Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
IMG_2879.mp4

Overview

General Information

Sample name:IMG_2879.mp4
(renamed file extension from JPG to mp4)
Original sample name:IMG_2879.JPG
Analysis ID:1445852
MD5:2276ca86ca713ad22d76457615e8c727
SHA1:48e0f4ff39254cb417b032f73cc607d524908878
SHA256:86dae22df32447e4fe1cce4f6fd20c9d19ea557d8f640e4c974753b5ebd4de97
Infos:

Detection

Score:3
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Queries disk information (often used to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Uses code obfuscation techniques (call, push, ret)

Classification

  • System is w10x64
  • Video.UI.exe (PID: 3196 cmdline: "C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exe" -ServerName:Microsoft.ZuneVideo.AppX758ya5sqdjd98rx6z7g95nw6jy7bqx9y.mca MD5: FE340ECB1D09B5BAA66DFE25AF11654F)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 13.107.246.67:443 -> 192.168.2.4:49739 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.246.67:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: Joe Sandbox ViewIP Address: 13.107.246.67 13.107.246.67
Source: Joe Sandbox ViewJA3 fingerprint: 28a2c9bd18a11de089ef85a160da29e4
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /PlayReady/ACT/Activation.asmx?WSDL&Client=Win10&LinkId=613387 HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Microsoft-PlayReady-DRM/1.0Host: activation2.playready.microsoft.com
Source: global trafficDNS traffic detected: DNS query: settings-ssl.xboxlive.com
Source: unknownHTTP traffic detected: POST /PlayReady/ACT/Activation.asmx HTTP/1.1Connection: Keep-AliveContent-Type: text/xml; charset=utf-8Accept: */*User-Agent: Microsoft-PlayReady-DRM/1.0x-playready-info: OSVersion=10.0; ClientDllVersion=Windows.Media.Protection.PlayReady.dll/10.0.19041.2006 (WinBuild.160101.0800); Session=fa58d78ad5ed7305c0ed9c15cee9fb11; StoreAppID=Microsoft.ZuneVideo_8wekyb3d8bbwe!Microsoft.ZuneVideo; X-XblCorrelationId: 5574449021208076118SOAPAction: "http://schemas.microsoft.com/PlayReady/ActivationService/v1/Activate"Content-Length: 3580Host: activation2.playready.microsoft.com
Source: 57C8EDB95DF3F0AD4EE2DC2B8CFD41570.1.drString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab
Source: Video.UI.exe, 00000001.00000003.1778736636.00000265E8A5B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://dmd-ca-beta2/CertEnroll/Microsoft%20Digital%20Media%20Authority%202005.crl
Source: Video.UI.exe, 00000001.00000003.1778736636.00000265E8A5B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://dmd-ca-beta2/CertEnroll/dmd-ca-beta2_Microsoft%20Digital%20Media%20Authority%202005.crt0d
Source: Video.UI.exe, 00000001.00000002.2910897243.00000265DB22C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://json-schema.org/draft-04/schema
Source: Video.UI.exe, 00000001.00000002.2926398742.00000265E8E75000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ns.apple.com/HDRGainMap/1.
Source: Video.UI.exe, 00000001.00000003.1697633187.00000265E8625000.00000004.00000020.00020000.00000000.sdmp, Video.UI.exe, 00000001.00000003.1742362950.00000265E7DE1000.00000004.00000020.00020000.00000000.sdmp, Video.UI.exe, 00000001.00000003.1662956529.00000265E8402000.00000004.00000020.00020000.00000000.sdmp, Video.UI.exe, 00000001.00000003.1663252720.00000265E8502000.00000004.00000020.00020000.00000000.sdmp, Video.UI.exe, 00000001.00000003.1757950524.00000265E8529000.00000004.00000020.00020000.00000000.sdmp, Video.UI.exe, 00000001.00000002.2911756392.00000265DB3A8000.00000004.00000020.00020000.00000000.sdmp, Video.UI.exe, 00000001.00000003.1742577616.00000265E8525000.00000004.00000020.00020000.00000000.sdmp, Video.UI.exe, 00000001.00000002.2926398742.00000265E8E55000.00000004.00000020.00020000.00000000.sdmp, IMG_2879.mp4String found in binary or memory: http://ns.apple.com/HDRGainMap/1.0/
Source: Video.UI.exe, 00000001.00000003.1779015016.00000265E8813000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/soap/http
Source: Video.UI.exe, 00000001.00000002.2921668578.00000265E7D1D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://activity.windows.com/UserActivity.ReadWrite.CreatedByApp82J
Source: Video.UI.exe, 00000001.00000002.2921634310.00000265E7C95000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://android.notify.windows.com/iOS
Source: Video.UI.exe, 00000001.00000002.2921634310.00000265E7C95000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://android.notify.windows.com/iOSWM/MediaClassPrimaryID
Source: Video.UI.exe, 00000001.00000002.2921634310.00000265E7C95000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.live.com
Source: Video.UI.exe, 00000001.00000002.2921634310.00000265E7C95000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.live.com/
Source: Video.UI.exe, 00000001.00000003.2272832446.00000265E7D52000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.windows.local
Source: Video.UI.exe, 00000001.00000002.2921919917.00000265E7D62000.00000004.00000020.00020000.00000000.sdmp, Video.UI.exe, 00000001.00000003.2272863476.00000265E7D5A000.00000004.00000020.00020000.00000000.sdmp, Video.UI.exe, 00000001.00000003.2272832446.00000265E7D52000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.windows.local/
Source: Video.UI.exe, 00000001.00000002.2921919917.00000265E7D62000.00000004.00000020.00020000.00000000.sdmp, Video.UI.exe, 00000001.00000003.2272863476.00000265E7D5A000.00000004.00000020.00020000.00000000.sdmp, Video.UI.exe, 00000001.00000003.2272832446.00000265E7D52000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.windows.net
Source: Video.UI.exe, 00000001.00000002.2921919917.00000265E7D62000.00000004.00000020.00020000.00000000.sdmp, Video.UI.exe, 00000001.00000003.2272863476.00000265E7D5A000.00000004.00000020.00020000.00000000.sdmp, Video.UI.exe, 00000001.00000003.2272832446.00000265E7D52000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.windows.net/
Source: Video.UI.exe, 00000001.00000002.2921919917.00000265E7D62000.00000004.00000020.00020000.00000000.sdmp, Video.UI.exe, 00000001.00000003.2272863476.00000265E7D5A000.00000004.00000020.00020000.00000000.sdmp, Video.UI.exe, 00000001.00000003.2272832446.00000265E7D52000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.windows.netNetscape
Source: Video.UI.exe, 00000001.00000002.2921944106.00000265E7D83000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://settings-ssl.xboxlive.com/
Source: Video.UI.exe, 00000001.00000002.2921944106.00000265E7D83000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://settings-ssl.xboxlive.com/UP
Source: Video.UI.exe, 00000001.00000002.2921668578.00000265E7CE4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://settings-ssl.xboxlive.com/XBLWinClient/v10_video/configuration.xml
Source: Video.UI.exe, 00000001.00000002.2913395537.00000265E1D9B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://wns.windows.com/.dll
Source: Video.UI.exe, 00000001.00000002.2921919917.00000265E7D62000.00000004.00000020.00020000.00000000.sdmp, Video.UI.exe, 00000001.00000003.2272863476.00000265E7D5A000.00000004.00000020.00020000.00000000.sdmp, Video.UI.exe, 00000001.00000003.2272832446.00000265E7D52000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://xsts.auth.xboxlive.com
Source: Video.UI.exe, 00000001.00000002.2921919917.00000265E7D62000.00000004.00000020.00020000.00000000.sdmp, Video.UI.exe, 00000001.00000003.2272863476.00000265E7D5A000.00000004.00000020.00020000.00000000.sdmp, Video.UI.exe, 00000001.00000003.2272832446.00000265E7D52000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://xsts.auth.xboxlive.com/Enrolment
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 13.107.246.67:443 -> 192.168.2.4:49739 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.246.67:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: classification engineClassification label: clean3.winMP4@1/17@1/1
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\LocalState\Database\Jump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: d3d11.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: d2d1.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: dwrite.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: dxgi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: sharedui.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: vccorlib140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: msvcp140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: concrt140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: vcruntime140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: vcruntime140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: msvcp140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: vcruntime140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: windows.ui.xaml.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: bcp47langs.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: dcomp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: twinapi.appcore.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: windows.staterepositorycore.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: windows.ui.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: windowmanagementapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: inputhost.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: propsys.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: netutils.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: resourcepolicyclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: rometadata.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: dxcore.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: windows.applicationmodel.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: esent.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: windows.storage.applicationdata.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: wldp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: logoncli.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: threadpoolwinrt.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: windows.globalization.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: bcp47mrm.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: profapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: clipc.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: mrmcorer.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: windows.staterepositoryclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: appxdeploymentclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: windows.ui.xaml.controls.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: windows.shell.servicehostbuilder.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: execmodelproxy.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: rmclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: uiamanager.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: windows.ui.core.textinput.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: windows.ui.immersive.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: dataexchange.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: windows.system.profile.retailinfo.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: windows.media.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: windows.graphics.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: windows.ui.xaml.phone.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: twinapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: windows.energy.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: windows.networking.connectivity.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: windows.devices.enumeration.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: directmanipulation.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: wuceffects.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: userenv.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: profext.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: windows.media.playback.mediaplayer.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: mfplat.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: rtworkq.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: windows.media.mediacontrol.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: mmdevapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: devobj.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: mfmediaengine.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: xmllite.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: audioses.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: windows.media.devices.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: windows.media.playback.proxystub.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: devdispitemprovider.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: ddores.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: windows.web.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: defaultdevicemanager.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: comppkgsup.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: windows.staterepositoryps.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: mfmp4srcsnk.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: appcontracts.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: usermgrproxy.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: cdprt.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: cdp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: dsreg.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: mfps.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: mfsrcsnk.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: msamrnbsource.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: mfasfsrcsnk.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: mfds.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: msflacdecoder.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: avrt.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: mfmpeg2srcsnk.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: mfmkvsrcsnk.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: mfnetsrc.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: mfnetcore.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: windows.media.protection.playready.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: wpnapps.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: msxml6.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: windows.networking.backgroundtransfer.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: systemeventsbrokerclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: windows.applicationmodel.lockscreen.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: wincorlib.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: wininet.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: lockappbroker.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: biwinrt.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: winnsi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: dnsapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: rasadhlp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: dhcpcsvc6.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: dhcpcsvc.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: fwpuclnt.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: windows.security.authentication.web.core.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: onecorecommonproxystub.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: webio.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: schannel.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: mfsvr.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: windows.applicationmodel.background.timebroker.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: vaultcli.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: microsoftaccountwamextension.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: mskeyprotect.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: ncryptsslp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: dpapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: gpapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: cryptnet.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: gnsdk_fp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: mf.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeSection loaded: dwmapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32Jump to behavior
Source: IMG_2879.mp4Static file information: File size 2585783 > 1048576
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeCode function: 1_2_00000265E8D033A0 push BA000002h; iretd 1_2_00000265E8D033A5
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeCode function: 1_2_00000265E8D0234F push ebp; ret 1_2_00000265E8D02350
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdateJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeFile opened: PhysicalDrive0Jump to behavior
Source: Video.UI.exe, 00000001.00000002.2924149841.00000265E87BD000.00000004.00000020.00020000.00000000.sdmp, Video.UI.exe, 00000001.00000002.2923832335.00000265E8771000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
Source: Video.UI.exe, 00000001.00000002.2923471201.00000265E871B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW@Pw
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\LocalState\Database\anonymous\edbtmp.log VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\LocalState\Database\anonymous\edbtmp.log VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\LocalState\Database\anonymous\edbres00001.jrs VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\LocalState\Database\anonymous\edbres00002.jrs VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\LocalState\Database\anonymous\edb.log VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\LocalState\Database\anonymous\edb.log VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\LocalState\Database\anonymous\edb.log VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\LocalState\Database\anonymous\edb.chk VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\LocalState\Database\anonymous\EntClientDb.jfm VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\LocalState\Database\anonymous\EntClientDb.edb VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\LocalState\Database\anonymous\EntClientDb.edb VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\LocalState\Database\anonymous\tmp.edb VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeQueries volume information: C:\Windows\Fonts\segoeuisl.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeQueries volume information: C:\Windows\Fonts\segmdl2.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\LocalState\SRPData.xml VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
DLL Side-Loading
1
DLL Side-Loading
1
Masquerading
OS Credential Dumping1
Query Registry
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Virtualization/Sandbox Evasion
LSASS Memory11
Security Software Discovery
Remote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
DLL Side-Loading
Security Account Manager1
Virtualization/Sandbox Evasion
SMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Obfuscated Files or Information
NTDS21
System Information Discovery
Distributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://login.windows.local0%URL Reputationsafe
https://login.windows.net0%URL Reputationsafe
https://login.windows.net/0%URL Reputationsafe
http://schemas.xmlsoap.org/soap/http0%URL Reputationsafe
https://android.notify.windows.com/iOS0%URL Reputationsafe
https://xsts.auth.xboxlive.com0%URL Reputationsafe
https://login.windows.local/0%URL Reputationsafe
http://dmd-ca-beta2/CertEnroll/dmd-ca-beta2_Microsoft%20Digital%20Media%20Authority%202005.crt0d0%Avira URL Cloudsafe
http://json-schema.org/draft-04/schema0%Avira URL Cloudsafe
https://settings-ssl.xboxlive.com/XBLWinClient/v10_video/configuration.xml0%Avira URL Cloudsafe
http://dmd-ca-beta2/CertEnroll/Microsoft%20Digital%20Media%20Authority%202005.crl0%Avira URL Cloudsafe
https://login.windows.netNetscape0%Avira URL Cloudsafe
https://xsts.auth.xboxlive.com/Enrolment0%Avira URL Cloudsafe
https://settings-ssl.xboxlive.com/UP0%Avira URL Cloudsafe
https://activity.windows.com/UserActivity.ReadWrite.CreatedByApp82J0%Avira URL Cloudsafe
https://android.notify.windows.com/iOSWM/MediaClassPrimaryID0%Avira URL Cloudsafe
https://settings-ssl.xboxlive.com/0%Avira URL Cloudsafe
https://wns.windows.com/.dll0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
part-0039.t-0009.t-msedge.net
13.107.246.67
truefalse
    unknown
    settings-ssl.xboxlive.com
    unknown
    unknownfalse
      unknown
      NameSourceMaliciousAntivirus DetectionReputation
      https://login.windows.localVideo.UI.exe, 00000001.00000003.2272832446.00000265E7D52000.00000004.00000020.00020000.00000000.sdmpfalse
      • URL Reputation: safe
      unknown
      https://login.windows.netVideo.UI.exe, 00000001.00000002.2921919917.00000265E7D62000.00000004.00000020.00020000.00000000.sdmp, Video.UI.exe, 00000001.00000003.2272863476.00000265E7D5A000.00000004.00000020.00020000.00000000.sdmp, Video.UI.exe, 00000001.00000003.2272832446.00000265E7D52000.00000004.00000020.00020000.00000000.sdmpfalse
      • URL Reputation: safe
      unknown
      https://login.windows.net/Video.UI.exe, 00000001.00000002.2921919917.00000265E7D62000.00000004.00000020.00020000.00000000.sdmp, Video.UI.exe, 00000001.00000003.2272863476.00000265E7D5A000.00000004.00000020.00020000.00000000.sdmp, Video.UI.exe, 00000001.00000003.2272832446.00000265E7D52000.00000004.00000020.00020000.00000000.sdmpfalse
      • URL Reputation: safe
      unknown
      https://login.windows.netNetscapeVideo.UI.exe, 00000001.00000002.2921919917.00000265E7D62000.00000004.00000020.00020000.00000000.sdmp, Video.UI.exe, 00000001.00000003.2272863476.00000265E7D5A000.00000004.00000020.00020000.00000000.sdmp, Video.UI.exe, 00000001.00000003.2272832446.00000265E7D52000.00000004.00000020.00020000.00000000.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      http://schemas.xmlsoap.org/soap/httpVideo.UI.exe, 00000001.00000003.1779015016.00000265E8813000.00000004.00000020.00020000.00000000.sdmpfalse
      • URL Reputation: safe
      unknown
      https://android.notify.windows.com/iOSWM/MediaClassPrimaryIDVideo.UI.exe, 00000001.00000002.2921634310.00000265E7C95000.00000004.00000020.00020000.00000000.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      http://dmd-ca-beta2/CertEnroll/dmd-ca-beta2_Microsoft%20Digital%20Media%20Authority%202005.crt0dVideo.UI.exe, 00000001.00000003.1778736636.00000265E8A5B000.00000004.00000020.00020000.00000000.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      https://android.notify.windows.com/iOSVideo.UI.exe, 00000001.00000002.2921634310.00000265E7C95000.00000004.00000020.00020000.00000000.sdmpfalse
      • URL Reputation: safe
      unknown
      https://xsts.auth.xboxlive.comVideo.UI.exe, 00000001.00000002.2921919917.00000265E7D62000.00000004.00000020.00020000.00000000.sdmp, Video.UI.exe, 00000001.00000003.2272863476.00000265E7D5A000.00000004.00000020.00020000.00000000.sdmp, Video.UI.exe, 00000001.00000003.2272832446.00000265E7D52000.00000004.00000020.00020000.00000000.sdmpfalse
      • URL Reputation: safe
      unknown
      https://settings-ssl.xboxlive.com/XBLWinClient/v10_video/configuration.xmlVideo.UI.exe, 00000001.00000002.2921668578.00000265E7CE4000.00000004.00000020.00020000.00000000.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      https://activity.windows.com/UserActivity.ReadWrite.CreatedByApp82JVideo.UI.exe, 00000001.00000002.2921668578.00000265E7D1D000.00000004.00000020.00020000.00000000.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      https://settings-ssl.xboxlive.com/Video.UI.exe, 00000001.00000002.2921944106.00000265E7D83000.00000004.00000020.00020000.00000000.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      https://xsts.auth.xboxlive.com/EnrolmentVideo.UI.exe, 00000001.00000002.2921919917.00000265E7D62000.00000004.00000020.00020000.00000000.sdmp, Video.UI.exe, 00000001.00000003.2272863476.00000265E7D5A000.00000004.00000020.00020000.00000000.sdmp, Video.UI.exe, 00000001.00000003.2272832446.00000265E7D52000.00000004.00000020.00020000.00000000.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      http://json-schema.org/draft-04/schemaVideo.UI.exe, 00000001.00000002.2910897243.00000265DB22C000.00000004.00000020.00020000.00000000.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      https://login.windows.local/Video.UI.exe, 00000001.00000002.2921919917.00000265E7D62000.00000004.00000020.00020000.00000000.sdmp, Video.UI.exe, 00000001.00000003.2272863476.00000265E7D5A000.00000004.00000020.00020000.00000000.sdmp, Video.UI.exe, 00000001.00000003.2272832446.00000265E7D52000.00000004.00000020.00020000.00000000.sdmpfalse
      • URL Reputation: safe
      unknown
      https://settings-ssl.xboxlive.com/UPVideo.UI.exe, 00000001.00000002.2921944106.00000265E7D83000.00000004.00000020.00020000.00000000.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      http://dmd-ca-beta2/CertEnroll/Microsoft%20Digital%20Media%20Authority%202005.crlVideo.UI.exe, 00000001.00000003.1778736636.00000265E8A5B000.00000004.00000020.00020000.00000000.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      https://wns.windows.com/.dllVideo.UI.exe, 00000001.00000002.2913395537.00000265E1D9B000.00000004.00000020.00020000.00000000.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      13.107.246.67
      part-0039.t-0009.t-msedge.netUnited States
      8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
      Joe Sandbox version:40.0.0 Tourmaline
      Analysis ID:1445852
      Start date and time:2024-05-22 17:11:34 +02:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 4m 44s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:default.jbs
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:18
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Sample name:IMG_2879.mp4
      (renamed file extension from JPG to mp4)
      Original Sample Name:IMG_2879.JPG
      Detection:CLEAN
      Classification:clean3.winMP4@1/17@1/1
      EGA Information:
      • Successful, ratio: 100%
      HCA Information:Failed
      • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, BackgroundTransferHost.exe, RuntimeBroker.exe, WMIADAP.exe, SIHClient.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
      • Excluded IPs from analysis (whitelisted): 88.221.124.10, 184.28.89.167, 93.184.221.240
      • Excluded domains from analysis (whitelisted): fs.microsoft.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, wu.ec.azureedge.net, ctldl.windowsupdate.com, e87.dspb.akamaiedge.net, wu.azureedge.net, activation2.playready.microsoft.com, fe3cr.delivery.mp.microsoft.com, e11290.dspg.akamaiedge.net, go.microsoft.com, ocsp.digicert.com, star-azurefd-prod.trafficmanager.net, go.microsoft.com.edgekey.net, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, hlb.apr-52dd2-0.edgecastdns.net, settings-ssl.xboxlive.com.edgekey.net, wu-b-net.trafficmanager.net, traf-activation-global.trafficmanager.net
      • Not all processes where analyzed, report is missing behavior information
      • Report size getting too big, too many NtEnumerateKey calls found.
      • Report size getting too big, too many NtOpenKey calls found.
      • Report size getting too big, too many NtOpenKeyEx calls found.
      • Report size getting too big, too many NtProtectVirtualMemory calls found.
      • Report size getting too big, too many NtQueryValueKey calls found.
      • VT rate limit hit for: IMG_2879.mp4
      No simulations
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      13.107.246.67o365svc.db.exeGet hashmaliciousUnknownBrowse
        https://portal.confideshare.com/ice/anonymouspdf?ZDc1YmM4ZTAtODI3OS00ZGQ3LTlhNDEtNjNiMTA1NjE5MDdlL2NhYzQ1MWM0LWUwY2MtNGRmMC1iMmEyLTExODM4MGY5NzRkNi8xL1VTIC0gRWFzdA==Get hashmaliciousUnknownBrowse
          https://weblaunch.blifax.com/listener3/redirect?l=e6df36b9-5af1-4758-b7e4-83fbf7f30dfb&id=e0d346f1-f241-ee11-acc4-000c295a2555&u=http%253Aeyesontheguys.com%2Fwinner%2F03013%2F%2FYnJhbmRvbi5nYXJjaWFAZ3RmY3Uub3JnGet hashmaliciousHTMLPhisherBrowse
            https://u44480879.ct.sendgrid.net/ls/click?upn=u001.K3PKLmjBF8yuYObBAUhMhoYgMCf2QPF8-2BZI72vFIksvq5gv1YdeLmebXIjmharYkUcFgg0gxX-2FWnhhIuwG1v7hZ1jSPSflMHjG28wduJ6WYURJRkvoZYkrpgydIv6UCw7t1grI-2FOHPnDvS00ShpX9xXHYT95jO14dPyhKlpfAgbiguCssCUSGyzsUXoj0i5OD5WgRtFSbHv5xA6nkt2-2BnV2PahLYLwt63WRXCeSfWq4QVMqO-2BJ19jNeGlkPsSJ7LjTRQ_i2l0JY0a-2B5IHliMJOpuAQskejvIIAloJuWpirDIyAKvqXPSxi-2BJFNs3s-2BBhNyt3IuemV4R9vgK4lniAodKDuO5I3mYVK4xxASVKvZBnT0EvvqLHkUoab3uOwe13cn6mNyhQaL1Vcdvxd7XZ0GFfTZ9aBlD2GiHfinlIyB6vRF7bjNGZmtvLv3o0jYjOgY4RXF495TuUjjBZNoMguN8rUGoiNOkgNXvc2IiDsbNfgghazj2fwqVSs1vbmTcZe0zePKD2UCPQB-2F0HgPY4-2FJ1DTehOrWMbxZ-2FvJVCWppZOFHMlDv0TKEyx1-2FUlF330qgqw9RpmfgzpuSa3QNju2XxovCzCQMgiykbvuS-2BASB-2BwolLPpkcOYAm2PSCx0uDNQdWPLOarKIcv5eBG38XDZm38U-2BPUlNv7WKbMtJQtnyTRX26RGa2QEgMJJEg7pVaW1E3fNSFtUzV-2B9TRB6AR-2F0dQVDjN-2BDXbuC2wdD8XIcTiR0x13qN9Ue7Uy0B1mkdyBFM-2F-2FLCkULNCj3vHyywuiz7XFtD80zjdMZ6p7qRnJvTxE0OErqVvXV7ExeSfPpIkvRb2vtYGXyPwsJU84YitEGasTuan1Qb7qY-2BCjK-2BGu2OF5qtxAM4ffvs-2FAs5ymdEqvJZV5Bn1jeQjLz6wDOoEy-2B8bZnhDZ-2BAPDyVjfuq0GObtbYn-2Fb4GPUYaWbH-2F93IuGgnTByDILI-2FWE9MVp3RKV-2F-2BBryOsBGlBUQrWR2ImfTNzWzMbBrj-2BKqW5yNH1deqIdAglTH68WrBSO0mlGYUjctN4j364ck9SzZdvU5uN2VirSfK9wZwGXR-2B6p-2FOHwxd9cjm1b-2BjZRFALK9cu3efthTs-2BPI5tXAxrm5lL9s-2B9SEQz4IW6nJ3DWzdxXvZ4LC5H5taTAQj2lceiCXaxhPNI6PfuuInsvKiGXyFdparkshCJAzM5SH0o7fpSAMjEQa7MyV8onNWGet hashmaliciousHTMLPhisherBrowse
              https://ipfs.io/ipfs/bafkreiaifz4xo7tqmc7x3hbuqb4wsvlnyylklzgwnldgkszguv3ly2jdoy#YOUREMAILGet hashmaliciousUnknownBrowse
                Purchase order 0012May21-24.xlsGet hashmaliciousUnknownBrowse
                  RFQ# 296902.xlsGet hashmaliciousUnknownBrowse
                    https://winrocket07.z13.web.core.windows.net/Get hashmaliciousTechSupportScamBrowse
                      https://20maymic17.z13.web.core.windows.net/Get hashmaliciousTechSupportScamBrowse
                        May-Document-6_2024-1352.xlsxGet hashmaliciousUnknownBrowse
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          part-0039.t-0009.t-msedge.netRe_ Bridge Drainage Enquiry.emlGet hashmaliciousHTMLPhisherBrowse
                          • 13.107.213.67
                          o365svc.db.exeGet hashmaliciousUnknownBrowse
                          • 13.107.246.67
                          https://portal.confideshare.com/ice/anonymouspdf?ZDc1YmM4ZTAtODI3OS00ZGQ3LTlhNDEtNjNiMTA1NjE5MDdlL2NhYzQ1MWM0LWUwY2MtNGRmMC1iMmEyLTExODM4MGY5NzRkNi8xL1VTIC0gRWFzdA==Get hashmaliciousUnknownBrowse
                          • 13.107.246.67
                          https://weblaunch.blifax.com/listener3/redirect?l=e6df36b9-5af1-4758-b7e4-83fbf7f30dfb&id=e0d346f1-f241-ee11-acc4-000c295a2555&u=http%253Aeyesontheguys.com%2Fwinner%2F03013%2F%2FYnJhbmRvbi5nYXJjaWFAZ3RmY3Uub3JnGet hashmaliciousHTMLPhisherBrowse
                          • 13.107.246.67
                          https://u44480879.ct.sendgrid.net/ls/click?upn=u001.K3PKLmjBF8yuYObBAUhMhoYgMCf2QPF8-2BZI72vFIksvq5gv1YdeLmebXIjmharYkUcFgg0gxX-2FWnhhIuwG1v7hZ1jSPSflMHjG28wduJ6WYURJRkvoZYkrpgydIv6UCw7t1grI-2FOHPnDvS00ShpX9xXHYT95jO14dPyhKlpfAgbiguCssCUSGyzsUXoj0i5OD5WgRtFSbHv5xA6nkt2-2BnV2PahLYLwt63WRXCeSfWq4QVMqO-2BJ19jNeGlkPsSJ7LjTRQ_i2l0JY0a-2B5IHliMJOpuAQskejvIIAloJuWpirDIyAKvqXPSxi-2BJFNs3s-2BBhNyt3IuemV4R9vgK4lniAodKDuO5I3mYVK4xxASVKvZBnT0EvvqLHkUoab3uOwe13cn6mNyhQaL1Vcdvxd7XZ0GFfTZ9aBlD2GiHfinlIyB6vRF7bjNGZmtvLv3o0jYjOgY4RXF495TuUjjBZNoMguN8rUGoiNOkgNXvc2IiDsbNfgghazj2fwqVSs1vbmTcZe0zePKD2UCPQB-2F0HgPY4-2FJ1DTehOrWMbxZ-2FvJVCWppZOFHMlDv0TKEyx1-2FUlF330qgqw9RpmfgzpuSa3QNju2XxovCzCQMgiykbvuS-2BASB-2BwolLPpkcOYAm2PSCx0uDNQdWPLOarKIcv5eBG38XDZm38U-2BPUlNv7WKbMtJQtnyTRX26RGa2QEgMJJEg7pVaW1E3fNSFtUzV-2B9TRB6AR-2F0dQVDjN-2BDXbuC2wdD8XIcTiR0x13qN9Ue7Uy0B1mkdyBFM-2F-2FLCkULNCj3vHyywuiz7XFtD80zjdMZ6p7qRnJvTxE0OErqVvXV7ExeSfPpIkvRb2vtYGXyPwsJU84YitEGasTuan1Qb7qY-2BCjK-2BGu2OF5qtxAM4ffvs-2FAs5ymdEqvJZV5Bn1jeQjLz6wDOoEy-2B8bZnhDZ-2BAPDyVjfuq0GObtbYn-2Fb4GPUYaWbH-2F93IuGgnTByDILI-2FWE9MVp3RKV-2F-2BBryOsBGlBUQrWR2ImfTNzWzMbBrj-2BKqW5yNH1deqIdAglTH68WrBSO0mlGYUjctN4j364ck9SzZdvU5uN2VirSfK9wZwGXR-2B6p-2FOHwxd9cjm1b-2BjZRFALK9cu3efthTs-2BPI5tXAxrm5lL9s-2B9SEQz4IW6nJ3DWzdxXvZ4LC5H5taTAQj2lceiCXaxhPNI6PfuuInsvKiGXyFdparkshCJAzM5SH0o7fpSAMjEQa7MyV8onNWGet hashmaliciousHTMLPhisherBrowse
                          • 13.107.246.67
                          https://open.memb.theofficialboard.com/259/42780/c/1000/qW0e==AO2czN1EmMyIDZiJmMykzYwYjZ2QTO0IDZkNGNzUzYj9SZ2lGd1NWZ4V2LyZmLkJXYvJGbhl2YpZmZvVGa05yd3d3LvoDc0RHaj7zmQzvQrZhYUmR6U8gNT1zzqhEU08h8Mvuop0dgR2BEdDs2bzkgPsituVOQ-UYJE241FjvVmRdF8l_RYrsWeydgWxMbNLC1e-3BI-mklFUF5BQlQG3GO2XJaBqaGet hashmaliciousUnknownBrowse
                          • 13.107.213.67
                          https://docsend.com/view/mdchukx3ui72iuwyGet hashmaliciousHTMLPhisherBrowse
                          • 13.107.213.67
                          https://ipfs.io/ipfs/bafkreiaifz4xo7tqmc7x3hbuqb4wsvlnyylklzgwnldgkszguv3ly2jdoy#YOUREMAILGet hashmaliciousUnknownBrowse
                          • 13.107.246.67
                          0af4a52e.0cce76886785b0ff1283f346.workers.devemailantonio.cataneo@axactor.com.msgGet hashmaliciousHTMLPhisherBrowse
                          • 13.107.213.67
                          Purchase order 0012May21-24.xlsGet hashmaliciousUnknownBrowse
                          • 13.107.246.67
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          MICROSOFT-CORP-MSN-AS-BLOCKUS2T6MGxlKZT.exeGet hashmaliciousSmokeLoaderBrowse
                          • 20.42.73.29
                          https://mev-web.ca/?f=QeYBR2wfYK3JYIrbEQZr1C%2bgf3gU%2fmUvL9ovUEhJVZnxPIANQz6rboUW4U4PnItNOSuc98KvirQj3pwhsBFRc8hSk5YuKckp9PXbo9m%2baI9y9BiUYstagDwEu3371ebTwoTckHFX6OqMDkbqHH4mz6uY9e9M%2f9uY9zyYLM%2f9CmDvFT2uK2iCdJwzdbXIyiq2%2b9ClzMjyENFwui3qHuWODETmn%2b6yk0qQuV9sQ%2fGi6URseZjJRDXWcmWLNhvjc38WMu6H6e6u2IwMZcnl78FMfEZPvqt9omZdBVKeliCJX88SZ7m5zXYeBaIXu8XXIgDTSHNQrcMQ6iWL3ktNU9KNVy2%2fbL15XB8sLGGe1uVAbQ9hwGnOnoH4sBJOe3%2fpYYneZARrLcwphZSIduyqT3At%2f6Bzn57i7UC9z7ZDalFnOM1dZy5wNqsV62py1LJecHSNYxeFwHwj8D54XILdKl0BfW7sHpba1eyZjI%2bO8%2bGRE69nPLRa%2ffTy6B9wpFibF3RTGet hashmaliciousUnknownBrowse
                          • 20.104.163.113
                          https://cs-server-s2s.yellowblue.io/sync-iframeGet hashmaliciousUnknownBrowse
                          • 13.107.42.14
                          11650000000026213681.exeGet hashmaliciousDBatLoaderBrowse
                          • 150.171.41.11
                          11650000000026213681.exeGet hashmaliciousDBatLoaderBrowse
                          • 13.107.137.11
                          http://adsbymediavine.comGet hashmaliciousUnknownBrowse
                          • 13.107.42.14
                          ZAMOWIEN.EXE.exeGet hashmaliciousAgentTesla, DBatLoaderBrowse
                          • 13.107.139.11
                          https://internal--alert-teamapp-site.ipns.dweb.link/#YW1hbmRhLm1vcnJpc29uQG9uZWFtZXJpY2EuY29tGet hashmaliciousHTMLPhisherBrowse
                          • 13.107.253.45
                          https://markkaleelcpa-my.sharepoint.com/:b:/p/mark/EdMYrJ-SJnZMoOxQFVo0rPIBwnXkE3DnasKEJCVIoBuoZQ?e=sy8Kb5&xsdata=MDV8MDJ8Z29yZGl5ZW5rby5hbmFzdGFzaWFAZGVtZS1ncm91cC5jb218ZjBmNzUyMDgyMTI5NDQ5MjJlMDkwOGRjN2E0OTQ1ZTZ8NGUyY2JmNjJjY2ZiNDNhN2JlM2Y3ZWI3YTg1OGJjZWN8MHwwfDYzODUxOTcwMjM0NzEwNDE0NHxVbmtub3dufFRXRnBiR1pzYjNkOGV5SldJam9pTUM0d0xqQXdNREFpTENKUUlqb2lWMmx1TXpJaUxDSkJUaUk2SWsxaGFXd2lMQ0pYVkNJNk1uMD18MHx8fA%3d%3d&sdata=YmpzRTZlMXNTdjk2Z0dONFAwYlNkVWtJU3A1MmdrUEFmSkNuaVBVeGtVZz0%3dGet hashmaliciousHTMLPhisherBrowse
                          • 52.104.71.55
                          http://url2.mailanyone.net/scanner?d=4%7Cmail%2F90%2F1715682600%2F1s6pTH-0000Fr-6D%7Cin2f%7C57e1b682%7C28613012%7C14303582%7C66433DF3D46FD0B9149B37AF26642EB9&m=1s6pTH-0000Fr-6D&o=%2Fphtu%3A%2Fptsacblmus.i-mdktcnai.ypos.%2F%2Faicm5sor35feg%2Fa-5ce90-285-f10f8-1963002105dab%2Fc%2FQn7UrkNU_s_0P8LqAhGaAAIAeQtaA%3F%25ge%3Dtrr27BeTag%252%25ltUA223r%25sh%2522tp%252tF%2553252%25A2ap52eopnFrbnmoleduudmsle2co%25t.2w522%252%25Fpi2C%25eedr2Rnpct%25iosOtB3222%257%25%25AA225u%253n%25222ll%25%2521%25Cl322%25nul%25Ai77De%26dg%25DwQst2aF%25%3Db6fBkf2LXU3hwBIL4xHiGTWDIqObb0zE5ov3Ct%25VGteD%26ereVsc5ors7%3Da8indb59bd247b4ba3633fb4ee51eb8d&s=9OHmoQ0JkwbsHuMKJ_DcFrbob0AGet hashmaliciousUnknownBrowse
                          • 52.146.76.30
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          28a2c9bd18a11de089ef85a160da29e4https://url12.mailanyone.net/scanner?m=1s9N28-0000qa-3G&d=4%7Cmail%2F90%2F1716288000%2F1s9N28-0000qa-3G%7Cin12d%7C57e1b682%7C11949542%7C14589158%7C664C7BD820EF00EA9CDA64C5861AF4A9&o=%2Fphta%3A%2Fvtslekssiaipcr.te%2Ftoenscino-x-pk%2F6tRunvbhyfphp.x&s=qPX4ToIpiLV6GTYf9V69nGT5pssGet hashmaliciousHtmlDropper, HTMLPhisherBrowse
                          • 13.107.246.67
                          http://sonarr.vertras.xyzGet hashmaliciousUnknownBrowse
                          • 13.107.246.67
                          file.exeGet hashmaliciousUnknownBrowse
                          • 13.107.246.67
                          https://mev-web.ca/?f=QeYBR2wfYK3JYIrbEQZr1C%2bgf3gU%2fmUvL9ovUEhJVZnxPIANQz6rboUW4U4PnItNOSuc98KvirQj3pwhsBFRc8hSk5YuKckp9PXbo9m%2baI9y9BiUYstagDwEu3371ebTwoTckHFX6OqMDkbqHH4mz6uY9e9M%2f9uY9zyYLM%2f9CmDvFT2uK2iCdJwzdbXIyiq2%2b9ClzMjyENFwui3qHuWODETmn%2b6yk0qQuV9sQ%2fGi6URseZjJRDXWcmWLNhvjc38WMu6H6e6u2IwMZcnl78FMfEZPvqt9omZdBVKeliCJX88SZ7m5zXYeBaIXu8XXIgDTSHNQrcMQ6iWL3ktNU9KNVy2%2fbL15XB8sLGGe1uVAbQ9hwGnOnoH4sBJOe3%2fpYYneZARrLcwphZSIduyqT3At%2f6Bzn57i7UC9z7ZDalFnOM1dZy5wNqsV62py1LJecHSNYxeFwHwj8D54XILdKl0BfW7sHpba1eyZjI%2bO8%2bGRE69nPLRa%2ffTy6B9wpFibF3RTGet hashmaliciousUnknownBrowse
                          • 13.107.246.67
                          https://www.google.com.bh/url?hl=en&q=https://www.google.com.bh/url?hl%3Den%26q%3Dhttp://www.google.com/amp/www.google.com/amp/www.google.com/amp/%252574%252569%25256E%252579%252575%252572%25256C%25252E%252563%25256F%25256D%25252F%25256D%252576%252574%252575%252575%252566%252537%252533%26source%3Dgmail%26ust%3D1716286979743000%26usg%3DAOvVaw0kIG15Hao_4RLWdhQSbrTj&source=gmail&ust=1716287016979000&usg=AOvVaw2OvZXU7t2_QCy0TjxskKGnGet hashmaliciousUnknownBrowse
                          • 13.107.246.67
                          https://rstgmbh-rstsrl.start.pageGet hashmaliciousHTMLPhisherBrowse
                          • 13.107.246.67
                          https://url12.mailanyone.net/scanner?m=1s9PCz-0000cD-4j&d=4%7Cmail%2F90%2F1716296400%2F1s9PCz-0000cD-4j%7Cin12g%7C57e1b682%7C11949542%7C14589158%7C664C9C811D87B03FE2E6472997A0C22E&o=%2Fphtl%3A%2Fatsnhtaageeteoilogt.rgsigc%2Faz.&s=1YKQiaLIfHH0tTbjCAvEAnTGAIUGet hashmaliciousUnknownBrowse
                          • 13.107.246.67
                          ELECTRONIC RECEIPT_Borlandgroover.htmlGet hashmaliciousUnknownBrowse
                          • 13.107.246.67
                          https://url2.mailanyone.net/scanner?m=1s7d43-000AYw-4l&d=4%7Cmail%2F90%2F1715873400%2F1s7d43-000AYw-4l%7Cin2i%7C57e1b682%7C17902772%7C12174482%7C6646269FFDF04F1A20FD74D40B7BD076&o=%2Fphtn%3A%2F2tsemdtd.i-ie-velhryciefear%2Finog.00355g-j-klmth.&s=jwSy6ONi-ccgLa5D6t6NeC_1lr0Get hashmaliciousUnknownBrowse
                          • 13.107.246.67
                          http://twomancake.comGet hashmaliciousUnknownBrowse
                          • 13.107.246.67
                          No context
                          Process:C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exe
                          File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                          Category:dropped
                          Size (bytes):1520
                          Entropy (8bit):5.0183726539703795
                          Encrypted:false
                          SSDEEP:24:2dzI4+uTOBzpoD2h9f0lM702X9bh9q02Xiwqh9U02XiSbh9Uydq2X4h9Uy72Xyh2:cK88z2D2ff97DtbfqDtqfUD9bfUywBfW
                          MD5:E72FC6D9DAF66E2D8BC9FE37BE8CE4D8
                          SHA1:667F95190910D5841E4531330001423CBB8E2030
                          SHA-256:B5CCAFA927AF87CEA7E85A2D197C2E841E557B87900665C12FA6F8059B8B9356
                          SHA-512:5D56979DBDB586601570DB6AEE666EA1DF489F3EB25285DEDC4A216834955E590158058D6B0C23D084C6C059AD91CF7B7FC32436E572693A96527F3D6E14160C
                          Malicious:false
                          Reputation:moderate, very likely benign file
                          Preview:<?xml version="1.0" encoding="utf-8"?>..<clientConfiguration xmlns="http://schemas.microsoft.com/XblWinClient/2012/03" version="1">.. <targetedClient>XblWinClient</targetedClient > .. <rights>Copyright (c) Microsoft Corporation. All rights reserved.</rights>.. <configuration name="Playback" minBuild="16122.1018">.. <property name="UseAdaptiveMediaSourcePercent" value="50" type="int32"/>.. <property name="UseDashContentForMBRSourcePercent" value="100" type="int32"/>.. </configuration>.. <configuration name="Playback" minBuild="16122.1018" maxBuild="17032.1033">.. <property name="UseDashContentForMBRSourcePercentBeforeRS2" value="0" type="int32"/>.. </configuration>.. <configuration name="Playback" minBuild="17032.1034">.. <property name="UseDashContentForMBRSourcePercentBeforeRS2" value="100" type="int32"/>.. </configuration>.. <configuration name="Groveler" minBuild="17063.0" maxBuild="17082.9999">..
                          Process:C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exe
                          File Type:Microsoft Cabinet archive data, Windows 2000/XP setup, 4770 bytes, 1 file, at 0x2c +A "disallowedcert.stl", number 1, 1 datablock, 0x1 compression
                          Category:dropped
                          Size (bytes):4770
                          Entropy (8bit):7.946747821604857
                          Encrypted:false
                          SSDEEP:96:9/nBu64pydcvOHRUfu0xK1bQYMRSRNoYmxYvk56sHMZhh4m:9/nBuP2cGxUfu6K1bpWJ6vfh4m
                          MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
                          SHA1:719C37C320F518AC168C86723724891950911CEA
                          SHA-256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
                          SHA-512:02F88DA4B610678C31664609BCFA9D61DB8D0B0617649981AF948F670F41A6207B4EC19FECCE7385A24E0C609CBBF3F2B79A8ACAF09A03C2C432CC4DCE75E9DB
                          Malicious:false
                          Reputation:moderate, very likely benign file
                          Preview:MSCF............,...................O.................2Wqh .disallowedcert.stl....^K...CK.wTS...:.w.K'.C0T.....Bh.{....C.).*.....Y@...(..).R."E..D^6........u....|f~3...o.3. ..SPK.k.o#...."{-.U..P........:..aPr.@.d......Dy.h.....)..:...!./\A.....A<I_<$...q.h..........'.....7....H...@`T..K.S.%...Y4..R.....`.....-....D...(..b..-c."...G.=.dx..S+..2.a.E....d.L...77J...c.[..@..iT&..^78..g....NW6.Ek..FY.F........cNt.O.*..R....*......D...... k........J.y...z.d...;.9_t...].@....yw..}.x....d.t..`f\K..;|.*h.X...4/.;.xT......q>.0...<...3...X..L$.&.,b.....\V....\......G..O..@..H3.....t..J..).x.?.{[..G>.7...<...^Q..z..Gw9P..d....i].n%K}.*z..2.Py...A..s...z..@...4..........4.....*Y.d..._Z.5.s..fl.C..#.K{9^.E...k..z.Ma..G.(.....5g. ...}.t.#4....$;.,....S@fs....k......u .^2.#_...I........;.......w..P...UCY...$;.S._|.x..dK...[i..q..^.l..A.?.....'N.. .L.l......m.*.+f#]............A.;.....Z..rIt....RW....Kr1e=8.=.z:Oi.z.d..r..C_......o...]j.N;.s....3@3.dgrv.
                          Process:C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exe
                          File Type:data
                          Category:dropped
                          Size (bytes):338
                          Entropy (8bit):3.1689404034189526
                          Encrypted:false
                          SSDEEP:6:kKriwN+SkQlPlEGYRMY9z+s3Ql2DUevat:ikPlE99SCQl2DUevat
                          MD5:EB4622071C815463D74F0CEC17CA2F3E
                          SHA1:51739F3B3E347CCB8070D40546E0E3766B5316FD
                          SHA-256:B8034C66CA5D39F279B1F2A52146BA314F8B5D5AA9317019F6BC07591768DF30
                          SHA-512:0B8CA5E886C277A7E59F05167856AB7CF57E05CC22AE760E73E5BA3BFB615262942A37F28E1F7768D7A9F1E924914534BA5AAF33405C42D11F361093905B416F
                          Malicious:false
                          Reputation:low
                          Preview:p...... .........|.yZ...(....................................................... .........p.........$...............h.t.t.p.:././.c.t.l.d.l...w.i.n.d.o.w.s.u.p.d.a.t.e...c.o.m./.m.s.d.o.w.n.l.o.a.d./.u.p.d.a.t.e./.v.3./.s.t.a.t.i.c./.t.r.u.s.t.e.d.r./.e.n./.d.i.s.a.l.l.o.w.e.d.c.e.r.t.s.t.l...c.a.b...".7.4.6.7.8.7.a.3.f.0.d.9.1.:.0."...
                          Process:C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exe
                          File Type:RAGE Package Format (RPF),
                          Category:dropped
                          Size (bytes):5113
                          Entropy (8bit):6.060158387992208
                          Encrypted:false
                          SSDEEP:96:wXI1IDJZ1Gv4BNMYVUXiksiGAshzcEet7Y/v3QZMhMKUVeU:WI1oQ8LQifiDF0U
                          MD5:B4870A9B83C6DED6A5D49A42D2E46951
                          SHA1:4EC2F16DAAD723EE965FDDA049BF4727C2CD6B1B
                          SHA-256:387EB603EF586322A745507F439A35F5141330A5C5DD478C9D7F672312E4A6EB
                          SHA-512:48375763F453EFDADA10DCC7FE7ACA87258EA4C65D4A28FAFDFF332C96F617086B239430311550429FC249C5187E6400074C2AAA55DD7C8D1159789E5582EB08
                          Malicious:false
                          Reputation:low
                          Preview:PRKF...................................,.........HJ.D..W.....SZh.......^..........|.......@.=!.[[.>...F2...g.4JO..4..B.G.$umz6..?.UD....f,]..;N..o=..:|..2$b....... W.x.&.#9...O..Gz.)c...FBX.e"3?9z.......<....B+.. .DN......j9.d...-...I............................................@.{..F.\..i.!.....{,......a......P.....3.(..r........oLm:Qn.V........... o...pt..Z..(.FH.....m^.a.X..|fi.%.*1.I....~.e...................@.b.3@Q|........9.E....u.D....L..s..c.S.D.......%_oO.*..J.d,............. .ee...*..j....W....R....|..:.o.$. ..-F..q....M...................@.=!.[[.>...F2...g.4JO..4..B.G.$umz6..?.UD....f,]..;N..o=..:|.............A....|Z%.A...(.CN...d...S>....uF..a....^)...z.uO.....I..L..\".`....b..R.F..%A5J"4...........P.......@CHAI.......@........CERT...................Xb.K....#...anxq............x.`7.%..U.@ HX.?....Q.wT{,'.2D...............................(...<......................................................b.3@Q|........9.E....u.D....L..s..c.S.D.......%_oO.*..J
                          Process:C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exe
                          File Type:data
                          Category:dropped
                          Size (bytes):528384
                          Entropy (8bit):0.01313071988458288
                          Encrypted:false
                          SSDEEP:12:26maq+baPtV0wfDXECEevFWccv8jvgBZYGSaWn0:26mZ+gJfltvI5CIj0Ln0
                          MD5:7B9AE7FCDD1EF2FEFC805F081D197242
                          SHA1:4EDA6003BD4D8034FC82B8526DA0258FBD4C5904
                          SHA-256:A7E74D4465A31D90F1992EEFA8018172EE40B46327398AAD1142FCF26C6B7551
                          SHA-512:EF9CD11760872E470A83D633323FB46F44F18DFDA67999E34062BB5828C6BFB9CC4A6B9229AD8EE1AD42C4D390C06FF116D6B94DC4906C8504D8A20FD89F5AA1
                          Malicious:false
                          Reputation:low
                          Preview:........A.s..%-.i...0...........*:~xZ...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                          Process:C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exe
                          File Type:Extensible storage engine DataBase, version 0x620, checksum 0xd6713859, page size 8192, DirtyShutdown, Windows version 10.0
                          Category:dropped
                          Size (bytes):3670016
                          Entropy (8bit):0.26999678753770245
                          Encrypted:false
                          SSDEEP:1536:VSh2kKY8kWtnb0gTC0/k63bBu7fhWx7M6qSh2BKY8keHyDFqfKzgTC0/k63bBu77:V6fL4c6q6WLkC6O
                          MD5:65B65A17CC62DF5B0EF0FA87FAE0E0BF
                          SHA1:C3EC0A9566EA523CE8B5AB8C8A73226D4E4169A8
                          SHA-256:1D2BEA25B370110C564F2CAC271E9B19C766AC115D919ECE40A1E5162076DEF9
                          SHA-512:42D3F1BFD406B4721743DB0B42DFB7C4866241B41125A20A945C760C5CB03DD30F588591C6582D9F06F592AFCAF371F39600E86805765F0F063EA009181488C6
                          Malicious:false
                          Reputation:low
                          Preview:.q8Y... .......-.......f.M......|...........................................|..h....................................|..........................................................................................................eJ........... ...................................................................................................... ............|...................................................................................................................................................................................................|..................................M.A......|..................UI.......|I.........................................................................................................................................................................................................................................................................................................................................................................................
                          Process:C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exe
                          File Type:data
                          Category:dropped
                          Size (bytes):16384
                          Entropy (8bit):0.04701171654913191
                          Encrypted:false
                          SSDEEP:3:kltvZQFqMK/9l7pdZsHl/hFbO+ll/AYsHl/all:stvKQMKFfdS1qatABo
                          MD5:70E308DF1D9F7D77089DD1A0A4B9F5BE
                          SHA1:1A76FAF87579718B42E41EFCB6C8FE956889AD53
                          SHA-256:B64A028A876233667F8CFAE8B35C6DD225464A9D2701CF24B78A089A9167DFE5
                          SHA-512:A91927566BF276220CCBD0203A5DAE0A20182863323F4BA1662337E3FDD0E84CDA1E4A24EAD72C3EB6F332EA61F15600AEA997218DDB6125A88FB9C6E61D0440
                          Malicious:false
                          Reputation:low
                          Preview:.FS..........................................|.......|.......................|I...........Q......|+.................UI.......|I.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                          Process:C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exe
                          File Type:data
                          Category:dropped
                          Size (bytes):8192
                          Entropy (8bit):0.6204673321019797
                          Encrypted:false
                          SSDEEP:12:HRY+fUI1+uJ18+fUI1+uJ1QQelBsLRY+fUI1+uJ18+fUI1+uJ1QQelBs:HK+fUO/8+fUO/QOK+fUO/8+fUO/Q
                          MD5:CF3D82C71932EEF1446A6A68B79A61CC
                          SHA1:059CCB7FF9E214B20439869549F9DB621A9F0115
                          SHA-256:220C5C31CACA7F53C28F5B1053DC0393DF1B49F39EBD5F3B13894FF82A126B9E
                          SHA-512:53EE0EFBAE19D8E5D66C8440FB91118869F90D646E6C990926C11BBD11EEC007CD06CD353AA89FCC3466CF27B66F06A6F446606D202EE75D8CC886FC2F776F7A
                          Malicious:false
                          Reputation:low
                          Preview:.9...........................|..................C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\LocalState\Database\anonymous\...............................................................................................................................................................C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\LocalState\Database\anonymous\................................................................................................................................................................0u..,.....................5w.................................................................................................................................................................................................................................................................................................................................................................................................................
                          Process:C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exe
                          File Type:data
                          Category:dropped
                          Size (bytes):2097152
                          Entropy (8bit):0.684829234442577
                          Encrypted:false
                          SSDEEP:1536:rZPwRR1dREBmHlBDulBuIya+ciyIzWMWrMxBiNQAMfO489idE15T8AZ5yeh0G32m:rZ4RRLDZvOdbRxsWCta6mv
                          MD5:7A33C27776D29457F30B4E3349FA0FF0
                          SHA1:41F4157F313959974BDEBC3029143EFA537F3FF6
                          SHA-256:A577AB878A11074D68F31A2652605FF3777E7491B37BD3A94C7EA512DBEA0768
                          SHA-512:8844809F7F7E9FC25527CF3995C4696EEFCF9FDE7E85E87A808C57102E02544DBAF9B516CD32EEDAE122E361FEEAD00E9F32D5DCFABEFA4442653E26B9DB4278
                          Malicious:false
                          Reputation:low
                          Preview:D.\:........... .....|...............................|..................C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\LocalState\Database\anonymous\...............................................................................................................................................................C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\LocalState\Database\anonymous\................................................................................................................................................................0u..,.....................5w.......................................#.................................................................................................................................................................................................................................................................................................................................................
                          Process:C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exe
                          File Type:data
                          Category:dropped
                          Size (bytes):2097152
                          Entropy (8bit):0.0
                          Encrypted:false
                          SSDEEP:3::
                          MD5:B2D1236C286A3C0704224FE4105ECA49
                          SHA1:7D76D48D64D7AC5411D714A4BB83F37E3E5B8DF6
                          SHA-256:5647F05EC18958947D32874EEB788FA396A05D0BAB7C1B71F112CEB7E9B31EEE
                          SHA-512:731859029215873FDAC1C9F2F8BD25A334ABF0F3A9E1B057CF2CACC2826D86B0C26A3FA920A936421401C0471F38857CB53BA905489EA46B185209FDFF65B3B6
                          Malicious:false
                          Reputation:moderate, very likely benign file
                          Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                          Process:C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exe
                          File Type:data
                          Category:dropped
                          Size (bytes):2097152
                          Entropy (8bit):0.0
                          Encrypted:false
                          SSDEEP:3::
                          MD5:B2D1236C286A3C0704224FE4105ECA49
                          SHA1:7D76D48D64D7AC5411D714A4BB83F37E3E5B8DF6
                          SHA-256:5647F05EC18958947D32874EEB788FA396A05D0BAB7C1B71F112CEB7E9B31EEE
                          SHA-512:731859029215873FDAC1C9F2F8BD25A334ABF0F3A9E1B057CF2CACC2826D86B0C26A3FA920A936421401C0471F38857CB53BA905489EA46B185209FDFF65B3B6
                          Malicious:false
                          Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                          Process:C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exe
                          File Type:data
                          Category:dropped
                          Size (bytes):2097152
                          Entropy (8bit):0.0
                          Encrypted:false
                          SSDEEP:3::
                          MD5:B2D1236C286A3C0704224FE4105ECA49
                          SHA1:7D76D48D64D7AC5411D714A4BB83F37E3E5B8DF6
                          SHA-256:5647F05EC18958947D32874EEB788FA396A05D0BAB7C1B71F112CEB7E9B31EEE
                          SHA-512:731859029215873FDAC1C9F2F8BD25A334ABF0F3A9E1B057CF2CACC2826D86B0C26A3FA920A936421401C0471F38857CB53BA905489EA46B185209FDFF65B3B6
                          Malicious:false
                          Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                          Process:C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exe
                          File Type:Extensible storage engine DataBase, version 0x620, checksum 0x94058f85, page size 8192, JustCreated, Windows version 0.0
                          Category:dropped
                          Size (bytes):262144
                          Entropy (8bit):0.020338118405975675
                          Encrypted:false
                          SSDEEP:12:2X00OjNkX00OjN2zbsXDABAM+afrNQnoAIrlKVsaY5uhkrYaqaJdGlu:K+jy+j8PszA9+MyjVsfUh7Pu
                          MD5:88BD0602DCA0C198C110EBA8C9367D63
                          SHA1:CAC7268A3FCE39A5810A8D3314D1822D7E5BD3E7
                          SHA-256:A8990E1A321F6016D27D2CA27DF29C49DD2CB3CE7CB10E6C590DCA9B75092DE0
                          SHA-512:84CDAC6A21C9D0F16035B87D5B3BA512D970A5DDCD4B48232B4D9D40C97AC9EDAD4DE23E0B320B88EA5E940733D2194F65F8F0073E629B87B7423D38B0021BB2
                          Malicious:false
                          Preview:....... .......@........X.b.....|+.......................................................................................................................................................................................................... ...................................................................................................... ...................................................................................................................................................................................................................................................M}'......|+.....................................................................................................................................................................................................................................................................................................................................................................................................................
                          Process:C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exe
                          File Type:ASCII text, with no line terminators
                          Category:dropped
                          Size (bytes):264
                          Entropy (8bit):4.858868896394348
                          Encrypted:false
                          SSDEEP:6:e28IqUHeE7PnC8vPNhy5mOw1SEGmNrDnb:eCznv3Ow4FsrDnb
                          MD5:D351BE60C090C96DC7D64F41B58D7157
                          SHA1:435987B7FEF6D39741B278DBFB37BB6D164DAB7F
                          SHA-256:91829CB86AACA5130B23674233EB519B8D38C648C791D15B737F738462592F3A
                          SHA-512:3DBA3F45BC67CE2AFE7497797C15F7294997EB906743D008F08B8D091FBCE09C3D097C0C17EC961E12BF55F1353F8CF58C4C15D30A84F79725CDEEC6019FE327
                          Malicious:false
                          Preview:<SRPData version="1" sessionId="1"><Outcomes><Outcome id="videoCompleted" timesOccurred="0" /></Outcomes><Threshold launches="1" daysLaunched="1" dayOfLastLaunch="22" monthOfLastLaunch="5" yearOfLastLaunch="2024" userHasAccepted="false" timesPolled="0"/></SRPData>
                          Process:C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exe
                          File Type:ASCII text, with no line terminators
                          Category:dropped
                          Size (bytes):264
                          Entropy (8bit):4.858868896394348
                          Encrypted:false
                          SSDEEP:6:e28IqUHeE7PnC8vPNhy5mOw1SEGmNrDnb:eCznv3Ow4FsrDnb
                          MD5:D351BE60C090C96DC7D64F41B58D7157
                          SHA1:435987B7FEF6D39741B278DBFB37BB6D164DAB7F
                          SHA-256:91829CB86AACA5130B23674233EB519B8D38C648C791D15B737F738462592F3A
                          SHA-512:3DBA3F45BC67CE2AFE7497797C15F7294997EB906743D008F08B8D091FBCE09C3D097C0C17EC961E12BF55F1353F8CF58C4C15D30A84F79725CDEEC6019FE327
                          Malicious:false
                          Preview:<SRPData version="1" sessionId="1"><Outcomes><Outcome id="videoCompleted" timesOccurred="0" /></Outcomes><Threshold launches="1" daysLaunched="1" dayOfLastLaunch="22" monthOfLastLaunch="5" yearOfLastLaunch="2024" userHasAccepted="false" timesPolled="0"/></SRPData>
                          Process:C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exe
                          File Type:MS Windows registry file, NT/2000 or above
                          Category:dropped
                          Size (bytes):16384
                          Entropy (8bit):1.839540100047094
                          Encrypted:false
                          SSDEEP:96:DJM9FR4CAD149tISVCXFB5XPWmUWIYKkHKzvkk3oJo0H0SIf:VM9S143IS2PxnKMKokYoTS
                          MD5:ABDA2021E55945E3254BE6466AAF1397
                          SHA1:975C0499FCD4FFCB15BA63A46129CFAF900C76C0
                          SHA-256:F35DB18D76D60CF9AD99A5C207F6B7C184F15549BC10A8B2696AC8009D5401C9
                          SHA-512:7325A4E3382D3A453BFE03A994165AE98CE49A4E99B7A439A17CB038AEDFF4AEBC5E5E911CDF40C92B6442E18E4316FC08B46EDAC81C30DB719C43B7E3741FCE
                          Malicious:false
                          Preview:regf........b.Q.7.................. .... ......y.b.3.d.8.b.b.w.e.\.S.e.t.t.i.n.g.s.\.s.e.t.t.i.n.g.s...d.a.t...y..j.....J.....y..j.....J.........z..j.....J.....rmtm..)rZ................................................................................................................................................................................................................................................................................................................................................E..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                          Process:C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exe
                          File Type:MS Windows registry file, NT/2000 or above
                          Category:dropped
                          Size (bytes):12288
                          Entropy (8bit):2.3559595906992983
                          Encrypted:false
                          SSDEEP:96:YJn9FR4CAD149tISVCXFB5XPWmUWIYKkHKzvkk3oJo0H0SIf:8n9S143IS2PxnKMKokYoTS
                          MD5:0124EB2FB8B1D4F55F232C4884DE2334
                          SHA1:DBBCE891DC1141EA382FCEBF01B5E4AEE9BF2FC4
                          SHA-256:D64C1FFBB5C0126131A18317D8BC1EDF7B8A5BBA0B456D72E9957F4268DAB9EC
                          SHA-512:F3DB615DD93460A732A0F41CEAB8B9746B726B9AA6AF52ADA398DCA726316698F2EFB6E692B464470B227F97DCCB95FF4C3E2CD9566E5E8DA06849D90682EFE9
                          Malicious:false
                          Preview:regf........b.Q.7.................. .... ......y.b.3.d.8.b.b.w.e.\.S.e.t.t.i.n.g.s.\.s.e.t.t.i.n.g.s...d.a.t...y..j.....J.....y..j.....J.........z..j.....J.....rmtm..)rZ................................................................................................................................................................................................................................................................................................................................................E..HvLE............. .........T..:K..._\.o...... ..hbin................b.Q.7..........nk,.T...7..................................x...............................Test....p...sk..h...h.......t.......H...X.............4.........?.......................?....................... ... ...............YQ..fr]%dc;.............nk .K.5yZ...................................h...............................Configuration...p...sk..x...x.......t.......H...X.............4.........?.......................
                          File type:ISO Media, HEIF Image HEVC Main or Main Still Picture Profile
                          Entropy (8bit):7.9996405369074814
                          TrID:
                          • Generic MP4 container (3007/2) 59.98%
                          • MacBinary 2 header (1003/3) 20.01%
                          • Adobe PhotoShop Brush (1003/3) 20.01%
                          File name:IMG_2879.mp4
                          File size:2'585'783 bytes
                          MD5:2276ca86ca713ad22d76457615e8c727
                          SHA1:48e0f4ff39254cb417b032f73cc607d524908878
                          SHA256:86dae22df32447e4fe1cce4f6fd20c9d19ea557d8f640e4c974753b5ebd4de97
                          SHA512:5597b41a2a64d6c2b86508d3deaf1465a3d92ee53f06a7bb6c12a78e526335793f4cdfbaef855383ef67a6e35d1d13db23e43a49f12ff664a4b506fb93c9e597
                          SSDEEP:49152:uJYCHnFtaG57DAE2P7v4Tu4KqS9F8SKhAaffN+G6oWDysmI4KlJEEXKwC:DAxwjv4a48O5VRHtj3Kl2Wi
                          TLSH:17C5335FDB490F86EF2F7070ACE7760D6DA756A7A70293635E24176C40C91C2B84988F
                          File Content Preview:...(ftypheic....mif1MiHEMiPrmiafMiHBheic....meta.......!hdlr........pict................$dinf....dref............url ........pitm.........<iinf.....2....infe........hvc1.....infe........hvc1.....infe........hvc1.....infe........hvc1.....infe........hvc1..
                          Icon Hash:74f0dcc4c4c4e0e4
                          TimestampSource PortDest PortSource IPDest IP
                          May 22, 2024 17:12:35.724757910 CEST49739443192.168.2.413.107.246.67
                          May 22, 2024 17:12:35.724838972 CEST4434973913.107.246.67192.168.2.4
                          May 22, 2024 17:12:35.724925995 CEST49739443192.168.2.413.107.246.67
                          May 22, 2024 17:12:35.735596895 CEST49739443192.168.2.413.107.246.67
                          May 22, 2024 17:12:35.735632896 CEST4434973913.107.246.67192.168.2.4
                          May 22, 2024 17:12:36.388222933 CEST4434973913.107.246.67192.168.2.4
                          May 22, 2024 17:12:36.388314009 CEST49739443192.168.2.413.107.246.67
                          May 22, 2024 17:12:36.391004086 CEST49739443192.168.2.413.107.246.67
                          May 22, 2024 17:12:36.391030073 CEST4434973913.107.246.67192.168.2.4
                          May 22, 2024 17:12:36.391521931 CEST4434973913.107.246.67192.168.2.4
                          May 22, 2024 17:12:36.399380922 CEST49739443192.168.2.413.107.246.67
                          May 22, 2024 17:12:36.446495056 CEST4434973913.107.246.67192.168.2.4
                          May 22, 2024 17:12:36.645932913 CEST4434973913.107.246.67192.168.2.4
                          May 22, 2024 17:12:36.645966053 CEST4434973913.107.246.67192.168.2.4
                          May 22, 2024 17:12:36.646054029 CEST49739443192.168.2.413.107.246.67
                          May 22, 2024 17:12:36.646115065 CEST4434973913.107.246.67192.168.2.4
                          May 22, 2024 17:12:36.646178961 CEST49739443192.168.2.413.107.246.67
                          May 22, 2024 17:12:36.647116899 CEST4434973913.107.246.67192.168.2.4
                          May 22, 2024 17:12:36.647182941 CEST4434973913.107.246.67192.168.2.4
                          May 22, 2024 17:12:36.647361994 CEST49739443192.168.2.413.107.246.67
                          May 22, 2024 17:12:36.728176117 CEST49739443192.168.2.413.107.246.67
                          May 22, 2024 17:12:36.728215933 CEST4434973913.107.246.67192.168.2.4
                          May 22, 2024 17:12:36.728243113 CEST49739443192.168.2.413.107.246.67
                          May 22, 2024 17:12:36.728257895 CEST4434973913.107.246.67192.168.2.4
                          May 22, 2024 17:12:37.236850023 CEST49741443192.168.2.413.107.246.67
                          May 22, 2024 17:12:37.236947060 CEST4434974113.107.246.67192.168.2.4
                          May 22, 2024 17:12:37.237078905 CEST49741443192.168.2.413.107.246.67
                          May 22, 2024 17:12:37.251368046 CEST49741443192.168.2.413.107.246.67
                          May 22, 2024 17:12:37.251442909 CEST4434974113.107.246.67192.168.2.4
                          May 22, 2024 17:12:37.933793068 CEST4434974113.107.246.67192.168.2.4
                          May 22, 2024 17:12:37.934015989 CEST49741443192.168.2.413.107.246.67
                          May 22, 2024 17:12:38.066632032 CEST49741443192.168.2.413.107.246.67
                          May 22, 2024 17:12:38.066703081 CEST4434974113.107.246.67192.168.2.4
                          May 22, 2024 17:12:38.067595005 CEST4434974113.107.246.67192.168.2.4
                          May 22, 2024 17:12:38.072453022 CEST49741443192.168.2.413.107.246.67
                          May 22, 2024 17:12:38.078847885 CEST49741443192.168.2.413.107.246.67
                          May 22, 2024 17:12:38.078912020 CEST4434974113.107.246.67192.168.2.4
                          May 22, 2024 17:12:38.305751085 CEST4434974113.107.246.67192.168.2.4
                          May 22, 2024 17:12:38.305809021 CEST4434974113.107.246.67192.168.2.4
                          May 22, 2024 17:12:38.305852890 CEST4434974113.107.246.67192.168.2.4
                          May 22, 2024 17:12:38.305954933 CEST4434974113.107.246.67192.168.2.4
                          May 22, 2024 17:12:38.306013107 CEST49741443192.168.2.413.107.246.67
                          May 22, 2024 17:12:38.306014061 CEST49741443192.168.2.413.107.246.67
                          May 22, 2024 17:12:38.306014061 CEST49741443192.168.2.413.107.246.67
                          May 22, 2024 17:12:38.806090117 CEST49741443192.168.2.413.107.246.67
                          May 22, 2024 17:12:38.806128025 CEST4434974113.107.246.67192.168.2.4
                          May 22, 2024 17:12:38.806148052 CEST49741443192.168.2.413.107.246.67
                          May 22, 2024 17:12:38.806157112 CEST4434974113.107.246.67192.168.2.4
                          TimestampSource PortDest PortSource IPDest IP
                          May 22, 2024 17:12:33.596498966 CEST6291553192.168.2.41.1.1.1
                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                          May 22, 2024 17:12:33.596498966 CEST192.168.2.41.1.1.10xcfa9Standard query (0)settings-ssl.xboxlive.comA (IP address)IN (0x0001)false
                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                          May 22, 2024 17:12:33.607194901 CEST1.1.1.1192.168.2.40xcfa9No error (0)settings-ssl.xboxlive.comsettings-ssl.xboxlive.com.edgekey.netCNAME (Canonical name)IN (0x0001)false
                          May 22, 2024 17:12:35.724100113 CEST1.1.1.1192.168.2.40x3281No error (0)ep-afd-activation-cubaf8a6apchfsg5.z01.azurefd.netstar-azurefd-prod.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                          May 22, 2024 17:12:35.724100113 CEST1.1.1.1192.168.2.40x3281No error (0)shed.dual-low.part-0039.t-0009.t-msedge.netpart-0039.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                          May 22, 2024 17:12:35.724100113 CEST1.1.1.1192.168.2.40x3281No error (0)part-0039.t-0009.t-msedge.net13.107.246.67A (IP address)IN (0x0001)false
                          May 22, 2024 17:12:35.724100113 CEST1.1.1.1192.168.2.40x3281No error (0)part-0039.t-0009.t-msedge.net13.107.213.67A (IP address)IN (0x0001)false
                          • activation2.playready.microsoft.com
                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          0192.168.2.44973913.107.246.674433196C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exe
                          TimestampBytes transferredDirectionData
                          2024-05-22 15:12:36 UTC200OUTGET /PlayReady/ACT/Activation.asmx?WSDL&Client=Win10&LinkId=613387 HTTP/1.1
                          Connection: Keep-Alive
                          Accept: */*
                          User-Agent: Microsoft-PlayReady-DRM/1.0
                          Host: activation2.playready.microsoft.com
                          2024-05-22 15:12:36 UTC466INHTTP/1.1 200 OK
                          Date: Wed, 22 May 2024 15:12:36 GMT
                          Content-Type: text/xml; charset=utf-8
                          Content-Length: 6250
                          Connection: close
                          Cache-Control: private, max-age=0
                          X-AspNet-Version: 4.0.30319
                          Request-Context: appId=cid-v1:79cef274-7303-4874-9131-e08bd3e00d78
                          Access-Control-Expose-Headers: Request-Context
                          X-Powered-By: ASP.NET
                          x-azure-ref: 20240522T151236Z-16f669959b4gz86b1uee05t9pw000000036000000000kuhs
                          X-Cache: CONFIG_NOCACHE
                          Accept-Ranges: bytes
                          2024-05-22 15:12:36 UTC6250INData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 77 73 64 6c 3a 64 65 66 69 6e 69 74 69 6f 6e 73 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 22 20 78 6d 6c 6e 73 3a 73 6f 61 70 31 32 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 77 73 64 6c 2f 73 6f 61 70 31 32 2f 22 20 78 6d 6c 6e 73 3a 68 74 74 70 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 77 73 64 6c 2f 68 74 74 70 2f 22 20 78 6d 6c 6e 73 3a 6d 69 6d 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 77 73 64 6c 2f 6d 69 6d 65
                          Data Ascii: <?xml version="1.0" encoding="utf-8"?><wsdl:definitions xmlns:s="http://www.w3.org/2001/XMLSchema" xmlns:soap12="http://schemas.xmlsoap.org/wsdl/soap12/" xmlns:http="http://schemas.xmlsoap.org/wsdl/http/" xmlns:mime="http://schemas.xmlsoap.org/wsdl/mime


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          1192.168.2.44974113.107.246.674433196C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exe
                          TimestampBytes transferredDirectionData
                          2024-05-22 15:12:38 UTC595OUTPOST /PlayReady/ACT/Activation.asmx HTTP/1.1
                          Connection: Keep-Alive
                          Content-Type: text/xml; charset=utf-8
                          Accept: */*
                          User-Agent: Microsoft-PlayReady-DRM/1.0
                          x-playready-info: OSVersion=10.0; ClientDllVersion=Windows.Media.Protection.PlayReady.dll/10.0.19041.2006 (WinBuild.160101.0800); Session=fa58d78ad5ed7305c0ed9c15cee9fb11; StoreAppID=Microsoft.ZuneVideo_8wekyb3d8bbwe!Microsoft.ZuneVideo;
                          X-XblCorrelationId: 5574449021208076118
                          SOAPAction: "http://schemas.microsoft.com/PlayReady/ActivationService/v1/Activate"
                          Content-Length: 3580
                          Host: activation2.playready.microsoft.com
                          2024-05-22 15:12:38 UTC3580OUTData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 78 73 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 20 78 6d 6c 6e 73 3a 78 73 64 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 22 20 78 6d 6c 6e 73 3a 73 6f 61 70 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 6f 61 70 3a 42 6f 64 79 3e 3c 41 63 74 69 76 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 6d 69 63 72 6f
                          Data Ascii: <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"><soap:Body><Activate xmlns="http://schemas.micro
                          2024-05-22 15:12:38 UTC466INHTTP/1.1 200 OK
                          Date: Wed, 22 May 2024 15:12:38 GMT
                          Content-Type: text/xml; charset=utf-8
                          Content-Length: 7264
                          Connection: close
                          Cache-Control: private, max-age=0
                          X-AspNet-Version: 4.0.30319
                          Request-Context: appId=cid-v1:79cef274-7303-4874-9131-e08bd3e00d78
                          Access-Control-Expose-Headers: Request-Context
                          X-Powered-By: ASP.NET
                          x-azure-ref: 20240522T151238Z-16f669959b4f5hg46qn0sb4crc000000035000000000uum5
                          X-Cache: CONFIG_NOCACHE
                          Accept-Ranges: bytes
                          2024-05-22 15:12:38 UTC7264INData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 6f 61 70 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 78 6d 6c 6e 73 3a 78 73 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 20 78 6d 6c 6e 73 3a 78 73 64 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 22 3e 3c 73 6f 61 70 3a 42 6f 64 79 3e 3c 41 63 74 69 76 61 74 65 52 65 73 70 6f 6e 73 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d
                          Data Ascii: <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema"><soap:Body><ActivateResponse xmlns="http://schem


                          Click to jump to process

                          Click to jump to process

                          Target ID:1
                          Start time:11:12:22
                          Start date:22/05/2024
                          Path:C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exe
                          Wow64 process (32bit):false
                          Commandline:"C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19071.19011.0_x64__8wekyb3d8bbwe\Video.UI.exe" -ServerName:Microsoft.ZuneVideo.AppX758ya5sqdjd98rx6z7g95nw6jy7bqx9y.mca
                          Imagebase:0x7ff652a00000
                          File size:25'966'080 bytes
                          MD5 hash:FE340ECB1D09B5BAA66DFE25AF11654F
                          Has elevated privileges:false
                          Has administrator privileges:false
                          Programmed in:C, C++ or other language
                          Reputation:moderate
                          Has exited:false

                          Reset < >

                            Execution Graph

                            Execution Coverage:25.2%
                            Dynamic/Decrypted Code Coverage:0%
                            Signature Coverage:0%
                            Total number of Nodes:2
                            Total number of Limit Nodes:0
                            execution_graph 120 265e8d0018b SetEndOfFile 121 265e8d0019d 120->121

                            Callgraph

                            • Executed
                            • Not Executed
                            • Opacity -> Relevance
                            • Disassembly available
                            callgraph 0 Function_00000265E8D05C95 1 Function_00000265E8D02916 2 Function_00000265E8D03F9A 3 Function_00000265E8D05C1B 4 Function_00000265E75F111D 5 Function_00000265E8D0531C 6 Function_00000265E75F251A 7 Function_00000265E8D0259F 8 Function_00000265E8D05F9F 9 Function_00000265E8D0621F 10 Function_00000265E8D00DA0 11 Function_00000265E8D033A0 12 Function_00000265E8D00D20 13 Function_00000265E8D022A4 14 Function_00000265E8D01624 15 Function_00000265E8D03F24 16 Function_00000265E8D06324 17 Function_00000265E75F6214 18 Function_00000265E8D04605 19 Function_00000265E8D04289 20 Function_00000265E75F288F 21 Function_00000265E8D0018B 22 Function_00000265E8D0530C 23 Function_00000265E75F128B 24 Function_00000265E75F0505 25 Function_00000265E8D03B36 26 Function_00000265E75F15C0 27 Function_00000265E8D006BD 28 Function_00000265E75F1C39 29 Function_00000265E8D00D41 30 Function_00000265E75F2937 31 Function_00000265E8D027C2 32 Function_00000265E8D01642 33 Function_00000265E8D02844 34 Function_00000265E75F15B2 35 Function_00000265E75F1BB0 36 Function_00000265E75F1D2F 37 Function_00000265E75F1A2D 38 Function_00000265E75F2C29 39 Function_00000265E8D00F30 40 Function_00000265E8D035D6 41 Function_00000265E8D00458 42 Function_00000265E8D04AD9 43 Function_00000265E8D0305A 44 Function_00000265E8D0215C 45 Function_00000265E8D0045E 46 Function_00000265E8D026DE 47 Function_00000265E75F6354 48 Function_00000265E8D006C5 49 Function_00000265E8D00DCA 50 Function_00000265E8D000CB 51 Function_00000265E8D03CCC 52 Function_00000265E8D0044D 53 Function_00000265E8D0234F 54 Function_00000265E8D02FD0 55 Function_00000265E8D02651 56 Function_00000265E8D01D53 57 Function_00000265E8D03153 58 Function_00000265E75F4745 59 Function_00000265E8D06575 60 Function_00000265E8D028F5 61 Function_00000265E8D061F5 62 Function_00000265E8D05176 63 Function_00000265E8D02677 64 Function_00000265E8D006F9 65 Function_00000265E8D05A7A 66 Function_00000265E8D016FB 67 Function_00000265E75F20FD 68 Function_00000265E8D038FC 69 Function_00000265E8D006FD 70 Function_00000265E75F207B 71 Function_00000265E8D0287F 72 Function_00000265E75F1579 73 Function_00000265E8D06566 74 Function_00000265E75F20F2 75 Function_00000265E8D06267 76 Function_00000265E8D017EA 77 Function_00000265E8D00F6B 78 Function_00000265E8D0476C 79 Function_00000265E8D0416E 80 Function_00000265E75F1169 81 Function_00000265E75F1CE6 82 Function_00000265E75F20E6 83 Function_00000265E8D01674

                            Control-flow Graph

                            APIs
                            Memory Dump Source
                            • Source File: 00000001.00000002.2925015368.00000265E8D00000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000265E8D00000, based on PE: false
                            Joe Sandbox IDA Plugin
                            • Snapshot File: hcaresult_1_2_265e8d00000_Video.jbxd
                            Similarity
                            • API ID: File
                            • String ID:
                            • API String ID: 749574446-0
                            • Opcode ID: cd1b186bdcfa44fff865d8135a4a748934d4eda89c0c3b056c9ec28890b180d6
                            • Instruction ID: a7f7316600e938fcc7451eb9ebde5398164adf9596264d0960734228e7601776
                            • Opcode Fuzzy Hash: cd1b186bdcfa44fff865d8135a4a748934d4eda89c0c3b056c9ec28890b180d6
                            • Instruction Fuzzy Hash: 31F0523011CF4C8FFB66DF28894822A77E2F768300F94052BE481C3192DF3AD9829342

                            Control-flow Graph

                            Memory Dump Source
                            • Source File: 00000001.00000002.2920108063.00000265E75F0000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000265E75F0000, based on PE: false
                            Joe Sandbox IDA Plugin
                            • Snapshot File: hcaresult_1_2_265e75f0000_Video.jbxd
                            Similarity
                            • API ID:
                            • String ID:
                            • API String ID:
                            • Opcode ID: 54d0e4a1d6b7d4d852a76a5556ee26338138116022f7396f042c598d372b7747
                            • Instruction ID: 379d07f58652695bf1c78d6e57c261d592e74ba5567000bdacc42aa179a6df81
                            • Opcode Fuzzy Hash: 54d0e4a1d6b7d4d852a76a5556ee26338138116022f7396f042c598d372b7747
                            • Instruction Fuzzy Hash: D441043060CB588FE71DDE18D845635B7E1FB56320F2442AFD1DAC72A3E636A9068782

                            Control-flow Graph

                            • Executed
                            • Not Executed
                            control_flow_graph 34 265e75f1a2d-265e75f1a4a 35 265e75f1a94-265e75f1a97 34->35 36 265e75f1a4c-265e75f1a5b 34->36 38 265e75f1a99-265e75f1aa4 35->38 39 265e75f1aa8-265e75f1add 35->39 36->35 37 265e75f1a5d-265e75f1a8f 36->37 37->35 38->39
                            Memory Dump Source
                            • Source File: 00000001.00000002.2920108063.00000265E75F0000.00000020.00000001.00020000.00000000.sdmp, Offset: 00000265E75F0000, based on PE: false
                            Joe Sandbox IDA Plugin
                            • Snapshot File: hcaresult_1_2_265e75f0000_Video.jbxd
                            Similarity
                            • API ID:
                            • String ID:
                            • API String ID:
                            • Opcode ID: aeddb90ddc40b9ef1058ef80066596d7a7d8f500a2ca7339dd41f413c1859a76
                            • Instruction ID: fc4d716a49f4bff95113e6843c3097ee980e6d2cc05f5e93220f1d5a6e4285a3
                            • Opcode Fuzzy Hash: aeddb90ddc40b9ef1058ef80066596d7a7d8f500a2ca7339dd41f413c1859a76
                            • Instruction Fuzzy Hash: 8221A23120CF1D4FE75AEB18E885AA573E1F798320F18426BC446C32A5DF25E946CBC2