Source: unknown | TCP traffic detected without corresponding DNS query: 102.182.145.130 |
Source: unknown | TCP traffic detected without corresponding DNS query: 102.182.145.130 |
Source: unknown | TCP traffic detected without corresponding DNS query: 102.182.145.130 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.173.254.105 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.173.254.105 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.173.254.105 |
Source: unknown | TCP traffic detected without corresponding DNS query: 64.207.182.168 |
Source: unknown | TCP traffic detected without corresponding DNS query: 64.207.182.168 |
Source: unknown | TCP traffic detected without corresponding DNS query: 64.207.182.168 |
Source: unknown | TCP traffic detected without corresponding DNS query: 64.207.182.168 |
Source: unknown | TCP traffic detected without corresponding DNS query: 64.207.182.168 |
Source: unknown | TCP traffic detected without corresponding DNS query: 64.207.182.168 |
Source: unknown | TCP traffic detected without corresponding DNS query: 64.207.182.168 |
Source: unknown | TCP traffic detected without corresponding DNS query: 64.207.182.168 |
Source: unknown | TCP traffic detected without corresponding DNS query: 64.207.182.168 |
Source: unknown | TCP traffic detected without corresponding DNS query: 51.89.199.141 |
Source: unknown | TCP traffic detected without corresponding DNS query: 51.89.199.141 |
Source: unknown | TCP traffic detected without corresponding DNS query: 51.89.199.141 |
Source: unknown | TCP traffic detected without corresponding DNS query: 51.89.199.141 |
Source: unknown | TCP traffic detected without corresponding DNS query: 51.89.199.141 |
Source: unknown | TCP traffic detected without corresponding DNS query: 51.89.199.141 |
Source: unknown | TCP traffic detected without corresponding DNS query: 51.89.199.141 |
Source: unknown | TCP traffic detected without corresponding DNS query: 102.182.145.130 |
Source: unknown | TCP traffic detected without corresponding DNS query: 102.182.145.130 |
Source: unknown | TCP traffic detected without corresponding DNS query: 102.182.145.130 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.173.254.105 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.173.254.105 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.173.254.105 |
Source: unknown | TCP traffic detected without corresponding DNS query: 64.207.182.168 |
Source: unknown | TCP traffic detected without corresponding DNS query: 64.207.182.168 |
Source: unknown | TCP traffic detected without corresponding DNS query: 64.207.182.168 |
Source: unknown | TCP traffic detected without corresponding DNS query: 64.207.182.168 |
Source: unknown | TCP traffic detected without corresponding DNS query: 64.207.182.168 |
Source: unknown | TCP traffic detected without corresponding DNS query: 64.207.182.168 |
Source: unknown | TCP traffic detected without corresponding DNS query: 64.207.182.168 |
Source: unknown | TCP traffic detected without corresponding DNS query: 64.207.182.168 |
Source: unknown | TCP traffic detected without corresponding DNS query: 64.207.182.168 |
Source: unknown | TCP traffic detected without corresponding DNS query: 51.89.199.141 |
Source: unknown | TCP traffic detected without corresponding DNS query: 51.89.199.141 |
Source: unknown | TCP traffic detected without corresponding DNS query: 51.89.199.141 |
Source: unknown | TCP traffic detected without corresponding DNS query: 51.89.199.141 |
Source: unknown | TCP traffic detected without corresponding DNS query: 51.89.199.141 |
Source: unknown | TCP traffic detected without corresponding DNS query: 51.89.199.141 |
Source: unknown | TCP traffic detected without corresponding DNS query: 51.89.199.141 |
Source: WpPortingLibrary.exe, 00000003.00000002.503525412.0000000003250000.00000004.00000001.sdmp | String found in binary or memory: http://102.182.145.130/h84kVVvyZLtR8YY/cEnY6TFzK/AmNS6FU7LXcmZHrA26R/A6CfQNnHg6slnlDaP5/ |
Source: WpPortingLibrary.exe, 00000003.00000002.503525412.0000000003250000.00000004.00000001.sdmp | String found in binary or memory: http://102.182.145.130/h84kVVvyZLtR8YY/cEnY6TFzK/AmNS6FU7LXcmZHrA26R/A6CfQNnHg6slnlDaP5/X- |
Source: WpPortingLibrary.exe, 00000003.00000003.361330882.000000000325E000.00000004.00000001.sdmp | String found in binary or memory: http://173.173.254.105/LN19JoV6Jo34Ba/UOjzG3KqtwalQ/Gy4EZLufQaYY3rmRrq0/Su721nFGl8jnm9/v1RyG4lzB/ |
Source: WpPortingLibrary.exe, 00000003.00000002.503525412.0000000003250000.00000004.00000001.sdmp | String found in binary or memory: http://51.89.199.141:8080/0fVL69rn/PVbyHTnRzq/3Wii09TSPPBnNOl/ |
Source: WpPortingLibrary.exe, 00000003.00000002.500142679.0000000000E5A000.00000004.00000020.sdmp | String found in binary or memory: http://51.89.199.141:8080/0fVL69rn/PVbyHTnRzq/3Wii09TSPPBnNOl/. |
Source: WpPortingLibrary.exe, 00000003.00000002.503525412.0000000003250000.00000004.00000001.sdmp | String found in binary or memory: http://51.89.199.141:8080/0fVL69rn/PVbyHTnRzq/3Wii09TSPPBnNOl/T) |
Source: WpPortingLibrary.exe, 00000003.00000002.503525412.0000000003250000.00000004.00000001.sdmp | String found in binary or memory: http://51.89.199.141:8080/0fVL69rn/PVbyHTnRzq/3Wii09TSPPBnNOl/d( |
Source: WpPortingLibrary.exe, 00000003.00000002.503525412.0000000003250000.00000004.00000001.sdmp | String found in binary or memory: http://64.207.182.168:8080/hdXW/ |
Source: WpPortingLibrary.exe, 00000003.00000002.503525412.0000000003250000.00000004.00000001.sdmp | String found in binary or memory: http://64.207.182.168:8080/hdXW/O |
Source: WpPortingLibrary.exe, 00000003.00000002.503525412.0000000003250000.00000004.00000001.sdmp | String found in binary or memory: http://64.207.182.168:8080/hdXW/l |
Source: WpPortingLibrary.exe, 00000003.00000002.503525412.0000000003250000.00000004.00000001.sdmp | String found in binary or memory: http://64.207.182.168:8080/hdXW/ll |
Source: svchost.exe, 00000004.00000002.501472156.0000017996C16000.00000004.00000001.sdmp | String found in binary or memory: http://crl3.digicert.com/Omniroot2025.crl0 |
Source: svchost.exe, 00000004.00000002.501472156.0000017996C16000.00000004.00000001.sdmp | String found in binary or memory: http://ocsp.digicert.com0: |
Source: svchost.exe, 00000004.00000002.501376722.0000017996C00000.00000004.00000001.sdmp | String found in binary or memory: http://ocsp.msocsp.com0 |
Source: svchost.exe, 00000004.00000002.503056387.0000017997060000.00000002.00000001.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous. |
Source: svchost.exe, 00000009.00000002.304660388.00000189FAC13000.00000004.00000001.sdmp | String found in binary or memory: http://www.bingmapsportal.com |
Source: svchost.exe, 00000007.00000002.499986642.000002776643E000.00000004.00000001.sdmp | String found in binary or memory: https://%s.dnet.xboxlive.com |
Source: svchost.exe, 00000007.00000002.499986642.000002776643E000.00000004.00000001.sdmp | String found in binary or memory: https://%s.xboxlive.com |
Source: svchost.exe, 00000007.00000002.499986642.000002776643E000.00000004.00000001.sdmp | String found in binary or memory: https://activity.windows.com |
Source: svchost.exe, 00000009.00000003.304378373.00000189FAC60000.00000004.00000001.sdmp | String found in binary or memory: https://appexmapsappupdate.blob.core.windows.net |
Source: svchost.exe, 00000007.00000002.499986642.000002776643E000.00000004.00000001.sdmp | String found in binary or memory: https://bn2.notify.windows.com/v2/register/xplatform/device |
Source: svchost.exe, 00000007.00000002.499986642.000002776643E000.00000004.00000001.sdmp | String found in binary or memory: https://co4-df.notify.windows.com/v2/register/xplatform/device |
Source: svchost.exe, 00000009.00000003.304423488.00000189FAC5C000.00000004.00000001.sdmp | String found in binary or memory: https://dev.ditu.live.com/REST/v1/Imagery/Copyright/ |
Source: svchost.exe, 00000009.00000003.304378373.00000189FAC60000.00000004.00000001.sdmp | String found in binary or memory: https://dev.ditu.live.com/REST/v1/Locations |
Source: svchost.exe, 00000009.00000003.304448108.00000189FAC3D000.00000004.00000001.sdmp | String found in binary or memory: https://dev.ditu.live.com/REST/v1/Routes/ |
Source: svchost.exe, 00000009.00000003.304378373.00000189FAC60000.00000004.00000001.sdmp | String found in binary or memory: https://dev.ditu.live.com/mapcontrol/logging.ashx |
Source: svchost.exe, 00000009.00000002.304752691.00000189FAC4E000.00000004.00000001.sdmp | String found in binary or memory: https://dev.ditu.live.com/mapcontrol/mapconfiguration.ashx?name=native&v= |
Source: svchost.exe, 00000009.00000003.304448108.00000189FAC3D000.00000004.00000001.sdmp | String found in binary or memory: https://dev.virtualearth.net/REST/v1/Routes/ |
Source: svchost.exe, 00000009.00000003.304378373.00000189FAC60000.00000004.00000001.sdmp | String found in binary or memory: https://dev.virtualearth.net/REST/v1/Routes/Driving |
Source: svchost.exe, 00000009.00000003.304378373.00000189FAC60000.00000004.00000001.sdmp | String found in binary or memory: https://dev.virtualearth.net/REST/v1/Routes/Transit |
Source: svchost.exe, 00000009.00000003.304378373.00000189FAC60000.00000004.00000001.sdmp | String found in binary or memory: https://dev.virtualearth.net/REST/v1/Routes/Walking |
Source: svchost.exe, 00000009.00000003.304448108.00000189FAC3D000.00000004.00000001.sdmp | String found in binary or memory: https://dev.virtualearth.net/REST/v1/Transit/Schedules/ |
Source: svchost.exe, 00000009.00000003.304448108.00000189FAC3D000.00000004.00000001.sdmp | String found in binary or memory: https://dev.virtualearth.net/mapcontrol/HumanScaleServices/GetBubbles.ashx?n= |
Source: svchost.exe, 00000009.00000003.304378373.00000189FAC60000.00000004.00000001.sdmp | String found in binary or memory: https://dev.virtualearth.net/mapcontrol/logging.ashx |
Source: svchost.exe, 00000009.00000003.304448108.00000189FAC3D000.00000004.00000001.sdmp | String found in binary or memory: https://dev.virtualearth.net/webservices/v1/LoggingService/LoggingService.svc/Log? |
Source: svchost.exe, 00000009.00000003.304423488.00000189FAC5C000.00000004.00000001.sdmp | String found in binary or memory: https://dynamic.api.tiles.ditu.live.com/odvs/gd?pv=1&r= |
Source: svchost.exe, 00000009.00000003.304461962.00000189FAC57000.00000004.00000001.sdmp | String found in binary or memory: https://dynamic.api.tiles.ditu.live.com/odvs/gdi?pv=1&r= |
Source: svchost.exe, 00000009.00000003.304461962.00000189FAC57000.00000004.00000001.sdmp | String found in binary or memory: https://dynamic.api.tiles.ditu.live.com/odvs/gdv?pv=1&r= |
Source: svchost.exe, 00000009.00000003.304362631.00000189FAC63000.00000004.00000001.sdmp, svchost.exe, 00000009.00000003.304423488.00000189FAC5C000.00000004.00000001.sdmp | String found in binary or memory: https://dynamic.t |
Source: svchost.exe, 00000009.00000003.304378373.00000189FAC60000.00000004.00000001.sdmp | String found in binary or memory: https://dynamic.t0.tiles.ditu.live.com/comp/gen.ashx |
Source: svchost.exe, 00000009.00000003.304448108.00000189FAC3D000.00000004.00000001.sdmp | String found in binary or memory: https://ecn.dev.virtualearth.net/REST/v1/Imagery/Copyright/ |
Source: svchost.exe, 00000009.00000003.282341155.00000189FAC31000.00000004.00000001.sdmp | String found in binary or memory: https://ecn.dev.virtualearth.net/mapcontrol/mapconfiguration.ashx?name=native&v= |
Source: svchost.exe, 00000009.00000003.304448108.00000189FAC3D000.00000004.00000001.sdmp | String found in binary or memory: https://t0.ssl.ak.dynamic.tiles.virtualearth.net/comp/gen.ashx |
Source: svchost.exe, 00000009.00000003.304448108.00000189FAC3D000.00000004.00000001.sdmp | String found in binary or memory: https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gd?pv=1&r= |
Source: svchost.exe, 00000009.00000003.304448108.00000189FAC3D000.00000004.00000001.sdmp | String found in binary or memory: https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gdi?pv=1&r= |
Source: svchost.exe, 00000009.00000003.304448108.00000189FAC3D000.00000004.00000001.sdmp | String found in binary or memory: https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gdv?pv=1&r= |
Source: svchost.exe, 00000009.00000003.282341155.00000189FAC31000.00000004.00000001.sdmp | String found in binary or memory: https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gri?pv=1&r= |
Source: svchost.exe, 00000009.00000002.304715723.00000189FAC3A000.00000004.00000001.sdmp | String found in binary or memory: https://t0.ssl.ak.tiles.virtualearth.net/tiles/gen |
Source: svchost.exe, 00000009.00000002.304752691.00000189FAC4E000.00000004.00000001.sdmp | String found in binary or memory: https://t0.tiles.ditu.live.com/tiles/gen |
Source: WpPortingLibrary.exe, 00000003.00000002.503525412.0000000003250000.00000004.00000001.sdmp | String found in binary or memory: http://102.182.145.130/h84kVVvyZLtR8YY/cEnY6TFzK/AmNS6FU7LXcmZHrA26R/A6CfQNnHg6slnlDaP5/ |
Source: WpPortingLibrary.exe, 00000003.00000002.503525412.0000000003250000.00000004.00000001.sdmp | String found in binary or memory: http://102.182.145.130/h84kVVvyZLtR8YY/cEnY6TFzK/AmNS6FU7LXcmZHrA26R/A6CfQNnHg6slnlDaP5/X- |
Source: WpPortingLibrary.exe, 00000003.00000003.361330882.000000000325E000.00000004.00000001.sdmp | String found in binary or memory: http://173.173.254.105/LN19JoV6Jo34Ba/UOjzG3KqtwalQ/Gy4EZLufQaYY3rmRrq0/Su721nFGl8jnm9/v1RyG4lzB/ |
Source: WpPortingLibrary.exe, 00000003.00000002.503525412.0000000003250000.00000004.00000001.sdmp | String found in binary or memory: http://51.89.199.141:8080/0fVL69rn/PVbyHTnRzq/3Wii09TSPPBnNOl/ |
Source: WpPortingLibrary.exe, 00000003.00000002.500142679.0000000000E5A000.00000004.00000020.sdmp | String found in binary or memory: http://51.89.199.141:8080/0fVL69rn/PVbyHTnRzq/3Wii09TSPPBnNOl/. |
Source: WpPortingLibrary.exe, 00000003.00000002.503525412.0000000003250000.00000004.00000001.sdmp | String found in binary or memory: http://51.89.199.141:8080/0fVL69rn/PVbyHTnRzq/3Wii09TSPPBnNOl/T) |
Source: WpPortingLibrary.exe, 00000003.00000002.503525412.0000000003250000.00000004.00000001.sdmp | String found in binary or memory: http://51.89.199.141:8080/0fVL69rn/PVbyHTnRzq/3Wii09TSPPBnNOl/d( |
Source: WpPortingLibrary.exe, 00000003.00000002.503525412.0000000003250000.00000004.00000001.sdmp | String found in binary or memory: http://64.207.182.168:8080/hdXW/ |
Source: WpPortingLibrary.exe, 00000003.00000002.503525412.0000000003250000.00000004.00000001.sdmp | String found in binary or memory: http://64.207.182.168:8080/hdXW/O |
Source: WpPortingLibrary.exe, 00000003.00000002.503525412.0000000003250000.00000004.00000001.sdmp | String found in binary or memory: http://64.207.182.168:8080/hdXW/l |
Source: WpPortingLibrary.exe, 00000003.00000002.503525412.0000000003250000.00000004.00000001.sdmp | String found in binary or memory: http://64.207.182.168:8080/hdXW/ll |
Source: svchost.exe, 00000004.00000002.501472156.0000017996C16000.00000004.00000001.sdmp | String found in binary or memory: http://crl3.digicert.com/Omniroot2025.crl0 |
Source: svchost.exe, 00000004.00000002.501472156.0000017996C16000.00000004.00000001.sdmp | String found in binary or memory: http://ocsp.digicert.com0: |
Source: svchost.exe, 00000004.00000002.501376722.0000017996C00000.00000004.00000001.sdmp | String found in binary or memory: http://ocsp.msocsp.com0 |
Source: svchost.exe, 00000004.00000002.503056387.0000017997060000.00000002.00000001.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous. |
Source: svchost.exe, 00000009.00000002.304660388.00000189FAC13000.00000004.00000001.sdmp | String found in binary or memory: http://www.bingmapsportal.com |
Source: svchost.exe, 00000007.00000002.499986642.000002776643E000.00000004.00000001.sdmp | String found in binary or memory: https://%s.dnet.xboxlive.com |
Source: svchost.exe, 00000007.00000002.499986642.000002776643E000.00000004.00000001.sdmp | String found in binary or memory: https://%s.xboxlive.com |
Source: svchost.exe, 00000007.00000002.499986642.000002776643E000.00000004.00000001.sdmp | String found in binary or memory: https://activity.windows.com |
Source: svchost.exe, 00000009.00000003.304378373.00000189FAC60000.00000004.00000001.sdmp | String found in binary or memory: https://appexmapsappupdate.blob.core.windows.net |
Source: svchost.exe, 00000007.00000002.499986642.000002776643E000.00000004.00000001.sdmp | String found in binary or memory: https://bn2.notify.windows.com/v2/register/xplatform/device |
Source: svchost.exe, 00000007.00000002.499986642.000002776643E000.00000004.00000001.sdmp | String found in binary or memory: https://co4-df.notify.windows.com/v2/register/xplatform/device |
Source: svchost.exe, 00000009.00000003.304423488.00000189FAC5C000.00000004.00000001.sdmp | String found in binary or memory: https://dev.ditu.live.com/REST/v1/Imagery/Copyright/ |
Source: svchost.exe, 00000009.00000003.304378373.00000189FAC60000.00000004.00000001.sdmp | String found in binary or memory: https://dev.ditu.live.com/REST/v1/Locations |
Source: svchost.exe, 00000009.00000003.304448108.00000189FAC3D000.00000004.00000001.sdmp | String found in binary or memory: https://dev.ditu.live.com/REST/v1/Routes/ |
Source: svchost.exe, 00000009.00000003.304378373.00000189FAC60000.00000004.00000001.sdmp | String found in binary or memory: https://dev.ditu.live.com/mapcontrol/logging.ashx |
Source: svchost.exe, 00000009.00000002.304752691.00000189FAC4E000.00000004.00000001.sdmp | String found in binary or memory: https://dev.ditu.live.com/mapcontrol/mapconfiguration.ashx?name=native&v= |
Source: svchost.exe, 00000009.00000003.304448108.00000189FAC3D000.00000004.00000001.sdmp | String found in binary or memory: https://dev.virtualearth.net/REST/v1/Routes/ |
Source: svchost.exe, 00000009.00000003.304378373.00000189FAC60000.00000004.00000001.sdmp | String found in binary or memory: https://dev.virtualearth.net/REST/v1/Routes/Driving |
Source: svchost.exe, 00000009.00000003.304378373.00000189FAC60000.00000004.00000001.sdmp | String found in binary or memory: https://dev.virtualearth.net/REST/v1/Routes/Transit |
Source: svchost.exe, 00000009.00000003.304378373.00000189FAC60000.00000004.00000001.sdmp | String found in binary or memory: https://dev.virtualearth.net/REST/v1/Routes/Walking |
Source: svchost.exe, 00000009.00000003.304448108.00000189FAC3D000.00000004.00000001.sdmp | String found in binary or memory: https://dev.virtualearth.net/REST/v1/Transit/Schedules/ |
Source: svchost.exe, 00000009.00000003.304448108.00000189FAC3D000.00000004.00000001.sdmp | String found in binary or memory: https://dev.virtualearth.net/mapcontrol/HumanScaleServices/GetBubbles.ashx?n= |
Source: svchost.exe, 00000009.00000003.304378373.00000189FAC60000.00000004.00000001.sdmp | String found in binary or memory: https://dev.virtualearth.net/mapcontrol/logging.ashx |
Source: svchost.exe, 00000009.00000003.304448108.00000189FAC3D000.00000004.00000001.sdmp | String found in binary or memory: https://dev.virtualearth.net/webservices/v1/LoggingService/LoggingService.svc/Log? |
Source: svchost.exe, 00000009.00000003.304423488.00000189FAC5C000.00000004.00000001.sdmp | String found in binary or memory: https://dynamic.api.tiles.ditu.live.com/odvs/gd?pv=1&r= |
Source: svchost.exe, 00000009.00000003.304461962.00000189FAC57000.00000004.00000001.sdmp | String found in binary or memory: https://dynamic.api.tiles.ditu.live.com/odvs/gdi?pv=1&r= |
Source: svchost.exe, 00000009.00000003.304461962.00000189FAC57000.00000004.00000001.sdmp | String found in binary or memory: https://dynamic.api.tiles.ditu.live.com/odvs/gdv?pv=1&r= |
Source: svchost.exe, 00000009.00000003.304362631.00000189FAC63000.00000004.00000001.sdmp, svchost.exe, 00000009.00000003.304423488.00000189FAC5C000.00000004.00000001.sdmp | String found in binary or memory: https://dynamic.t |
Source: svchost.exe, 00000009.00000003.304378373.00000189FAC60000.00000004.00000001.sdmp | String found in binary or memory: https://dynamic.t0.tiles.ditu.live.com/comp/gen.ashx |
Source: svchost.exe, 00000009.00000003.304448108.00000189FAC3D000.00000004.00000001.sdmp | String found in binary or memory: https://ecn.dev.virtualearth.net/REST/v1/Imagery/Copyright/ |
Source: svchost.exe, 00000009.00000003.282341155.00000189FAC31000.00000004.00000001.sdmp | String found in binary or memory: https://ecn.dev.virtualearth.net/mapcontrol/mapconfiguration.ashx?name=native&v= |
Source: svchost.exe, 00000009.00000003.304448108.00000189FAC3D000.00000004.00000001.sdmp | String found in binary or memory: https://t0.ssl.ak.dynamic.tiles.virtualearth.net/comp/gen.ashx |
Source: svchost.exe, 00000009.00000003.304448108.00000189FAC3D000.00000004.00000001.sdmp | String found in binary or memory: https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gd?pv=1&r= |
Source: svchost.exe, 00000009.00000003.304448108.00000189FAC3D000.00000004.00000001.sdmp | String found in binary or memory: https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gdi?pv=1&r= |
Source: svchost.exe, 00000009.00000003.304448108.00000189FAC3D000.00000004.00000001.sdmp | String found in binary or memory: https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gdv?pv=1&r= |
Source: svchost.exe, 00000009.00000003.282341155.00000189FAC31000.00000004.00000001.sdmp | String found in binary or memory: https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gri?pv=1&r= |
Source: svchost.exe, 00000009.00000002.304715723.00000189FAC3A000.00000004.00000001.sdmp | String found in binary or memory: https://t0.ssl.ak.tiles.virtualearth.net/tiles/gen |
Source: svchost.exe, 00000009.00000002.304752691.00000189FAC4E000.00000004.00000001.sdmp | String found in binary or memory: https://t0.tiles.ditu.live.com/tiles/gen |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF8240 |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF3BA0 |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF1C70 |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF7740 |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF3F20 |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF6530 |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF3D10 |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E792DE |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E75ABE |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E7573E |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E780CE |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E758AE |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E87069 |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E7380E |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E79DDE |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF8240 |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF3BA0 |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF1C70 |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF7740 |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF3F20 |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF6530 |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF3D10 |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E792DE |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E75ABE |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E7573E |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E780CE |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E758AE |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E87069 |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E7380E |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E79DDE |
Source: C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe | Code function: 3_2_02A78240 |
Source: C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe | Code function: 3_2_02A73BA0 |
Source: C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe | Code function: 3_2_02A73F20 |
Source: C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe | Code function: 3_2_02A76530 |
Source: C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe | Code function: 3_2_02A73D10 |
Source: C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe | Code function: 3_2_02A71C70 |
Source: C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe | Code function: 3_2_02A77740 |
Source: C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe | Code function: 3_2_029F5ABE |
Source: C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe | Code function: 3_2_029F92DE |
Source: C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe | Code function: 3_2_029F573E |
Source: C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe | Code function: 3_2_029F58AE |
Source: C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe | Code function: 3_2_029F80CE |
Source: C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe | Code function: 3_2_029F380E |
Source: C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe | Code function: 3_2_02A07069 |
Source: C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe | Code function: 3_2_029F9DDE |
Source: unknown | Process created: C:\Users\user\Desktop\FsWcL0gpTv.exe 'C:\Users\user\Desktop\FsWcL0gpTv.exe' |
Source: unknown | Process created: C:\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s NgcSvc |
Source: unknown | Process created: C:\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s NgcCtnrSvc |
Source: unknown | Process created: C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe |
Source: unknown | Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS |
Source: unknown | Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p |
Source: unknown | Process created: C:\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localservice -p -s CDPSvc |
Source: unknown | Process created: C:\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k networkservice -p -s DoSvc |
Source: unknown | Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k NetworkService -p |
Source: unknown | Process created: C:\Windows\System32\SgrmBroker.exe C:\Windows\system32\SgrmBroker.exe |
Source: unknown | Process created: C:\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s wscsvc |
Source: unknown | Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p |
Source: unknown | Process created: C:\Program Files\Windows Defender\MpCmdRun.exe 'C:\Program Files\Windows Defender\mpcmdrun.exe' -wdenable |
Source: unknown | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Process created: C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Program Files\Windows Defender\MpCmdRun.exe 'C:\Program Files\Windows Defender\mpcmdrun.exe' -wdenable |
Source: unknown | Process created: C:\Users\user\Desktop\FsWcL0gpTv.exe 'C:\Users\user\Desktop\FsWcL0gpTv.exe' |
Source: unknown | Process created: C:\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s NgcSvc |
Source: unknown | Process created: C:\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s NgcCtnrSvc |
Source: unknown | Process created: C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe |
Source: unknown | Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS |
Source: unknown | Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p |
Source: unknown | Process created: C:\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localservice -p -s CDPSvc |
Source: unknown | Process created: C:\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k networkservice -p -s DoSvc |
Source: unknown | Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k NetworkService -p |
Source: unknown | Process created: C:\Windows\System32\SgrmBroker.exe C:\Windows\system32\SgrmBroker.exe |
Source: unknown | Process created: C:\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s wscsvc |
Source: unknown | Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p |
Source: unknown | Process created: C:\Program Files\Windows Defender\MpCmdRun.exe 'C:\Program Files\Windows Defender\mpcmdrun.exe' -wdenable |
Source: unknown | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Process created: C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Program Files\Windows Defender\MpCmdRun.exe 'C:\Program Files\Windows Defender\mpcmdrun.exe' -wdenable |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF5DF0 push ecx; mov dword ptr [esp], 0000AAF5h |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF5EF0 push ecx; mov dword ptr [esp], 0000669Ch |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF5DC0 push ecx; mov dword ptr [esp], 000089FAh |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF5CD0 push ecx; mov dword ptr [esp], 00001CE1h |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF5EA0 push ecx; mov dword ptr [esp], 0000A3FDh |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF5D90 push ecx; mov dword ptr [esp], 0000B2E0h |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF5D50 push ecx; mov dword ptr [esp], 00006847h |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF5D20 push ecx; mov dword ptr [esp], 0000C5A1h |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF5F20 push ecx; mov dword ptr [esp], 0000E36Ch |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF5D00 push ecx; mov dword ptr [esp], 00001F9Eh |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF5E10 push ecx; mov dword ptr [esp], 0000F5B3h |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E77ABE push ecx; mov dword ptr [esp], 0000E36Ch |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E77A8E push ecx; mov dword ptr [esp], 0000669Ch |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E93E9C push ebx; iretd |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E93E9C push FFFFFF95h; iretd |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E77A3E push ecx; mov dword ptr [esp], 0000A3FDh |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E778EE push ecx; mov dword ptr [esp], 00006847h |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E778BE push ecx; mov dword ptr [esp], 0000C5A1h |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E7789E push ecx; mov dword ptr [esp], 00001F9Eh |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E7786E push ecx; mov dword ptr [esp], 00001CE1h |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E939D9 push ss; iretd |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E779AE push ecx; mov dword ptr [esp], 0000F5B3h |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E8858F push edi; iretd |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E7798E push ecx; mov dword ptr [esp], 0000AAF5h |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E7795E push ecx; mov dword ptr [esp], 000089FAh |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E7792E push ecx; mov dword ptr [esp], 0000B2E0h |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF5DF0 push ecx; mov dword ptr [esp], 0000AAF5h |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF5EF0 push ecx; mov dword ptr [esp], 0000669Ch |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF5DC0 push ecx; mov dword ptr [esp], 000089FAh |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF5CD0 push ecx; mov dword ptr [esp], 00001CE1h |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF5EA0 push ecx; mov dword ptr [esp], 0000A3FDh |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF5D90 push ecx; mov dword ptr [esp], 0000B2E0h |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF5D50 push ecx; mov dword ptr [esp], 00006847h |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF5D20 push ecx; mov dword ptr [esp], 0000C5A1h |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF5F20 push ecx; mov dword ptr [esp], 0000E36Ch |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF5D00 push ecx; mov dword ptr [esp], 00001F9Eh |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF5E10 push ecx; mov dword ptr [esp], 0000F5B3h |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E77ABE push ecx; mov dword ptr [esp], 0000E36Ch |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E77A8E push ecx; mov dword ptr [esp], 0000669Ch |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E93E9C push ebx; iretd |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E93E9C push FFFFFF95h; iretd |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E77A3E push ecx; mov dword ptr [esp], 0000A3FDh |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E778EE push ecx; mov dword ptr [esp], 00006847h |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E778BE push ecx; mov dword ptr [esp], 0000C5A1h |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E7789E push ecx; mov dword ptr [esp], 00001F9Eh |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E7786E push ecx; mov dword ptr [esp], 00001CE1h |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E939D9 push ss; iretd |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E779AE push ecx; mov dword ptr [esp], 0000F5B3h |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E8858F push edi; iretd |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E7798E push ecx; mov dword ptr [esp], 0000AAF5h |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E7795E push ecx; mov dword ptr [esp], 000089FAh |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E7792E push ecx; mov dword ptr [esp], 0000B2E0h |
Source: C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe | Code function: 3_2_02A75EA0 push ecx; mov dword ptr [esp], 0000A3FDh |
Source: C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe | Code function: 3_2_02A75D90 push ecx; mov dword ptr [esp], 0000B2E0h |
Source: C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe | Code function: 3_2_02A75DF0 push ecx; mov dword ptr [esp], 0000AAF5h |
Source: C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe | Code function: 3_2_02A75EF0 push ecx; mov dword ptr [esp], 0000669Ch |
Source: C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe | Code function: 3_2_02A75DC0 push ecx; mov dword ptr [esp], 000089FAh |
Source: svchost.exe, 00000004.00000002.501755488.0000017996C64000.00000004.00000001.sdmp | Binary or memory string: "@Hyper-V RAW |
Source: svchost.exe, 00000006.00000002.291934886.000001A7A3940000.00000002.00000001.sdmp, svchost.exe, 00000007.00000002.501249467.0000027767140000.00000002.00000001.sdmp, svchost.exe, 0000000C.00000002.309736997.0000027366290000.00000002.00000001.sdmp | Binary or memory string: A Virtual Machine could not be started because Hyper-V is not installed. |
Source: svchost.exe, 00000004.00000002.500177833.000001799182A000.00000004.00000001.sdmp | Binary or memory string: Hyper-V RAW`s |
Source: svchost.exe, 00000001.00000002.494050614.0000020E88002000.00000004.00000001.sdmp | Binary or memory string: HvHostWdiSystemHostScDeviceEnumWiaRpctrkwksAudioEndpointBuilderhidservdot3svcDsSvcfhsvcWPDBusEnumsvsvcwlansvcEmbeddedModeirmonSensorServicevmicvssNgcSvcsysmainDevQueryBrokerStorSvcvmickvpexchangevmicshutdownvmicguestinterfacevmicvmsessionNcbServiceNetmanDeviceAssociationServiceTabletInputServicePcaSvcIPxlatCfgSvcCscServiceUmRdpService |
Source: WpPortingLibrary.exe, 00000003.00000002.503525412.0000000003250000.00000004.00000001.sdmp, svchost.exe, 00000004.00000002.501721455.0000017996C57000.00000004.00000001.sdmp | Binary or memory string: Hyper-V RAW |
Source: svchost.exe, 00000006.00000002.291934886.000001A7A3940000.00000002.00000001.sdmp, svchost.exe, 00000007.00000002.501249467.0000027767140000.00000002.00000001.sdmp, svchost.exe, 0000000C.00000002.309736997.0000027366290000.00000002.00000001.sdmp | Binary or memory string: A communication protocol error has occurred between the Hyper-V Host and Guest Compute Service. |
Source: svchost.exe, 00000006.00000002.291934886.000001A7A3940000.00000002.00000001.sdmp, svchost.exe, 00000007.00000002.501249467.0000027767140000.00000002.00000001.sdmp, svchost.exe, 0000000C.00000002.309736997.0000027366290000.00000002.00000001.sdmp | Binary or memory string: The communication protocol version between the Hyper-V Host and Guest Compute Services is not supported. |
Source: WpPortingLibrary.exe, 00000003.00000002.503525412.0000000003250000.00000004.00000001.sdmp | Binary or memory string: Hyper-V RAW |
Source: svchost.exe, 00000007.00000002.500021852.0000027766466000.00000004.00000001.sdmp, svchost.exe, 00000008.00000002.500101123.0000021FB9C29000.00000004.00000001.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll |
Source: svchost.exe, 00000006.00000002.291934886.000001A7A3940000.00000002.00000001.sdmp, svchost.exe, 00000007.00000002.501249467.0000027767140000.00000002.00000001.sdmp, svchost.exe, 0000000C.00000002.309736997.0000027366290000.00000002.00000001.sdmp | Binary or memory string: An unknown internal message was received by the Hyper-V Compute Service. |
Source: svchost.exe, 00000004.00000002.501755488.0000017996C64000.00000004.00000001.sdmp | Binary or memory string: "@Hyper-V RAW |
Source: svchost.exe, 00000006.00000002.291934886.000001A7A3940000.00000002.00000001.sdmp, svchost.exe, 00000007.00000002.501249467.0000027767140000.00000002.00000001.sdmp, svchost.exe, 0000000C.00000002.309736997.0000027366290000.00000002.00000001.sdmp | Binary or memory string: A Virtual Machine could not be started because Hyper-V is not installed. |
Source: svchost.exe, 00000004.00000002.500177833.000001799182A000.00000004.00000001.sdmp | Binary or memory string: Hyper-V RAW`s |
Source: svchost.exe, 00000001.00000002.494050614.0000020E88002000.00000004.00000001.sdmp | Binary or memory string: HvHostWdiSystemHostScDeviceEnumWiaRpctrkwksAudioEndpointBuilderhidservdot3svcDsSvcfhsvcWPDBusEnumsvsvcwlansvcEmbeddedModeirmonSensorServicevmicvssNgcSvcsysmainDevQueryBrokerStorSvcvmickvpexchangevmicshutdownvmicguestinterfacevmicvmsessionNcbServiceNetmanDeviceAssociationServiceTabletInputServicePcaSvcIPxlatCfgSvcCscServiceUmRdpService |
Source: WpPortingLibrary.exe, 00000003.00000002.503525412.0000000003250000.00000004.00000001.sdmp, svchost.exe, 00000004.00000002.501721455.0000017996C57000.00000004.00000001.sdmp | Binary or memory string: Hyper-V RAW |
Source: svchost.exe, 00000006.00000002.291934886.000001A7A3940000.00000002.00000001.sdmp, svchost.exe, 00000007.00000002.501249467.0000027767140000.00000002.00000001.sdmp, svchost.exe, 0000000C.00000002.309736997.0000027366290000.00000002.00000001.sdmp | Binary or memory string: A communication protocol error has occurred between the Hyper-V Host and Guest Compute Service. |
Source: svchost.exe, 00000006.00000002.291934886.000001A7A3940000.00000002.00000001.sdmp, svchost.exe, 00000007.00000002.501249467.0000027767140000.00000002.00000001.sdmp, svchost.exe, 0000000C.00000002.309736997.0000027366290000.00000002.00000001.sdmp | Binary or memory string: The communication protocol version between the Hyper-V Host and Guest Compute Services is not supported. |
Source: WpPortingLibrary.exe, 00000003.00000002.503525412.0000000003250000.00000004.00000001.sdmp | Binary or memory string: Hyper-V RAW |
Source: svchost.exe, 00000007.00000002.500021852.0000027766466000.00000004.00000001.sdmp, svchost.exe, 00000008.00000002.500101123.0000021FB9C29000.00000004.00000001.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll |
Source: svchost.exe, 00000006.00000002.291934886.000001A7A3940000.00000002.00000001.sdmp, svchost.exe, 00000007.00000002.501249467.0000027767140000.00000002.00000001.sdmp, svchost.exe, 0000000C.00000002.309736997.0000027366290000.00000002.00000001.sdmp | Binary or memory string: An unknown internal message was received by the Hyper-V Compute Service. |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF3F20 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF4E20 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E75ABE mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E70456 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E769BE mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E7095E mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EB1030 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF3F20 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EF4E20 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E75ABE mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E70456 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E769BE mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02E7095E mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\FsWcL0gpTv.exe | Code function: 0_2_02EB1030 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe | Code function: 3_2_02A73F20 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe | Code function: 3_2_02A74E20 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe | Code function: 3_2_029F5ABE mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe | Code function: 3_2_029F0456 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe | Code function: 3_2_029F69BE mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe | Code function: 3_2_029F095E mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\offreg\WpPortingLibrary.exe | Code function: 3_2_02A31030 mov eax, dword ptr fs:[00000030h] |