Windows Analysis Report
AirDroid_Cast_Desktop_Client_1.2.1.0.exe

Overview

General Information

Sample name: AirDroid_Cast_Desktop_Client_1.2.1.0.exe
Analysis ID: 1527909
MD5: 637a0fd3e65d39ad0c6c3d5cc042c4de
SHA1: b47fd7f796afc81221206c91bdcc3e8e9ddc91d3
SHA256: 91226bee406922357d5d1ea945a5b6e8866e0ee7a75d897ecf339f6ff38c18c9
Infos:

Detection

Score: 26
Range: 0 - 100
Whitelisted: false
Confidence: 20%

Compliance

Score: 49
Range: 0 - 100

Signatures

.NET source code contains method to dynamically call methods (often used by packers)
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Yara detected Generic Downloader
Abnormal high CPU Usage
Allocates memory with a write watch (potentially for evading sandboxes)
Binary contains a suspicious time stamp
Connects to many different domains
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates driver files
Detected TCP or UDP traffic on non-standard ports
Detected non-DNS traffic on DNS port
Drops PE files
Drops certificate files (DER)
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
HTML page contains hidden javascript code
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Installs a raw input device (often for capturing keystrokes)
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
PE file contains executable resources (Code or Archives)
PE file contains more sections than normal
PE file contains sections with non-standard names
PE file does not import any functions
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Sleep loop found (likely to delay execution)
Stores files to the Windows start menu directory
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Very long cmdline option found, this is very uncommon (may be encrypted or packed)

Classification

Source: https://m-embed.airdroid.com/cast_link.html?airdroidCast-code=028461947 HTTP Parser: Base64 decoded: <?xml version="1.0" encoding="utf-8"?> <svg version="1.1" xmlns="http://www.w3.org/2000/svg"><defs><linearGradient id="grad" gradientUnits="objectBoundingBox" x1="0.5" y1="0.0" x2="0.5" y2="1.0"><stop offset="0%" stop-color="#42c662"/><stop offset="61%" s...

Compliance

barindex
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Window detected: < &BackI &AgreeCancelSand Studio Sand StudioLicense AgreementPlease review the license terms before installing AirDroid Cast 1.2.1.0.Press Page Down to see the rest of the agreement.AIRDROID END USER LICENSE AGREEMENTEffective Date: 24 July2020TheAirDroid End User License Agreement(thereinafter "Agreement") is jointly concluded by You (the "End User"/"User") and SAND STUDIO for Your use of Services (defined below) provided by SAND STUDIO. "SAND STUDIO" refers to SAND STUDIO PTE.LTD. and/or any associated operator (hereinafter collectively referred to as "SAND STUDIO" the "Company" "We" "Us" or "Our") that may exist with respect to its related services and both You and We will be legally bound by this Agreement. Please read terms in this Agreement carefully before using the Services (defined below) offered by Us.By visiting our websites or using our Services in any manner You agree that You have read and agree to be bound by the terms and conditions of this Agreement. Use of the Companys services is expressly conditioned upon Your assent to all or parts of the terms and conditions of this Agreement to the exclusion of all other terms.This Agreement applies when You enter into this Agreement with us as an INDIVIDUAL rather than as an Enterprise User. If You are an Enterprise User employee agent trustee of an Enterprise User authorized person to supervise or manage the use of AirDroid by an Enterprise User or other person to use AirDroid Services for the interest of an enterprise please visit theAirdroid Enterprise User License Agreementread and decide whether to agree to theAirdroid Enterprise User License Agreement.The terms of this Agreement that are or may be material to Your rights and interests have been marked in bold and please pay specific attention to them.I. DEFINITIONIn this Agreement1. The"Website"means the www.airdroid.com website and domain name and any other linked pages features contents or application services (including but not limited to any mobile application services) offered from time to time by the Company in connection therewith.2. The"AirDroid Services"or"Services"mean all software products services websites and relevant contents provided by the Company.3. The"AirDroid Account"or"Account"means the users account created by the user when using AirDroid Services the username and password of which can identify You.4. The"AirDroid Contents"or"Contents"mean all materials offered displayed or performed on the Services including but not limited to software text graphics articles photographs images illustrations etc.5."Third Party Services"mean third party websites services and/or contents that are not owned or controlled by the Company during the Services.6."Affiliates" for the purpose of this Agreement mean enterprises that directly or indirectly control the Company or are under the control of the Company or are under control together with the Company. For the purpose of this definition "control" refers to
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe Static PE information: certificate valid
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe File opened: C:\Program Files (x86)\AirDroid Cast\MSVCR100.dll Jump to behavior
Source: unknown HTTPS traffic detected: 172.202.163.200:443 -> 192.168.2.4:49735 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.35.72:443 -> 192.168.2.4:49736 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.107.246.60:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:49777 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.202.163.200:443 -> 192.168.2.4:49778 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:49827 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:49826 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.230.180:443 -> 192.168.2.4:49828 version: TLS 1.2
Source: unknown HTTPS traffic detected: 170.106.112.204:443 -> 192.168.2.4:49861 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.181.65:443 -> 192.168.2.4:49870 version: TLS 1.2
Source: unknown HTTPS traffic detected: 170.106.112.204:443 -> 192.168.2.4:49875 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49888 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49913 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:49970 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:49979 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.35.72:443 -> 192.168.2.4:50010 version: TLS 1.2
Source: unknown HTTPS traffic detected: 173.222.162.32:443 -> 192.168.2.4:50109 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.107.246.60:443 -> 192.168.2.4:50225 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50254 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50255 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50256 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50257 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50260 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50261 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50262 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50263 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50264 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50265 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50272 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50274 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50275 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50276 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50280 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50281 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50282 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50283 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50285 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50286 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50288 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50287 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50294 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50291 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50292 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50293 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50295 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50296 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50299 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50298 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50301 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50302 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50304 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50305 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50307 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50308 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50310 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50311 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50314 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50313 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50316 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50317 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50319 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50320 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50322 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50323 version: TLS 1.2
Source: unknown HTTPS traffic detected: 20.189.173.3:443 -> 192.168.2.4:50336 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50338 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50339 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50343 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50344 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50347 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50348 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50352 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50353 version: TLS 1.2
Source: Binary string: ]c:\borrar\EmptyDll\Release\EmptyDll.pdb source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp
Source: Binary string: F:\SourceCode\QRCoder\QRCoder\obj\Release\QRCoder.pdb source: AirDroidCast.exe, 00000009.00000002.6309499575.0000000012A12000.00000002.00000001.01000000.00000030.sdmp
Source: Binary string: E:\GitCode\tb-scrcyp\win\scrcpy-1.17lib\Win32\Debug\libscrcpy.pdb source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003045000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: vccorlib120.i386.pdb0 source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ucrtbase.pdb source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: E:\GitCode\airdroid_business_win_source\Launcher\Release\Launcher.pdb source: Launcher.exe, 00000006.00000002.2304489262.00000000010B4000.00000002.00000001.01000000.00000011.sdmp, Launcher.exe, 00000006.00000000.2222831243.00000000010B4000.00000002.00000001.01000000.00000011.sdmp
Source: Binary string: C:\dev\sqlite\dotnet\bin\2010\Win32\ReleaseNativeOnly\SQLite.Interop.pdb source: AirDroidCast.exe, 00000009.00000002.6336760625.00000000661F4000.00000002.00000001.01000000.0000002A.sdmp
Source: Binary string: c:\borrar\EmptyDll\Release\EmptyDll.pdb source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp
Source: Binary string: Helper.pdb source: Helper.exe, 00000004.00000000.2127526906.00000000000C2000.00000002.00000001.01000000.0000000E.sdmp
Source: Binary string: c:\dev\sqlite\dotnet\obj\2010\System.Data.SQLite.2010\Release\System.Data.SQLite.pdb source: AirDroidCast.exe, 00000009.00000002.6242501724.000000000E8A2000.00000002.00000001.01000000.00000027.sdmp
Source: Binary string: F:\SourceCode\QRCoder\QRCoder\obj\Release\QRCoder.pdb@ source: AirDroidCast.exe, 00000009.00000002.6309499575.0000000012A12000.00000002.00000001.01000000.00000030.sdmp
Source: Binary string: msvcr100.i386.pdb source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003045000.00000004.00000020.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6328410303.0000000066061000.00000020.00000001.01000000.0000002B.sdmp
Source: Binary string: vcruntime140.i386.pdb source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: vcruntime140.i386.pdbGCTL source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: D:\Project\SVN_Code\usbmuxd-vs\Release\libimdusb.pdb source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: vccorlib140.i386.pdb source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: msvcp140.i386.pdbGCTL source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003045000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: msvcr120.i386.pdb source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000031E2000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\dev\sqlite\dotnet\bin\2010\Win32\ReleaseNativeOnly\SQLite.Interop.pdb) source: AirDroidCast.exe, 00000009.00000002.6336760625.00000000661F4000.00000002.00000001.01000000.0000002A.sdmp
Source: Binary string: msvcp120.i386.pdb source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003045000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: vccorlib140.i386.pdbGCTL source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: e:\NLog\build\obj\Debug\.NET Framework 2.0\NLog.pdb source: AirDroidCast.exe, 00000009.00000002.6218378783.000000000BF02000.00000002.00000001.01000000.0000001B.sdmp
Source: Binary string: msvcp140.i386.pdb source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003045000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ucrtbase.pdbUGP source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: E:\Win-2623\download\chromium\src\out\Release\libcef.dll.pdb source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: vccorlib120.i386.pdb source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: E:\GitCode\tb-scrcyp\win\scrcpy-1.17lib\Win32\Debug\libscrcpy.pdb66 source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003045000.00000004.00000020.00020000.00000000.sdmp

Networking

barindex
Source: Yara match File source: C:\Program Files (x86)\AirDroid Cast\Android.dll, type: DROPPED
Source: unknown Network traffic detected: DNS query count 35
Source: global traffic TCP traffic: 192.168.2.4:49959 -> 49.51.230.107:9088
Source: global traffic TCP traffic: 192.168.2.4:50026 -> 1.1.1.1:53
Source: global traffic HTTP traffic detected: GET /p20/config/get?q=060171db4cdf21247c1106dd350462c553d869f2f6aa952e711efe06dd1efbc309196f07d75123bdd2e805ab9881a0a65983f146469c00e8959989774fcce1fc49df2dd68644032a677dbae13b26f87958db153d6b84bde73c4054cecc59167e374011feba57c5abf996e738f2328cdf9efe9dc6debee02e8ae353a220430037&_t=4b01aa57d89c4930828cc218434270fe&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: srv3.airdroid.com
Source: global traffic HTTP traffic detected: GET /p20/config/get?q=060171db4cdf2124a748bf3099787f00ca8f311896c8501e99528cb63c8ed93d3c6e1f1786ab03871ec49c1d73049355af6b05b48c94538ed401a7824a1c1dd733092cfabc7c86949eab0fad91133ac1efd5a78a27bf69ec09e4cdad9e556bc4640745088d2470adbb9050b532896bdce5a58fe5471c8641&_t=1bfd2a911da54bd2b90dc561d3cd5196&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: srv3.airdroid.com
Source: global traffic HTTP traffic detected: GET /?id=-999&st=gopush&side=pub&key=p-713--999&_t=ccb849caa0ba4cde8786dcfe4a60420e&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: lb.airdroid.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /p20/config/get?q=060171db4cdf2124790835ed4a14a722fb0a1ea01fb5d10db87f753d016ca5c7154675f8eb96f45f5e9e7e63137d451c38f3f0c7b4487c8f9b5659506404791cf4ae381e8652a49921f678278545d440&_t=a3b9b14e6e95428288f28e4cba19e9fc&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: srv3.airdroid.com
Source: global traffic HTTP traffic detected: GET /p20/pc/getconfig?_t=a9de59c2c8bd41c9a88e34ed59bca69d&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: srv3.airdroid.com
Source: global traffic HTTP traffic detected: GET /pushtodevicebyaccountid?appType=airdroid&accountId=-999&deviceType=phone&msg=%7b%22pid%22%3a%22734743740%22%2c%22uri%22%3a%22%5c%2fcfunc%5c%2fserver_info_response%5c%2f%22%2c%22result%22%3a%7b%22sname%22%3a%22066656%22%2c%22ip%22%3a%22192.168.2.4%22%2c%22fport%22%3a%2230001%22%2c%22channel_id%22%3a%22-999%22%7d%7d&expire=0&token=c3aadea79a48d66055f0a36f08994148&session=&_t=3a388f0f311a4ae2b177b192821786b1&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: push.airdroid.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /user/cantrial?q=7b81265dfb489e1ee9cd6e0341638d121e94fa51e9fde186b92c31e1ed68b1ec421a2be27e5a6cd3c5c0948d7fec53ce55af4ae424f65be44785e5110107fb7a&_t=7e2d5e07b5454a34be380176919b1e74&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: id-cast.airdroid.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /channel/save?key=p-713-&deviceType=PC&appType=airdroid&accountId=-999&appChannel=airdroid&token=0&session=&_t=70172575129846468ef6a2fb86fac030&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: push.airdroid.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /p20/DeviceAll/UpdateNetInfo?device_id=0aebe46aed374d01b57a5a418751ed64&mac=ECF4BBEA1588&local_ip=192.168.2.4&local_port=30001&session=&_t=edfe90c0fb2b4adba7cb5e7d79ae6273&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: srv3.airdroid.com
Source: global traffic HTTP traffic detected: GET /p20/pc/getcustomurl?country=&lang=en&is_vip=0&is_unlock=0&app_channel=0&user_type=personal&_t=8c827a979e1145f8a009a7e50fe69b92&app_ver=1.2.1.0&device_type=63&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: srv3.airdroid.com
Source: global traffic HTTP traffic detected: GET /sharecode/new/?q=b232ab4d8990730a5a18ac5e893e1c30ed666a6dabd904613d5043c1e43f807ab746797dc38e48bed2c6fb62c2597f18d2e805ab9881a0a6dfa54a844bac2d08e62b9b55b223cb128604f02b123554032ab6807638a3c77bbb9050b532896bdc05365709f880b8717fad0b77eea46025cb94582e5c39c7290175877a18f509fb24243c7b1c9a677dfe7e1666613a25a38672a7a66f9da128b6ac3da381a288df3a009444a9e20a520996ca55c27d36652e0a8c9ab2b34f316850eeef2d75e0a8afdff23b49f79128421a2be27e5a6cd3c5c0948d7fec53ced2e805ab9881a0a67d40ceea6d9d0d8b4e786dee9570650842c21cc6b4790dff&_t=8d469ef68b2d4cd5a754687b51c15374&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: id-cast.airdroid.com
Source: global traffic HTTP traffic detected: GET /channel/save?key=p-713-&deviceType=PC&appType=airdroid&accountId=-999&appChannel=airdroid&token=0&session=&_t=bb8de68b59634c85a7d19d7cdd7ce770&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: push.airdroid.com
Source: global traffic HTTP traffic detected: GET /p20/crossrecommend/getcrossrecommend?q=7b81265dfb489e1ee65fdc5bcd9589e7ddbed44605e23cf5b82aa069433fee17d2e805ab9881a0a6dfa54a844bac2d08e62b9b55b223cb128604f02b123554035480db629fbed72d354b04dfeef93d05481e8599b83a9041d7ebc9a573e03f0b44e9a6313eaac0dab8641e71b13c9e0400bb212cd4b7191d89cf20646cf12fd7f521f10f1dc970e8fb6dfa1a649f41a62ec62cfa1731602f4dab9ba34912bc52cb3f30f06e02f1d3&_t=6b0cdea836ec40c5aedce8e0f5da570d&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: srv3.airdroid.com
Source: global traffic HTTP traffic detected: GET /p20/crossrecommend/getcrossrecommend?q=7b81265dfb489e1ee65fdc5bcd9589e7ddbed44605e23cf5b82aa069433fee17d2e805ab9881a0a6dfa54a844bac2d08e62b9b55b223cb128604f02b123554035480db629fbed72d354b04dfeef93d05481e8599b83a9041d7ebc9a573e03f0b44e9a6313eaac0dab8641e71b13c9e0400bb212cd4b7191d89cf20646cf12fd7f521f10f1dc970e8fb6dfa1a649f41a62ec62cfa1731602f4dab9ba34912bc52cb3f30f06e02f1d3&_t=9033b1b788ed4d07bb80582a0fdc589d&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: srv3.airdroid.com
Source: global traffic HTTP traffic detected: GET /channel/save?key=p-713-&deviceType=PC&appType=airdroid&accountId=-999&appChannel=airdroid&token=0&session=&_t=8efb6c156acc495ea9ffe05072ab8145&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: push.airdroid.com
Source: global traffic HTTP traffic detected: GET /p20/config/get?q=060171db4cdf21247c1106dd350462c553d869f2f6aa952e711efe06dd1efbc309196f07d75123bdd2e805ab9881a0a65983f146469c00e8959989774fcce1fc49df2dd68644032a677dbae13b26f87958db153d6b84bde73c4054cecc59167e374011feba57c5abf996e738f2328cdf9efe9dc6debee02e8ae353a220430037&_t=ce466132074f43d2a38f4cb1416e1215&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: srv3.airdroid.com
Source: global traffic HTTP traffic detected: POST /cast/startup/?unique_id=ECF4BBEA1588&account_id=-999&device_id=&wan_ip=&local_ip=192.168.2.4&os=windows&os_version=64%20bit%7CWindows%2010%20Enterprise&app_version=1.2.1.0&network=&wifi_ssid=&type=1&device_type=63&channel=0&startup_time=2024-10-07%2009:57:18&using_duration=10&end_time=2024-10-07%2009:57:28&mac=ECF4BBEA1588&app_ver=1.2.1.0&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2 HTTP/1.1Content-Type: text/htmlHost: stat3.airdroid.comContent-Length: 386Expect: 100-continueConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /p20/config/get?q=060171db4cdf2124f2510574a425110d991082c5820bc755711efe06dd1efbc309196f07d75123bdd2e805ab9881a0a65983f146469c00e8959989774fcce1fc49df2dd68644032a677dbae13b26f87958db153d6b84bde73c4054cecc59167e374011feba57c5abf996e738f2328cdf9efe9dc6debee02e8ae353a220430037&_t=44493533a46342ccbd047c74dcec1350&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: srv3.airdroid.com
Source: global traffic HTTP traffic detected: GET /channel/save?key=p-713-&deviceType=PC&appType=airdroid&accountId=-999&appChannel=airdroid&token=0&session=&_t=98d109053230477d9221c316731e070d&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: push.airdroid.com
Source: global traffic HTTP traffic detected: GET /p20/crossrecommend/getcrossrecommend?q=7b81265dfb489e1ee65fdc5bcd9589e7ddbed44605e23cf5b82aa069433fee17d2e805ab9881a0a6dfa54a844bac2d08e62b9b55b223cb128604f02b123554035480db629fbed72d354b04dfeef93d05481e8599b83a9041d7ebc9a573e03f0b44e9a6313eaac0dab8641e71b13c9e0400bb212cd4b7191d89cf20646cf12fd7f521f10f1dc970e8fb6dfa1a649f41a62ec62cfa1731602f4dab9ba34912bc52cb3f30f06e02f1d3&_t=0851dce681624a1295e68ebb91a6148c&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: srv3.airdroid.com
Source: global traffic HTTP traffic detected: GET /p20/crossrecommend/getcrossrecommend?q=7b81265dfb489e1ee65fdc5bcd9589e7ddbed44605e23cf5b82aa069433fee17d2e805ab9881a0a6dfa54a844bac2d08e62b9b55b223cb128604f02b123554035480db629fbed72d354b04dfeef93d05481e8599b83a9041d7ebc9a573e03f0b44e9a6313eaac0dab8641e71b13c9e0400bb212cd4b7191d89cf20646cf12fd7f521f10f1dc970e8fb6dfa1a649f41a62ec62cfa1731602f4dab9ba34912bc52cb3f30f06e02f1d3&_t=7c9ffe77ca66447fa59db466fc0b27e0&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: srv3.airdroid.com
Source: global traffic HTTP traffic detected: GET /p20/pc/upgradewebpackage?inner_version=1210&v=1.2.1.0&type=63&_t=41d71d0921b2479cbcf0865adb45a9ef&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: srv3.airdroid.com
Source: global traffic HTTP traffic detected: POST /OneCollector/1.0/ HTTP/1.1Accept: */*APIKey: cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521AuthMsaDeviceTicket: t=GwAWAbuEBAAU2qcZHJoKGNizGOeyqM4OaIoSZ0MOZgAAEJanOM/f8BEauEo6GRqguxLgAJt0LBh1uWaBD08sPTthnLouxyOeqq8UXC40zxYtXUeuLL3jc98oc4sgTt8Qg5RgpVyPUGOqQCdIMU+jHj5jPNgpCOYLzgjk7/68jQbYqRpL5buJGDaKHJUU4Qzi5sjC1iwUwrkBZLfklCNSWdGai+iykzR0ELnFD4lJb88vZch+TXuihcRzjbZvJG6mFONQPa3ignNQpsSbQgkMM4xuASI/kaIM+YTU5dBQE1SH8k0CwZj5Yc3H1S94NyGSn+DeuALqccEE8gt3uchW9hnkYs9tmlAQt7GBc9BBk/kSpz+oHgE=&p=Client-Id: NO_AUTHContent-Encoding: deflateContent-Type: application/bond-compact-binaryExpect: 100-continueSDK-Version: EVT-Windows-C++-No-3.4.15.1Upload-Time: 1728295295819Host: self.events.data.microsoft.comContent-Length: 7973Connection: Keep-AliveCache-Control: no-cache
Source: Joe Sandbox View IP Address: 104.18.137.17 104.18.137.17
Source: Joe Sandbox View IP Address: 104.16.118.116 104.16.118.116
Source: Joe Sandbox View IP Address: 104.16.78.142 104.16.78.142
Source: Joe Sandbox View JA3 fingerprint: 28a2c9bd18a11de089ef85a160da29e4
Source: Joe Sandbox View JA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e
Source: Joe Sandbox View JA3 fingerprint: a0e9f5d64349fb13191bc781f81f42e1
Source: Joe Sandbox View JA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
Source: Network traffic Suricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49826 -> 49.51.42.41:443
Source: Network traffic Suricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49827 -> 49.51.42.41:443
Source: Network traffic Suricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49859 -> 49.51.42.41:443
Source: Network traffic Suricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49860 -> 49.51.42.41:443
Source: Network traffic Suricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49890 -> 49.51.42.41:443
Source: Network traffic Suricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49936 -> 170.106.112.204:443
Source: Network traffic Suricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49891 -> 49.51.42.41:443
Source: Network traffic Suricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49916 -> 49.51.181.65:443
Source: Network traffic Suricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:50005 -> 49.51.42.41:443
Source: Network traffic Suricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:50007 -> 170.106.112.204:443
Source: Network traffic Suricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:50009 -> 49.51.42.41:443
Source: Network traffic Suricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49957 -> 49.51.42.41:443
Source: Network traffic Suricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:50022 -> 49.51.42.41:443
Source: Network traffic Suricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:50047 -> 170.106.112.204:443
Source: Network traffic Suricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:50066 -> 49.51.42.41:443
Source: Network traffic Suricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:50100 -> 49.51.42.41:443
Source: Network traffic Suricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:50101 -> 49.51.42.41:443
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknown TCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknown TCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknown TCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknown TCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknown TCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknown TCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknown TCP traffic detected without corresponding DNS query: 93.184.221.240
Source: unknown TCP traffic detected without corresponding DNS query: 93.184.221.240
Source: unknown TCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknown TCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknown TCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknown TCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknown TCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknown TCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknown TCP traffic detected without corresponding DNS query: 172.202.163.200
Source: unknown TCP traffic detected without corresponding DNS query: 104.18.38.233
Source: unknown TCP traffic detected without corresponding DNS query: 172.64.149.23
Source: unknown TCP traffic detected without corresponding DNS query: 172.64.149.23
Source: unknown TCP traffic detected without corresponding DNS query: 104.18.38.233
Source: unknown TCP traffic detected without corresponding DNS query: 104.18.38.233
Source: unknown TCP traffic detected without corresponding DNS query: 172.64.149.23
Source: unknown TCP traffic detected without corresponding DNS query: 172.64.149.23
Source: unknown TCP traffic detected without corresponding DNS query: 104.18.38.233
Source: unknown TCP traffic detected without corresponding DNS query: 13.107.246.60
Source: unknown TCP traffic detected without corresponding DNS query: 13.107.246.60
Source: unknown TCP traffic detected without corresponding DNS query: 13.107.246.60
Source: unknown TCP traffic detected without corresponding DNS query: 13.107.246.60
Source: unknown TCP traffic detected without corresponding DNS query: 13.107.246.60
Source: unknown TCP traffic detected without corresponding DNS query: 13.107.246.60
Source: unknown TCP traffic detected without corresponding DNS query: 13.107.246.60
Source: unknown TCP traffic detected without corresponding DNS query: 13.107.246.60
Source: unknown TCP traffic detected without corresponding DNS query: 13.107.246.60
Source: unknown TCP traffic detected without corresponding DNS query: 13.107.246.60
Source: unknown TCP traffic detected without corresponding DNS query: 13.107.246.60
Source: unknown TCP traffic detected without corresponding DNS query: 13.107.246.60
Source: unknown TCP traffic detected without corresponding DNS query: 13.107.246.60
Source: unknown TCP traffic detected without corresponding DNS query: 13.107.246.60
Source: unknown TCP traffic detected without corresponding DNS query: 13.107.246.60
Source: unknown TCP traffic detected without corresponding DNS query: 13.107.246.60
Source: unknown TCP traffic detected without corresponding DNS query: 13.107.246.60
Source: unknown TCP traffic detected without corresponding DNS query: 13.107.246.60
Source: unknown TCP traffic detected without corresponding DNS query: 13.107.246.60
Source: unknown TCP traffic detected without corresponding DNS query: 13.107.246.60
Source: unknown TCP traffic detected without corresponding DNS query: 13.107.246.60
Source: unknown TCP traffic detected without corresponding DNS query: 13.107.246.60
Source: unknown TCP traffic detected without corresponding DNS query: 13.107.246.60
Source: unknown TCP traffic detected without corresponding DNS query: 13.107.246.60
Source: unknown TCP traffic detected without corresponding DNS query: 13.107.246.60
Source: global traffic HTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=DRyKK4Eby6agGce&MD=km2sG7cX HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global traffic HTTP traffic detected: GET /pc/installstat?mac=ECF4BBEA1588&os_ver=10%2E0&os_lang=2057&ui_lang=1033&air_ver=1.2.1.0&os=windows&step=1 HTTP/1.1User-Agent: NSIS InetBgDL (Mozilla)Host: stat3.airdroid.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /pc/installstat?mac=ECF4BBEA1588&os_ver=10%2E0&os_lang=2057&ui_lang=1033&air_ver=1.2.1.0&os=windows&step=2 HTTP/1.1User-Agent: NSIS InetBgDL (Mozilla)Host: stat3.airdroid.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /rules/other-Win32-v19.bundle HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120402v21s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120608v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule224902v2s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120600v4s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120609v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120612v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120614v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120610v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120613v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120611v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /thankyou/install-airdroid-cast.html HTTP/1.1Host: www.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /rules/rule120617v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120619v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120616v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120615v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120618v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /assets/css/main-b0d5f56ad2.min.css HTTP/1.1Host: css-1-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /assets/css/nav-1965d8efa6.min.css HTTP/1.1Host: css-1-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /assets/css/swiper-d339c965d0.min.css HTTP/1.1Host: css-1-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /assets/css/thankCast-e792eba9a8.min.css HTTP/1.1Host: css-1-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /assets/js/framework-d621d0521a.min.js HTTP/1.1Host: js-1-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /rules/rule120620v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120624v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120623v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120621v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120622v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Close
Source: global traffic HTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=DRyKK4Eby6agGce&MD=km2sG7cX HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global traffic HTTP traffic detected: GET /assets/img/header/new-16d9649831.gif HTTP/1.1Host: cdn1.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://css-1-cdn.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/header/pic_business-17c59424d8.png HTTP/1.1Host: cdn1.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://css-1-cdn.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/sprite_1x_default-5d3c37748f.png HTTP/1.1Host: cdn1.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://css-1-cdn.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/ic_successful@2x-eee87c7ece.png HTTP/1.1Host: img-4-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/airplay_step02-966986a14c.gif HTTP/1.1Host: img-4-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/logo/logo_bz-white@2x-5cb5211350.png HTTP/1.1Host: cdn1.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /assets/img/sprite_2x_default-f15882b89f.png HTTP/1.1Host: cdn1.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://css-1-cdn.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/logo/logo_green@2x-1cc91453e3.png HTTP/1.1Host: cdn1.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_wlan_step02@2x-8beb560a2d.png HTTP/1.1Host: img-1-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_wlan_step03@2x-458292f9b6.png HTTP/1.1Host: img-2-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_airplay_step01@2x-9b7b40ced3.png HTTP/1.1Host: img-3-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/userCenter/newUserCenter/loading-5f964989ce.gif HTTP/1.1Host: img-5-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://css-1-cdn.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_wlan_step01@2x-b8b0f2660e.png HTTP/1.1Host: img-5-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/js/framework-d621d0521a.min.js HTTP/1.1Host: js-1-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /rules/rule120625v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120627v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120626v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120628v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120629v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120631v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120630v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120632v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120633v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /assets/img/logo/logo_blue@2x-ab392758f7.png HTTP/1.1Host: cdn1.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/header/user_default_photo-fe4db896c6.jpg HTTP/1.1Host: cdn1.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_airplay_step03@2x-35eac09b1f.png HTTP/1.1Host: img-5-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/logo/logo_cast_green@2x-9039eedc04.png HTTP/1.1Host: cdn1.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_cable_step01@2x-b0172193b9.png HTTP/1.1Host: img-1-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/sprite_1x_default-5d3c37748f.png HTTP/1.1Host: cdn1.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/logo/logo_bz-white@2x-5cb5211350.png HTTP/1.1Host: cdn1.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/header/new-16d9649831.gif HTTP/1.1Host: cdn1.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/sprite_2x_default-f15882b89f.png HTTP/1.1Host: cdn1.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/logo/logo_green@2x-1cc91453e3.png HTTP/1.1Host: cdn1.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/header/pic_business-17c59424d8.png HTTP/1.1Host: cdn1.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_cable_step02@2x-fd247908d3.png HTTP/1.1Host: img-2-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/ic_successful@2x-eee87c7ece.png HTTP/1.1Host: img-4-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_cable_step03@2x-8a5fe510b4.png HTTP/1.1Host: img-3-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_comment_logo_mud@2x-354bc693b3.png HTTP/1.1Host: img-3-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /rules/rule120634v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_starrating_2@2x-9e788c186a.png HTTP/1.1Host: img-4-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /rules/rule120635v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120637v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /p20/config/get?q=060171db4cdf21247c1106dd350462c553d869f2f6aa952e711efe06dd1efbc309196f07d75123bdd2e805ab9881a0a65983f146469c00e8959989774fcce1fc49df2dd68644032a677dbae13b26f87958db153d6b84bde73c4054cecc59167e374011feba57c5abf996e738f2328cdf9efe9dc6debee02e8ae353a220430037&_t=4b01aa57d89c4930828cc218434270fe&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: srv3.airdroid.com
Source: global traffic HTTP traffic detected: GET /p20/config/get?q=060171db4cdf2124a748bf3099787f00ca8f311896c8501e99528cb63c8ed93d3c6e1f1786ab03871ec49c1d73049355af6b05b48c94538ed401a7824a1c1dd733092cfabc7c86949eab0fad91133ac1efd5a78a27bf69ec09e4cdad9e556bc4640745088d2470adbb9050b532896bdce5a58fe5471c8641&_t=1bfd2a911da54bd2b90dc561d3cd5196&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: srv3.airdroid.com
Source: global traffic HTTP traffic detected: GET /rules/rule120636v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /?id=-999&st=gopush&side=pub&key=p-713--999&_t=ccb849caa0ba4cde8786dcfe4a60420e&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: lb.airdroid.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /rules/rule120638v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120639v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_comment_logo_product_hunt@2x-dc0f9577b6.png HTTP/1.1Host: img-1-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/ic_symbol-c7d5cf270a.png HTTP/1.1Host: img-5-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_comment_logo_softpedia@2x-57561c6da1.png HTTP/1.1Host: img-2-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_logo_cnet@2x-2dfebc57ee.png HTTP/1.1Host: img-1-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_logo_cult@2x-4e47193fb6.png HTTP/1.1Host: img-2-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_logo_ber@2x-619e6468d4.png HTTP/1.1Host: img-1-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_logo_softpedia@2x-4b68bae15d.png HTTP/1.1Host: img-3-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /rules/rule120640v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120641v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_wlan_step02@2x-8beb560a2d.png HTTP/1.1Host: img-1-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /rules/rule120642v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /assets/img/header/user_default_photo-fe4db896c6.jpg HTTP/1.1Host: cdn1.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /p20/config/get?q=060171db4cdf2124790835ed4a14a722fb0a1ea01fb5d10db87f753d016ca5c7154675f8eb96f45f5e9e7e63137d451c38f3f0c7b4487c8f9b5659506404791cf4ae381e8652a49921f678278545d440&_t=a3b9b14e6e95428288f28e4cba19e9fc&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: srv3.airdroid.com
Source: global traffic HTTP traffic detected: GET /assets/img/logo/logo_blue@2x-ab392758f7.png HTTP/1.1Host: cdn1.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/logo/logo_cast_green@2x-9039eedc04.png HTTP/1.1Host: cdn1.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/userCenter/newUserCenter/loading-5f964989ce.gif HTTP/1.1Host: img-5-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_wlan_step01@2x-b8b0f2660e.png HTTP/1.1Host: img-5-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/airplay_step02-966986a14c.gif HTTP/1.1Host: img-4-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_airplay_step03@2x-35eac09b1f.png HTTP/1.1Host: img-5-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_airplay_step01@2x-9b7b40ced3.png HTTP/1.1Host: img-3-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /p20/pc/getconfig?_t=a9de59c2c8bd41c9a88e34ed59bca69d&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: srv3.airdroid.com
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_cable_step01@2x-b0172193b9.png HTTP/1.1Host: img-1-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_cable_step03@2x-8a5fe510b4.png HTTP/1.1Host: img-3-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_comment_logo_mud@2x-354bc693b3.png HTTP/1.1Host: img-3-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_wlan_step03@2x-458292f9b6.png HTTP/1.1Host: img-2-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_cable_step02@2x-fd247908d3.png HTTP/1.1Host: img-2-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_logo_techtimes@2x-709466896c.png HTTP/1.1Host: img-5-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /rules/rule120644v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120643v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /pushtodevicebyaccountid?appType=airdroid&accountId=-999&deviceType=phone&msg=%7b%22pid%22%3a%22734743740%22%2c%22uri%22%3a%22%5c%2fcfunc%5c%2fserver_info_response%5c%2f%22%2c%22result%22%3a%7b%22sname%22%3a%22066656%22%2c%22ip%22%3a%22192.168.2.4%22%2c%22fport%22%3a%2230001%22%2c%22channel_id%22%3a%22-999%22%7d%7d&expire=0&token=c3aadea79a48d66055f0a36f08994148&session=&_t=3a388f0f311a4ae2b177b192821786b1&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: push.airdroid.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_logo_pcworld@2x-9e15f7927c.png HTTP/1.1Host: img-1-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /rules/rule120646v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120645v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120647v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/ic_users@2x-04270d54ad.png HTTP/1.1Host: img-2-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_logo_mud@2x-6a33c4e4e1.png HTTP/1.1Host: img-4-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_starrating_2@2x-9e788c186a.png HTTP/1.1Host: img-4-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_comment_logo_softpedia@2x-57561c6da1.png HTTP/1.1Host: img-2-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_comment_logo_product_hunt@2x-dc0f9577b6.png HTTP/1.1Host: img-1-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /user/cantrial?q=7b81265dfb489e1ee9cd6e0341638d121e94fa51e9fde186b92c31e1ed68b1ec421a2be27e5a6cd3c5c0948d7fec53ce55af4ae424f65be44785e5110107fb7a&_t=7e2d5e07b5454a34be380176919b1e74&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: id-cast.airdroid.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/ic_symbol-c7d5cf270a.png HTTP/1.1Host: img-5-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_logo_softpedia@2x-4b68bae15d.png HTTP/1.1Host: img-3-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/ic_lifetime@2x-191b1ae413.png HTTP/1.1Host: img-5-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/ic_pay@2x-c386c8df8d.png HTTP/1.1Host: img-3-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_logo_ber@2x-619e6468d4.png HTTP/1.1Host: img-1-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/ic_free@2x-64d0975140.png HTTP/1.1Host: img-4-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_logo_cult@2x-4e47193fb6.png HTTP/1.1Host: img-2-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /channel/save?key=p-713-&deviceType=PC&appType=airdroid&accountId=-999&appChannel=airdroid&token=0&session=&_t=70172575129846468ef6a2fb86fac030&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: push.airdroid.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /assets/lang/en-32fa979c00.js HTTP/1.1Host: js-1-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /rules/rule120648v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120649v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /p20/DeviceAll/UpdateNetInfo?device_id=0aebe46aed374d01b57a5a418751ed64&mac=ECF4BBEA1588&local_ip=192.168.2.4&local_port=30001&session=&_t=edfe90c0fb2b4adba7cb5e7d79ae6273&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: srv3.airdroid.com
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_logo_cnet@2x-2dfebc57ee.png HTTP/1.1Host: img-1-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/js/common-5a36f9767a.min.js HTTP/1.1Host: js-1-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /p20/pc/getcustomurl?country=&lang=en&is_vip=0&is_unlock=0&app_channel=0&user_type=personal&_t=8c827a979e1145f8a009a7e50fe69b92&app_ver=1.2.1.0&device_type=63&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: srv3.airdroid.com
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_logo_techtimes@2x-709466896c.png HTTP/1.1Host: img-5-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /rules/rule120650v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120651v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120652v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120653v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120654v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /assets/js/en-public-f125bb5bb4.min.js HTTP/1.1Host: js-1-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/js/server-b0866ccd7b.min.js HTTP/1.1Host: js-1-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/js/base-a2d6eba316.min.js HTTP/1.1Host: js-1-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/js/baseCommonActivity-314926f4e0.min.js HTTP/1.1Host: js-1-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /6324853.js HTTP/1.1Host: js.hs-scripts.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /rules/rule120655v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120656v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /assets/js/activityCommonEntry-a46e980aad.min.js HTTP/1.1Host: js-1-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/js/en-cast-second-nav-caa33cae56.min.js HTTP/1.1Host: js-1-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /rules/rule120657v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120658v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120659v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global traffic HTTP traffic detected: GET /sharecode/new/?q=b232ab4d8990730a5a18ac5e893e1c30ed666a6dabd904613d5043c1e43f807ab746797dc38e48bed2c6fb62c2597f18d2e805ab9881a0a6dfa54a844bac2d08e62b9b55b223cb128604f02b123554032ab6807638a3c77bbb9050b532896bdc05365709f880b8717fad0b77eea46025cb94582e5c39c7290175877a18f509fb24243c7b1c9a677dfe7e1666613a25a38672a7a66f9da128b6ac3da381a288df3a009444a9e20a520996ca55c27d36652e0a8c9ab2b34f316850eeef2d75e0a8afdff23b49f79128421a2be27e5a6cd3c5c0948d7fec53ced2e805ab9881a0a67d40ceea6d9d0d8b4e786dee9570650842c21cc6b4790dff&_t=8d469ef68b2d4cd5a754687b51c15374&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: id-cast.airdroid.com
Source: global traffic HTTP traffic detected: GET /assets/js/tabPanel-285508b3c2.min.js HTTP/1.1Host: js-1-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /rules/rule120660v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /6324853.js HTTP/1.1Host: js.hs-scripts.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /assets/js/swiper-ade426db9c.min.js HTTP/1.1Host: js-1-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /rules/rule120661v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /assets/js/thankCast-e8d4d72858.min.js HTTP/1.1Host: js-1-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /rules/rule120662v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /channel/save?key=p-713-&deviceType=PC&appType=airdroid&accountId=-999&appChannel=airdroid&token=0&session=&_t=bb8de68b59634c85a7d19d7cdd7ce770&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: push.airdroid.com
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_logo_mud@2x-6a33c4e4e1.png HTTP/1.1Host: img-4-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/ic_users@2x-04270d54ad.png HTTP/1.1Host: img-2-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /rules/rule120663v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/ic_free@2x-64d0975140.png HTTP/1.1Host: img-4-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/lang/en-32fa979c00.js HTTP/1.1Host: js-1-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/ic_pay@2x-c386c8df8d.png HTTP/1.1Host: img-3-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/js/baseCommonActivity-314926f4e0.min.js HTTP/1.1Host: js-1-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/js/base-a2d6eba316.min.js HTTP/1.1Host: js-1-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/ic_lifetime@2x-191b1ae413.png HTTP/1.1Host: img-5-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/js/server-b0866ccd7b.min.js HTTP/1.1Host: js-1-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/thankyou/pic_logo_pcworld@2x-9e15f7927c.png HTTP/1.1Host: img-1-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/js/en-public-f125bb5bb4.min.js HTTP/1.1Host: js-1-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/js/en-cast-second-nav-caa33cae56.min.js HTTP/1.1Host: js-1-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /rules/rule120664v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120665v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120666v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /assets/img/G2/pic_badge_5-306a40f197.png HTTP/1.1Host: cdn1.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/G2/pic_badge_3-2d1abc3d6b.png HTTP/1.1Host: cdn1.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/G2/pic_badge_1-de0b639b36.png HTTP/1.1Host: cdn1.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/G2/pic_badge_4-af281ab904.png HTTP/1.1Host: cdn1.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/G2/pic_badge_2-0d797e7a53.png HTTP/1.1Host: cdn1.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /rules/rule120667v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120669v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120668v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /p20/crossrecommend/getcrossrecommend?q=7b81265dfb489e1ee65fdc5bcd9589e7ddbed44605e23cf5b82aa069433fee17d2e805ab9881a0a6dfa54a844bac2d08e62b9b55b223cb128604f02b123554035480db629fbed72d354b04dfeef93d05481e8599b83a9041d7ebc9a573e03f0b44e9a6313eaac0dab8641e71b13c9e0400bb212cd4b7191d89cf20646cf12fd7f521f10f1dc970e8fb6dfa1a649f41a62ec62cfa1731602f4dab9ba34912bc52cb3f30f06e02f1d3&_t=6b0cdea836ec40c5aedce8e0f5da570d&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: srv3.airdroid.com
Source: global traffic HTTP traffic detected: GET /assets/js/tabPanel-285508b3c2.min.js HTTP/1.1Host: js-1-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/js/activityCommonEntry-a46e980aad.min.js HTTP/1.1Host: js-1-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/js/thankCast-e8d4d72858.min.js HTTP/1.1Host: js-1-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /rules/rule120670v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /web-interactives-embed.js HTTP/1.1Host: js.hubspot.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://www.airdroid.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /analytics/1728294900000/6324853.js HTTP/1.1Host: js.hs-analytics.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /v2/6324853/banner.js HTTP/1.1Host: js.hs-banner.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /leadflows.js HTTP/1.1Host: js.hsleadflows.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://www.airdroid.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /fb.js HTTP/1.1Host: js.hsadspixel.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /conversations-embed.js HTTP/1.1Host: js.usemessages.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /rules/rule120671v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120672v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120674v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120673v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Close
Source: global traffic HTTP traffic detected: GET /rules/rule120675v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /assets/js/swiper-ade426db9c.min.js HTTP/1.1Host: js-1-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/G2/pic_badge_2-0d797e7a53.png HTTP/1.1Host: cdn1.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/G2/pic_badge_4-af281ab904.png HTTP/1.1Host: cdn1.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/G2/pic_badge_3-2d1abc3d6b.png HTTP/1.1Host: cdn1.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/G2/pic_badge_5-306a40f197.png HTTP/1.1Host: cdn1.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /assets/img/G2/pic_badge_1-de0b639b36.png HTTP/1.1Host: cdn1.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en
Source: global traffic HTTP traffic detected: GET /p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /fb.js HTTP/1.1Host: js.hsadspixel.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /web-interactives/public/v1/embed/combinedConfigs?portalId=6324853&currentUrl=https%3A%2F%2Fwww.airdroid.com%2Fthankyou%2Finstall-airdroid-cast.html HTTP/1.1Host: cta-service-cms2.hubspot.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Origin: https://www.airdroid.comSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /conversations-embed.js HTTP/1.1Host: js.usemessages.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /v2/6324853/banner.js HTTP/1.1Host: js.hs-banner.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /analytics/1728294900000/6324853.js HTTP/1.1Host: js.hs-analytics.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /hs-script-loader-public/v1/config/pixels-and-events/json?portalId=6324853 HTTP/1.1Host: api.hubapi.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Origin: https://www.airdroid.comSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /web-interactives-embed.js HTTP/1.1Host: js.hubspot.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /rules/rule120678v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120676v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120677v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120679v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120680v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /leadflows.js HTTP/1.1Host: js.hsleadflows.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /lead-flows-config/v1/config/json?portalId=6324853&utk=6aa7734ded5ca49f9a0d86e49629bf43&__hstc=197314800.6aa7734ded5ca49f9a0d86e49629bf43.1728295046858.1728295046858.1728295046858.1&__hssc=197314800.1.1728295046859&currentUrl=https%3A%2F%2Fwww.airdroid.com%2Fthankyou%2Finstall-airdroid-cast.html HTTP/1.1Host: forms.hubspot.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Origin: https://www.airdroid.comSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /web-interactives/public/v1/embed/combinedConfigs?portalId=6324853&currentUrl=https%3A%2F%2Fwww.airdroid.com%2Fthankyou%2Finstall-airdroid-cast.html HTTP/1.1Host: cta-service-cms2.hubspot.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: __cf_bm=OBTw7uaaFeyPF1EDdc1GuG5wO6ZET2Y.O1bq8ydB40Q-1728295047-1.0.1.1-sGyyzXh1wlqmsGS94Z45rubz5D9UVID0iXJt2QpUDY8G3prwteMqZ2U3M4z_cxePLlK_mtfn3_6f9WKtEhR.2w; _cfuvid=Ddd1lMzH.IvzvPlxRmsxoRA0A2g5tgppQNB2y5kPM0A-1728295047650-0.0.1.1-604800000
Source: global traffic HTTP traffic detected: GET /assets/img/favicon-cast-973b301f96.ico HTTP/1.1Host: img-2-cdn.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en; __hstc=197314800.6aa7734ded5ca49f9a0d86e49629bf43.1728295046858.1728295046858.1728295046858.1; hubspotutk=6aa7734ded5ca49f9a0d86e49629bf43; __hssrc=1; __hssc=197314800.1.1728295046859
Source: global traffic HTTP traffic detected: GET /livechat-public/v1/message/public?portalId=6324853&conversations-embed=static-1.18177&mobile=false&messagesUtk=4a2c6293365442e18d8414d2ce2df8ae&traceId=4a2c6293365442e18d8414d2ce2df8ae HTTP/1.1Host: api.hubspot.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0X-HubSpot-Messages-Uri: https://www.airdroid.com/thankyou/install-airdroid-cast.htmlUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Origin: https://www.airdroid.comSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /hs-script-loader-public/v1/config/pixels-and-events/json?portalId=6324853 HTTP/1.1Host: api.hubapi.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /p20/crossrecommend/getcrossrecommend?q=7b81265dfb489e1ee65fdc5bcd9589e7ddbed44605e23cf5b82aa069433fee17d2e805ab9881a0a6dfa54a844bac2d08e62b9b55b223cb128604f02b123554035480db629fbed72d354b04dfeef93d05481e8599b83a9041d7ebc9a573e03f0b44e9a6313eaac0dab8641e71b13c9e0400bb212cd4b7191d89cf20646cf12fd7f521f10f1dc970e8fb6dfa1a649f41a62ec62cfa1731602f4dab9ba34912bc52cb3f30f06e02f1d3&_t=9033b1b788ed4d07bb80582a0fdc589d&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: srv3.airdroid.com
Source: global traffic HTTP traffic detected: GET /rules/rule224901v11s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120601v3s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120682v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120681v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120602v10s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /channel/save?key=p-713-&deviceType=PC&appType=airdroid&accountId=-999&appChannel=airdroid&token=0&session=&_t=8efb6c156acc495ea9ffe05072ab8145&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: push.airdroid.com
Source: global traffic HTTP traffic detected: GET /p20/config/get?q=060171db4cdf21247c1106dd350462c553d869f2f6aa952e711efe06dd1efbc309196f07d75123bdd2e805ab9881a0a65983f146469c00e8959989774fcce1fc49df2dd68644032a677dbae13b26f87958db153d6b84bde73c4054cecc59167e374011feba57c5abf996e738f2328cdf9efe9dc6debee02e8ae353a220430037&_t=ce466132074f43d2a38f4cb1416e1215&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: srv3.airdroid.com
Source: global traffic HTTP traffic detected: GET /__ptq.gif?k=1&sd=1280x1024&cd=24-bit&cs=UTF-8&ln=en-us&bfp=471034161&v=1.1&a=6324853&rcu=https%3A%2F%2Fwww.airdroid.com%2Fthankyou%2Finstall-airdroid-cast.html&pu=https%3A%2F%2Fwww.airdroid.com%2Fthankyou%2Finstall-airdroid-cast.html&t=Thanks+for+installing+AirDroid+Cast!&cts=1728295046870&vi=6aa7734ded5ca49f9a0d86e49629bf43&nc=true&u=197314800.6aa7734ded5ca49f9a0d86e49629bf43.1728295046858.1728295046858.1728295046858.1&b=197314800.1.1728295046859&cc=15 HTTP/1.1Host: track.hubspot.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: __cf_bm=OBTw7uaaFeyPF1EDdc1GuG5wO6ZET2Y.O1bq8ydB40Q-1728295047-1.0.1.1-sGyyzXh1wlqmsGS94Z45rubz5D9UVID0iXJt2QpUDY8G3prwteMqZ2U3M4z_cxePLlK_mtfn3_6f9WKtEhR.2w; _cfuvid=Ddd1lMzH.IvzvPlxRmsxoRA0A2g5tgppQNB2y5kPM0A-1728295047650-0.0.1.1-604800000
Source: global traffic HTTP traffic detected: GET /embed/v3/counters.gif?key=config-loaded-success&value=1 HTTP/1.1Host: perf-na1.hsforms.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /rules/rule701201v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule701200v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700201v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702351v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700200v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /livechat-public/v1/message/public?portalId=6324853&conversations-embed=static-1.18177&mobile=false&messagesUtk=4a2c6293365442e18d8414d2ce2df8ae&traceId=4a2c6293365442e18d8414d2ce2df8ae HTTP/1.1Host: api.hubspot.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: __cf_bm=OBTw7uaaFeyPF1EDdc1GuG5wO6ZET2Y.O1bq8ydB40Q-1728295047-1.0.1.1-sGyyzXh1wlqmsGS94Z45rubz5D9UVID0iXJt2QpUDY8G3prwteMqZ2U3M4z_cxePLlK_mtfn3_6f9WKtEhR.2w; _cfuvid=Ddd1lMzH.IvzvPlxRmsxoRA0A2g5tgppQNB2y5kPM0A-1728295047650-0.0.1.1-604800000
Source: global traffic HTTP traffic detected: GET /lead-flows-config/v1/config/json?portalId=6324853&utk=6aa7734ded5ca49f9a0d86e49629bf43&__hstc=197314800.6aa7734ded5ca49f9a0d86e49629bf43.1728295046858.1728295046858.1728295046858.1&__hssc=197314800.1.1728295046859&currentUrl=https%3A%2F%2Fwww.airdroid.com%2Fthankyou%2Finstall-airdroid-cast.html HTTP/1.1Host: forms.hubspot.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: __cf_bm=OBTw7uaaFeyPF1EDdc1GuG5wO6ZET2Y.O1bq8ydB40Q-1728295047-1.0.1.1-sGyyzXh1wlqmsGS94Z45rubz5D9UVID0iXJt2QpUDY8G3prwteMqZ2U3M4z_cxePLlK_mtfn3_6f9WKtEhR.2w; _cfuvid=Ddd1lMzH.IvzvPlxRmsxoRA0A2g5tgppQNB2y5kPM0A-1728295047650-0.0.1.1-604800000
Source: global traffic HTTP traffic detected: GET /embed/v3/counters.gif?key=config-loaded-success&value=1 HTTP/1.1Host: perf-na1.hsforms.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: __cf_bm=ICha9WnhxFy7ak_aAVkMPfwOeTCzR5LZiUVULIlbZjc-1728295049-1.0.1.1-4nY5bHDfULzdjTFRY.wIpj5AqmBNUrjS66FP4NR02YtlHBvDBD75CnodNXmpr_FwVmRxgsTf4bumY0b20VXjjA; _cfuvid=Jjr5opNGQvf8usTDHeEC1RCSbANAYvU3TLC.JKHWvlo-1728295049352-0.0.1.1-604800000
Source: global traffic HTTP traffic detected: GET /__ptq.gif?k=1&sd=1280x1024&cd=24-bit&cs=UTF-8&ln=en-us&bfp=471034161&v=1.1&a=6324853&rcu=https%3A%2F%2Fwww.airdroid.com%2Fthankyou%2Finstall-airdroid-cast.html&pu=https%3A%2F%2Fwww.airdroid.com%2Fthankyou%2Finstall-airdroid-cast.html&t=Thanks+for+installing+AirDroid+Cast!&cts=1728295046870&vi=6aa7734ded5ca49f9a0d86e49629bf43&nc=true&u=197314800.6aa7734ded5ca49f9a0d86e49629bf43.1728295046858.1728295046858.1728295046858.1&b=197314800.1.1728295046859&cc=15 HTTP/1.1Host: track.hubspot.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: __cf_bm=OBTw7uaaFeyPF1EDdc1GuG5wO6ZET2Y.O1bq8ydB40Q-1728295047-1.0.1.1-sGyyzXh1wlqmsGS94Z45rubz5D9UVID0iXJt2QpUDY8G3prwteMqZ2U3M4z_cxePLlK_mtfn3_6f9WKtEhR.2w; _cfuvid=Ddd1lMzH.IvzvPlxRmsxoRA0A2g5tgppQNB2y5kPM0A-1728295047650-0.0.1.1-604800000
Source: global traffic HTTP traffic detected: GET /p20/config/get?q=060171db4cdf2124f2510574a425110d991082c5820bc755711efe06dd1efbc309196f07d75123bdd2e805ab9881a0a65983f146469c00e8959989774fcce1fc49df2dd68644032a677dbae13b26f87958db153d6b84bde73c4054cecc59167e374011feba57c5abf996e738f2328cdf9efe9dc6debee02e8ae353a220430037&_t=44493533a46342ccbd047c74dcec1350&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: srv3.airdroid.com
Source: global traffic HTTP traffic detected: GET /cast_link.html?airdroidCast-code=028461947 HTTP/1.1Host: m-embed.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en; __hstc=197314800.6aa7734ded5ca49f9a0d86e49629bf43.1728295046858.1728295046858.1728295046858.1; hubspotutk=6aa7734ded5ca49f9a0d86e49629bf43; __hssrc=1; __hssc=197314800.1.1728295046859
Source: global traffic HTTP traffic detected: GET /rules/rule702350v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700051v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700050v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule701250v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /assets/img/favicon-cast-973b301f96.ico HTTP/1.1Host: img-2-cdn.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en; __hstc=197314800.6aa7734ded5ca49f9a0d86e49629bf43.1728295046858.1728295046858.1728295046858.1; hubspotutk=6aa7734ded5ca49f9a0d86e49629bf43; __hssrc=1; __hssc=197314800.1.1728295046859
Source: global traffic HTTP traffic detected: GET /rules/rule701251v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /2409231703/css/common.min.css HTTP/1.1Host: m-embed.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://m-embed.airdroid.com/cast_link.html?airdroidCast-code=028461947Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en; __hstc=197314800.6aa7734ded5ca49f9a0d86e49629bf43.1728295046858.1728295046858.1728295046858.1; hubspotutk=6aa7734ded5ca49f9a0d86e49629bf43; __hssrc=1; __hssc=197314800.1.1728295046859; _gcl_au=1.1.1125598324.1728295050
Source: global traffic HTTP traffic detected: GET /pagead/viewthroughconversion/628991428/?random=1728295049594&cv=11&fst=1728295049594&bg=ffffff&guid=ON&async=1&gtm=45be4a20za200&gcd=13l3l3l3l1l1&dma=0&tag_exp=101671035~101747727&u_w=1280&u_h=1024&url=https%3A%2F%2Fwww.airdroid.com%2Fthankyou%2Finstall-airdroid-cast.html&hn=www.googleadservices.com&frm=0&tiba=Thanks%20for%20installing%20AirDroid%20Cast!&did=dZTQ1Zm&gdid=dZTQ1Zm&npa=0&pscdl=noapi&auid=1125598324.1728295050&uaa=x86&uab=64&uafvl=Google%2520Chrome%3B117.0.5938.132%7CNot%253BA%253DBrand%3B8.0.0.0%7CChromium%3B117.0.5938.132&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1&data=event%3Dgtag.config&rfmt=3&fmt=4 HTTP/1.1Host: googleads.g.doubleclick.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiTocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /td/rul/628991428?random=1728295049594&cv=11&fst=1728295049594&fmt=3&bg=ffffff&guid=ON&async=1&gtm=45be4a20za200&gcd=13l3l3l3l1l1&dma=0&tag_exp=101671035~101747727&u_w=1280&u_h=1024&url=https%3A%2F%2Fwww.airdroid.com%2Fthankyou%2Finstall-airdroid-cast.html&hn=www.googleadservices.com&frm=0&tiba=Thanks%20for%20installing%20AirDroid%20Cast!&did=dZTQ1Zm&gdid=dZTQ1Zm&npa=0&pscdl=noapi&auid=1125598324.1728295050&uaa=x86&uab=64&uafvl=Google%2520Chrome%3B117.0.5938.132%7CNot%253BA%253DBrand%3B8.0.0.0%7CChromium%3B117.0.5938.132&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1&data=event%3Dgtag.config HTTP/1.1Host: td.doubleclick.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiTocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /rules/rule701151v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702950v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule701150v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702951v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702201v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /channel/save?key=p-713-&deviceType=PC&appType=airdroid&accountId=-999&appChannel=airdroid&token=0&session=&_t=98d109053230477d9221c316731e070d&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: push.airdroid.com
Source: global traffic HTTP traffic detected: GET /2409231703/js/common.min.js HTTP/1.1Host: m-embed.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://m-embed.airdroid.com/cast_link.html?airdroidCast-code=028461947Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en; __hstc=197314800.6aa7734ded5ca49f9a0d86e49629bf43.1728295046858.1728295046858.1728295046858.1; hubspotutk=6aa7734ded5ca49f9a0d86e49629bf43; __hssrc=1; __hssc=197314800.1.1728295046859; _gcl_au=1.1.1125598324.1728295050
Source: global traffic HTTP traffic detected: GET /2409231703/img/download/x2/pic_see_more@2x.png HTTP/1.1Host: m-embed.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://m-embed.airdroid.com/cast_link.html?airdroidCast-code=028461947Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en; __hstc=197314800.6aa7734ded5ca49f9a0d86e49629bf43.1728295046858.1728295046858.1728295046858.1; hubspotutk=6aa7734ded5ca49f9a0d86e49629bf43; __hssrc=1; __hssc=197314800.1.1728295046859; _gcl_au=1.1.1125598324.1728295050
Source: global traffic HTTP traffic detected: GET /2409231703/img/download/x2/pic_cast_logo@2x.png HTTP/1.1Host: m-embed.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://m-embed.airdroid.com/cast_link.html?airdroidCast-code=028461947Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en; __hstc=197314800.6aa7734ded5ca49f9a0d86e49629bf43.1728295046858.1728295046858.1728295046858.1; hubspotutk=6aa7734ded5ca49f9a0d86e49629bf43; __hssrc=1; __hssc=197314800.1.1728295046859; _gcl_au=1.1.1125598324.1728295050
Source: global traffic HTTP traffic detected: GET /2409231703/img/download/x2/pic_bottom_left@2x.png HTTP/1.1Host: m-embed.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://m-embed.airdroid.com/cast_link.html?airdroidCast-code=028461947Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en; __hstc=197314800.6aa7734ded5ca49f9a0d86e49629bf43.1728295046858.1728295046858.1728295046858.1; hubspotutk=6aa7734ded5ca49f9a0d86e49629bf43; __hssrc=1; __hssc=197314800.1.1728295046859; _gcl_au=1.1.1125598324.1728295050
Source: global traffic HTTP traffic detected: GET /2409231703/img/download/x2/pic_bottom_right@2x.png HTTP/1.1Host: m-embed.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://m-embed.airdroid.com/cast_link.html?airdroidCast-code=028461947Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en; __hstc=197314800.6aa7734ded5ca49f9a0d86e49629bf43.1728295046858.1728295046858.1728295046858.1; hubspotutk=6aa7734ded5ca49f9a0d86e49629bf43; __hssrc=1; __hssc=197314800.1.1728295046859; _gcl_au=1.1.1125598324.1728295050
Source: global traffic HTTP traffic detected: GET /rules/rule700401v2s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702200v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700400v2s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700350v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700351v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /2409231703/img/download/x1/pic_cast_logo.png HTTP/1.1Host: m-embed.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://m-embed.airdroid.com/cast_link.html?airdroidCast-code=028461947Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en; __hstc=197314800.6aa7734ded5ca49f9a0d86e49629bf43.1728295046858.1728295046858.1728295046858.1; hubspotutk=6aa7734ded5ca49f9a0d86e49629bf43; __hssrc=1; __hssc=197314800.1.1728295046859; _gcl_au=1.1.1125598324.1728295050
Source: global traffic HTTP traffic detected: GET /pagead/viewthroughconversion/628991428/?random=1728295049594&cv=11&fst=1728295049594&bg=ffffff&guid=ON&async=1&gtm=45be4a20za200&gcd=13l3l3l3l1l1&dma=0&tag_exp=101671035~101747727&u_w=1280&u_h=1024&url=https%3A%2F%2Fwww.airdroid.com%2Fthankyou%2Finstall-airdroid-cast.html&hn=www.googleadservices.com&frm=0&tiba=Thanks%20for%20installing%20AirDroid%20Cast!&did=dZTQ1Zm&gdid=dZTQ1Zm&npa=0&pscdl=noapi&auid=1125598324.1728295050&uaa=x86&uab=64&uafvl=Google%2520Chrome%3B117.0.5938.132%7CNot%253BA%253DBrand%3B8.0.0.0%7CChromium%3B117.0.5938.132&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1&data=event%3Dgtag.config&rfmt=3&fmt=4 HTTP/1.1Host: googleads.g.doubleclick.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiTocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: test_cookie=CheckForPermission
Source: global traffic HTTP traffic detected: GET /pagead/1p-user-list/628991428/?random=1728295049594&cv=11&fst=1728291600000&bg=ffffff&guid=ON&async=1&gtm=45be4a20za200&gcd=13l3l3l3l1l1&dma=0&tag_exp=101671035~101747727&u_w=1280&u_h=1024&url=https%3A%2F%2Fwww.airdroid.com%2Fthankyou%2Finstall-airdroid-cast.html&hn=www.googleadservices.com&frm=0&tiba=Thanks%20for%20installing%20AirDroid%20Cast!&did=dZTQ1Zm&gdid=dZTQ1Zm&npa=0&pscdl=noapi&auid=1125598324.1728295050&uaa=x86&uab=64&uafvl=Google%2520Chrome%3B117.0.5938.132%7CNot%253BA%253DBrand%3B8.0.0.0%7CChromium%3B117.0.5938.132&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1&data=event%3Dgtag.config&rfmt=3&fmt=3&is_vtc=1&cid=CAQSGwDpaXnfGhzM_FnSCMzKLQIovG9YS6P_DfJmKw&random=2975559918&rmt_tld=0&ipr=y HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiTocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /2409231703/img/download/x2/pic_see_more@2x.png HTTP/1.1Host: m-embed.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en; __hstc=197314800.6aa7734ded5ca49f9a0d86e49629bf43.1728295046858.1728295046858.1728295046858.1; hubspotutk=6aa7734ded5ca49f9a0d86e49629bf43; __hssrc=1; __hssc=197314800.1.1728295046859; _gcl_au=1.1.1125598324.1728295050
Source: global traffic HTTP traffic detected: GET /2409231703/img/download/x2/pic_cast_logo@2x.png HTTP/1.1Host: m-embed.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en; __hstc=197314800.6aa7734ded5ca49f9a0d86e49629bf43.1728295046858.1728295046858.1728295046858.1; hubspotutk=6aa7734ded5ca49f9a0d86e49629bf43; __hssrc=1; __hssc=197314800.1.1728295046859; _gcl_au=1.1.1125598324.1728295050
Source: global traffic HTTP traffic detected: GET /2409231703/img/download/x2/pic_bottom_right@2x.png HTTP/1.1Host: m-embed.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en; __hstc=197314800.6aa7734ded5ca49f9a0d86e49629bf43.1728295046858.1728295046858.1728295046858.1; hubspotutk=6aa7734ded5ca49f9a0d86e49629bf43; __hssrc=1; __hssc=197314800.1.1728295046859; _gcl_au=1.1.1125598324.1728295050
Source: global traffic HTTP traffic detected: GET /rules/rule703900v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /2409231703/img/download/x2/pic_bottom_left@2x.png HTTP/1.1Host: m-embed.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en; __hstc=197314800.6aa7734ded5ca49f9a0d86e49629bf43.1728295046858.1728295046858.1728295046858.1; hubspotutk=6aa7734ded5ca49f9a0d86e49629bf43; __hssrc=1; __hssc=197314800.1.1728295046859; _gcl_au=1.1.1125598324.1728295050
Source: global traffic HTTP traffic detected: GET /rules/rule701501v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule701500v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703901v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /p20/crossrecommend/getcrossrecommend?q=7b81265dfb489e1ee65fdc5bcd9589e7ddbed44605e23cf5b82aa069433fee17d2e805ab9881a0a6dfa54a844bac2d08e62b9b55b223cb128604f02b123554035480db629fbed72d354b04dfeef93d05481e8599b83a9041d7ebc9a573e03f0b44e9a6313eaac0dab8641e71b13c9e0400bb212cd4b7191d89cf20646cf12fd7f521f10f1dc970e8fb6dfa1a649f41a62ec62cfa1731602f4dab9ba34912bc52cb3f30f06e02f1d3&_t=0851dce681624a1295e68ebb91a6148c&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: srv3.airdroid.com
Source: global traffic HTTP traffic detected: GET /rules/rule702801v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /2409231703/js/common.min.js HTTP/1.1Host: m-embed.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en; __hstc=197314800.6aa7734ded5ca49f9a0d86e49629bf43.1728295046858.1728295046858.1728295046858.1; hubspotutk=6aa7734ded5ca49f9a0d86e49629bf43; __hssrc=1; __hssc=197314800.1.1728295046859; _gcl_au=1.1.1125598324.1728295050
Source: global traffic HTTP traffic detected: GET /2409231703/lang/en.js HTTP/1.1Host: m-embed.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://m-embed.airdroid.com/cast_link.html?airdroidCast-code=028461947Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en; __hstc=197314800.6aa7734ded5ca49f9a0d86e49629bf43.1728295046858.1728295046858.1728295046858.1; hubspotutk=6aa7734ded5ca49f9a0d86e49629bf43; __hssrc=1; __hssc=197314800.1.1728295046859; _gcl_au=1.1.1125598324.1728295050
Source: global traffic HTTP traffic detected: GET /pagead/1p-user-list/628991428/?random=1728295049594&cv=11&fst=1728291600000&bg=ffffff&guid=ON&async=1&gtm=45be4a20za200&gcd=13l3l3l3l1l1&dma=0&tag_exp=101671035~101747727&u_w=1280&u_h=1024&url=https%3A%2F%2Fwww.airdroid.com%2Fthankyou%2Finstall-airdroid-cast.html&hn=www.googleadservices.com&frm=0&tiba=Thanks%20for%20installing%20AirDroid%20Cast!&did=dZTQ1Zm&gdid=dZTQ1Zm&npa=0&pscdl=noapi&auid=1125598324.1728295050&uaa=x86&uab=64&uafvl=Google%2520Chrome%3B117.0.5938.132%7CNot%253BA%253DBrand%3B8.0.0.0%7CChromium%3B117.0.5938.132&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1&data=event%3Dgtag.config&rfmt=3&fmt=3&is_vtc=1&cid=CAQSGwDpaXnfGhzM_FnSCMzKLQIovG9YS6P_DfJmKw&random=2975559918&rmt_tld=0&ipr=y HTTP/1.1Host: www.google.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiTocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /2409231703/img/download/x1/pic_cast_logo.png HTTP/1.1Host: m-embed.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en; __hstc=197314800.6aa7734ded5ca49f9a0d86e49629bf43.1728295046858.1728295046858.1728295046858.1; hubspotutk=6aa7734ded5ca49f9a0d86e49629bf43; __hssrc=1; __hssc=197314800.1.1728295046859; _gcl_au=1.1.1125598324.1728295050
Source: global traffic HTTP traffic detected: GET /rules/rule703350v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703501v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702800v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703351v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703500v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule701050v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702751v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule701800v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule701051v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule701801v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /p20/web/getbinary?type=cast_apk&channel= HTTP/1.1Host: srv3.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Origin: https://m-embed.airdroid.comSec-Fetch-Site: same-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://m-embed.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /2409231703/lang/en.js HTTP/1.1Host: m-embed.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en; __hstc=197314800.6aa7734ded5ca49f9a0d86e49629bf43.1728295046858.1728295046858.1728295046858.1; hubspotutk=6aa7734ded5ca49f9a0d86e49629bf43; __hssrc=1; __hssc=197314800.1.1728295046859; _gcl_au=1.1.1125598324.1728295050
Source: global traffic HTTP traffic detected: GET /rules/rule703401v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702750v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703400v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702301v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702300v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /2409231703/img/favicon-cast.ico HTTP/1.1Host: m-embed.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://m-embed.airdroid.com/cast_link.html?airdroidCast-code=028461947Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en; __hstc=197314800.6aa7734ded5ca49f9a0d86e49629bf43.1728295046858.1728295046858.1728295046858.1; hubspotutk=6aa7734ded5ca49f9a0d86e49629bf43; __hssrc=1; __hssc=197314800.1.1728295046859; _gcl_au=1.1.1125598324.1728295050
Source: global traffic HTTP traffic detected: GET /p20/web/getbinary?type=cast_apk&channel= HTTP/1.1Host: srv3.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en; __hstc=197314800.6aa7734ded5ca49f9a0d86e49629bf43.1728295046858.1728295046858.1728295046858.1; hubspotutk=6aa7734ded5ca49f9a0d86e49629bf43; __hssrc=1; __hssc=197314800.1.1728295046859; _gcl_au=1.1.1125598324.1728295050
Source: global traffic HTTP traffic detected: GET /AirDroid_Cast_1.1.5.1_sandstudio.apk HTTP/1.1Host: dl.airdroid.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://m-embed.airdroid.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en; __hstc=197314800.6aa7734ded5ca49f9a0d86e49629bf43.1728295046858.1728295046858.1728295046858.1; hubspotutk=6aa7734ded5ca49f9a0d86e49629bf43; __hssrc=1; __hssc=197314800.1.1728295046859; _gcl_au=1.1.1125598324.1728295050
Source: global traffic HTTP traffic detected: GET /rules/rule702500v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700501v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702501v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700500v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702551v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /p20/crossrecommend/getcrossrecommend?q=7b81265dfb489e1ee65fdc5bcd9589e7ddbed44605e23cf5b82aa069433fee17d2e805ab9881a0a6dfa54a844bac2d08e62b9b55b223cb128604f02b123554035480db629fbed72d354b04dfeef93d05481e8599b83a9041d7ebc9a573e03f0b44e9a6313eaac0dab8641e71b13c9e0400bb212cd4b7191d89cf20646cf12fd7f521f10f1dc970e8fb6dfa1a649f41a62ec62cfa1731602f4dab9ba34912bc52cb3f30f06e02f1d3&_t=7c9ffe77ca66447fa59db466fc0b27e0&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: srv3.airdroid.com
Source: global traffic HTTP traffic detected: GET /p20/pc/upgradewebpackage?inner_version=1210&v=1.2.1.0&type=63&_t=41d71d0921b2479cbcf0865adb45a9ef&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0 HTTP/1.1Host: srv3.airdroid.com
Source: global traffic HTTP traffic detected: GET /2409231703/img/favicon-cast.ico HTTP/1.1Host: m-embed.airdroid.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: lang=en; __hstc=197314800.6aa7734ded5ca49f9a0d86e49629bf43.1728295046858.1728295046858.1728295046858.1; hubspotutk=6aa7734ded5ca49f9a0d86e49629bf43; __hssrc=1; __hssc=197314800.1.1728295046859; _gcl_au=1.1.1125598324.1728295050
Source: global traffic HTTP traffic detected: GET /rules/rule702150v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702151v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702550v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule701350v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule701351v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703001v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700751v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700750v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703000v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700151v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703451v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703450v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700150v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700901v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700900v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702251v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702250v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702651v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702650v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703101v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702901v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703100v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702900v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703600v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703601v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703851v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703850v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703800v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703701v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703801v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703700v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703751v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703750v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule701300v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule701301v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule704051v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702051v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule701700v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule704050v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule701701v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702050v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700701v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700700v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700550v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700551v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703651v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703650v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700600v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700601v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703151v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703150v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703951v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703950v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702850v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702851v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700001v2s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule701401v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule701400v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule701951v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule701950v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700851v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700850v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700000v2s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule701851v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule701850v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703051v3s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703050v3s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700101v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702101v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702100v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700100v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700951v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700950v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703551v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703550v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700451v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702701v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702700v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700450v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule701901v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule701900v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule704001v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule704000v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703251v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703250v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702401v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702400v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule701551v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule701550v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700301v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700300v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702001v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702000v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702601v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702600v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703201v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703200v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700251v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700250v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700651v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule700650v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703301v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule703300v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule701751v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule701750v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule701651v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule701650v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702451v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule701101v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule702450v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule701100v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120128v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120603v8s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule230104v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120607v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule230157v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule230158v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule230162v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule230164v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule230165v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule230166v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule230167v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule230168v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule230169v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule230170v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule230172v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule230171v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule230173v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule230174v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule120119v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule224900v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule704101v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule704100v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule704201v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule704151v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule704200v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule704150v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET /rules/rule226009v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global traffic HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Close
Source: global traffic HTTP traffic detected: GET /p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Close
Source: global traffic HTTP traffic detected: GET /p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Close
Source: global traffic HTTP traffic detected: GET /p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Close
Source: global traffic HTTP traffic detected: GET /p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Close
Source: global traffic HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Close
Source: global traffic HTTP traffic detected: GET /p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Close
Source: global traffic HTTP traffic detected: GET /p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Close
Source: global traffic HTTP traffic detected: GET /p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Close
Source: global traffic HTTP traffic detected: GET /p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Close
Source: global traffic HTTP traffic detected: GET /p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Close
Source: global traffic HTTP traffic detected: GET /p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Close
Source: global traffic HTTP traffic detected: GET /p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Close
Source: global traffic HTTP traffic detected: GET /p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Close
Source: global traffic HTTP traffic detected: GET /p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Close
Source: global traffic HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Close
Source: global traffic HTTP traffic detected: GET /p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Close
Source: global traffic HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Close
Source: global traffic HTTP traffic detected: GET /p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Close
Source: global traffic HTTP traffic detected: GET /p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Close
Source: global traffic HTTP traffic detected: GET /p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Close
Source: global traffic HTTP traffic detected: GET /p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Host: srv3.airdroid.comConnection: Keep-Alive
Source: Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: <ShareToFacebook>https://www.facebook.com/dialog/share?app_id=145634995501895&amp;display=popup&amp;href=http%3A%2F%2Fwww.airdroid.com&amp;redirect_uri=http%3A%2F%2Fwww.facebook.com</ShareToFacebook> equals www.facebook.com (Facebook)
Source: Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: <ShareToFacebook>https://www.facebook.com/dialog/share?app_id=145634995501895&display=popup&href=http%3A%2F%2Fwww.airdroid.com&redirect_uri=http%3A%2F%2Fwww.facebook.comfacebook.com</ShareToFacebook> equals www.facebook.com (Facebook)
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: <iTongWeiBo>http://www.facebook.com/AppleAAThai</iTongWeiBo> equals www.facebook.com (Facebook)
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: <iTongWeiBo>https://www.facebook.com/pages/%C4%90%E1%BB%93ng-B%E1%BB%99/625446587487119</iTongWeiBo> equals www.facebook.com (Facebook)
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: <iTongWeiBo>https://www.facebook.com/pages/IClover/116533728554734</iTongWeiBo> equals www.facebook.com (Facebook)
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000004450000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: Memory.RendererUsedmail.google.com.gmaildocs.google.comdrive.google.com.docsplus.google.com.plusinbox.google.com.inboxwww.youtube.com.youtube.top10sina.com.cnfacebook.combaidu.comqq.comtwitter.comtaobao.comlive.comyahooamazonwikipediaRenderThreadImpl::InitSkiaRenderercontent::RenderThreadImpl::InitializeCompositorThreadcontent::RenderThreadImpl::ScheduleIdleHandlercontent::RenderThreadImpl::GetGpuFactorieschrome://gpu/RenderThreadImpl::CreateOffscreenContext3d_IpcMessageHandlerClass::OnCreateNewFrame_IpcMessageHandlerClass::OnCreateNewFrameProxy_IpcMessageHandlerClass::OnSetZoomLevelForCurrentURL_IpcMessageHandlerClass::OnCreateNewView_IpcMessageHandlerClass::OnNetworkConnectionChanged_IpcMessageHandlerClass::OnCreateNewSharedWorker_IpcMessageHandlerClass::OnUpdateTimezone_IpcMessageHandlerClass::OnPurgePluginListCacheRenderThreadImpl::EstablishGpuChannelSyncICU default timezone is set to Renderer::FILE equals www.youtube.com (Youtube)
Source: AirDroidCast.exe, 00000009.00000002.6038136579.000000000580E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: com.tumblr.https://www.tumblr.com/4com.google.android.youtube0https://www.youtube.com/,net.slickdeals.android,http://slickdeals.net/,com.soundcloud.android.https://soundcloud.com/0com.stackexchange.marvin2http://stackoverflow.com/ equals www.youtube.com (Youtube)
Source: AirDroidCast.exe, 00000009.00000002.6038136579.000000000580E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: com.whatsapp2https://web.whatsapp.com/&com.facebook.katana2https://www.facebook.com/"com.facebook.orca,org.telegram.messenger equals www.facebook.com (Facebook)
Source: AirDroidCast.exe, 00000009.00000002.6038136579.000000000580E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: default_new.png*com.google.android.gm0https://mail.google.com/:com.google.android.apps.inbox2https://inbox.google.com/.com.google.android.keep0https://keep.google.com/&com.twitter.android(https://twitter.com/8com.google.android.apps.plusZhttps://plus.google.com/u/0/notifications/all6com.google.android.calendar>https://www.google.com/calendar&com.groupme.android0https://app.groupme.com/*com.instagram.android*http://instagram.com/ equals www.twitter.com (Twitter)
Source: AirDroidCast.exe, 00000009.00000002.6038136579.0000000005071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.facebook.com/dialog/oauth?client_id={0}&scope={1}&display=popup&redirect_uri={2}&response_type=codedhttp://www.facebook.com/connect/login_success.html8manage_pages,publish_actions equals www.facebook.com (Facebook)
Source: AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.facebook.com/dialog/share?app_id=145634995501895&display=popup&href=http%3A%2F%2Fwww.airdroid.com&redirect_uri=http%3A%2F%2Fwww.facebook.com equals www.facebook.com (Facebook)
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000004450000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: www.youtube.com equals www.youtube.com (Youtube)
Source: global traffic DNS traffic detected: DNS query: stat3.airdroid.com
Source: global traffic DNS traffic detected: DNS query: srv3.airdroid.com
Source: global traffic DNS traffic detected: DNS query: www.airdroid.com
Source: global traffic DNS traffic detected: DNS query: css-1-cdn.airdroid.com
Source: global traffic DNS traffic detected: DNS query: js-1-cdn.airdroid.com
Source: global traffic DNS traffic detected: DNS query: cdn1.airdroid.com
Source: global traffic DNS traffic detected: DNS query: img-4-cdn.airdroid.com
Source: global traffic DNS traffic detected: DNS query: img-5-cdn.airdroid.com
Source: global traffic DNS traffic detected: DNS query: img-1-cdn.airdroid.com
Source: global traffic DNS traffic detected: DNS query: img-2-cdn.airdroid.com
Source: global traffic DNS traffic detected: DNS query: img-3-cdn.airdroid.com
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: global traffic DNS traffic detected: DNS query: 96.4.1.0.in-addr.arpa
Source: global traffic DNS traffic detected: DNS query: lb.airdroid.com
Source: global traffic DNS traffic detected: DNS query: push.airdroid.com
Source: global traffic DNS traffic detected: DNS query: id-cast.airdroid.com
Source: global traffic DNS traffic detected: DNS query: js.hs-scripts.com
Source: global traffic DNS traffic detected: DNS query: us-east-1-data.airdroid.com
Source: global traffic DNS traffic detected: DNS query: js.hsleadflows.net
Source: global traffic DNS traffic detected: DNS query: js.hubspot.com
Source: global traffic DNS traffic detected: DNS query: js.hs-analytics.net
Source: global traffic DNS traffic detected: DNS query: js.usemessages.com
Source: global traffic DNS traffic detected: DNS query: js.hsadspixel.net
Source: global traffic DNS traffic detected: DNS query: js.hs-banner.com
Source: global traffic DNS traffic detected: DNS query: api.hubapi.com
Source: global traffic DNS traffic detected: DNS query: cta-service-cms2.hubspot.com
Source: global traffic DNS traffic detected: DNS query: api.hubspot.com
Source: global traffic DNS traffic detected: DNS query: forms.hubspot.com
Source: global traffic DNS traffic detected: DNS query: a.nel.cloudflare.com
Source: global traffic DNS traffic detected: DNS query: track.hubspot.com
Source: global traffic DNS traffic detected: DNS query: perf-na1.hsforms.com
Source: global traffic DNS traffic detected: DNS query: m-embed.airdroid.com
Source: global traffic DNS traffic detected: DNS query: googleads.g.doubleclick.net
Source: global traffic DNS traffic detected: DNS query: td.doubleclick.net
Source: global traffic DNS traffic detected: DNS query: dl.airdroid.com
Source: unknown HTTP traffic detected: POST /p20/config/batchget? HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.65 Safari/534.24Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5Content-Type: application/x-www-form-urlencodedHost: srv3.airdroid.comContent-Length: 146Expect: 100-continue
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://.css
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://.jpg
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000004450000.00000004.00000020.00020000.00000000.sdmp, Helper.exe, 00000004.00000002.2140928933.0000000003448000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6038136579.0000000005071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000004450000.00000004.00000020.00020000.00000000.sdmp, Helper.exe, 00000004.00000002.2140928933.0000000003448000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6038136579.0000000005071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1:
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000004450000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://127.0.0.1http://localhosthttp://127.0.0.1:http://localhost:chrome://chrome-extension-resource
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://EVSecure-crl.geotrust.com/GeoTrustPCA.crl0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://EVSecure-ocsp.geotrust.com0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://EVSecure-ocsp.thawte.com0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://aia.startssl.com/certs/ca.crt02
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://aia1.wosign.com/ca1-class3-server.cer0
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://andserver.tongbu.com/tui/zs/recommend?rectype=1&amp;page=1&amp;pageSize=36&amp;rf=zs3
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://apidata.appleAA.com/TbzsData/tbzs20Device.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://apidata.dongbo.vn/TbzsData/tbzs20Device.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://apidata.tongbu.com/TbzsData/tbzs20Device.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://apidata.tongbu.com/TbzsPost/TbzsData/TbZsApkDeviceJoinUp.ashx?~method=CollectStatus
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://apk.tongbu.com/api/v1/update
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://app.api.tongbu.com/app.html?t=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://app.tongbu.com/?s=zsv2
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://au1.appleAA.com/index.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://au1.leaderhero.com/Grappa.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://au1.leaderhero.com/index.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://au1.tongbu.com/index.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://au11.appleAA.com/index.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://au11.leaderhero.com/index.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://au11.tongbu.com/index.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://au21.appleAA.com/index.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://au21.tongbu.com/index.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://bbs.appleAA.com/thread-85930-1-1.html
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://bbs.appleAA.com/thread-87066-1-1.html
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://bbs.appleAA.com/thread-96450-1-1.html
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://bbs.tongbu.com/forum-8-1.html
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://bbs.tongbu.com/thread-105373-1-1.html
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://bbs.tongbu.com/thread-55460-1-1.html?s=3.0
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://bbs.tongbu.com/thread-85930-1-1.html
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://bbs.tongbu.com/thread-87066-1-1.html
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://bbs.tongbu.com/thread-96450-1-1.html
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://certificates.godaddy.com/repository/gd_intermediate.crt0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://certificates.godaddy.com/repository/gdroot.crl0K
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://certificates.godaddy.com/repository0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://certificates.godaddy.com/repository100.
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://certificates.starfieldtech.com/repository/sfroot.crl0Q
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://certificates.starfieldtech.com/repository0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://certificates.starfieldtech.com/repository110/
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6324479836.00000000154BF000.00000004.00000020.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004717000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6185719139.00000000099D9000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://certs.godaddy.com/repository/1301
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://certs.starfieldtech.com/repository/1402
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000004450000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://clients2.google.com/service/update2
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000004450000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://clients2.google.com/service/update2https://clients2.google.com/service/update20.0.0.0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://clients3.google.com/cert_upload_json
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://config.appleAA.com/tbtui/tuiver.ashx?deviceid=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://config.dongbo.vn/tbtui/tuiver.ashx?deviceid=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://config.tongbu.com/tbtui/tuicode.ashx?ProductType=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://config.tongbu.com/tbtui/tuicode.ashx?deviceid=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://config.tongbu.com/tbtui/tuiregisndesc.ashx?rg=
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://corppki/aia/mswww(6).crt0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://corppki/crl/mswww(6).crl0y
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crbug.com/334408
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crbug.com/334408a
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000004450000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crbug.com/482256
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000004450000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crbug.com/482256Cache.match()
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000004450000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crbug.com/499216
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crbug.com/511119
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000004450000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crbug.com/520784
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000004450000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crbug.com/520784Cache.match()
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.1958158678.0000000004851000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003045000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.1958882274.000000000484A000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.1957929974.000000000484A000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.1958632786.000000000484A000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2403956126.0000000004825000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.2371933145.0000000004825000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.1957990124.000000000484F000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.1926310156.0000000004855000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.1927926139.0000000004855000.00000004.00000020.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6185719139.00000000099D9000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl04
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.1958158678.0000000004851000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.1958882274.000000000484A000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.1957929974.000000000484A000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.1958632786.000000000484A000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2403956126.0000000004825000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.2371933145.0000000004825000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.1957990124.000000000484F000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.1926310156.0000000004855000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.1927926139.0000000004855000.00000004.00000020.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6185719139.00000000099D9000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.comodoca.com/AddTrustExternalCARoot.crl06
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.comodoca.com/COMODOCertificationAuthority.crl0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.comodoca.com/COMODOCertificationAuthority.crl0l
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.comodoca.com/COMODOCertificationAuthority.crl0t
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.comodoca.com/SecureCertificateServices.crl09
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.comodoca.com/TrustedCertificateServices.crl0:
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.comodoca.com/UTN-DATACorpSGC.crl0/
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.entrust.net/2048ca.crl0;
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.entrust.net/2048ca.crl0O
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.entrust.net/g2ca.crl0;
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.entrust.net/rootca1.crl0;
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.geotrust.com/crls/gtglobal.crl04
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.geotrust.com/crls/secureca.crl0F
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.geotrust.com/crls/secureca.crl0N
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.globalsign.net/root-r2.crl0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.globalsign.net/root.crl0=
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6324479836.00000000154BF000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.godaddy.com/gdroot-g2.crl0F
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6324479836.00000000154BF000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.godaddy.com/gdroot.crl0F
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.godaddy.com/gds1-20
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.sectigo.com/COMODOTimeStampingCA_2.crl0r
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003045000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.sectigo.com/SectigoPublicCodeSigningCAR36.crl0y
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003045000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.sectigo.com/SectigoPublicCodeSigningRootR46.crl0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.sectigo.com/SectigoRSACodeSigningCA.crl0s
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003045000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.serverpass.telesec.de/crt/DT_ROOT_CA_2.cer0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.serverpass.telesec.de/rl/DT_ROOT_CA_2.crl0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.starfieldtech.com/sfroot-g2.crl0L
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.starfieldtech.com/sfroot.crl0L
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.startssl.com/sfsca.crl0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.thawte.com/ThawtePCA-G3.crl0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.thawte.com/ThawtePCA.crl0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.thawte.com/ThawtePremiumServerCA.crl0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootCA.crl07
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl4.digicert.com/DigiCertGlobalRootCA.crl0=
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0=
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crls1.wosign.com/ca1.crl0q
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crt.sectigo.com/COMODOTimeStampingCA_2.crt0#
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003045000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crt.sectigo.com/SectigoPublicCodeSigningCAR36.crt0#
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003045000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crt.sectigo.com/SectigoPublicCodeSigningRootR46.p7c0#
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crt.sectigo.com/SectigoRSACodeSigningCA.crt0#
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003045000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://css.dongbo.vn/appjb/css/inside_view.css
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://data.tongbu.com/tbzs30/sitexml.aspx
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000004450000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://dev.chromium.org/throttling
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://driver.appleAA.com/vendors.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2140928933.0000000003448000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6038136579.0000000005071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://driver.tongbu.com/
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://driver.tongbu.com/vendors.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://en.tongbu.com/css/inside_view.css
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://en.tongbu.com/js/inside_view.js
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://en.tongbu.com/js/jquery.tongbu.js?0112
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://exslt.org/common
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://exslt.org/commonnetworkRequestIdmessageIdparametersrelatedMessageId%d
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://g.symcb.com/GeoTrustPCA-G3.crl0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://g.symcb.com/crls/gtglobal.crl0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://g.symcb.com/crls/gtglobal.crl0.
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://g.symcd.com0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://g.symcd.com0L
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://g1.symcb.com/GeoTrustPCA.crl0)
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://g1.symcb.com/crls/gtglobal.crl0/
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://g2.symcb.com0G
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://g2.symcb.com0L
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://html4/loose.dtd
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://icl.com/saxon
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://icl.com/saxonFound
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2378705742.00000000007D2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://id-cast.airdroid.com/win/getInstallPage
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2140928933.0000000003448000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6038136579.0000000005071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://itunes.apple.com/
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://js.dongbo.vn/appjb/inside_view.js
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://js.dongbo.vn/common/jquery.tongbu.js?0112
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://m.airdroid.com
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://news.appleAA.com/?s=zsv2
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://news.tongbu.com/41623.html
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://news.tongbu.com/72024.html
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://news.tongbu.com/81721.html
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://news.tongbu.com/?s=zsv2
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000000.1756486864.0000000000408000.00000002.00000001.01000000.00000003.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2374420202.0000000000408000.00000002.00000001.01000000.00000003.sdmp String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.1958158678.0000000004851000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003045000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.1958882274.000000000484A000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.1957929974.000000000484A000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.1958632786.000000000484A000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2403956126.0000000004825000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.2371933145.0000000004825000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.1957990124.000000000484F000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.1926310156.0000000004855000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.1927926139.0000000004855000.00000004.00000020.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6185719139.00000000099D9000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.comodoca.com0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.digicert.com0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.digicert.com0K
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.digicert.com0M
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.entrust.net00
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.entrust.net02
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.entrust.net03
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.geotrust.com0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.geotrust.com0L
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.globalsign.com/rootr10
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6324479836.00000000154BF000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.godaddy.com/02
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6324479836.00000000154BF000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.godaddy.com/05
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.godaddy.com/0J
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.godaddy.com0F
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003045000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.sectigo.com0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.starfieldtech.com/08
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.starfieldtech.com/0;
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.starfieldtech.com0L
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.startssl.com/ca0-
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.startssl.com/ca00
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.thawte.com0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.thawte.com0;
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp02.telesec.de/ocspr0A
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp1.wosign.com/ca108
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://pc.airdroid.com/
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://redirect.appleAA.com/feedback?lan=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://redirect.appleAA.com/inside.php?lan=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://redirect.appleAA.com/inside/view?appleid=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://redirect.appleAA.com/url.php?ver=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2140928933.0000000003448000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6038136579.0000000005071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://redirect.tongbu.com/feedback?lan=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2140928933.0000000003448000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6038136579.0000000005071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://redirect.tongbu.com/inside.php?lan=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2140928933.0000000003448000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6038136579.0000000005071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://redirect.tongbu.com/inside/view?appleid=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2140928933.0000000003448000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6038136579.0000000005071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://redirect.tongbu.com/url.php?ver=
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://s1.symcb.com/pca3-g5.crl0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://s2.symcb.com0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://s2.symcb.com0e
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://s2.symcb.com0k
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://server.appleAA.com/soft/AppErrorload.aspx?loadid=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://server.appleAA.com/soft/UserSoftPost.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://server.appleAA.com/update/otherupdate.aspx?v=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://server.dongbo.vn/soft/AppErrorload.aspx?loadid=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://server.dongbo.vn/soft/UserSoftPost.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://server.dongbo.vn/tbCloud/TbzsData/Install.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://server.dongbo.vn/tbCloud/TbzsData/PCData.aspx?op=1&amp;v=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://server.dongbo.vn/tbCloud/TbzsData/RubbishApi.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://server.dongbo.vn/tbCloud/TbzsData/tbzs20ver.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://server.dongbo.vn/tbCloud/TbzsData/tbzsMsg.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://server.dongbo.vn/tbcloud/itunes/itunesPv.aspx?v=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://server.dongbo.vn/tbcloud/itunes/itunespv_appload.aspx?v=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://server.dongbo.vn/update/otherupdate.aspx?v=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2140928933.0000000003448000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6038136579.0000000005071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://server.tongbu.com/soft/AppErrorload.aspx?loadid=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://server.tongbu.com/soft/UserSoftPost.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://server.tongbu.com/tbCloud/TbzsData/Install.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://server.tongbu.com/tbCloud/TbzsData/PCData.aspx?op=1&amp;v=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://server.tongbu.com/tbCloud/TbzsData/RubbishApi.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://server.tongbu.com/tbCloud/TbzsData/tbzsMsg.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://server.tongbu.com/tbCloud/TbzsData/tbzsSeaVer.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://server.tongbu.com/tbcloud/itunes/itunesPv.aspx?v=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2140928933.0000000003448000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6038136579.0000000005071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://server.tongbu.com/tbcloud/itunes/itunespv_appload.aspx?v=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2140928933.0000000003448000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6038136579.0000000005071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://server.tongbu.com/update/otherupdate.aspx?v=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://server.tongbu.com/update/ulog/kkzsupdate.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://server.tongbu.com/update/ulog/wxtoolupdate.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://sss.appleAA.com/test/itunes/getAppsData.php
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://sss.appleAA.com/test/itunes/getUpdateUrl.php
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://sss.tongbu.com/test/itunes/getAppsData.php
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://sss.tongbu.com/test/itunes/getUpdateUrl.php
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://support.apple.com/kb/ht2731
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://t.appleAA.com/device/
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://t.appleAA.com/infopage/downheader.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://t.appleAA.com/infopage/mounter.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://t.appleAA.com/infopage/payment.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://t.appleAA.com/infopage/regular.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://t.appleAA.com/shell/
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://t.appleAA.com/tbzs20/ZSUpdateLog.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://t.appleAA.com/tbzs20/settings.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://t.appleAA.com/tbzs20/sitexml.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://t.appleAA.com/tbzs30/ZSUpdateLog.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://t.appleAA.com/tbzs30/sitexml.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://t.dongbo.com/tbzs30/sitexml.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://t.dongbo.vn/device/
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://t.dongbo.vn/infopage/downheader.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://t.dongbo.vn/infopage/mounter.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://t.dongbo.vn/infopage/payment.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://t.dongbo.vn/infopage/regular.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://t.dongbo.vn/shell/
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://t.dongbo.vn/tbzs20/ZSUpdateLog.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://t.dongbo.vn/tbzs20/settings.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://t.dongbo.vn/tbzs20/sitexml.aspx
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://t.symcb.com/ThawtePCA.crl0)
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://t.symcd.com01
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://t.tongbu.com/device/
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://t.tongbu.com/infopage/downheader.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://t.tongbu.com/infopage/mounter.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://t.tongbu.com/infopage/payment.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://t.tongbu.com/infopage/regular.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://t.tongbu.com/shell/
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://t.tongbu.com/tbzs20/ZSUpdateLog.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://t.tongbu.com/tbzs20/settings.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://t.tongbu.com/tbzs20/sitexml.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://t.tongbu.com/tbzs30/ZSUpdateLog.aspx
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://t1.symcb.com/ThawtePCA.crl0)
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://t1.symcb.com/ThawtePCA.crl0/
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://t2.symcb.com0;
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://t2.symcb.com0A
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tbconfig.tongbu.com/android/atui.ashx?appname=androiddaemon&amp;channel=&amp;channel_ext=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tbconfig.tongbu.com/android/atui.ashx?appname=androidtui&amp;channel=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tblab.dongbo.vn/rankingdata/getAppsData.php
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tblab.dongbo.vn/rankingdata/getUpdateUrl.php
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tbsoftup.appleAA.com/tbsoft.aspx?type=207&amp;s=pc&amp;sn=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tbsoftup.appleAA.com/tbsoft.aspx?type=211&amp;s=pc&amp;break=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tbsoftup.dongbo.vn/tbsoft.aspx?type=207&amp;s=pc&amp;sn=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tbsoftup.dongbo.vn/tbsoft.aspx?type=208&amp;s=pc&amp;sn=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tbsoftup.tongbu.com/tbsoft.aspx?type=207&amp;s=pc&amp;sn=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tbsoftup.tongbu.com/tbsoft.aspx?type=208&amp;s=pc&amp;sn=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tbsoftup.tongbu.com/tbsoft.aspx?type=213&amp;s=pc&amp;lan=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tbsoftup.tongbu.com/tbsoft.aspx?type=216&amp;s=pc&amp;break=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tbzsapi.appleAA.com/api.aspx?type=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tbzsapi.appleAA.com/tbzsdata/Install.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tbzsapi.appleAA.com/tbzsdata/PCData.aspx?op=1&amp;v=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tbzsapi.appleAA.com/tbzsdata/RubbishApi.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tbzsapi.appleAA.com/tbzsdata/WarrantLog.aspx?t=1
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tbzsapi.appleAA.com/tbzsdata/itunes/iTunesOffset.aspx?v=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tbzsapi.appleAA.com/tbzsdata/itunesPv.aspx?v=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tbzsapi.appleAA.com/tbzsdata/itunespv_appload.aspx?v=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tbzsapi.appleAA.com/tbzsdata/tbzs20ver.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tbzsapi.appleAA.com/tbzsdata/tbzsMsg.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tbzsapi.appleAA.com/tbzsdata/tbzsjbPlugins.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tbzsapi.tongbu.com/Tongbu.PC/PcApi.ashx?PushAd&amp;device=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tbzsapi.tongbu.com/api.aspx?type=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tbzsapi.tongbu.com/tbzsdata/Install.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tbzsapi.tongbu.com/tbzsdata/PCData.aspx?op=1&amp;v=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tbzsapi.tongbu.com/tbzsdata/RubbishApi.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tbzsapi.tongbu.com/tbzsdata/WarrantLog.aspx?t=1
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tbzsapi.tongbu.com/tbzsdata/itunes/iTunesOffset.aspx?v=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tbzsapi.tongbu.com/tbzsdata/itunesPv.aspx?v=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tbzsapi.tongbu.com/tbzsdata/itunespv_appload.aspx?v=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tbzsapi.tongbu.com/tbzsdata/tbzs20ver.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tbzsapi.tongbu.com/tbzsdata/tbzsMsg.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tbzsapi.tongbu.com/tbzsdata/tbzsjbPlugins.aspx
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tdshidai.appleAA.com/TbzsStat?v=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tdshidai.tongbu.com/TbzsStat_v2?v=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tintuc.dongbo.vn/view/52848.html
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tintuc.dongbo.vn/view/52852.html
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tintuc.dongbo.vn/view/52854.html
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tintuc.dongbo.vn/view/52863.html
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tintuc.dongbo.vn/view/52864.html
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tintuc.dongbo.vn/view/52866.html
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tintuc.dongbo.vn/view/52946.html
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tintuc.dongbo.vn/view/53279.html
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tintuc.dongbo.vn/view/53280.html
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tm.appleAA.com/music/api/music.aspx?mode=musicFindLogAdd&amp;tag=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tm.tongbu.com/music/api/music.aspx?mode=musicFindLogAdd&amp;tag=
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://tools.ietf.org/html/rfc3986#section-2.1.
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://tools.ietf.org/html/rfc3986#section-2.1.The
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tui.appleAA.com/?s=zsv2
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://tui.tongbu.com/?s=zsv2
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://upload.qiniu.com
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://v2.appleAA.com/app/api/apidown?appleid=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://v2.appleAA.com/appshare/api/partnersdownload?appleid=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://v2.appleAA.com/css/inside_view.css
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://v2.appleAA.com/js/inside_view.js
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://v2.appleAA.com/js/jquery.tongbu.js?0112
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://v2.dongbo.vn/app/api/apidown?appleid=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://v2.dongbo.vn/app/feedback?lan=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://v2.dongbo.vn/app/inside
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://v2.dongbo.vn/appshare/app/
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://v2.tongbu.com/android/app/index.html?apk=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://v2.tongbu.com/app/
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://v2.tongbu.com/app/api/apidown?appleid=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://v2.tongbu.com/appshare/api/partnersdownload?appleid=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://v2.tongbu.com/appshare/app/
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://v2.tongbu.com/css/inside_view.css
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://v2.tongbu.com/js/inside_view.js
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://v2.tongbu.com/js/jquery.tongbu.js?0112
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://v3.tongbu.com/face/
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://web.airdroid.com?token=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://weibo.com/tongbuassistant
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://wpad/wpad.dat
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://wpad/wpad.datFindProxyForURLWPAD
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.airdroid.com/
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.airdroid.com/pricing/airdroid-cast/?lang=
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.apple.com/DTDs/PropertyList-1.0.dtd
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://www.apple.com/cn/itunes/download/
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://www.appleAA.com
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://www.appleAA.com/?s=zsv2
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.certplus.com/CRL/class2.crl0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.digicert.com/CACerts/DigiCertHighAssuranceEVRootCA.crt0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.digicert.com/ssl-cps-repository.htm0
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://www.dongbo.vn
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://www.dongbo.vn/pc.php
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.entrust.net/CPS0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.entrust.net/rpa0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.geotrust.com/resources/cps0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.geotrust.com/resources/cps0)
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.geotrust.com/resources/cps0A
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.google.com/support/talk/bin/request.py
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://www.iClover.com
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.ibm.com/data/dtd/v11/ibmxhtml1-transitional.dtd
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.ibm.com/data/dtd/v11/ibmxhtml1-transitional.dtd-//W3C//DTD
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000004450000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.ietf.org/id/draft-holmer-rmcat-transport-wide-cc-extensions
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000004450000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.ietf.org/id/draft-holmer-rmcat-transport-wide-cc-extensionsVP8VP9H264dektu
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.jclark.com/xt
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.jclark.com/xtxsltSortComp:
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.keynectis.com/PC07
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.keynectis.com/PC08
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.sourcenext.com/product/titlelist/
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.startssl.com/intermediate.pdf0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.startssl.com/policy.pdf04
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.startssl.com/sfsca.crl0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.startssl.com/sfsca.crt0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.symauth.com/cps0(
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.symauth.com/rpa0)
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.symauth.com/rpa00
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.symauth.com/rpa04
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.telesec.de/serverpass/cps.html0
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://www.tongbu.com/?s=zsv2
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://www.tongbu.com/zhushou
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.trustcenter.de/crl/v2/tc_class_2_ca_II.crl
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000004450000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/abs-send-time
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/abs-send-timeurn:3gpp:video-orientationurn:ietf:params:
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.wosign.com/policy/0
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://www.yueyuzhushou.com/
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://www.yueyuzhushou.com/?s=zsv2
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://xmlsoft.org/XSLT/
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://xmlsoft.org/XSLT/Extension
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://xmlsoft.org/XSLT/namespace
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://xmlsoft.org/XSLT/namespacexsltNumberFormatDecimal:
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6324479836.00000000154BF000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://certs.godaddy.com/repository/0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://certs.starfieldtech.com/repository/0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000004450000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://chrome.google.com/webstore
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000004450000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://chrome.google.com/webstorehttps://clients2.google.com/service/update2/crx/detail/
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000004450000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://clients2.google.com/service/update2
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000004450000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://clients2.google.com/service/update2/crx
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://code.google.com/p/chromium/issues/detail?id=437569#c2
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002806000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://crbug.com/229412.
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002806000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://crbug.com/229412.Cannot
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000004450000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://crbug.com/401439).
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003045000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://d.android.com/reference/android/media/MediaFormat
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003045000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://developer.android.com/studio/releases/platform-tools
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003045000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://developer.android.com/studio/releases/platform-toolsFailed
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://developer.bluetooth.org/gatt/characteristics/Pages/CharacteristicsHome.aspx
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://developer.bluetooth.org/gatt/descriptors/Pages/DescriptorsHomePage.aspx
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://developer.bluetooth.org/gatt/services/Pages/ServicesHome.aspx
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003045000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://github.com/Genymobile/scrcpy
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://goo.gl/Y0ZkNV).
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://goo.gl/Y0ZkNV).localhost
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://goo.gl/rStTGz
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://help.airdroid.com/?source=pc
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://id-cast.airdroid.com/avatar/edit?q=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://id-cast.airdroid.com/country/getcountry?q=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://id-cast.airdroid.com/pc/autosignin
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://id-cast.airdroid.com/phone/unbinduserwithpwd?q=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://id-cast.airdroid.com/user/Captcha
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://id-cast.airdroid.com/user/signin
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://id-cast.airdroid.com/user/signup
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://id-cast.airdroid.com/user/tploginpc?service=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://id-cast.airdroid.com/user/tpsignuppc
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://id4.airdroid.com/p20/user/genquicksignintoken?q=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://lb.airdroid.com/?id=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://lb.airdroid.com?id=
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://log.getdropbox.com/hpkp
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://play.google.com/store/apps/details?id=com.sand.airdroid&amp;referrer=utm_source%3Dwin%26utm_
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://redirector.gvt1.com/edgedl/chrome/dict/
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://redirector.gvt1.com/edgedl/chrome/dict/SpellingServiceFeedbackEnabledhttps://www.googleapis.
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003045000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://sectigo.com/CPS0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://sectigo.com/CPS0B
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://sectigo.com/CPS0C
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://sectigo.com/CPS0D
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://secure.comodo.com/CPS0I
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://srv3.airdroid.com/p20/DeviceAll/Init?name=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://srv3.airdroid.com/p20/DeviceAll/UnBind?deviceId=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://srv3.airdroid.com/p20/DeviceAll/UpdateNetInfo?device_id=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://srv3.airdroid.com/p20/apk/getblacklist?q=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://srv3.airdroid.com/p20/apk/geticons?packageName=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://srv3.airdroid.com/p20/apk/updateblacklist/?q=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://srv3.airdroid.com/p20/cast/pcupgrade
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://srv3.airdroid.com/p20/cast/status?q=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://srv3.airdroid.com/p20/device/find?q=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://srv3.airdroid.com/p20/deviceall/index?q=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://srv3.airdroid.com/p20/friend/
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://srv3.airdroid.com/p20/friend/sysmsg?q=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://srv3.airdroid.com/p20/pc/getbetarelation?q=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://srv3.airdroid.com/p20/pc/getconfig
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://srv3.airdroid.com/p20/pc/getcustomurl?country=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://stat-push.airdroid.com/push/msg
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2403956126.0000000004825000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.2371933145.0000000004825000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://stat3.airdroid.com/
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2403956126.0000000004825000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.2371933145.0000000004825000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://stat3.airdroid.com/4~u
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://stat3.airdroid.com/cast/startup/?unique_id=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://stat3.airdroid.com/encrypt/rsa?q=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://stat3.airdroid.com/error/collection?q=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://stat3.airdroid.com/file/download
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://stat3.airdroid.com/file/upload
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://stat3.airdroid.com/login/pc/?account_id=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://stat3.airdroid.com/pc/appmsg
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://stat3.airdroid.com/pc/connect
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2378705742.00000000007D2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://stat3.airdroid.com/pc/installstat?
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.2371933145.00000000048A0000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.2373708801.00000000048B0000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2404459855.00000000048B1000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://stat3.airdroid.com/pc/installstat?mac=ECF4BBEA15
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.2371933145.0000000004825000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://stat3.airdroid.com/pc/installstat?mac=ECF4BBEA1588&os_ver=10%2E0&os_lang=2057&ui_lang=1033&a
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.2371933145.00000000048A0000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.2373708801.00000000048B0000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2404459855.00000000048B1000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://stat3.airdroid.com/pc/installstat?mac=ECF4BBEA15N
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://stat3.airdroid.com/pc/log
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://stat3.airdroid.com/pc/use?q=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://stat3.airdroid.com/push/collect?q=
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000004450000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://storage.googleapis.com/mandoline/
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000004450000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://storage.googleapis.com/mandoline/latest/win/e:
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://td.airdroid.com/castwinstat?v=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://uc-file.airdroid.com/msg/get
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://uc.airdroid.com/avatar/auth?q=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://uc.airdroid.com/response?q=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://uc.airdroid.com/v2/auth?q=
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://webcast.airdroid.com/
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003045000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://wiki.libsdl.org/SDL_HINT_RENDER_DRIVER
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.airdroid.cn/user-center/#cast-team-manage?lang=
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.2371933145.00000000048A0000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.2373708801.00000000048B0000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2404459855.00000000048B1000.00000004.00000020.00020000.00000000.sdmp, Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.airdroid.com
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp, Helper.exe, 00000004.00000002.2137312482.0000000002522000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6277046795.0000000011411000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6227897477.000000000E1FE000.00000004.00000020.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6227897477.000000000E189000.00000004.00000020.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6227897477.000000000E1B7000.00000004.00000020.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6185719139.00000000099B0000.00000004.00000020.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5967265325.0000000002401000.00000004.00000020.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6185719139.00000000099D9000.00000004.00000020.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6160606042.00000000069C0000.00000004.00000020.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6185719139.00000000099C3000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.airdroid.com/
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2378705742.00000000007D2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.airdroid.com/PublisherInstaller
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.1958158678.0000000004851000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.1958882274.000000000484A000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.1957929974.000000000484A000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.1958839967.00000000048B1000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.1958632786.000000000484A000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.1958125105.00000000048C1000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.1957990124.000000000484F000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.1957821099.0000000004891000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.1988556733.00000000048B1000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.airdroid.com/legal/privacy
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2404459855.00000000048B1000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.2371933145.0000000004825000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.2373456059.00000000048CF000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.airdroid.com/thankyou/install-airdroid-cast.html
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2403956126.0000000004825000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.2371933145.0000000004825000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.airdroid.com/thankyou/install-airdroid-cast.html&
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.2371933145.00000000048A0000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.2373708801.00000000048B0000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2404459855.00000000048B1000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.airdroid.com/thankyou/install-airdroid-cast.html.Z
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2403956126.00000000048A0000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.2371933145.00000000048A0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.airdroid.com/thankyou/install-airdroid-cast.html3t
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2376543318.0000000000625000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.airdroid.com/thankyou/install-airdroid-cast.htmlC:
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2403956126.00000000048A0000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.2371933145.00000000048A0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.airdroid.com/thankyou/install-airdroid-cast.htmlXu
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2403956126.0000000004825000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.2371933145.0000000004825000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.airdroid.com/thankyou/install-airdroid-cast.htmlb
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2403956126.0000000004825000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.2371933145.0000000004825000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.airdroid.com/thankyou/install-airdroid-cast.htmle
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.2371933145.00000000048A0000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.2373708801.00000000048B0000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2404459855.00000000048B1000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.airdroid.com/thankyou/install-airdroid-cast.htmlh
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2403956126.0000000004825000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.2371933145.0000000004825000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.airdroid.com/thankyou/install-airdroid-cast.htmli
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2378705742.0000000000836000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.airdroid.com/thankyou/install-airdroid-cast.htmll
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2378705742.00000000007D2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.airdroid.com/thankyou/install-airdroid-cast.htmlopen
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2403956126.00000000048A0000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.2371933145.00000000048A0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.airdroid.com/thankyou/install-airdroid-cast.htmlrt(
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2403956126.00000000048A0000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.2371933145.00000000048A0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.airdroid.com/thankyou/install-airdroid-cast.htmls
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.alphassl.com/repository/03
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.chromestatus.com/feature/4765305641369600
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.chromestatus.com/feature/5663288008376320
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.chromestatus.com/features/%s
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.chromestatus.com/features/4668884095336448
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.chromestatus.com/features/6750456638341120
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.digicert.com/CPS0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.geotrust.com/resources/cps04
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.geotrust.com/resources/cps06
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.geotrust.com/resources/repository0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.globalsign.com/repository/03
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000004450000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.google.
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000004450000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.google./_/chrome/ServiceWorker.DiskCache.InitResultServiceWorker.DiskCache.ReadResponseR
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000004450000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.google.com/speech-api/full-duplex/v1
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000004450000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.google.com/speech-api/full-duplex/v1/down?/up?
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000004450000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.google.com/speech-api/v1/recognize?xjerr=1&client=chromium&
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000004450000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.google.com/speech-api/v1/recognize?xjerr=1&client=chromium&hypothesesParseServerResponse
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000004450000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.googleapis.com/geolocation/v1/geolocate
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000004450000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.googleapis.com/geolocation/v1/geolocate4
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.googleapis.com/rpc
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.googleapis.com/rpcresult.spellingCheckResponse.misspellingserror
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.thawte.com/cps
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.thawte.com/cps0
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.thawte.com/cps0)
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.thawte.com/cps02
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.thawte.com/cps04
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.thawte.com/cps07
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://xhr.spec.whatwg.org/.
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49744
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49986
Source: unknown Network traffic detected: HTTP traffic on port 49817 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49743
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49985
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49742
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49984
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49983
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49982
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49981
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49980
Source: unknown Network traffic detected: HTTP traffic on port 49932 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49852 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50131 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50211 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50177 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50257 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49979
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49736
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49978
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49735
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49977
Source: unknown Network traffic detected: HTTP traffic on port 49772 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49976
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49975
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49974
Source: unknown Network traffic detected: HTTP traffic on port 50085 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49972
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49971
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49970
Source: unknown Network traffic detected: HTTP traffic on port 50165 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49784 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49749 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50004 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49909 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50292 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49969
Source: unknown Network traffic detected: HTTP traffic on port 49978 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49886 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49968
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49967
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49966
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49965
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49964
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49963
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49962
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49961
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49960
Source: unknown Network traffic detected: HTTP traffic on port 49966 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50189 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49760 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50108 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50073 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50028 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49805 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49958
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49957
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49956
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49955
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49954
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49953
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49952
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49951
Source: unknown Network traffic detected: HTTP traffic on port 49839 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49864 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49950
Source: unknown Network traffic detected: HTTP traffic on port 50280 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49944 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49910 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50051 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49796 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50153 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49949
Source: unknown Network traffic detected: HTTP traffic on port 50235 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49948
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49947
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49946
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49945
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49944
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49943
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49788
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49787
Source: unknown Network traffic detected: HTTP traffic on port 50061 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49786
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49785
Source: unknown Network traffic detected: HTTP traffic on port 49922 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49784
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49783
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49782
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49781
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49780
Source: unknown Network traffic detected: HTTP traffic on port 49968 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50221 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49807 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50301 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49759 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49779
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49778
Source: unknown Network traffic detected: HTTP traffic on port 50347 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49777
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49776
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49775
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49774
Source: unknown Network traffic detected: HTTP traffic on port 49862 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49773
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49772
Source: unknown Network traffic detected: HTTP traffic on port 50282 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50247 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50095 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50155 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49991 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49769
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49768
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49767
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49766
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49765
Source: unknown Network traffic detected: HTTP traffic on port 50313 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49763
Source: unknown Network traffic detected: HTTP traffic on port 50038 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49762
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49761
Source: unknown Network traffic detected: HTTP traffic on port 50143 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49760
Source: unknown Network traffic detected: HTTP traffic on port 49840 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50208 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49956 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50259 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49759
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49758
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49757
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49999
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49756
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49998
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49755
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49997
Source: unknown Network traffic detected: HTTP traffic on port 50121 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49996
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49995
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49994
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49751
Source: unknown Network traffic detected: HTTP traffic on port 50016 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49750
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49992
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49991
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49990
Source: unknown Network traffic detected: HTTP traffic on port 49786 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49874 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49747 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49829 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50199 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49749
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49748
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49747
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49989
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49746
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49988
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49745
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49987
Source: unknown Network traffic detected: HTTP traffic on port 50036 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50336
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50339
Source: unknown Network traffic detected: HTTP traffic on port 49672 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50338
Source: unknown Network traffic detected: HTTP traffic on port 50151 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50116 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50225 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49769 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49803 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50071 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50305 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49849 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49900 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50106
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50348
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50105
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50347
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50108
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50107
Source: unknown Network traffic detected: HTTP traffic on port 49837 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50109
Source: unknown Network traffic detected: HTTP traffic on port 49929 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50100
Source: unknown Network traffic detected: HTTP traffic on port 49872 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50339 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50344
Source: unknown Network traffic detected: HTTP traffic on port 50352 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50101
Source: unknown Network traffic detected: HTTP traffic on port 50243 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50343
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50104
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50103
Source: unknown Network traffic detected: HTTP traffic on port 49964 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50128 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49798 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50197 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49735 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50117
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50116
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50119
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50118
Source: unknown Network traffic detected: HTTP traffic on port 50317 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50111
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50353
Source: unknown Network traffic detected: HTTP traffic on port 49930 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50110
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50352
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50113
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50112
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50115
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50114
Source: unknown Network traffic detected: HTTP traffic on port 49745 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49986 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49850 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50175 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50213 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49757 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49799
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50128
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49798
Source: unknown Network traffic detected: HTTP traffic on port 50012 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50127
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49797
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49796
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50129
Source: unknown Network traffic detected: HTTP traffic on port 50255 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49795
Source: unknown Network traffic detected: HTTP traffic on port 49952 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49794
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49793
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49792
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49791
Source: unknown Network traffic detected: HTTP traffic on port 50093 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50122
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50121
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50124
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50123
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50126
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50125
Source: unknown Network traffic detected: HTTP traffic on port 49825 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49884 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49907 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49789
Source: unknown Network traffic detected: HTTP traffic on port 49779 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49859 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49894 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50106 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50081 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50304
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50305
Source: unknown Network traffic detected: HTTP traffic on port 50173 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50308
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50307
Source: unknown Network traffic detected: HTTP traffic on port 49919 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49954 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50014 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49788 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49988 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49767 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50302
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50301
Source: unknown Network traffic detected: HTTP traffic on port 49827 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50046 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49882 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50141 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50233 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50314
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50317
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50316
Source: unknown Network traffic detected: HTTP traffic on port 49976 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50319
Source: unknown Network traffic detected: HTTP traffic on port 50118 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49815 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50311
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50310
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50313
Source: unknown Network traffic detected: HTTP traffic on port 50223 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50024 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50163 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49860 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49755 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49998 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50245 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50320
Source: unknown Network traffic detected: HTTP traffic on port 50058 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50322
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50323
Source: unknown Network traffic detected: HTTP traffic on port 50002 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50185 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49920 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49926 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50054
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50296
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50053
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50295
Source: unknown Network traffic detected: HTTP traffic on port 49789 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50056
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50298
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50055
Source: unknown Network traffic detected: HTTP traffic on port 49766 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50058
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50057
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50299
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50059
Source: unknown Network traffic detected: HTTP traffic on port 49961 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50061
Source: unknown Network traffic detected: HTTP traffic on port 50286 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50060
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50063
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50062
Source: unknown Network traffic detected: HTTP traffic on port 50343 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50045 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50148 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50274 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50065
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50064
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50067
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50066
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50069
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50068
Source: unknown Network traffic detected: HTTP traffic on port 50205 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50240 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50183 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50070
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50072
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50071
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50074
Source: unknown Network traffic detected: HTTP traffic on port 49823 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50073
Source: unknown Network traffic detected: HTTP traffic on port 50080 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50308 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49869 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50227 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50195 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50075
Source: unknown Network traffic detected: HTTP traffic on port 50057 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50078
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50077
Source: unknown Network traffic detected: HTTP traffic on port 50114 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49892 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50079
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50081
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50080
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50082
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50085
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50084
Source: unknown Network traffic detected: HTTP traffic on port 49904 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49847 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50087
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50086
Source: unknown Network traffic detected: HTTP traffic on port 49870 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50089
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50088
Source: unknown Network traffic detected: HTTP traffic on port 50079 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50090
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50092
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50094
Source: unknown Network traffic detected: HTTP traffic on port 49983 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50093
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50096
Source: unknown Network traffic detected: HTTP traffic on port 49938 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50023 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50095
Source: unknown Network traffic detected: HTTP traffic on port 49811 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50018
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50017
Source: unknown Network traffic detected: HTTP traffic on port 50193 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50259
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50019
Source: unknown Network traffic detected: HTTP traffic on port 49813 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49951 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50010
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50251
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50012
Source: unknown Network traffic detected: HTTP traffic on port 49916 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50254
Source: unknown Network traffic detected: HTTP traffic on port 50055 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50253
Source: unknown Network traffic detected: HTTP traffic on port 50090 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50014
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50256
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50255
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50016
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50258
Source: unknown Network traffic detected: HTTP traffic on port 50353 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50015
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50257
Source: unknown Network traffic detected: HTTP traffic on port 50161 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50261
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50260
Source: unknown Network traffic detected: HTTP traffic on port 49776 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49845 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50029
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50028
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50021
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50263
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50020
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50262
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50023
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50265
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50022
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50264
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50025
Source: unknown Network traffic detected: HTTP traffic on port 49742 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50024
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50027
Source: unknown Network traffic detected: HTTP traffic on port 49780 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49879 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49985 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50264 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50030
Source: unknown Network traffic detected: HTTP traffic on port 50021 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50272
Source: unknown Network traffic detected: HTTP traffic on port 50138 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50271
Source: unknown Network traffic detected: HTTP traffic on port 50067 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50039
Source: unknown Network traffic detected: HTTP traffic on port 49995 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50298 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49928 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50032
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50274
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50031
Source: unknown Network traffic detected: HTTP traffic on port 49857 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50276
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50033
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50275
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50036
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50035
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50038
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50037
Source: unknown Network traffic detected: HTTP traffic on port 50242 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49801 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50281
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50280
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50041
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50283
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50040
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50282
Source: unknown Network traffic detected: HTTP traffic on port 50104 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50089 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50203 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50276 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50033 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50171 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50043
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50285
Source: unknown Network traffic detected: HTTP traffic on port 49835 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50042
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50045
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50287
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50044
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50286
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50047
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50046
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50288
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50049
Source: unknown Network traffic detected: HTTP traffic on port 49880 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50050
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50292
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50291
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50052
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50294
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50051
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50293
Source: unknown Network traffic detected: HTTP traffic on port 50126 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49792 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49890 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50168 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50311 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50122 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50260 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49912 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49958 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50219 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49889 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49946 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50018 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50077 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50134 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50053 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49981 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50237 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49924 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50099 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49831 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50031 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50156 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50043 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50272 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50100 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49774 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49782 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50249 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50207 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50323 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49808 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50294 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50006 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50181 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50065 -> 443
Source: unknown HTTPS traffic detected: 172.202.163.200:443 -> 192.168.2.4:49735 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.35.72:443 -> 192.168.2.4:49736 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.107.246.60:443 -> 192.168.2.4:49744 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:49777 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.202.163.200:443 -> 192.168.2.4:49778 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:49827 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:49826 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.230.180:443 -> 192.168.2.4:49828 version: TLS 1.2
Source: unknown HTTPS traffic detected: 170.106.112.204:443 -> 192.168.2.4:49861 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.181.65:443 -> 192.168.2.4:49870 version: TLS 1.2
Source: unknown HTTPS traffic detected: 170.106.112.204:443 -> 192.168.2.4:49875 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49888 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49913 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:49970 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:49979 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.35.72:443 -> 192.168.2.4:50010 version: TLS 1.2
Source: unknown HTTPS traffic detected: 173.222.162.32:443 -> 192.168.2.4:50109 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.107.246.60:443 -> 192.168.2.4:50225 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50254 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50255 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50256 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50257 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50260 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50261 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50262 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50263 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50264 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50265 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50272 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50274 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50275 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50276 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50280 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50281 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50282 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50283 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50285 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50286 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50288 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50287 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50294 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50291 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50292 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50293 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50295 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50296 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50299 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50298 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50301 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50302 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50304 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50305 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50307 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50308 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50310 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50311 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50314 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50313 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50316 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50317 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50319 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50320 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50322 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50323 version: TLS 1.2
Source: unknown HTTPS traffic detected: 20.189.173.3:443 -> 192.168.2.4:50336 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50338 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50339 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50343 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50344 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50347 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50348 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50352 version: TLS 1.2
Source: unknown HTTPS traffic detected: 49.51.42.41:443 -> 192.168.2.4:50353 version: TLS 1.2
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000004450000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: RegisterRawInputDevices() failed for RIDEV_INPUTSINK memstr_e1fba189-e
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\VirtualDesktop\VirtualDesktop.cat Jump to dropped file
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process Stats: CPU usage > 49%
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\driver\amd64\libusb0.sys Jump to behavior
Source: ucrtbase.dll.0.dr Static PE information: Resource name: RT_VERSION type: COM executable for DOS
Source: postproc-55.dll.0.dr Static PE information: Number of sections : 12 > 10
Source: avfilter-7.dll.0.dr Static PE information: Number of sections : 11 > 10
Source: avcodec-58.dll.0.dr Static PE information: Number of sections : 12 > 10
Source: api-ms-win-crt-stdio-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-crt-private-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-crt-process-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-crt-math-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-crt-time-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-crt-locale-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-crt-utility-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-crt-filesystem-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-crt-multibyte-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-crt-heap-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-crt-runtime-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: api-ms-win-crt-string-l1-1-0.dll.0.dr Static PE information: No import functions for PE file found
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003045000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamemsvcp120.dll^ vs AirDroid_Cast_Desktop_Client_1.2.1.0.exe
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003045000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamemsvcp140.dll^ vs AirDroid_Cast_Desktop_Client_1.2.1.0.exe
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: std::stringRefCountedStringTraceEventMemoryOverheadresident_size%s/%sWorkItemCallback::Run\VarFileInfo\TranslationCompanyShortNameCompanyNameProductNameInternalNameCommentsProductShortNameProductVersionLegalCopyrightLegalTrademarksFileDescriptionFileVersionPrivateBuildSpecialBuildOriginalFilenameOfficial BuildLastChange\StringFileInfo\%04x%04x\%ls1 vs AirDroid_Cast_Desktop_Client_1.2.1.0.exe
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamelibcef.dll vs AirDroid_Cast_Desktop_Client_1.2.1.0.exe
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamelibimd.dllB vs AirDroid_Cast_Desktop_Client_1.2.1.0.exe
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamemsvcr120.dll^ vs AirDroid_Cast_Desktop_Client_1.2.1.0.exe
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamepostproc-55.dll. vs AirDroid_Cast_Desktop_Client_1.2.1.0.exe
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameswresample-3.dll. vs AirDroid_Cast_Desktop_Client_1.2.1.0.exe
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameswscale-5.dll. vs AirDroid_Cast_Desktop_Client_1.2.1.0.exe
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameucrtbase.dllj% vs AirDroid_Cast_Desktop_Client_1.2.1.0.exe
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamevccorlib120.DLL^ vs AirDroid_Cast_Desktop_Client_1.2.1.0.exe
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamevccorlib140.DLL^ vs AirDroid_Cast_Desktop_Client_1.2.1.0.exe
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamevcruntime140.dll^ vs AirDroid_Cast_Desktop_Client_1.2.1.0.exe
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000031E2000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamemsvcr100_clr0400.dll^ vs AirDroid_Cast_Desktop_Client_1.2.1.0.exe
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: AirDroidCastInstaller.exe.0.dr, iPqB10mZn73WBojA0P.cs Cryptographic APIs: 'CreateDecryptor'
Source: AirDroidCastInstaller.exe.0.dr, iPqB10mZn73WBojA0P.cs Cryptographic APIs: 'CreateDecryptor'
Source: AirDroidCastInstaller.exe.0.dr, iPqB10mZn73WBojA0P.cs Cryptographic APIs: 'CreateDecryptor'
Source: jmdns.dll.0.dr, DNSStateTask.cs Task registration methods: 'createOugoing'
Source: Helper.exe, 00000004.00000002.2137312482.0000000002507000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000004.00000002.2140928933.0000000003448000.00000004.00000800.00020000.00000000.sdmp, Helper.exe, 00000007.00000002.2240434241.0000000002D3E000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6038136579.0000000005071000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: ,.abap,.as,.ada,.adb,.htaccess,.htgroups,.htpasswd,.conf,.asciidoc,.asm,.ahk,.bat,.cmd,.c9search_results,.cpp,.c,.cc,.cxx,.h,.hh,.hpp,.clj,.cbl,.cob,.coffee,.cf,.cson,.cakefile,.cfm,.cs,.css,.curly,.d,.di,.dart,.diff,.patch,.dot,.erl,.hrl,.ejs,.frt,.fs,.ldr,.ftl,.glsl,.frag,.vert,.go,.groovy,.haml,.hbs,.handlebars,.tpl,.mustache,.hs,.hx,.html,.htm,.xhtml,.cshtml,.erb,.rhtml,.ini,.cfg,.prefs,.jack,.jade,.java,.js,.jsm,.json,.oexe,.jq,.jsp,.jsx,.jl,.tex,.latex,.ltx,.bib,.less,.liquid,.lisp,.ls,.logic,.lql,.lsl,.lua,.lp,.lucene,.makefile,.gnumakefile,.ocamlmakefile,.make,.matlab,.md,.markdown,.mel,.mysql,.mc,.mush,.nix,.m,.mm,.ml,.mli,.pas,.p,.pl,.pm,.pgsql,.php,.phtml,.ps1,.plg,.prolog,.properties,.proto,.py,.r,.rd,.rb,.ru,.gemspec,.rake,.guardfile,.rakefile,.gemfile,.rs,.sass,.scad,.scala,.scm,.rkt,.scss,.sh,.bash,..bashrc,.sjs,.space,.snippets,.soy,.sql,.styl,.stylus,.svg,.tcl,.txt,.log,.textile,.toml,.twig,.ts,.typescript,.str,.vbs,.vm,.v,.vh,.sv,.svh,.xml,.rdf,.rss,.wsdl,.xslt,.atom,.mathml,.mml,.xul,.xbl,.xq,.yaml,.yml,.strings,.sln,.lang
Source: AirDroidCast.exe, 00000009.00000002.5999506937.0000000004071000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: ,.abap,.as,.ada,.adb,.htaccess,.htgroups,.htpasswd,.conf,.asciidoc,.asm,.ahk,.bat,.cmd,.c9search_results,.cpp,.c,.cc,.cxx,.h,.hh,.hpp,.clj,.cbl,.cob,.coffee,.cf,.cson,.cakefile,.cfm,.cs,.css,.curly,.d,.di,.dart,.diff,.patch,.dot,.erl,.hrl,.ejs,.frt,.fs,.ldr,.ftl,.glsl,.frag,.vert,.go,.groovy,.haml,.hbs,.handlebars,.tpl,.mustache,.hs,.hx,.html,.htm,.xhtml,.cshtml,.erb,.rhtml,.ini,.cfg,.prefs,.jack,.jade,.java,.js,.jsm,.json,.oexe,.jq,.jsp,.jsx,.jl,.tex,.latex,.ltx,.bib,.less,.liquid,.lisp,.ls,.logic,.lql,.lsl,.lua,.lp,.lucene,.makefile,.gnumakefile,.ocamlmakefile,.make,.matlab,.md,.markdown,.mel,.mysql,.mc,.mush,.nix,.m,.mm,.ml,.mli,.pas,.p,.pl,.pm,.pgsql,.php,.phtml,.ps1,.plg,.prolog,.properties,.proto,.py,.r,.rd,.rb,.ru,.gemspec,.rake,.guardfile,.rakefile,.gemfile,.rs,.sass,.scad,.scala,.scm,.rkt,.scss,.sh,.bash,..bashrc,.sjs,.space,.snippets,.soy,.sql,.styl,.stylus,.svg,.tcl,.txt,.log,.textile,.toml,.twig,.ts,.typescript,.str,.vbs,.vm,.v,.vh,.sv,.svh,.xml,.rdf,.rss,.wsdl,.xslt,.atom,.mathml,.mml,.xul,.xbl,.xq,.yaml,.yml,.strings,.sln,.lang4'^q4'^q
Source: classification engine Classification label: sus26.troj.evad.winEXE@70/937@129/46
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\AirDroid Cast.lnk Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Mutant created: NULL
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5596:120:WilError_03
Source: C:\Program Files (x86)\AirDroid Cast\usbmuxd\usbmuxd.exe Mutant created: \Sessions\1\BaseNamedObjects\???d??????????
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5244:120:WilError_03
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Users\user\AppData\Local\Temp\nsz8951.tmp Jump to behavior
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : select AddressWidth from Win32_Processor
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File read: C:\Users\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: Helper.exe, 00000004.00000002.2140928933.0000000003448000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6038136579.0000000005071000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: SELECT * FROM [task] ORDER BY completed_time DESC,modify_time DESC, sort ASC;jSelect seq from [sqlite_sequence] WHERE [name]='task'LDELETE FROM [task] WHERE create_time<'0SELECT * from [task] {0},AND Description='{0}'
Source: Helper.exe, 00000004.00000002.2140928933.0000000003448000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6038136579.0000000005071000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: SELECT * FROM [task] {0} ORDER BY completed_time DESC,modify_time DESC, sort ASC; AND class='{0}'
Source: Helper.exe, 00000004.00000002.2140928933.0000000003448000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6038136579.0000000005071000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: INSERT INTO [play_record](dna,title,artist,album,genre,play_duration,duration,play_date,favorite,auto_play,upload) VALUES('{0}', '{1}', '{2}', '{3}','{4}' ,{5}, {6} , '{7}' ,{8},{9},{10});
Source: Helper.exe, 00000004.00000002.2140928933.0000000003448000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6038136579.0000000005071000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: select file_path from [music_info] where file_exist=1 and state=1l select wave from [music_info] where file_path='{0}';
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6336760625.00000000661F4000.00000002.00000001.01000000.0000002A.sdmp Binary or memory string: UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
Source: Helper.exe, 00000004.00000002.2140928933.0000000003448000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6038136579.0000000005071000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: update [music_info] set wave_analysis={0} where file_path='{1}';nupdate [music_info] set wave_analysis=0, {0} where {1};
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'
Source: Helper.exe, 00000004.00000002.2140928933.0000000003448000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6038136579.0000000005071000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: SELECT ROWID FROM [AirNotify] where Title='{0}' and Content='{1}' order by MsgDate desc limit 1;
Source: Helper.exe, 00000004.00000002.2140928933.0000000003448000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6038136579.0000000005071000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: INSERT INTO [music_info](file_path,music_category,music_folder,file_last_modify,file_size,file_exist,state,media_kind,width,height) VALUES('{0}','{1}','{2}','{3}','{4}',1,1,{5},{6},{7});
Source: Helper.exe, 00000004.00000002.2140928933.0000000003448000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6038136579.0000000005071000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: update [music_info] set file_exist_playlist={0} {1} where file_path='{2}';
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
Source: Helper.exe, 00000004.00000002.2140928933.0000000003448000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6038136579.0000000005071000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: select sql from sqlite_master where tbl_name='{0}' and type='table';
Source: Helper.exe, 00000004.00000002.2140928933.0000000003448000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6038136579.0000000005071000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: select [type],[SKU] from [OpenWith_Soft] where [UDID]='{0}' order by [ROWID] asc;
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6336760625.00000000661F4000.00000002.00000001.01000000.0000002A.sdmp Binary or memory string: INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);
Source: Helper.exe, 00000004.00000002.2140928933.0000000003448000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6038136579.0000000005071000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: select file_exist_playlist from [music_info] where file_path='{0}';
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND coalesce(rootpage,1)>0
Source: Helper.exe, 00000004.00000002.2140928933.0000000003448000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6038136579.0000000005071000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: update [monitored_folder] set [isMonitor] = 0 where music_folder='{0}';
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: SELECT name FROM sqlite_master WHERE type='table';
Source: AirDroidCast.exe, 00000009.00000002.6336760625.00000000661F4000.00000002.00000001.01000000.0000002A.sdmp Binary or memory string: CREATE TABLE "%w"."%w_node"(nodeno INTEGER PRIMARY KEY, data BLOB);CREATE TABLE "%w"."%w_rowid"(rowid INTEGER PRIMARY KEY, nodeno INTEGER);CREATE TABLE "%w"."%w_parent"(nodeno INTEGER PRIMARY KEY, parentnode INTEGER);INSERT INTO '%q'.'%q_node' VALUES(1, zeroblob(%d))
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6336760625.00000000661F4000.00000002.00000001.01000000.0000002A.sdmp Binary or memory string: CREATE TABLE %Q.'%q_docsize'(docid INTEGER PRIMARY KEY, size BLOB);
Source: Helper.exe, 00000004.00000002.2140928933.0000000003448000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6038136579.0000000005071000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: UPDATE [music_info] SET file_last_modify='{0}',music_category='{1}',music_folder='{2}' WHERE file_path='{3}';vUPDATE [music_info] SET file_exist=0 WHERE file_path='{0}';^delete from [music_info] where file_path='{0}';Xinsert into [music_info]({0}) values({1});
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6336760625.00000000661F4000.00000002.00000001.01000000.0000002A.sdmp Binary or memory string: CREATE TABLE IF NOT EXISTS %Q.'%q_stat'(id INTEGER PRIMARY KEY, value BLOB);
Source: Helper.exe, 00000004.00000002.2140928933.0000000003448000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6038136579.0000000005071000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: Select Identifier from [Ignore_Package_Info] where DeviceId ={0}xSelect rowid from [Ignore_Device_Info] where DeviceId='{0}';
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6336760625.00000000661F4000.00000002.00000001.01000000.0000002A.sdmp Binary or memory string: CREATE TABLE %Q.'%q_segdir'(level INTEGER,idx INTEGER,start_block INTEGER,leaves_end_block INTEGER,end_block INTEGER,root BLOB,PRIMARY KEY(level, idx));
Source: Helper.exe, 00000004.00000002.2140928933.0000000003448000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6038136579.0000000005071000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: SELECT ROWID FROM [task] WHERE [name]='{0}' AND (save_path='{1}' or save_path='{2}');
Source: Helper.exe, 00000004.00000002.2140928933.0000000003448000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6038136579.0000000005071000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: select [type],[SKU] from [OpenWith_Soft] where [UDID]='{0}' and type={1} order by [ROWID] asc;
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6336760625.00000000661F4000.00000002.00000001.01000000.0000002A.sdmp Binary or memory string: UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
Source: Helper.exe, 00000004.00000002.2140928933.0000000003448000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6038136579.0000000005071000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: UPDATE [music_info] SET file_last_modify='{0}',music_category='{1}',music_folder='{2}',state={3} WHERE file_path='{4}';
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6336760625.00000000661F4000.00000002.00000001.01000000.0000002A.sdmp Binary or memory string: UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6336760625.00000000661F4000.00000002.00000001.01000000.0000002A.sdmp Binary or memory string: CREATE TABLE %Q.'%q_segments'(blockid INTEGER PRIMARY KEY, block BLOB);
Source: AirDroidCast.exe, 00000009.00000002.6336760625.00000000661F4000.00000002.00000001.01000000.0000002A.sdmp Binary or memory string: CREATE TABLE xx( name TEXT, /* Name of table or index */ path TEXT, /* Path to page from root */ pageno INTEGER, /* Page number */ pagetype TEXT, /* 'internal', 'leaf' or 'overflow' */ ncell INTEGER, /* Cells on page (0 for overflow) */ payload INTEGER, /* Bytes of payload on this page */ unused INTEGER, /* Bytes of unused space on this page */ mx_payload INTEGER, /* Largest payload size of all cells */ pgoffset INTEGER, /* Offset of page in file */ pgsize INTEGER, /* Size of the page */ schema TEXT HIDDEN /* Database schema being analyzed */);
Source: Helper.exe, 00000004.00000002.2140928933.0000000003448000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6038136579.0000000005071000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: select [InputPath],[OutputPath],[Name],[Format],[FileSize],[Duration],[Status] from [MediaConvert] where 1=1;
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File read: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe "C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe"
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /cef
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Process created: C:\Program Files (x86)\AirDroid Cast\Launcher.exe "C:\Program Files (x86)\AirDroid Cast\Launcher.exe"
Source: C:\Program Files (x86)\AirDroid Cast\Launcher.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "/C:\Program Files (x86)\AirDroid Cast\helper.exe" "/shortcut" "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe"
Source: C:\Program Files (x86)\AirDroid Cast\Launcher.exe Process created: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe"
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://www.airdroid.com/thankyou/install-airdroid-cast.html
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2464 --field-trial-handle=2088,i,4236861329904630897,4026922523893907418,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe "C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe" devices
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\usbmuxd\usbmuxd.exe "C:\Program Files (x86)\AirDroid Cast\usbmuxd\usbmuxd.exe" -r airdroid_cast_lockdown
Source: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Program Files (x86)\AirDroid Cast\usbmuxd\usbmuxd.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe Process created: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe adb -L tcp:5037 fork-server server --reply-fd 612
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1728295044&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://m-embed.airdroid.com/cast_link.html?airdroidCast-code=028461947
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2052 --field-trial-handle=1992,i,17023292212832463388,15458255884109808151,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1728632298&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1728924290&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1729227592&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1729436201&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1729881109&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1731740999&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1731930001&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1732385552&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1732572421&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1732808823&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1733037619&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1733430021&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1733614776&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1733818369&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1734072662&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1734299484&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1734536931&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1734795916&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1735073456&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1735321796&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1735561937&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1735867118&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1736174910&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1737079663&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /cef Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Process created: C:\Program Files (x86)\AirDroid Cast\Launcher.exe "C:\Program Files (x86)\AirDroid Cast\Launcher.exe" Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://www.airdroid.com/thankyou/install-airdroid-cast.html Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Launcher.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "/C:\Program Files (x86)\AirDroid Cast\helper.exe" "/shortcut" "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe "C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe" devices
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\usbmuxd\usbmuxd.exe "C:\Program Files (x86)\AirDroid Cast\usbmuxd\usbmuxd.exe" -r airdroid_cast_lockdown
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1728295044&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1728632298&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1728924290&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1729227592&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1729436201&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1729881109&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2464 --field-trial-handle=2088,i,4236861329904630897,4026922523893907418,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe Process created: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe adb -L tcp:5037 fork-server server --reply-fd 612
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2052 --field-trial-handle=1992,i,17023292212832463388,15458255884109808151,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: shfolder.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: winnsi.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: schannel.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: riched20.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: usp10.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: msls31.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: mskeyprotect.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: ntasn1.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: dpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: ncrypt.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: ncryptsslp.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: linkinfo.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: ntshrui.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: cscapi.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: windows.shell.servicehostbuilder.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: onecoreuapcommonproxystub.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: ieframe.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: netapi32.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: wkscli.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: windows.staterepositoryps.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: edputil.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: mlang.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: policymanager.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: msvcp110_win.dll Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Section loaded: onecorecommonproxystub.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: version.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: mscorjit.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Launcher.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Launcher.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Launcher.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Launcher.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Launcher.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Launcher.exe Section loaded: msimg32.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Launcher.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Launcher.exe Section loaded: oledlg.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Launcher.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Launcher.exe Section loaded: oleacc.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Launcher.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Launcher.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Launcher.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Launcher.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: version.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: mscorjit.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: sxs.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: rasapi32.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: rasman.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: rtutils.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: linkinfo.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: dhcpcsvc6.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ntshrui.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: cscapi.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: schannel.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: scrrun.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: mscoree.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: apphelp.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: version.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: vcruntime140_clr0400.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: mscorjit.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: windows.storage.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: wldp.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: profapi.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: cryptsp.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: rsaenh.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: cryptbase.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: rasapi32.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: rasman.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: rtutils.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: uxtheme.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: mswsock.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: wbemcomn.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: winhttp.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: dwrite.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: iphlpapi.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: dhcpcsvc6.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: dhcpcsvc.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: amsi.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: userenv.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: dnsapi.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: rasadhlp.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: fwpuclnt.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: secur32.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: sspicli.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: schannel.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: windows.devices.radios.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: capabilityaccessmanagerclient.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: windows.devices.bluetooth.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: windows.networking.hostname.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: windows.networking.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: biwinrt.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: windows.networking.connectivity.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: firewallapi.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: fwbase.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: mskeyprotect.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: ntasn1.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: ncrypt.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: ncryptsslp.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: msasn1.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: gpapi.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: windowscodecs.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: textshaping.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: textinputframework.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: coreuicomponents.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: coremessaging.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: ntmarta.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: coremessaging.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: winnsi.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: napinsp.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: pnrpnsp.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: wshbth.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: nlaapi.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: winrnr.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: winmm.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: libusb0.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: avutil-56.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: avcodec-58.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: swscale-5.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: sdl2.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: swresample-3.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: libx265_main12.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: libx265.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: libx265_main10.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: libx265.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: devobj.dll
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Section loaded: msvcr100.dll
Source: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe Section loaded: apphelp.dll
Source: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe Section loaded: adbwinapi.dll
Source: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe Section loaded: cryptbase.dll
Source: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe Section loaded: adbwinusbapi.dll
Source: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe Section loaded: winusb.dll
Source: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe Section loaded: mswsock.dll
Source: C:\Program Files (x86)\AirDroid Cast\usbmuxd\usbmuxd.exe Section loaded: apphelp.dll
Source: C:\Program Files (x86)\AirDroid Cast\usbmuxd\usbmuxd.exe Section loaded: libusb-1.0.dll
Source: C:\Program Files (x86)\AirDroid Cast\usbmuxd\usbmuxd.exe Section loaded: libusb0.dll
Source: C:\Program Files (x86)\AirDroid Cast\usbmuxd\usbmuxd.exe Section loaded: mswsock.dll
Source: C:\Program Files (x86)\AirDroid Cast\usbmuxd\usbmuxd.exe Section loaded: windows.storage.dll
Source: C:\Program Files (x86)\AirDroid Cast\usbmuxd\usbmuxd.exe Section loaded: wldp.dll
Source: C:\Program Files (x86)\AirDroid Cast\usbmuxd\usbmuxd.exe Section loaded: profapi.dll
Source: C:\Program Files (x86)\AirDroid Cast\usbmuxd\usbmuxd.exe Section loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\AirDroid Cast\usbmuxd\usbmuxd.exe Section loaded: uxtheme.dll
Source: C:\Program Files (x86)\AirDroid Cast\usbmuxd\usbmuxd.exe Section loaded: libusbk.dll
Source: C:\Program Files (x86)\AirDroid Cast\usbmuxd\usbmuxd.exe Section loaded: winusb.dll
Source: C:\Program Files (x86)\AirDroid Cast\usbmuxd\usbmuxd.exe Section loaded: hid.dll
Source: C:\Program Files (x86)\AirDroid Cast\usbmuxd\usbmuxd.exe Section loaded: devobj.dll
Source: C:\Program Files (x86)\AirDroid Cast\usbmuxd\usbmuxd.exe Section loaded: msasn1.dll
Source: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe Section loaded: adbwinapi.dll
Source: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe Section loaded: cryptbase.dll
Source: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe Section loaded: adbwinusbapi.dll
Source: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe Section loaded: winusb.dll
Source: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe Section loaded: mswsock.dll
Source: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe Section loaded: devobj.dll
Source: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe Section loaded: uxtheme.dll
Source: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe Section loaded: msasn1.dll
Source: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe Section loaded: windows.storage.dll
Source: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe Section loaded: wldp.dll
Source: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe Section loaded: profapi.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: mscoree.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: version.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: vcruntime140_clr0400.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: uxtheme.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: mscorjit.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: windows.storage.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: wldp.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: profapi.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: cryptsp.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: rsaenh.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: cryptbase.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: wbemcomn.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: rasapi32.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: rasman.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: rtutils.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: dwrite.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: mswsock.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: amsi.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: userenv.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: winhttp.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: iphlpapi.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: dhcpcsvc6.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: dhcpcsvc.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: dnsapi.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: rasadhlp.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: fwpuclnt.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: secur32.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: sspicli.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: schannel.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: textinputframework.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: coreuicomponents.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: coremessaging.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ntmarta.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: windows.devices.radios.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: capabilityaccessmanagerclient.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: windows.devices.bluetooth.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: windows.networking.hostname.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: windows.networking.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: biwinrt.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: windows.networking.connectivity.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: windows.networking.hostname.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: firewallapi.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: biwinrt.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: fwbase.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: winnsi.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: mskeyprotect.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ntasn1.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ncrypt.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ncryptsslp.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: msasn1.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: gpapi.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: mscoree.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: version.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: vcruntime140_clr0400.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: uxtheme.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: mscorjit.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: windows.storage.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: wldp.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: profapi.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: cryptsp.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: rsaenh.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: cryptbase.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: wbemcomn.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: rasapi32.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: rasman.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: rtutils.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: mswsock.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: amsi.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: userenv.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: winhttp.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: iphlpapi.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: dhcpcsvc6.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: dhcpcsvc.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: dwrite.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: dnsapi.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: rasadhlp.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: fwpuclnt.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: secur32.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: sspicli.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: schannel.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: textinputframework.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: coreuicomponents.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: coremessaging.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ntmarta.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: coremessaging.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: winnsi.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: windows.devices.radios.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: capabilityaccessmanagerclient.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: windows.devices.bluetooth.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: windows.networking.hostname.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: windows.networking.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: biwinrt.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: windows.networking.connectivity.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: windows.networking.hostname.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: firewallapi.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: biwinrt.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: fwbase.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: mskeyprotect.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ntasn1.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ncrypt.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ncryptsslp.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: msasn1.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: gpapi.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: mscoree.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: version.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: vcruntime140_clr0400.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: uxtheme.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: mscorjit.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: windows.storage.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: wldp.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: profapi.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: cryptsp.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: rsaenh.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: cryptbase.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: rasapi32.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: rasman.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: rtutils.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: wbemcomn.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: amsi.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: userenv.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: mswsock.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: winhttp.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: iphlpapi.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: dhcpcsvc6.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: dhcpcsvc.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: dnsapi.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: rasadhlp.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: dwrite.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: fwpuclnt.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: secur32.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: sspicli.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: schannel.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: windows.devices.radios.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: textinputframework.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: coreuicomponents.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: coremessaging.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ntmarta.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: capabilityaccessmanagerclient.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: windows.devices.bluetooth.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: windows.networking.hostname.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: windows.networking.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: biwinrt.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: windows.networking.connectivity.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: firewallapi.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: biwinrt.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: fwbase.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: winnsi.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: mskeyprotect.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ntasn1.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ncrypt.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ncryptsslp.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: msasn1.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: gpapi.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: mscoree.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: version.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: vcruntime140_clr0400.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: uxtheme.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: mscorjit.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: windows.storage.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: wldp.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: profapi.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: cryptsp.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: rsaenh.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: cryptbase.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: wbemcomn.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: rasapi32.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: rasman.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: rtutils.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: mswsock.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: winhttp.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: iphlpapi.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: dhcpcsvc6.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: dhcpcsvc.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: dwrite.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: amsi.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: userenv.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: dnsapi.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: rasadhlp.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: fwpuclnt.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: secur32.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: sspicli.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: schannel.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: textinputframework.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: coreuicomponents.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: coremessaging.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ntmarta.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: coremessaging.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: winnsi.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: windows.devices.radios.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: capabilityaccessmanagerclient.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: windows.devices.bluetooth.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: windows.networking.hostname.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: windows.networking.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: biwinrt.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: windows.networking.connectivity.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: firewallapi.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: biwinrt.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: fwbase.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: mskeyprotect.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ntasn1.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ncrypt.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ncryptsslp.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: msasn1.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: gpapi.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: mscoree.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: version.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: vcruntime140_clr0400.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: uxtheme.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: mscorjit.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: windows.storage.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: wldp.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: profapi.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: cryptsp.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: rsaenh.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: cryptbase.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: wbemcomn.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: rasapi32.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: rasman.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: rtutils.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: mswsock.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: winhttp.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Section loaded: iphlpapi.dll
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32 Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File written: C:\Users\user\AppData\Local\Temp\nsz8AD9.tmp\ioSpecial.ini Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Automated click: OK
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Automated click: Next >
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Automated click: I Agree
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Automated click: Install
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Window detected: < &BackI &AgreeCancelSand Studio Sand StudioLicense AgreementPlease review the license terms before installing AirDroid Cast 1.2.1.0.Press Page Down to see the rest of the agreement.AIRDROID END USER LICENSE AGREEMENTEffective Date: 24 July2020TheAirDroid End User License Agreement(thereinafter "Agreement") is jointly concluded by You (the "End User"/"User") and SAND STUDIO for Your use of Services (defined below) provided by SAND STUDIO. "SAND STUDIO" refers to SAND STUDIO PTE.LTD. and/or any associated operator (hereinafter collectively referred to as "SAND STUDIO" the "Company" "We" "Us" or "Our") that may exist with respect to its related services and both You and We will be legally bound by this Agreement. Please read terms in this Agreement carefully before using the Services (defined below) offered by Us.By visiting our websites or using our Services in any manner You agree that You have read and agree to be bound by the terms and conditions of this Agreement. Use of the Companys services is expressly conditioned upon Your assent to all or parts of the terms and conditions of this Agreement to the exclusion of all other terms.This Agreement applies when You enter into this Agreement with us as an INDIVIDUAL rather than as an Enterprise User. If You are an Enterprise User employee agent trustee of an Enterprise User authorized person to supervise or manage the use of AirDroid by an Enterprise User or other person to use AirDroid Services for the interest of an enterprise please visit theAirdroid Enterprise User License Agreementread and decide whether to agree to theAirdroid Enterprise User License Agreement.The terms of this Agreement that are or may be material to Your rights and interests have been marked in bold and please pay specific attention to them.I. DEFINITIONIn this Agreement1. The"Website"means the www.airdroid.com website and domain name and any other linked pages features contents or application services (including but not limited to any mobile application services) offered from time to time by the Company in connection therewith.2. The"AirDroid Services"or"Services"mean all software products services websites and relevant contents provided by the Company.3. The"AirDroid Account"or"Account"means the users account created by the user when using AirDroid Services the username and password of which can identify You.4. The"AirDroid Contents"or"Contents"mean all materials offered displayed or performed on the Services including but not limited to software text graphics articles photographs images illustrations etc.5."Third Party Services"mean third party websites services and/or contents that are not owned or controlled by the Company during the Services.6."Affiliates" for the purpose of this Agreement mean enterprises that directly or indirectly control the Company or are under the control of the Company or are under control together with the Company. For the purpose of this definition "control" refers to
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe File opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll Jump to behavior
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe Static PE information: certificate valid
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe Static file information: File size 97337128 > 1048576
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe File opened: C:\Program Files (x86)\AirDroid Cast\MSVCR100.dll Jump to behavior
Source: Binary string: ]c:\borrar\EmptyDll\Release\EmptyDll.pdb source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp
Source: Binary string: F:\SourceCode\QRCoder\QRCoder\obj\Release\QRCoder.pdb source: AirDroidCast.exe, 00000009.00000002.6309499575.0000000012A12000.00000002.00000001.01000000.00000030.sdmp
Source: Binary string: E:\GitCode\tb-scrcyp\win\scrcpy-1.17lib\Win32\Debug\libscrcpy.pdb source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003045000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: vccorlib120.i386.pdb0 source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ucrtbase.pdb source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: E:\GitCode\airdroid_business_win_source\Launcher\Release\Launcher.pdb source: Launcher.exe, 00000006.00000002.2304489262.00000000010B4000.00000002.00000001.01000000.00000011.sdmp, Launcher.exe, 00000006.00000000.2222831243.00000000010B4000.00000002.00000001.01000000.00000011.sdmp
Source: Binary string: C:\dev\sqlite\dotnet\bin\2010\Win32\ReleaseNativeOnly\SQLite.Interop.pdb source: AirDroidCast.exe, 00000009.00000002.6336760625.00000000661F4000.00000002.00000001.01000000.0000002A.sdmp
Source: Binary string: c:\borrar\EmptyDll\Release\EmptyDll.pdb source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp
Source: Binary string: Helper.pdb source: Helper.exe, 00000004.00000000.2127526906.00000000000C2000.00000002.00000001.01000000.0000000E.sdmp
Source: Binary string: c:\dev\sqlite\dotnet\obj\2010\System.Data.SQLite.2010\Release\System.Data.SQLite.pdb source: AirDroidCast.exe, 00000009.00000002.6242501724.000000000E8A2000.00000002.00000001.01000000.00000027.sdmp
Source: Binary string: F:\SourceCode\QRCoder\QRCoder\obj\Release\QRCoder.pdb@ source: AirDroidCast.exe, 00000009.00000002.6309499575.0000000012A12000.00000002.00000001.01000000.00000030.sdmp
Source: Binary string: msvcr100.i386.pdb source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003045000.00000004.00000020.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6328410303.0000000066061000.00000020.00000001.01000000.0000002B.sdmp
Source: Binary string: vcruntime140.i386.pdb source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: vcruntime140.i386.pdbGCTL source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: D:\Project\SVN_Code\usbmuxd-vs\Release\libimdusb.pdb source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: vccorlib140.i386.pdb source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: msvcp140.i386.pdbGCTL source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003045000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: msvcr120.i386.pdb source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000031E2000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\dev\sqlite\dotnet\bin\2010\Win32\ReleaseNativeOnly\SQLite.Interop.pdb) source: AirDroidCast.exe, 00000009.00000002.6336760625.00000000661F4000.00000002.00000001.01000000.0000002A.sdmp
Source: Binary string: msvcp120.i386.pdb source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003045000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: vccorlib140.i386.pdbGCTL source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: e:\NLog\build\obj\Debug\.NET Framework 2.0\NLog.pdb source: AirDroidCast.exe, 00000009.00000002.6218378783.000000000BF02000.00000002.00000001.01000000.0000001B.sdmp
Source: Binary string: msvcp140.i386.pdb source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003045000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ucrtbase.pdbUGP source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: E:\Win-2623\download\chromium\src\out\Release\libcef.dll.pdb source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: vccorlib120.i386.pdb source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.00000000032CA000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: E:\GitCode\tb-scrcyp\win\scrcpy-1.17lib\Win32\Debug\libscrcpy.pdb66 source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003045000.00000004.00000020.00020000.00000000.sdmp

Data Obfuscation

barindex
Source: AirDroidCastInstaller.exe.0.dr, iPqB10mZn73WBojA0P.cs .Net Code: typeof(Marshal).GetMethod("GetDelegateForFunctionPointer", new Type[2]{typeof(IntPtr),typeof(Type)})
Source: api-ms-win-crt-heap-l1-1-0.dll.0.dr Static PE information: 0xDF8B9828 [Fri Nov 5 04:33:44 2088 UTC]
Source: avcodec-58.dll.0.dr Static PE information: section name: .rotext
Source: avcodec-58.dll.0.dr Static PE information: section name: .rodata
Source: avfilter-7.dll.0.dr Static PE information: section name: .rodata
Source: ffmpeg.dll.0.dr Static PE information: section name: .00cfg
Source: ffmpeg.dll.0.dr Static PE information: section name: .voltbl
Source: libAirPlay.dll.0.dr Static PE information: section name: _RDATA
Source: libVD.dll.0.dr Static PE information: section name: _RDATA
Source: libVD_x64.dll.0.dr Static PE information: section name: _RDATA
Source: libWebRTC.dll.0.dr Static PE information: section name: .rodata
Source: libcef.dll.0.dr Static PE information: section name: .rodata
Source: libcef.dll.0.dr Static PE information: section name: _RDATA
Source: libscrcpy.dll.0.dr Static PE information: section name: .textbss
Source: libscrcpy.dll.0.dr Static PE information: section name: .msvcjmc
Source: libscrcpy.dll.0.dr Static PE information: section name: .00cfg
Source: msvcp140.dll.0.dr Static PE information: section name: .didat
Source: postproc-55.dll.0.dr Static PE information: section name: .xdata
Source: vccorlib120.dll.0.dr Static PE information: section name: minATL
Source: vccorlib140.dll.0.dr Static PE information: section name: minATL
Source: vcruntime140.dll.0.dr Static PE information: section name: _RDATA
Source: VirtualDesktop.dll.0.dr Static PE information: section name: _RDATA
Source: libimdusb.dll.0.dr Static PE information: section name: .text entropy: 6.89308602799101
Source: msvcr100.dll.0.dr Static PE information: section name: .text entropy: 6.9169969425576285
Source: msvcr120.dll.0.dr Static PE information: section name: .text entropy: 6.95576372950548
Source: usbmuxd.exe.0.dr Static PE information: section name: .text entropy: 6.866055164425
Source: AirDroidCastInstaller.exe.0.dr, iPqB10mZn73WBojA0P.cs High entropy of concatenated method names: 'ce4DmfsmSrOT856tDgfrkMb', 'rgvOFwdS8k', 'WT71lutR3e2XI', 'C9jldbf2y', 'KphhgdZ73', 'VyxZE6gLd', 'n6UDp8Lo6', 'comcAeOkL', 'E5vnx535A', 'der6pavoX'
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\DIHConfig.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Users\user\AppData\Local\Temp\nsz8AD9.tmp\LangDLL.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-namedpipe-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\driver\dpinst32.exe Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\libGLESv2.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-crt-time-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-crt-convert-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Users\user\AppData\Local\Temp\nsz8AD9.tmp\nsProcess.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-processthreads-l1-1-1.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\jmdns.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Users\user\AppData\Local\Temp\nsz8AD9.tmp\InstallOptions.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-file-l2-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\SDL2.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-crt-environment-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\avformat-58.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-datetime-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\vccorlib140.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-debug-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-memory-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\msvcp140.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\avdevice-58.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\libVD_x64.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\driver\x86\libusb0_x86.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\usbmuxd\libusb-1.0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\ffmpeg.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\libcef.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\AdbWinUsbApi.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-crt-stdio-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\msvcp120.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\msvcr120.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\avfilter-7.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\AirDroid_CefSharp.Core.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\System.Data.SQLite.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\AirDroid_CefSharp.BrowserSubprocess.Core.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\IKVM.OpenJDK.Charsets.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\InTheHand.Net.Personal.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-crt-string-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Users\user\AppData\Local\Temp\nsz8AD9.tmp\System.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-file-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\AirDroidCastInstaller.exe Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\driver\dpscat.exe Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\d3dcompiler_43.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\AirDroidHelper.exe Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\AirDroid_CefSharp.WinForms.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-crt-process-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-crt-heap-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\libVD.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\NLog.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\aapt.exe Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\usbmuxd\libusb0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-crt-multibyte-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\IKVM.OpenJDK.Text.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-localization-l1-2-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\driver\dpinst64.exe Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-file-l1-2-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-crt-conio-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\SQLite.Interop.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\avutil-56.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-rtlsupport-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-synch-l1-2-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\DIHConfig_x64.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-errorhandling-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-crt-private-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\swscale-5.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\AirDroid_CefSharp.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\postproc-55.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\driver\amd64\libusb0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-console-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\Launcher.exe Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-crt-runtime-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-interlocked-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-processenvironment-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-processthreads-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\d3dcompiler_47.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\swresample-3.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\QTConfig.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-synch-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-crt-utility-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\vcruntime140.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Users\user\AppData\Local\Temp\nsz8AD9.tmp\InetBgDL.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\libAirPlay.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\libEGL.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\driver\x86\libusb0.sys Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\QRCoder.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-sysinfo-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\AdbWinApi.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\IKVM.OpenJDK.Core.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\uninst.exe Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-heap-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\driver\amd64\libusb0.sys Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\Helper.exe Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\vccorlib120.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\Android.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-util-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\libimdusb.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\libusb0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\msvcr100.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\driver\x86\libusbK_x86.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\android_connect.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\avcodec-58.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-libraryloader-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-crt-filesystem-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\libWebRTC.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\ucrtbase.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\VirtualDesktop\VirtualDesktop.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-string-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-handle-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\usbmuxd\usbmuxd.exe Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\driver\amd64\libusbK.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\IKVM.OpenJDK.Util.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\libscrcpy.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\IKVM.Runtime.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\concrt140.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-crt-locale-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-crt-math-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-profile-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-timezone-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AirDroid Cast Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AirDroid Cast\AirDroid Cast.lnk Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AirDroid Cast\Uninstall.lnk Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Registry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Registry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Registry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Launcher.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Launcher.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Launcher.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Launcher.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Launcher.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Launcher.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\conhost.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\conhost.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process information set: NOOPENFILEERRORBOX

Malware Analysis System Evasion

barindex
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_NetworkAdapterConfiguration
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 980000 memory reserve | memory write watch Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2440000 memory reserve | memory write watch Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 4440000 memory reserve | memory write watch Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2BE0000 memory reserve | memory write watch Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2C50000 memory reserve | memory write watch Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 4C50000 memory reserve | memory write watch Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Memory allocated: 2630000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Memory allocated: 4070000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Memory allocated: 3EA0000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 1480000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2FF0000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 4FF0000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2AF0000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2C70000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 4C70000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 1810000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 33F0000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 3230000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2710000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 28A0000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 48A0000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2D20000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2F30000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 4F30000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: B10000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 24E0000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 44E0000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2AF0000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2D90000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2AF0000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: E40000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2820000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: FE0000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2BD0000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2E50000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2C60000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 16F0000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 3140000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 5140000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: D40000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2810000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 4810000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: AF0000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2690000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: AF0000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2640000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 26C0000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 46C0000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2A80000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2C70000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2A80000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 16C0000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 3150000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2EC0000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2250000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 23C0000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 43C0000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2D40000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2F90000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2DC0000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 3190000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 33A0000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 31B0000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 1330000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 32A0000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 1450000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 950000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2640000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 4640000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 1330000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2FA0000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 4FA0000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 1000000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2A10000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2810000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 980000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 25D0000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2400000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2400000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 25B0000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 45B0000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2780000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 29C0000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: 2780000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Window / User API: threadDelayed 526
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Window / User API: threadDelayed 526
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Window / User API: threadDelayed 401
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Window / User API: threadDelayed 4534
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Window / User API: threadDelayed 2199
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Window / User API: foregroundWindowGot 1753
Source: C:\Program Files (x86)\AirDroid Cast\usbmuxd\usbmuxd.exe Window / User API: threadDelayed 9996
Source: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe Window / User API: threadDelayed 7794
Source: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe Window / User API: threadDelayed 2174
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Window / User API: threadDelayed 374
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Window / User API: threadDelayed 452
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-namedpipe-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsz8AD9.tmp\LangDLL.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\DIHConfig.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\libGLESv2.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\driver\dpinst32.exe Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-crt-time-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-crt-convert-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-processthreads-l1-1-1.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsz8AD9.tmp\nsProcess.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\jmdns.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-file-l2-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsz8AD9.tmp\InstallOptions.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-crt-environment-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\avformat-58.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-datetime-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\vccorlib140.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-debug-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-memory-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\msvcp140.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\avdevice-58.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\libVD_x64.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\driver\x86\libusb0_x86.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\libcef.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\ffmpeg.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-crt-stdio-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\msvcr120.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\msvcp120.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\avfilter-7.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\AirDroid_CefSharp.Core.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\System.Data.SQLite.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\AirDroid_CefSharp.BrowserSubprocess.Core.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\InTheHand.Net.Personal.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\IKVM.OpenJDK.Charsets.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-crt-string-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsz8AD9.tmp\System.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-file-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\AirDroidCastInstaller.exe Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\driver\dpscat.exe Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\AirDroidHelper.exe Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\d3dcompiler_43.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\AirDroid_CefSharp.WinForms.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-crt-process-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-crt-heap-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\libVD.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\NLog.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\aapt.exe Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-crt-multibyte-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\IKVM.OpenJDK.Text.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-localization-l1-2-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\driver\dpinst64.exe Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-file-l1-2-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-crt-conio-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\SQLite.Interop.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-synch-l1-2-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-rtlsupport-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\DIHConfig_x64.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-errorhandling-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-crt-private-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\AirDroid_CefSharp.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\postproc-55.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-console-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-crt-runtime-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-interlocked-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-processenvironment-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-processthreads-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\d3dcompiler_47.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\QTConfig.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-synch-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\vcruntime140.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-crt-utility-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsz8AD9.tmp\InetBgDL.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\libAirPlay.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\driver\x86\libusb0.sys Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\libEGL.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\QRCoder.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-sysinfo-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\IKVM.OpenJDK.Core.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\uninst.exe Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-heap-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\driver\amd64\libusb0.sys Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\Android.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\vccorlib120.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-util-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\libimdusb.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\driver\x86\libusbK_x86.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\android_connect.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-libraryloader-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-crt-filesystem-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\libWebRTC.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\VirtualDesktop\VirtualDesktop.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-string-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-handle-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\IKVM.OpenJDK.Util.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\libscrcpy.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\IKVM.Runtime.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\concrt140.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-crt-locale-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-profile-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-crt-math-l1-1-0.dll Jump to dropped file
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Dropped PE file which has not been started: C:\Program Files (x86)\AirDroid Cast\api-ms-win-core-timezone-l1-1-0.dll Jump to dropped file
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 6536 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 5172 Thread sleep time: -30000s >= -30000s Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 2316 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe TID: 1220 Thread sleep time: -16602069666338586s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe TID: 2516 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\usbmuxd\usbmuxd.exe TID: 3852 Thread sleep time: -99960s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe TID: 7052 Thread sleep time: -7794000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe TID: 7052 Thread sleep time: -2174000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 5812 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 1620 Thread sleep time: -30000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 2996 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 5812 Thread sleep time: -600000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 2736 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 8140 Thread sleep time: -30000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 8100 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 7172 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 2736 Thread sleep time: -600000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 6464 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 4296 Thread sleep time: -30000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 6488 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 6464 Thread sleep time: -600000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 6296 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 7220 Thread sleep time: -30000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 1440 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 6296 Thread sleep time: -600000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 2740 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 7184 Thread sleep time: -30000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 7256 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 2740 Thread sleep time: -600000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 6360 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 340 Thread sleep time: -30000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 7612 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 928 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 6360 Thread sleep time: -600000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 5968 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 1472 Thread sleep time: -30000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 6364 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 5968 Thread sleep time: -600000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 4016 Thread sleep count: 44 > 30
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 1740 Thread sleep count: 97 > 30
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 4452 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 3648 Thread sleep time: -30000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 2436 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 4452 Thread sleep time: -600000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 1976 Thread sleep count: 32 > 30
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 5680 Thread sleep count: 262 > 30
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 6788 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 7880 Thread sleep time: -30000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 1532 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 6788 Thread sleep time: -600000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 4076 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 6196 Thread sleep time: -30000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 5116 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 4076 Thread sleep time: -600000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 7936 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 732 Thread sleep time: -30000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 8036 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 7936 Thread sleep time: -600000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 1516 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 6316 Thread sleep time: -30000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 5196 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 1516 Thread sleep time: -600000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 3704 Thread sleep count: 43 > 30
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 5860 Thread sleep count: 177 > 30
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 1348 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 5864 Thread sleep time: -30000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 4464 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 1348 Thread sleep time: -600000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 5668 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 5144 Thread sleep time: -30000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 7976 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 5668 Thread sleep time: -600000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 2872 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 1708 Thread sleep time: -30000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 3476 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 2872 Thread sleep time: -600000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 7792 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 6724 Thread sleep time: -30000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 5728 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 7820 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 7792 Thread sleep time: -600000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 5836 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 6332 Thread sleep time: -30000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 7832 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 7396 Thread sleep time: -1844674407370954s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 5836 Thread sleep time: -600000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 7776 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 7664 Thread sleep time: -30000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 2344 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 7776 Thread sleep time: -600000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 1028 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 4920 Thread sleep time: -30000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 5648 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 1028 Thread sleep time: -600000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 8152 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 2312 Thread sleep time: -30000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 7920 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 8152 Thread sleep time: -600000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 3060 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 5844 Thread sleep time: -30000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 2892 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 3060 Thread sleep time: -600000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 3096 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 7716 Thread sleep time: -30000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 6984 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 3096 Thread sleep time: -600000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 2328 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 7476 Thread sleep time: -30000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 7460 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 2328 Thread sleep time: -600000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 2076 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 3152 Thread sleep time: -30000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 716 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 2076 Thread sleep time: -600000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 9044 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 8996 Thread sleep time: -30000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 8956 Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe TID: 9044 Thread sleep time: -600000s >= -30000s
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : select AddressWidth from Win32_Processor
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe Last function: Thread delayed
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Last function: Thread delayed
Source: C:\Program Files (x86)\AirDroid Cast\usbmuxd\usbmuxd.exe Thread sleep count: Count: 9996 delay: -10
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File Volume queried: C:\Program Files (x86) FullSizeInformation Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe File Volume queried: C:\Program Files (x86) FullSizeInformation Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Thread delayed: delay time: 600000
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp Binary or memory string: eqEmuVL8Ia4
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: VMware, Inc.
Source: usbmuxd.exe, 0000000F.00000003.4452594356.0000000000F73000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \\?\scsi#disk&ven_vmware&prod_virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: VMware Inc.
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2403956126.0000000004825000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.2371933145.0000000004825000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW
Source: Launcher.exe, 00000006.00000002.2322790341.00000000018B3000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll(>
Source: Helper.exe, 00000007.00000002.2237470874.0000000000FBA000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp Binary or memory string: ,~BVMCI
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp Binary or memory string: evMCicOVHH7
Source: AirDroidCast.exe, 00000009.00000002.6169870870.00000000092B2000.00000002.00000001.01000000.00000016.sdmp Binary or memory string: VirtualMachineError
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: EADS Deutschland GmbHVMware, Inc.AGFA-Gevaert NVPhoto AIO Printer 922Sentech CameraEyeTV DiversityPSX Vibration Feedback ConverterGamtec.,Ltd SmartJoy PLUS AdapterCruzer MiniMC70 Rugged Mobile ComputerXR21V1410 USB-UART ICCanoScan D660UCatalinaExpert mouseCLOCK USB II
Source: Helper.exe, 00000007.00000002.2327414893.0000000006510000.00000004.00000020.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.5967265325.00000000024AC000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Gearway Electronics (Dong Guan) Co., Ltd.INGENICOSharp Corp.VMMobile Disk IIIBluetooth 2.0 adapter 100m CN-521v2 001 Backpack 40GB Hard DriveWG121(v1) 54 Mbps Wireless [Intersil ISL3886]USA-18X PDAInternal Keyboard/Trackpad (JIS)Nostromo 1745 GamePadPX-A650 [Stylus CX4700/CX4800/DX4800/DX4850]Savi Office Base Stationremote key/mouse/storage for P3 chipPhotoSmart 7345VMware Inc.ASUSTek Computer, Inc.MindShare, Inc.GDS-3000 OscilloscopePL512 Power Supply SystemG240 802.11bgWL-188 Wireless Network 300N USB AdapterBackPackWG121(v2) 54 Mbps Wireless [Intersil ISL3886]USA-28Xb PDA [no firmware]Aluminum Mini Keyboard (ANSI)Nostromo N50 GamePadPM-A750 [Stylus Photo RX520/RX530]USB DSP v4 Audio Interfaceremote storage for P3 chipDeskJet 630c`
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: VMnet
Source: Helper.exe, 00000004.00000002.2146310629.0000000005F72000.00000002.00000001.01000000.00000010.sdmp Binary or memory string: cVmCiE9yFTd
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: xvmcidct
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: TMT Technology, Inc.Spyrus, Inc.Qemu Audio DeviceWL532U 802.11g Adapter8055 Experiment Interface Board (address=2)PicoScope 2000 series PC OscilloscopeFrontline Test Equipment Bluetooth DeviceAVerTVEfficient ADSL ModemVS-700 M23D Optical MouseDigital IXUS 55WingMan Formula ForceRemote NDIS Network DeviceHDM Interface
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.2015852449.0000000000865000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.1927462378.0000000000869000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.1988610284.0000000000869000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.1957867712.0000000000869000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000003.2015370719.0000000000865000.00000004.00000020.00020000.00000000.sdmp, AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2378705742.0000000000861000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW(y
Source: Helper.exe, 00000007.00000002.2237470874.0000000000FCE000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Volume{a33c736e-61ca-11ee-8c18-806e6f6e6963}\DosDevices\D:
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000003CCA000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: e:\win-2623\download\chromium\src\net\proxy\polling_proxy_config_service.ccnet::PollingProxyConfigService::Core::CheckForChangesNownet::PollingProxyConfigService::Core::PollOnWorkerThreade:\win-2623\download\chromium\src\net\base\network_interfaces_win.cc%WINDIR%\system32\wlanapi.dllWlanOpenHandleWlanEnumInterfacesWlanQueryInterfaceWlanSetInterfaceWlanFreeMemoryWlanCloseHandleVMnetGetAdaptersAddresses failed: V(
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Qemu Audio Device
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002996000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: yuv420pyuyv422rgb24bgr24yuv422pyuv444pyuv410pyuv411pgray8,y8monowmonobpal8yuvj420pyuvj422pyuvj444pxvmcmcxvmcidctuyvy422uyyvyy411bgr8bgr4bgr4_bytergb8rgb4rgb4_bytenv12nv21argbabgrbgragray16bey16begray16ley16leyuv440pyuvj440pyuva420pvdpau_h264vdpau_mpeg1vdpau_mpeg2vdpau_wmv3vdpau_vc1rgb48bergb48lergb565bergb565lergb555bergb555lebgr565bebgr565lebgr555bebgr555levaapi_mocovaapi_idctvaapi_vldyuv420p16leyuv420p16beyuv422p16leyuv422p16beyuv444p16leyuv444p16bevdpau_mpeg4dxva2_vldrgb444lergb444bebgr444lebgr444beya8gray8abgr48bebgr48leyuv420p9beyuv420p9leyuv420p10beyuv420p10leyuv422p10beyuv422p10leyuv444p9beyuv444p9leyuv444p10beyuv444p10leyuv422p9beyuv422p9levda_vldgbrpgbrp9begbrp9legbrp10begbrp10legbrp16begbrp16leyuva422pyuva444pyuva420p9beyuva420p9leyuva422p9beyuva422p9leyuva444p9beyuva444p9leyuva420p10beyuva420p10leyuva422p10beyuva422p10leyuva444p10beyuva444p10leyuva420p16beyuva420p16leyuva422p16beyuva422p16leyuva444p16beyuva444p16levdpauxyz12lexyz12benv16nv20lenv20bergba64bergba64lebgra64bebgra64leyvyu422vdaya16beya16legbrapgbrap16begbrap16leqsvmmald3d11va_vld0rgbrgb00bgrbgr0yuv420p12beyuv420p12leyuv420p14beyuv420p14leyuv422p12beyuv422p12leyuv422p14beyuv422p14leyuv444p12beyuv444p12leyuv444p14beyuv444p14legbrp12begbrp12legbrp14begbrp14leyuvj411pbayer_bggr8bayer_rggb8bayer_gbrg8bayer_grbg8bayer_bggr16lebayer_bggr16bebayer_rggb16lebayer_rggb16bebayer_gbrg16lebayer_gbrg16bebayer_grbg16lebayer_grbg16beyuv440p10leyuv440p10beyuv440p12leyuv440p12beayuv64leayuv64bevideotoolbox_vldsmpte428-1log100log316iec61966-2-4bt1361eiec61966-2-1bt2020-10bt2020-20gbrycgcobt2020ncbt2020crgb32bgr32subtitle@
Source: usbmuxd.exe, 0000000F.00000003.4452594356.0000000000F73000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \\?\scsi#cdrom&ven_necvmwar&prod_vmware_sata_cd00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000002806000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: VMware Screen Codec / VMware Video
Source: usbmuxd.exe, 0000000F.00000003.4452594356.0000000000F73000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \\?\scsi#cdrom&ven_necvmwar&prod_vmware_sata_cd00#4&224f42ef&0&000000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Process information queried: ProcessInformation Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process token adjusted: Debug Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Process token adjusted: Debug Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Memory allocated: page read and write | page guard Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://www.airdroid.com/thankyou/install-airdroid-cast.html Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Launcher.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "/C:\Program Files (x86)\AirDroid Cast\helper.exe" "/shortcut" "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe "C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe" devices
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\usbmuxd\usbmuxd.exe "C:\Program Files (x86)\AirDroid Cast\usbmuxd\usbmuxd.exe" -r airdroid_cast_lockdown
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1728295044&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1728632298&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1728924290&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1729227592&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1729436201&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "C:\Program Files (x86)\AirDroid Cast\Helper.exe" /update /silent "C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe" "AirDroid Cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "C:\Users\user\AppData\Roaming\AirDroidCast\Cache\CacheInfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1729881109&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe Process created: C:\Program Files (x86)\AirDroid Cast\IncludeAdb\adb_helper.exe adb -L tcp:5037 fork-server server --reply-fd 612
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "c:\program files (x86)\airdroid cast\helper.exe" /update /silent "c:\program files (x86)\airdroid cast\airdroidcast.exe" "airdroid cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "c:\users\user\appdata\roaming\airdroidcast\cache\cacheinfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1728295044&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "c:\program files (x86)\airdroid cast\helper.exe" /update /silent "c:\program files (x86)\airdroid cast\airdroidcast.exe" "airdroid cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "c:\users\user\appdata\roaming\airdroidcast\cache\cacheinfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1728632298&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "c:\program files (x86)\airdroid cast\helper.exe" /update /silent "c:\program files (x86)\airdroid cast\airdroidcast.exe" "airdroid cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "c:\users\user\appdata\roaming\airdroidcast\cache\cacheinfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1728924290&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "c:\program files (x86)\airdroid cast\helper.exe" /update /silent "c:\program files (x86)\airdroid cast\airdroidcast.exe" "airdroid cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "c:\users\user\appdata\roaming\airdroidcast\cache\cacheinfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1729227592&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "c:\program files (x86)\airdroid cast\helper.exe" /update /silent "c:\program files (x86)\airdroid cast\airdroidcast.exe" "airdroid cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "c:\users\user\appdata\roaming\airdroidcast\cache\cacheinfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1729436201&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "c:\program files (x86)\airdroid cast\helper.exe" /update /silent "c:\program files (x86)\airdroid cast\airdroidcast.exe" "airdroid cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "c:\users\user\appdata\roaming\airdroidcast\cache\cacheinfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1729881109&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "c:\program files (x86)\airdroid cast\helper.exe" /update /silent "c:\program files (x86)\airdroid cast\airdroidcast.exe" "airdroid cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "c:\users\user\appdata\roaming\airdroidcast\cache\cacheinfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1731740999&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "c:\program files (x86)\airdroid cast\helper.exe" /update /silent "c:\program files (x86)\airdroid cast\airdroidcast.exe" "airdroid cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "c:\users\user\appdata\roaming\airdroidcast\cache\cacheinfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1731930001&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "c:\program files (x86)\airdroid cast\helper.exe" /update /silent "c:\program files (x86)\airdroid cast\airdroidcast.exe" "airdroid cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "c:\users\user\appdata\roaming\airdroidcast\cache\cacheinfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1732385552&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "c:\program files (x86)\airdroid cast\helper.exe" /update /silent "c:\program files (x86)\airdroid cast\airdroidcast.exe" "airdroid cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "c:\users\user\appdata\roaming\airdroidcast\cache\cacheinfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1732572421&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "c:\program files (x86)\airdroid cast\helper.exe" /update /silent "c:\program files (x86)\airdroid cast\airdroidcast.exe" "airdroid cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "c:\users\user\appdata\roaming\airdroidcast\cache\cacheinfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1732808823&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "c:\program files (x86)\airdroid cast\helper.exe" /update /silent "c:\program files (x86)\airdroid cast\airdroidcast.exe" "airdroid cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "c:\users\user\appdata\roaming\airdroidcast\cache\cacheinfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1733037619&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "c:\program files (x86)\airdroid cast\helper.exe" /update /silent "c:\program files (x86)\airdroid cast\airdroidcast.exe" "airdroid cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "c:\users\user\appdata\roaming\airdroidcast\cache\cacheinfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1733430021&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "c:\program files (x86)\airdroid cast\helper.exe" /update /silent "c:\program files (x86)\airdroid cast\airdroidcast.exe" "airdroid cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "c:\users\user\appdata\roaming\airdroidcast\cache\cacheinfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1733614776&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "c:\program files (x86)\airdroid cast\helper.exe" /update /silent "c:\program files (x86)\airdroid cast\airdroidcast.exe" "airdroid cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "c:\users\user\appdata\roaming\airdroidcast\cache\cacheinfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1733818369&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "c:\program files (x86)\airdroid cast\helper.exe" /update /silent "c:\program files (x86)\airdroid cast\airdroidcast.exe" "airdroid cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "c:\users\user\appdata\roaming\airdroidcast\cache\cacheinfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1734072662&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "c:\program files (x86)\airdroid cast\helper.exe" /update /silent "c:\program files (x86)\airdroid cast\airdroidcast.exe" "airdroid cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "c:\users\user\appdata\roaming\airdroidcast\cache\cacheinfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1734299484&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "c:\program files (x86)\airdroid cast\helper.exe" /update /silent "c:\program files (x86)\airdroid cast\airdroidcast.exe" "airdroid cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "c:\users\user\appdata\roaming\airdroidcast\cache\cacheinfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1734536931&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "c:\program files (x86)\airdroid cast\helper.exe" /update /silent "c:\program files (x86)\airdroid cast\airdroidcast.exe" "airdroid cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "c:\users\user\appdata\roaming\airdroidcast\cache\cacheinfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1734795916&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "c:\program files (x86)\airdroid cast\helper.exe" /update /silent "c:\program files (x86)\airdroid cast\airdroidcast.exe" "airdroid cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "c:\users\user\appdata\roaming\airdroidcast\cache\cacheinfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1735073456&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "c:\program files (x86)\airdroid cast\helper.exe" /update /silent "c:\program files (x86)\airdroid cast\airdroidcast.exe" "airdroid cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "c:\users\user\appdata\roaming\airdroidcast\cache\cacheinfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1735321796&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "c:\program files (x86)\airdroid cast\helper.exe" /update /silent "c:\program files (x86)\airdroid cast\airdroidcast.exe" "airdroid cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "c:\users\user\appdata\roaming\airdroidcast\cache\cacheinfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1735561937&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "c:\program files (x86)\airdroid cast\helper.exe" /update /silent "c:\program files (x86)\airdroid cast\airdroidcast.exe" "airdroid cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "c:\users\user\appdata\roaming\airdroidcast\cache\cacheinfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1735867118&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "c:\program files (x86)\airdroid cast\helper.exe" /update /silent "c:\program files (x86)\airdroid cast\airdroidcast.exe" "airdroid cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "c:\users\user\appdata\roaming\airdroidcast\cache\cacheinfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1736174910&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "c:\program files (x86)\airdroid cast\helper.exe" /update /silent "c:\program files (x86)\airdroid cast\airdroidcast.exe" "airdroid cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "c:\users\user\appdata\roaming\airdroidcast\cache\cacheinfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1737079663&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "c:\program files (x86)\airdroid cast\helper.exe" /update /silent "c:\program files (x86)\airdroid cast\airdroidcast.exe" "airdroid cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "c:\users\user\appdata\roaming\airdroidcast\cache\cacheinfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1728295044&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "c:\program files (x86)\airdroid cast\helper.exe" /update /silent "c:\program files (x86)\airdroid cast\airdroidcast.exe" "airdroid cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "c:\users\user\appdata\roaming\airdroidcast\cache\cacheinfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1728632298&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "c:\program files (x86)\airdroid cast\helper.exe" /update /silent "c:\program files (x86)\airdroid cast\airdroidcast.exe" "airdroid cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "c:\users\user\appdata\roaming\airdroidcast\cache\cacheinfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1728924290&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "c:\program files (x86)\airdroid cast\helper.exe" /update /silent "c:\program files (x86)\airdroid cast\airdroidcast.exe" "airdroid cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "c:\users\user\appdata\roaming\airdroidcast\cache\cacheinfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1729227592&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "c:\program files (x86)\airdroid cast\helper.exe" /update /silent "c:\program files (x86)\airdroid cast\airdroidcast.exe" "airdroid cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "c:\users\user\appdata\roaming\airdroidcast\cache\cacheinfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1729436201&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Process created: C:\Program Files (x86)\AirDroid Cast\Helper.exe "c:\program files (x86)\airdroid cast\helper.exe" /update /silent "c:\program files (x86)\airdroid cast\airdroidcast.exe" "airdroid cast" "https://srv3.airdroid.com/p20/cast/pcupgrade?v=1.2.1.0&inner_version=1210&type=63&lang=en&app_channel=0&os_version=10.0.19045&incremental_update=1&beta=0" "" 0 0 0 0 1 "c:\users\user\appdata\roaming\airdroidcast\cache\cacheinfo.txt" "https://www.airdroid.com/{0}/cast/?_t=1729881109&app_ver=1.2.1.0&device_type=63&app_channel=0&language=en&version=1210&os_verion=10.0&jtoken=&mode_type=2&account_id=0" "" -999
Source: Helper.exe, 00000004.00000002.2140928933.0000000003448000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6038136579.0000000005071000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: Progman
Source: AirDroid_Cast_Desktop_Client_1.2.1.0.exe, 00000000.00000002.2390369800.0000000004450000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Failed to allocate new window frame e:\win-2623\download\chromium\src\third_party\webrtc\modules\desktop_capture\desktop_frame_win.ccFailed to close the owned desktop handle: e:\win-2623\download\chromium\src\third_party\webrtc\modules\desktop_capture\win\desktop.ccFailed to query the desktop name: Failed to assign the desktop to the current thread: Failed to retrieve the handle of the desktop assigned to the current thread: ProgmanApplicationFrameWindowWindows.UI.Core.CoreWindow$F
Source: Helper.exe, 00000004.00000002.2140928933.0000000003448000.00000004.00000800.00020000.00000000.sdmp, AirDroidCast.exe, 00000009.00000002.6038136579.0000000005071000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: program managerVSOFTWARE\Microsoft\NET Framework Setup\NDP\
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\AirDroid_Cast_Desktop_Client_1.2.1.0.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Helper.exe VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Android.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Helper.exe VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Android.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Android.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\jmdns.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\IKVM.OpenJDK.Core.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\calibrib.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\calibriz.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\cambriai.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\cambriab.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\cambriaz.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\Candara.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\Candaral.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\Candarai.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\Candarali.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\Candarab.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\Candaraz.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\comic.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\comici.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\comicbd.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\comicz.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\constan.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\constani.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\constanb.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\constanz.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\corbel.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\corbell.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\corbeli.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\corbelli.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\corbelb.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\corbelz.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\cour.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\couri.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\courbd.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\courbi.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\ebrima.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\ebrimabd.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\framd.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\FRADM.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\framdit.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\FRADMIT.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\FRADMCN.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\FRAHV.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\FRAHVIT.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\Gabriola.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\gadugi.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\gadugib.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\georgia.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\georgiai.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\georgiab.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\georgiaz.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\impact.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\Inkfree.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\javatext.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\LeelawUI.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\LeelUIsl.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\LeelaUIb.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\lucon.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\malgun.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\malgunsl.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\malgunbd.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\himalaya.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\ntailu.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\ntailub.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\phagspa.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\phagspab.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\taile.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\taileb.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\msyi.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\monbaiti.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\mvboli.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\mmrtext.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\mmrtextb.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\Nirmala.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\NirmalaS.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\NirmalaB.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\pala.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\palai.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\palab.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\palabi.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\segoepr.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\segoeprb.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\segoesc.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\segoescb.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\seguihis.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\simsunb.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\sylfaen.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\symbol.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\tahoma.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\tahomabd.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\trebucit.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\trebucbd.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\trebucbi.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\verdanai.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\verdanab.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\verdanaz.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\webdings.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\holomdl2.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\AGENCYR.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\ANTQUABI.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\ARLRDBD.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\BASKVILL.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\BAUHS93.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\BELL.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\BELLI.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\BERNHC.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\BOD_B.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\BOD_BI.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\BOD_BLAI.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\BOD_PSTC.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\BOOKOS.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\BOOKOSB.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\BRLNSDB.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\BRLNSB.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\CALIFB.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\CALIST.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\CALISTB.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\SCHLBKI.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\SCHLBKB.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\CENTAUR.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\CENTURY.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\COLONNA.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\COPRGTB.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\DUBAI-REGULAR.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\ELEPHNT.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\FELIXTI.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\FORTE.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\FRSCRIPT.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\FTLTLT.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\GARAIT.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\GIL_____.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\GOTHIC.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\GOUDYSTO.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\HARLOWSI.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\HARNGTON.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\HTOWERT.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\JOKERMAN.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\LBRITED.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\LBRITEDI.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\LFAX.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\LFAXI.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\LSANS.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\LSANSI.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\LTYPE.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\MATURASC.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\NIAGSOL.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\PARCHM.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\PERBI___.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\ROCKB.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\TCB_____.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\TEMPSITC.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\OFFSYMSB.TTF VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\tahoma.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\tahomabd.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\NLog.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Services\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\IKVM.Runtime.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\System.Data.SQLite.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\IKVM.OpenJDK.Util.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Design\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Design.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\arial.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\simsun.ttc VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Windows\Fonts\arialbi.ttf VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\AirDroidCast.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\QRCoder.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\usbmuxd\usbmuxd.exe Queries volume information: C:\ProgramData\airdroid_cast_lockdown VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Helper.exe VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Android.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Helper.exe VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Android.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Helper.exe VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Android.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Helper.exe VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Android.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Helper.exe VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Android.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Helper.exe VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Android.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Helper.exe VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Android.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Helper.exe VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Android.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Helper.exe VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Android.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Helper.exe VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Android.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Helper.exe VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Android.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Helper.exe VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Android.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Helper.exe VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Android.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Helper.exe VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Android.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Helper.exe VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Android.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Helper.exe VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Android.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Helper.exe VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Android.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Helper.exe VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Android.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Helper.exe VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Android.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Helper.exe VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Android.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Helper.exe VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Android.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Helper.exe VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Android.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Helper.exe VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Android.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Helper.exe VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Android.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Helper.exe VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Program Files (x86)\AirDroid Cast\Android.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
Source: C:\Program Files (x86)\AirDroid Cast\Helper.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs