File name:

geek.exe

Full analysis: https://app.any.run/tasks/2c55d559-d853-432d-a7a5-8392e4cda17d
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: April 12, 2025, 10:55:01
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
stealer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

234F314F904536E9EA73F52E1F0FFA13

SHA1:

430D72AAD2930EF28D9270DB87BB14260D3E613F

SHA256:

7142BA9A0A96E7184D8DA2D5514D4416191494CC709F424F924CEB26332171EC

SSDEEP:

98304:3qJbc5xtz+kl/m5lifMc/PKkuExnaZ/l+7Y1rtJKCg85:6Jk+y/mnifVKkbaZ/l+7Y1rtECg85

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • geek64.exe (PID: 5408)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • geek.exe (PID: 6148)
    • Reads security settings of Internet Explorer

      • geek64.exe (PID: 5408)
    • There is functionality for taking screenshot (YARA)

      • geek.exe (PID: 6148)
      • geek64.exe (PID: 5408)
    • Starts POWERSHELL.EXE for commands execution

      • geek64.exe (PID: 5408)
    • Executes as Windows Service

      • VSSVC.exe (PID: 3024)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 5512)
    • Application launched itself

      • setup.exe (PID: 2088)
    • Searches for installed software

      • geek64.exe (PID: 5408)
  • INFO

    • Create files in a temporary directory

      • geek.exe (PID: 6148)
      • msiexec.exe (PID: 1164)
    • Checks supported languages

      • geek.exe (PID: 6148)
      • geek64.exe (PID: 5408)
      • msiexec.exe (PID: 5512)
      • setup.exe (PID: 456)
      • setup.exe (PID: 2088)
    • Checks proxy server information

      • geek64.exe (PID: 5408)
    • Reads the machine GUID from the registry

      • geek64.exe (PID: 5408)
    • Creates files or folders in the user directory

      • geek64.exe (PID: 5408)
    • Reads the computer name

      • geek64.exe (PID: 5408)
      • msiexec.exe (PID: 5512)
      • setup.exe (PID: 2088)
    • Reads the software policy settings

      • geek64.exe (PID: 5408)
      • slui.exe (PID: 5380)
    • Process checks computer location settings

      • geek64.exe (PID: 5408)
      • setup.exe (PID: 2088)
    • Manages system restore points

      • SrTasks.exe (PID: 3396)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:10:17 09:59:10+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 1875968
InitializedDataSize: 4758016
UninitializedDataSize: -
EntryPoint: 0x17f174
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.5.1.163
ProductVersionNumber: 1.5.1.163
FileFlagsMask: 0x001f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Windows, Latin1
CompanyName: Geek Uninstaller
Comments: https://geekuninstaller.com
FileDescription: Geek Uninstaller
FileVersion: 1.5.1.163
InternalName: Geek Uninstaller
LegalCopyright: Copyright (C) 2012-2022 Geek Uninstaller
OriginalFileName: geek.exe
ProductName: Geek-Uninstaller
ProductVersion: 1.5.1.163
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
162
Monitored processes
20
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start geek.exe geek64.exe sppextcomobj.exe no specs slui.exe powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs msiexec.exe no specs msiexec.exe no specs vssvc.exe no specs slui.exe no specs srtasks.exe no specs conhost.exe no specs setup.exe no specs setup.exe msiexec.exe no specs geek.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
456"C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\Installer\setup.exe" --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler --database=C:\WINDOWS\SystemTemp\MsEdgeCrashpad --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\Installer\setup.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x254,0x258,0x25c,0x230,0x260,0x7ff62f8c69a8,0x7ff62f8c69b4,0x7ff62f8c69c0C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\Installer\setup.exe
setup.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Edge Installer
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\installer\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
960powershell.exe Remove-AppxPackage Microsoft.HEIFImageExtension_1.0.22742.0_x64__8wekyb3d8bbweC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exegeek64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1164MsiExec.exe /X{90569A00-0530-31BE-8158-0728D7E1FFC3}C:\Windows\System32\msiexec.exegeek64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
1603
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1912\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2088"C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\Installer\setup.exe" --uninstall --msedge --channel=stable --msi --system-level --verbose-logging --force-uninstallC:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\Installer\setup.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Installer
Exit code:
93
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\installer\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2136powershell.exe Remove-AppxPackage Microsoft.GetHelp_10.1706.13331.0_x64__8wekyb3d8bbweC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exegeek64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\atl.dll
2984MsiExec.exe /X{90569A00-0530-31BE-8158-0728D7E1FFC3}C:\Windows\System32\msiexec.exegeek64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
1602
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3024C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3396C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11C:\Windows\System32\SrTasks.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Windows System Protection background tasks.
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4488\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
25 416
Read events
24 996
Write events
235
Delete events
185

Modification events

(PID) Process:(5408) geek64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(5408) geek64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(5408) geek64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(5408) geek64.exeKey:HKEY_CLASSES_ROOT\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMicrosoft.YourPhone_0.19051.7.0_x64__8wekyb3d8bbwe%5Cresources.pri\1d5ace4595840bd\a37dfe62
Operation:writeName:@{C:\Program Files\WindowsApps\Microsoft.YourPhone_0.19051.7.0_x64__8wekyb3d8bbwe\resources.pri? ms-resource://Microsoft.YourPhone/resources/AppName}
Value:
Your Phone
(PID) Process:(5408) geek64.exeKey:HKEY_CLASSES_ROOT\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMicrosoft.WebpImageExtension_1.0.22753.0_x64__8wekyb3d8bbwe%5Cresources.pri\1d5ace4f91f4df8\a37dfe62
Operation:writeName:@{C:\Program Files\WindowsApps\Microsoft.WebpImageExtension_1.0.22753.0_x64__8wekyb3d8bbwe\resources.pri? ms-resource://Microsoft.WebpImageExtension/resources/AppStoreName}
Value:
Webp Image Extensions
(PID) Process:(5408) geek64.exeKey:HKEY_CLASSES_ROOT\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMicrosoft.VP9VideoExtensions_1.0.22681.0_x64__8wekyb3d8bbwe%5Cresources.pri\1d5ace4f10ea0f5\a37dfe62
Operation:writeName:@{C:\Program Files\WindowsApps\Microsoft.VP9VideoExtensions_1.0.22681.0_x64__8wekyb3d8bbwe\resources.pri? ms-resource://Microsoft.VP9VideoExtensions/resources/AppStoreName}
Value:
VP9 Video Extensions
(PID) Process:(5408) geek64.exeKey:HKEY_CLASSES_ROOT\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMicrosoft.ScreenSketch_10.1907.2471.0_x64__8wekyb3d8bbwe%5Cresources.pri\1d5ace4a450ec0e\a37dfe62
Operation:writeName:@{C:\Program Files\WindowsApps\Microsoft.ScreenSketch_10.1907.2471.0_x64__8wekyb3d8bbwe\resources.pri? ms-resource://Microsoft.ScreenSketch/resources/AppName/Text}
Value:
Snip & Sketch
(PID) Process:(5408) geek64.exeKey:HKEY_CLASSES_ROOT\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMicrosoft.MixedReality.Portal_2000.19081.1301.0_x64__8wekyb3d8bbwe%5Cresources.pri\1d5ace4f533928b\a37dfe62
Operation:writeName:@{C:\Program Files\WindowsApps\Microsoft.MixedReality.Portal_2000.19081.1301.0_x64__8wekyb3d8bbwe\resources.pri? ms-resource://Microsoft.MixedReality.Portal/resources/AppName/Text}
Value:
Mixed Reality Portal
(PID) Process:(5408) geek64.exeKey:HKEY_CLASSES_ROOT\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMicrosoft.XboxGamingOverlay_2.34.28001.0_x64__8wekyb3d8bbwe%5Cresources.pri\1d5ace4bb18b302\a37dfe62
Operation:writeName:@{C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_2.34.28001.0_x64__8wekyb3d8bbwe\resources.pri? ms-resource://Microsoft.XboxGamingOverlay/resources/GameBar}
Value:
Xbox Game Bar
(PID) Process:(5408) geek64.exeKey:HKEY_CLASSES_ROOT\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMicrosoft.Xbox.TCUI_1.23.28002.0_x64__8wekyb3d8bbwe%5Cresources.pri\1d5ace4c21e5292\a37dfe62
Operation:writeName:@{C:\Program Files\WindowsApps\Microsoft.Xbox.TCUI_1.23.28002.0_x64__8wekyb3d8bbwe\resources.pri? ms-resource://Microsoft.Xbox.TCUI/resources/DisplayName}
Value:
Xbox Live
Executable files
1
Suspicious files
20
Text files
22
Unknown types
0

Dropped files

PID
Process
Filename
Type
5408geek64.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751binary
MD5:9C47C7CDF7DE1951B6194116E55089CE
SHA256:34EF7827F83B11ED82003D5B8834D34A2148FABF30EFBE3182A28D6FB4E5A1AA
5408geek64.exeC:\Users\admin\AppData\Roaming\Geek Uninstaller\IconsCache\Microsoft.GetHelp_8wekyb3d8bbwe_Get Help.icoimage
MD5:5A363A5076C98B7205474C12E6138B46
SHA256:628FB89C4B9E2032E6FDD77DC7CC4699C871EC95F51436A0601211F55A8637BF
5408geek64.exeC:\Users\admin\AppData\Roaming\Geek Uninstaller\IconsCache\Microsoft.WebpImageExtension_8wekyb3d8bbwe_Webp Image Extensions.icoimage
MD5:30E6CD8A49CEB9974E7A4704CC39406C
SHA256:84A8EEE47C77AB22D259FDB7BC94A82083B39656425F6E8942680CC7C45D5D38
5408geek64.exeC:\Users\admin\AppData\Roaming\Geek Uninstaller\IconsCache\Microsoft.Print3D_8wekyb3d8bbwe_Print 3D.icoimage
MD5:17B2C32DFF204ED5C66E969700412697
SHA256:30CF0610B982A7618E06C1505D225E274F34840E4D77DC2B46B580679560C9F1
5408geek64.exeC:\Users\admin\AppData\Roaming\Geek Uninstaller\IconsCache\Microsoft.ScreenSketch_8wekyb3d8bbwe_Snip & Sketch.icoimage
MD5:E069F4215D2B536CDBC0BF50D1741735
SHA256:2C273D2FAE3302B54AB2D32C6852B30C943ADFB4297F9615FAE8533F8A51413B
5408geek64.exeC:\Users\admin\AppData\Roaming\Geek Uninstaller\IconsCache\Microsoft.VP9VideoExtensions_8wekyb3d8bbwe_VP9 Video Extensions.icoimage
MD5:30E6CD8A49CEB9974E7A4704CC39406C
SHA256:84A8EEE47C77AB22D259FDB7BC94A82083B39656425F6E8942680CC7C45D5D38
5408geek64.exeC:\Users\admin\AppData\Roaming\Geek Uninstaller\IconsCache\Microsoft.YourPhone_8wekyb3d8bbwe_Your Phone.icoimage
MD5:3F7DA9AE833A8274C982448B166B3597
SHA256:D5A8BA6A04BBB8E971A432A67AE01F4257BE8DBE67F91208285B1C5E5E6D880B
5408geek64.exeC:\Users\admin\AppData\Roaming\Geek Uninstaller\IconsCache\Microsoft.MixedReality.Portal_8wekyb3d8bbwe_Mixed Reality Portal.icoimage
MD5:55CCB5C037EF6535D3C3419E2B6D86D0
SHA256:75BD9F56787CFD703609CD6B97A563968812079DD03C8348ED40C838C5735C27
5408geek64.exeC:\Users\admin\AppData\Roaming\Geek Uninstaller\IconsCache\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe_Xbox Game Bar.icoimage
MD5:55B67D04253F1A0C23A11F9FB97EE6F2
SHA256:04666BC93AF050A9170B5C9FFB08FFC8D6436A4D719DD3839299D77A77E98D6C
5408geek64.exeC:\Users\admin\AppData\Roaming\Geek Uninstaller\IconsCache\Microsoft.Xbox.TCUI_8wekyb3d8bbwe_Xbox Live.icoimage
MD5:88D5153162FDDDA296229CC400108EC2
SHA256:C715CF2EE597CC643336C5D7F758B733872DA7F7F0E6AA52FCDC02C78125DBDB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
29
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5408
geek64.exe
GET
200
2.19.217.103:80
http://x1.c.lencr.org/
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.22:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5408
geek64.exe
GET
200
2.16.2.75:80
http://r11.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBQaUrm0WeTDM5ghfoZtS72KO9ZnzgQUCLkRO6XQhRi06g%2BgrZ%2BGHo78OCcCEgYtafcrGXdlbTm4dvhQGJxV1g%3D%3D
unknown
whitelisted
1128
SIHClient.exe
GET
200
2.19.217.218:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
1128
SIHClient.exe
GET
200
2.19.217.218:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.22:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
5408
geek64.exe
173.230.144.164:443
geekuninstaller.com
Linode, LLC
US
unknown
5408
geek64.exe
2.19.217.103:80
x1.c.lencr.org
Akamai International B.V.
NL
whitelisted
5408
geek64.exe
2.16.2.75:80
r11.o.lencr.org
Akamai International B.V.
CZ
whitelisted
2112
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.216.77.22
  • 23.216.77.25
  • 23.216.77.6
  • 23.216.77.28
whitelisted
google.com
  • 142.250.186.142
whitelisted
geekuninstaller.com
  • 173.230.144.164
unknown
x1.c.lencr.org
  • 2.19.217.103
whitelisted
r11.o.lencr.org
  • 2.16.2.75
  • 2.16.2.73
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 40.126.32.76
  • 20.190.160.132
  • 40.126.32.133
  • 40.126.32.138
  • 40.126.32.74
  • 20.190.160.3
  • 20.190.160.4
  • 20.190.160.130
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted

Threats

No threats detected
No debug info