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://xsts.auth.xboxlive.com |
Source: backgroundTaskHost.exe, 00000009.00000002.1998194573.000002AFE60A4000.00000004.00000020.00020000.00000000.sdmp, Music.UI.exe, 00000011.00000002.2138228121.0000011FD152F000.00000004.00000020.00020000.00000000.sdmp, backgroundTaskHost.exe, 0000001C.00000002.2485881161.0000014F5D8D2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://xsts.auth.xboxlive.com/ |
Source: Music.UI.exe, 00000011.00000003.1941583856.0000011FD24FF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://xsts.auth.xboxlive.com3 |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: ondemandbrokerclient.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: mrmcorer.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: biwinrt.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: windows.staterepositorycore.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: policymanager.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: cdp.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: wincorlib.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: dsreg.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: windows.storage.applicationdata.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: logoncli.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: threadpoolwinrt.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: windows.applicationmodel.background.timebroker.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: windows.applicationmodel.background.systemeventsbroker.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: windows.services.targetedcontent.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: contentdeliverymanager.utilities.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: notificationcontrollerps.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: rmclient.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: windows.web.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: windows.globalization.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: bcp47mrm.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: windows.security.authentication.web.core.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: vaultcli.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: aadwamextension.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: windows.applicationmodel.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: cryptowinrt.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: ncryptprov.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: windows.web.http.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: windows.ui.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: windowmanagementapi.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: inputhost.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: firewallapi.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: fwbase.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: profext.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: certenroll.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: certca.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: dsparse.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: mlang.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: starttiledata.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: usermgrcli.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: usermgrproxy.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: windows.cloudstore.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: windows.cloudstore.schema.shell.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: tiledatarepository.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: staterepository.core.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: windows.staterepository.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: windows.staterepositoryclient.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: installservice.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: windows.networking.connectivity.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: windows.networking.hostname.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: flightsettings.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: wosc.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: updatepolicy.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: cabinet.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: dcntel.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: utcutil.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: appraiser.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: wdscore.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: xmllite.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: tdh.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: windows.networking.backgroundtransfer.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: systemeventsbrokerclient.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: rmclient.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: windows.security.authentication.onlineid.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: structuredquery.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: windows.storage.search.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: windows.staterepositorycore.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: windows.fileexplorer.common.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: windows.services.targetedcontent.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: execmodelclient.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: execmodelproxy.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: policymanager.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: appextension.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: appxdeploymentclient.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: mssrch.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: tquery.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: cryptdll.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: esent.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: contentdeliverymanager.utilities.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: cdp.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: dsreg.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: ntshrui.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: cscapi.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: linkinfo.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: familysafetyext.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: wpc.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: wlidprov.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: windows.networking.connectivity.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: npmproxy.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: windows.networking.hostname.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: netprofm.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: dusmapi.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: wpnapps.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: xmllite.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: usermgrcli.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: windows.ui.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: windowmanagementapi.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: inputhost.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: windows.internal.shell.broker.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: cryptowinrt.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: starttiledata.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: usermgrproxy.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: windows.cloudstore.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: windows.cloudstore.schema.shell.dll | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: apphelp.dll | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: twinapi.appcore.dll | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: wintypes.dll | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: mrmcorer.dll | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: biwinrt.dll | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: windows.staterepositorycore.dll | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: wincorlib.dll | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: windows.security.authentication.web.core.dll | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: usermgrproxy.dll | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: iertutil.dll | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: vaultcli.dll | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: threadpoolwinrt.dll | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: windows.storage.applicationdata.dll | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: windows.ui.xaml.dll | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: coremessaging.dll | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: bcp47langs.dll | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: dcomp.dll | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: wldp.dll | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: propsys.dll | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: userdeviceregistration.dll | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: ncrypt.dll | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: ntasn1.dll | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: cryptowinrt.dll | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: policymanager.dll | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: msvcp110_win.dll | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Section loaded: windowscodecs.dll | |
Source: C:\Program Files (x86)\Common Files\System\douyin.exe | Section loaded: apphelp.dll | |
Source: C:\Program Files (x86)\Common Files\System\douyin.exe | Section loaded: tier0.dll | |
Source: C:\Windows\SysWOW64\nslookup.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\SysWOW64\nslookup.exe | Section loaded: mswsock.dll | |
Source: C:\Windows\SysWOW64\nslookup.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\SysWOW64\nslookup.exe | Section loaded: napinsp.dll | |
Source: C:\Windows\SysWOW64\nslookup.exe | Section loaded: pnrpnsp.dll | |
Source: C:\Windows\SysWOW64\nslookup.exe | Section loaded: wshbth.dll | |
Source: C:\Windows\SysWOW64\nslookup.exe | Section loaded: nlaapi.dll | |
Source: C:\Windows\SysWOW64\nslookup.exe | Section loaded: winrnr.dll | |
Source: C:\Windows\SysWOW64\nslookup.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Windows\SysWOW64\nslookup.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Windows\SysWOW64\nslookup.exe | Section loaded: winnsi.dll | |
Source: C:\Windows\SysWOW64\nslookup.exe | Section loaded: wininet.dll | |
Source: C:\Windows\SysWOW64\nslookup.exe | Section loaded: mscoree.dll | |
Source: C:\Windows\SysWOW64\nslookup.exe | Section loaded: amsi.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: d3d11.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: sharedui.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: vccorlib140_app.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: msvcp140_app.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: concrt140_app.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: vcruntime140_app.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: dxgi.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: vcruntime140_app.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: windows.ui.xaml.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: coremessaging.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: bcp47langs.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: iertutil.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: dcomp.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: twinapi.appcore.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: wintypes.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: windows.staterepositorycore.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: windows.ui.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: windowmanagementapi.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: textinputframework.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: inputhost.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: propsys.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: coreuicomponents.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: coreuicomponents.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: ntmarta.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: uxtheme.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: urlmon.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: srvcli.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: netutils.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: resourcepolicyclient.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: d3d10warp.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: rometadata.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: dxcore.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: d2d1.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: dwrite.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: textshaping.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: windows.applicationmodel.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: esent.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: windows.storage.applicationdata.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: wldp.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: logoncli.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: mrmcorer.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: windows.staterepositoryclient.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: profapi.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: appxdeploymentclient.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: bcp47mrm.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: windows.ui.xaml.controls.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: windows.shell.servicehostbuilder.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: execmodelproxy.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: rmclient.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: uiamanager.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: windows.ui.core.textinput.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: windows.ui.immersive.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: dataexchange.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: threadpoolwinrt.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: windows.globalization.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: windows.system.profile.retailinfo.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: windows.media.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: windows.applicationmodel.lockscreen.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: wincorlib.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: lockappbroker.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: msvcp110_win.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: powrprof.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: umpdc.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: windows.graphics.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: windows.ui.xaml.phone.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: twinapi.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: windows.networking.connectivity.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: windows.media.playback.mediaplayer.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: mfplat.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: rtworkq.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: windows.media.mediacontrol.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: mmdevapi.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: devobj.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: mfmediaengine.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: xmllite.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: audioses.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: windows.media.devices.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: windows.media.playback.proxystub.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: comppkgsup.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: windows.devices.enumeration.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: devdispitemprovider.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: ddores.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: defaultdevicemanager.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: directmanipulation.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: msftedit.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: globinputhost.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: msxml6.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: wpnapps.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: windows.web.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: windowscodecs.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: wuceffects.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: wininet.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: windows.networking.backgroundtransfer.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: systemeventsbrokerclient.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: winhttp.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: mswsock.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: iphlpapi.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: userenv.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: winnsi.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: profext.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: biwinrt.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: dnsapi.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: rasadhlp.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: schannel.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: photometadatahandler.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: windows.security.authentication.web.core.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: vaultcli.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: microsoftaccountwamextension.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: mskeyprotect.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: ntasn1.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: ncrypt.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: ncryptsslp.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: msasn1.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: dpapi.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: gpapi.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: mfsrcsnk.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: appcontracts.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: usermgrproxy.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: cdprt.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: cdp.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: dsreg.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: mfps.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: mfmp4srcsnk.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: msamrnbsource.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: mfasfsrcsnk.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: mfds.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: msflacdecoder.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: avrt.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: mfmpeg2srcsnk.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: mfmkvsrcsnk.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: mfnetsrc.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: mfnetcore.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: dwmapi.dll | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Section loaded: gnsdk_fp.dll | |
Source: C:\Windows\System32\dllhost.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\dllhost.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\System32\dllhost.exe | Section loaded: thumbcache.dll | |
Source: C:\Windows\System32\dllhost.exe | Section loaded: propsys.dll | |
Source: C:\Windows\System32\dllhost.exe | Section loaded: photometadatahandler.dll | |
Source: C:\Windows\System32\dllhost.exe | Section loaded: windowscodecs.dll | |
Source: C:\Windows\System32\dllhost.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Windows\System32\dllhost.exe | Section loaded: thumbcache.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: powrprof.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: rmclient.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: umpdc.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: windows.applicationmodel.lockscreen.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: wincorlib.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: twinapi.appcore.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: lockappbroker.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: msvcp110_win.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: mrmcorer.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: windows.staterepositorycore.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: windows.ui.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: windowmanagementapi.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: wintypes.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: coremessaging.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: textinputframework.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: inputhost.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: propsys.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: coreuicomponents.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: coreuicomponents.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: ntmarta.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: lockcontroller.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: d3d11.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: dwmapi.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: dxgi.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: windows.networking.connectivity.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: npmproxy.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: dusmapi.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: wldp.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: settingsynccore.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: policymanager.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: capauthz.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: linkinfo.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: ntshrui.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: cscapi.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: windows.fileexplorer.common.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: iertutil.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: structuredquery.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: windows.storage.search.dll | |
Source: C:\Windows\System32\RuntimeBroker.exe | Section loaded: apphelp.dll | |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LEC3KQZZqZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\backgroundTaskHost.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\RuntimeBroker.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\BackgroundTransferHost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\BackgroundTransferHost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\backgroundTaskHost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\rundll32.exe | Process information set: NOOPENFILEERRORBOX | |