File name:

geek.exe

Full analysis: https://app.any.run/tasks/2c55d559-d853-432d-a7a5-8392e4cda17d
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: April 12, 2025, 10:55:01
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
stealer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

234F314F904536E9EA73F52E1F0FFA13

SHA1:

430D72AAD2930EF28D9270DB87BB14260D3E613F

SHA256:

7142BA9A0A96E7184D8DA2D5514D4416191494CC709F424F924CEB26332171EC

SSDEEP:

98304:3qJbc5xtz+kl/m5lifMc/PKkuExnaZ/l+7Y1rtJKCg85:6Jk+y/mnifVKkbaZ/l+7Y1rtECg85

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • geek64.exe (PID: 5408)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • geek64.exe (PID: 5408)
    • Executable content was dropped or overwritten

      • geek.exe (PID: 6148)
    • There is functionality for taking screenshot (YARA)

      • geek64.exe (PID: 5408)
      • geek.exe (PID: 6148)
    • Executes as Windows Service

      • VSSVC.exe (PID: 3024)
    • Starts POWERSHELL.EXE for commands execution

      • geek64.exe (PID: 5408)
    • Application launched itself

      • setup.exe (PID: 2088)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 5512)
    • Searches for installed software

      • geek64.exe (PID: 5408)
  • INFO

    • Reads the computer name

      • geek64.exe (PID: 5408)
      • msiexec.exe (PID: 5512)
      • setup.exe (PID: 2088)
    • Checks proxy server information

      • geek64.exe (PID: 5408)
    • Checks supported languages

      • geek.exe (PID: 6148)
      • msiexec.exe (PID: 5512)
      • setup.exe (PID: 2088)
      • setup.exe (PID: 456)
      • geek64.exe (PID: 5408)
    • Reads the software policy settings

      • geek64.exe (PID: 5408)
      • slui.exe (PID: 5380)
    • Reads the machine GUID from the registry

      • geek64.exe (PID: 5408)
    • Process checks computer location settings

      • geek64.exe (PID: 5408)
      • setup.exe (PID: 2088)
    • Create files in a temporary directory

      • geek.exe (PID: 6148)
      • msiexec.exe (PID: 1164)
    • Manages system restore points

      • SrTasks.exe (PID: 3396)
    • Creates files or folders in the user directory

      • geek64.exe (PID: 5408)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:10:17 09:59:10+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 1875968
InitializedDataSize: 4758016
UninitializedDataSize: -
EntryPoint: 0x17f174
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.5.1.163
ProductVersionNumber: 1.5.1.163
FileFlagsMask: 0x001f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Windows, Latin1
CompanyName: Geek Uninstaller
Comments: https://geekuninstaller.com
FileDescription: Geek Uninstaller
FileVersion: 1.5.1.163
InternalName: Geek Uninstaller
LegalCopyright: Copyright (C) 2012-2022 Geek Uninstaller
OriginalFileName: geek.exe
ProductName: Geek-Uninstaller
ProductVersion: 1.5.1.163
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
162
Monitored processes
20
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start geek.exe geek64.exe sppextcomobj.exe no specs slui.exe powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs msiexec.exe no specs msiexec.exe no specs vssvc.exe no specs slui.exe no specs srtasks.exe no specs conhost.exe no specs setup.exe no specs setup.exe msiexec.exe no specs geek.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
456"C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\Installer\setup.exe" --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler --database=C:\WINDOWS\SystemTemp\MsEdgeCrashpad --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\Installer\setup.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x254,0x258,0x25c,0x230,0x260,0x7ff62f8c69a8,0x7ff62f8c69b4,0x7ff62f8c69c0C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\Installer\setup.exe
setup.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Edge Installer
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\installer\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
960powershell.exe Remove-AppxPackage Microsoft.HEIFImageExtension_1.0.22742.0_x64__8wekyb3d8bbweC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exegeek64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1164MsiExec.exe /X{90569A00-0530-31BE-8158-0728D7E1FFC3}C:\Windows\System32\msiexec.exegeek64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
1603
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1912\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2088"C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\Installer\setup.exe" --uninstall --msedge --channel=stable --msi --system-level --verbose-logging --force-uninstallC:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\Installer\setup.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Installer
Exit code:
93
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\installer\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2136powershell.exe Remove-AppxPackage Microsoft.GetHelp_10.1706.13331.0_x64__8wekyb3d8bbweC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exegeek64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\atl.dll
2984MsiExec.exe /X{90569A00-0530-31BE-8158-0728D7E1FFC3}C:\Windows\System32\msiexec.exegeek64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
1602
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3024C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3396C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11C:\Windows\System32\SrTasks.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Windows System Protection background tasks.
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4488\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
25 416
Read events
24 996
Write events
235
Delete events
185

Modification events

(PID) Process:(5408) geek64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(5408) geek64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(5408) geek64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(5408) geek64.exeKey:HKEY_CLASSES_ROOT\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMicrosoft.YourPhone_0.19051.7.0_x64__8wekyb3d8bbwe%5Cresources.pri\1d5ace4595840bd\a37dfe62
Operation:writeName:@{C:\Program Files\WindowsApps\Microsoft.YourPhone_0.19051.7.0_x64__8wekyb3d8bbwe\resources.pri? ms-resource://Microsoft.YourPhone/resources/AppName}
Value:
Your Phone
(PID) Process:(5408) geek64.exeKey:HKEY_CLASSES_ROOT\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMicrosoft.WebpImageExtension_1.0.22753.0_x64__8wekyb3d8bbwe%5Cresources.pri\1d5ace4f91f4df8\a37dfe62
Operation:writeName:@{C:\Program Files\WindowsApps\Microsoft.WebpImageExtension_1.0.22753.0_x64__8wekyb3d8bbwe\resources.pri? ms-resource://Microsoft.WebpImageExtension/resources/AppStoreName}
Value:
Webp Image Extensions
(PID) Process:(5408) geek64.exeKey:HKEY_CLASSES_ROOT\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMicrosoft.VP9VideoExtensions_1.0.22681.0_x64__8wekyb3d8bbwe%5Cresources.pri\1d5ace4f10ea0f5\a37dfe62
Operation:writeName:@{C:\Program Files\WindowsApps\Microsoft.VP9VideoExtensions_1.0.22681.0_x64__8wekyb3d8bbwe\resources.pri? ms-resource://Microsoft.VP9VideoExtensions/resources/AppStoreName}
Value:
VP9 Video Extensions
(PID) Process:(5408) geek64.exeKey:HKEY_CLASSES_ROOT\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMicrosoft.ScreenSketch_10.1907.2471.0_x64__8wekyb3d8bbwe%5Cresources.pri\1d5ace4a450ec0e\a37dfe62
Operation:writeName:@{C:\Program Files\WindowsApps\Microsoft.ScreenSketch_10.1907.2471.0_x64__8wekyb3d8bbwe\resources.pri? ms-resource://Microsoft.ScreenSketch/resources/AppName/Text}
Value:
Snip & Sketch
(PID) Process:(5408) geek64.exeKey:HKEY_CLASSES_ROOT\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMicrosoft.MixedReality.Portal_2000.19081.1301.0_x64__8wekyb3d8bbwe%5Cresources.pri\1d5ace4f533928b\a37dfe62
Operation:writeName:@{C:\Program Files\WindowsApps\Microsoft.MixedReality.Portal_2000.19081.1301.0_x64__8wekyb3d8bbwe\resources.pri? ms-resource://Microsoft.MixedReality.Portal/resources/AppName/Text}
Value:
Mixed Reality Portal
(PID) Process:(5408) geek64.exeKey:HKEY_CLASSES_ROOT\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMicrosoft.XboxGamingOverlay_2.34.28001.0_x64__8wekyb3d8bbwe%5Cresources.pri\1d5ace4bb18b302\a37dfe62
Operation:writeName:@{C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_2.34.28001.0_x64__8wekyb3d8bbwe\resources.pri? ms-resource://Microsoft.XboxGamingOverlay/resources/GameBar}
Value:
Xbox Game Bar
(PID) Process:(5408) geek64.exeKey:HKEY_CLASSES_ROOT\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMicrosoft.Xbox.TCUI_1.23.28002.0_x64__8wekyb3d8bbwe%5Cresources.pri\1d5ace4c21e5292\a37dfe62
Operation:writeName:@{C:\Program Files\WindowsApps\Microsoft.Xbox.TCUI_1.23.28002.0_x64__8wekyb3d8bbwe\resources.pri? ms-resource://Microsoft.Xbox.TCUI/resources/DisplayName}
Value:
Xbox Live
Executable files
1
Suspicious files
20
Text files
22
Unknown types
0

Dropped files

PID
Process
Filename
Type
5408geek64.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B1D8E827B09770495C157EB924B07A1B_EFE37E64C41AB8D22D73FF6DE7AA9D4Ebinary
MD5:0F02DF6C9BC2B0D1ADBCF7B6A891C3E9
SHA256:3B16CD4942A4F136D645DB887D3DCB4446F00676907E970739490B53D18DBBCB
5408geek64.exeC:\Users\admin\AppData\Roaming\Geek Uninstaller\IconsCache\Microsoft.MicrosoftEdge.Stable_8wekyb3d8bbwe_Microsoft Edge.icoimage
MD5:C8512E17AFCA3CABDAD628271E128AF9
SHA256:DE5A52F86D172E80A8E85BBBA07E9113251618A0F5D0FB4707060A170BBBCE38
5408geek64.exeC:\Users\admin\AppData\Roaming\Geek Uninstaller\IconsCache\Microsoft.VP9VideoExtensions_8wekyb3d8bbwe_VP9 Video Extensions.icoimage
MD5:30E6CD8A49CEB9974E7A4704CC39406C
SHA256:84A8EEE47C77AB22D259FDB7BC94A82083B39656425F6E8942680CC7C45D5D38
5408geek64.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\update[1].txttext
MD5:83838B4289E8C584CFD2A53EF414D33D
SHA256:72727B107B79962C08A14D80FFA925387E83CD9ACACFBAB7C7F5DA679B5BDD91
6148geek.exeC:\Users\admin\AppData\Local\Temp\geek64.exeexecutable
MD5:2062E8118CF10D1FBA19A80A885C80F0
SHA256:316FBEC9ECA41DEEF9A63837DFAF4DE4369CA507C5B2143CD3A805CB238E5057
5408geek64.exeC:\Users\admin\AppData\Roaming\Geek Uninstaller\IconsCache\Microsoft.HEIFImageExtension_8wekyb3d8bbwe_HEIF Image Extensions.icoimage
MD5:30E6CD8A49CEB9974E7A4704CC39406C
SHA256:84A8EEE47C77AB22D259FDB7BC94A82083B39656425F6E8942680CC7C45D5D38
5408geek64.exeC:\Users\admin\AppData\Roaming\Geek Uninstaller\IconsCache\Microsoft.WebMediaExtensions_8wekyb3d8bbwe_Web Media Extensions.icoimage
MD5:30E6CD8A49CEB9974E7A4704CC39406C
SHA256:84A8EEE47C77AB22D259FDB7BC94A82083B39656425F6E8942680CC7C45D5D38
5408geek64.exeC:\Users\admin\AppData\Roaming\Geek Uninstaller\IconsCache\Microsoft.549981C3F5F10_8wekyb3d8bbwe_Cortana.icoimage
MD5:85538E2AFE3AD8902EBA14DC2160BE69
SHA256:D470DA64A300C2D6F60280582E650389369604637F7218628B169BC1A27FCB03
5408geek64.exeC:\Users\admin\AppData\Roaming\Geek Uninstaller\IconsCache\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe_Xbox Game Bar.icoimage
MD5:55B67D04253F1A0C23A11F9FB97EE6F2
SHA256:04666BC93AF050A9170B5C9FFB08FFC8D6436A4D719DD3839299D77A77E98D6C
5408geek64.exeC:\Users\admin\AppData\Roaming\Geek Uninstaller\cache.datbinary
MD5:B7AC2D94A885EBFA19B5B8BE84FAE3BF
SHA256:C60154B344B7605B6DC34913C5ABD64C99D3AA06CFAB59F6096A0382D8118892
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
29
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.22:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5408
geek64.exe
GET
200
2.16.2.75:80
http://r11.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBQaUrm0WeTDM5ghfoZtS72KO9ZnzgQUCLkRO6XQhRi06g%2BgrZ%2BGHo78OCcCEgYtafcrGXdlbTm4dvhQGJxV1g%3D%3D
unknown
whitelisted
5408
geek64.exe
GET
200
2.19.217.103:80
http://x1.c.lencr.org/
unknown
whitelisted
1128
SIHClient.exe
GET
200
2.19.217.218:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
1128
SIHClient.exe
GET
200
2.19.217.218:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.22:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
5408
geek64.exe
173.230.144.164:443
geekuninstaller.com
Linode, LLC
US
unknown
5408
geek64.exe
2.19.217.103:80
x1.c.lencr.org
Akamai International B.V.
NL
whitelisted
5408
geek64.exe
2.16.2.75:80
r11.o.lencr.org
Akamai International B.V.
CZ
whitelisted
2112
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.216.77.22
  • 23.216.77.25
  • 23.216.77.6
  • 23.216.77.28
whitelisted
google.com
  • 142.250.186.142
whitelisted
geekuninstaller.com
  • 173.230.144.164
unknown
x1.c.lencr.org
  • 2.19.217.103
whitelisted
r11.o.lencr.org
  • 2.16.2.75
  • 2.16.2.73
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 40.126.32.76
  • 20.190.160.132
  • 40.126.32.133
  • 40.126.32.138
  • 40.126.32.74
  • 20.190.160.3
  • 20.190.160.4
  • 20.190.160.130
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted

Threats

No threats detected
No debug info