Source: Yara match | File source: svchost.exe, type: SAMPLE |
Source: Yara match | File source: 00000006.00000002.263919430.0000000000B42000.00000002.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000006.00000000.259204194.0000000000B42000.00000002.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000003.233358475.0000000007201000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000000.227665901.0000000000F82000.00000002.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000001.00000002.494084624.0000000000122000.00000002.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000001.00000000.234021337.0000000000122000.00000002.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.234340681.0000000000F82000.00000002.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: svchost.exe PID: 3008, type: MEMORY |
Source: Yara match | File source: Process Memory Space: svchost.exe PID: 3260, type: MEMORY |
Source: Yara match | File source: Process Memory Space: svchost.exe PID: 4884, type: MEMORY |
Source: Yara match | File source: C:\Users\user\AppData\Roaming\SubDir\svchost.exe, type: DROPPED |
Source: Yara match | File source: 0.0.svchost.exe.f80000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 6.0.svchost.exe.b40000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 6.2.svchost.exe.b40000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 1.2.svchost.exe.120000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 1.0.svchost.exe.120000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.svchost.exe.f80000.0.unpack, type: UNPACKEDPE |
Source: C:\Users\user\Desktop\svchost.exe | DNS query: name: freegeoip.net |
Source: C:\Users\user\Desktop\svchost.exe | DNS query: name: api.ipify.org |
Source: C:\Users\user\Desktop\svchost.exe | DNS query: name: api.ipify.org |
Source: C:\Users\user\Desktop\svchost.exe | DNS query: name: api.ipify.org |
Source: C:\Users\user\Desktop\svchost.exe | DNS query: name: api.ipify.org |
Source: C:\Users\user\Desktop\svchost.exe | DNS query: name: api.ipify.org |
Source: C:\Users\user\Desktop\svchost.exe | DNS query: name: api.ipify.org |
Source: C:\Users\user\AppData\Roaming\SubDir\svchost.exe | DNS query: name: freegeoip.net |
Source: C:\Users\user\AppData\Roaming\SubDir\svchost.exe | DNS query: name: api.ipify.org |
Source: C:\Users\user\AppData\Roaming\SubDir\svchost.exe | DNS query: name: api.ipify.org |
Source: C:\Users\user\AppData\Roaming\SubDir\svchost.exe | DNS query: name: api.ipify.org |
Source: C:\Users\user\AppData\Roaming\SubDir\svchost.exe | DNS query: name: api.ipify.org |
Source: C:\Users\user\AppData\Roaming\SubDir\svchost.exe | DNS query: name: api.ipify.org |
Source: C:\Users\user\AppData\Roaming\SubDir\svchost.exe | DNS query: name: api.ipify.org |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: unknown | TCP traffic detected without corresponding DNS query: 139.196.56.98 |
Source: svchost.exe, 00000018.00000003.374682797.000001AB9515F000.00000004.00000001.sdmp | String found in binary or memory: Try it free for 30 days, no strings attached\r\n\r\nLike us on Facebook: http://www.facebook.com/spotify \r\nFollow us on Twitter: http://twitter.com/spotify","ProductTitle":"Spotify Music","SearchTitles":[{"SearchTitleString":"Spotify","SearchTitleType":"SearchHint"},{"SearchTitleString":"Music","SearchTitleType":"SearchHint"},{"SearchTitleString":"music apps","SearchTitleType":"SearchHint"},{"SearchTitleString":"free music","SearchTitleType":"SearchHint"},{"SearchTitleString":"pandora","SearchTitleType":"SearchHint"},{"SearchTitleString":"streaming","SearchTitleType":"SearchHint"},{"SearchTitleString":"soundcloud","SearchTitleType":"SearchHint"}],"Language":"en-us","Markets":["US","DZ","AR","AU","AT","BH","BD","BE","BR","BG","CA","CL","CN","CO","CR","HR","CY","CZ","DK","EG","EE","FI","FR","DE","GR","GT","HK","HU","IS","IN","ID","IQ","IE","IL","IT","JP","JO","KZ","KE","KW","LV","LB","LI","LT","LU","MY","MT","MR","MX","MA","NL","NZ","NG","NO","OM","PK","PE","PH","PL","PT","QA","RO","RU","SA","RS","SG","SK","SI","ZA","KR","ES","SE","CH","TW","TH","TT","TN","TR","UA","AE","GB","VN","YE","LY","LK","UY","VE","AF","AX","AL","AS","AO","AI", equals www.facebook.com (Facebook) |
Source: svchost.exe, 00000018.00000003.374682797.000001AB9515F000.00000004.00000001.sdmp | String found in binary or memory: Try it free for 30 days, no strings attached\r\n\r\nLike us on Facebook: http://www.facebook.com/spotify \r\nFollow us on Twitter: http://twitter.com/spotify","ProductTitle":"Spotify Music","SearchTitles":[{"SearchTitleString":"Spotify","SearchTitleType":"SearchHint"},{"SearchTitleString":"Music","SearchTitleType":"SearchHint"},{"SearchTitleString":"music apps","SearchTitleType":"SearchHint"},{"SearchTitleString":"free music","SearchTitleType":"SearchHint"},{"SearchTitleString":"pandora","SearchTitleType":"SearchHint"},{"SearchTitleString":"streaming","SearchTitleType":"SearchHint"},{"SearchTitleString":"soundcloud","SearchTitleType":"SearchHint"}],"Language":"en-us","Markets":["US","DZ","AR","AU","AT","BH","BD","BE","BR","BG","CA","CL","CN","CO","CR","HR","CY","CZ","DK","EG","EE","FI","FR","DE","GR","GT","HK","HU","IS","IN","ID","IQ","IE","IL","IT","JP","JO","KZ","KE","KW","LV","LB","LI","LT","LU","MY","MT","MR","MX","MA","NL","NZ","NG","NO","OM","PK","PE","PH","PL","PT","QA","RO","RU","SA","RS","SG","SK","SI","ZA","KR","ES","SE","CH","TW","TH","TT","TN","TR","UA","AE","GB","VN","YE","LY","LK","UY","VE","AF","AX","AL","AS","AO","AI", equals www.twitter.com (Twitter) |
Source: svchost.exe, 00000018.00000003.374656288.000001AB9516F000.00000004.00000001.sdmp | String found in binary or memory: Try it free for 30 days, no strings attached\r\n\r\nLike us on Facebook: http://www.facebook.com/spotify \r\nFollow us on Twitter: http://twitter.com/spotify","ProductTitle":"Spotify Music","SearchTitles":[{"SearchTitleString":"Spotify","SearchTitleType":"SearchHint"},{"SearchTitleString":"Music","SearchTitleType":"SearchHint"},{"SearchTitleString":"music apps","SearchTitleType":"SearchHint"},{"SearchTitleString":"free music","SearchTitleType":"SearchHint"},{"SearchTitleString":"pandora","SearchTitleType":"SearchHint"},{"SearchTitleString":"streaming","SearchTitleType":"SearchHint"},{"SearchTitleString":"soundcloud","SearchTitleType":"SearchHint"}],"Language":"en-us","Markets":["US","DZ","AR","AU","AT","BH","BD","BE","BR","BG","CA","CL","CN","CO","CR","HR","CY","CZ","DK","EG","EE","FI","FR","DE","GR","GT","HK","HU","IS","IN","ID","IQ","IE","IL","IT","JP","JO","KZ","KE","KW","LV","LB","LI","LT","LU","MY","MT","MR","MX","MA","NL","NZ","NG","NO","OM","PK","PE","PH","PL","PT","QA","RO","RU","SA","RS","SG","SK","SI","ZA","KR","ES","SE","CH","TW","TH","TT","TN","TR","UA","AE","GB","VN","YE","LY","LK","UY","VE","AF","AX","AL","AS","AO","AI","AQ","AG","AM","AW","BO","BQ","BA","BW","BV","IO","BN","BF","BI","KH","CM","CV","KY","CF","TD","TL","DJ","DM","DO","EC","SV","GQ","ER","ET","FK","FO","FJ","GF","PF","TF","GA","GM","GE","GH","GI","GL","GD","GP","GU","GG","GN","GW","GY","HT","HM","HN","AZ","BS","BB","BY","BZ","BJ","BM","BT","KM","CG","CD","CK","CX","CC","CI","CW","JM","SJ","JE","KI","KG","LA","LS","LR","MO","MK","MG","MW","IM","MH","MQ","MU","YT","FM","MD","MN","MS","MZ","MM","NA","NR","NP","MV","ML","NC","NI","NE","NU","NF","PW","PS","PA","PG","PY","RE","RW","BL","MF","WS","ST","SN","MP","PN","SX","SB","SO","SC","SL","GS","SH","KN","LC","PM","VC","TJ","TZ","TG","TK","TO","TM","TC","TV","UM","UG","VI","VG","WF","EH","ZM","ZW","UZ","VU","SR","SZ","AD","MC","SM","ME","VA","NEUTRAL"]}],"MarketProperties":[{"RelatedProducts":[],"Markets":["US"]}],"ProductASchema":"Product;3","ProductBSchema":"ProductUnifiedApp;3","ProductId":"9NCBCSZSJRSB","Properties":{"PackageFamilyName":"SpotifyAB.SpotifyMusic_zpdnekdrzrea0","PackageIdentityName":"SpotifyAB.SpotifyMusic","PublisherCertificateName":"CN=453637B3-4E12-4CDF-B0D3-2A3C863BF6EF","XboxCrossGenSetId":null,"XboxConsoleGenOptimized":null,"XboxConsoleGenCompatible":null},"AlternateIds":[{"IdType":"LegacyWindowsStoreProductId","Value":"ceac5d3f-8a4f-40e1-9a67-76d9108c7cb5"},{"IdType":"LegacyWindowsPhonePr |