ShadowPad-injected wmpnetwk.exe beaconing after API unhooking

Detects the legitimate wmpnetwk.exe process, commonly used as a target for ShadowPad process injection, initiating outbound network connections while simultaneously accessing Firefox browser profile data. This behavior is indicative of credential theft and command-and-control communication typical of post-compromise activity.