URL:

https://github.com/hillelkingqt/GeminiDesk/releases/tag/v8.2.0

Full analysis: https://app.any.run/tasks/0cbfd354-d496-4308-8a59-41c3b929c595
Verdict: Malicious activity
Analysis date: December 24, 2025, 21:00:53
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
github
nodejs
Indicators:
MD5:

AEDC6A42DBDFBB41F0EA6DBB934304A1

SHA1:

1B88F75EE550CD5B5821A4F0CF78076B22697DDA

SHA256:

BBFE44291D5900295B1FAF76D50DF3B0FC80F8FF04A0D19EE33DA2F43321A2A0

SSDEEP:

3:N8tEd9MHAJxc4W+S2qKtx:2uYHAJy49xz

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • reg.exe (PID: 8444)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • GeminiDesk-Setup-8.2.0.exe (PID: 9056)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • GeminiDesk-Setup-8.2.0.exe (PID: 9056)
    • Starts CMD.EXE for commands execution

      • GeminiDesk-Setup-8.2.0.exe (PID: 9056)
      • GeminiDesk.exe (PID: 8256)
    • Executable content was dropped or overwritten

      • GeminiDesk-Setup-8.2.0.exe (PID: 9056)
    • Get information on the list of running processes

      • GeminiDesk-Setup-8.2.0.exe (PID: 9056)
      • cmd.exe (PID: 9104)
    • Drops 7-zip archiver for unpacking

      • GeminiDesk-Setup-8.2.0.exe (PID: 9056)
    • Process drops legitimate windows executable

      • GeminiDesk-Setup-8.2.0.exe (PID: 9056)
    • Reads security settings of Internet Explorer

      • GeminiDesk-Setup-8.2.0.exe (PID: 9056)
    • There is functionality for taking screenshot (YARA)

      • GeminiDesk-Setup-8.2.0.exe (PID: 9056)
    • Application launched itself

      • GeminiDesk.exe (PID: 8256)
    • Uses REG/REGEDIT.EXE to modify registry

      • GeminiDesk.exe (PID: 8256)
    • Starts POWERSHELL.EXE for commands execution

      • cmd.exe (PID: 8732)
  • INFO

    • Checks supported languages

      • identity_helper.exe (PID: 2256)
      • GeminiDesk-Setup-8.2.0.exe (PID: 9056)
      • GeminiDesk.exe (PID: 8256)
      • GeminiDesk.exe (PID: 8276)
      • GeminiDesk.exe (PID: 6904)
      • GeminiDesk.exe (PID: 2424)
      • GeminiDesk.exe (PID: 8844)
      • GeminiDesk.exe (PID: 7404)
      • GeminiDesk.exe (PID: 3104)
      • GeminiDesk.exe (PID: 2460)
      • GeminiDesk.exe (PID: 8432)
      • GeminiDesk.exe (PID: 2600)
      • GeminiDesk.exe (PID: 4468)
      • GeminiDesk.exe (PID: 5180)
      • GeminiDesk.exe (PID: 9188)
      • GeminiDesk.exe (PID: 9172)
      • GeminiDesk.exe (PID: 1180)
      • GeminiDesk.exe (PID: 9192)
      • GeminiDesk.exe (PID: 3008)
      • GeminiDesk.exe (PID: 1420)
    • Application launched itself

      • msedge.exe (PID: 7624)
    • The sample compiled with english language support

      • msedge.exe (PID: 7624)
      • GeminiDesk-Setup-8.2.0.exe (PID: 9056)
    • Reads the computer name

      • identity_helper.exe (PID: 2256)
      • GeminiDesk-Setup-8.2.0.exe (PID: 9056)
      • GeminiDesk.exe (PID: 8256)
      • GeminiDesk.exe (PID: 8276)
      • GeminiDesk.exe (PID: 6904)
      • GeminiDesk.exe (PID: 4468)
      • GeminiDesk.exe (PID: 2600)
    • Manual execution by a user

      • GeminiDesk-Setup-8.2.0.exe (PID: 9056)
      • GeminiDesk.exe (PID: 8256)
    • Reads Environment values

      • identity_helper.exe (PID: 2256)
      • GeminiDesk.exe (PID: 8256)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 7624)
    • Create files in a temporary directory

      • GeminiDesk-Setup-8.2.0.exe (PID: 9056)
      • GeminiDesk.exe (PID: 8256)
    • Creates files or folders in the user directory

      • GeminiDesk-Setup-8.2.0.exe (PID: 9056)
      • GeminiDesk.exe (PID: 8256)
      • GeminiDesk.exe (PID: 8276)
    • Reads product name

      • GeminiDesk.exe (PID: 8256)
    • Process checks computer location settings

      • GeminiDesk.exe (PID: 8256)
      • GeminiDesk.exe (PID: 2424)
      • GeminiDesk.exe (PID: 8844)
      • GeminiDesk.exe (PID: 2460)
      • GeminiDesk.exe (PID: 3104)
      • GeminiDesk.exe (PID: 7404)
      • GeminiDesk.exe (PID: 8432)
      • GeminiDesk.exe (PID: 5180)
      • GeminiDesk.exe (PID: 1180)
      • GeminiDesk.exe (PID: 9188)
      • GeminiDesk.exe (PID: 9192)
      • GeminiDesk.exe (PID: 9172)
      • GeminiDesk.exe (PID: 1420)
      • GeminiDesk.exe (PID: 3008)
    • Checks proxy server information

      • GeminiDesk.exe (PID: 8256)
      • slui.exe (PID: 7548)
    • Reads the machine GUID from the registry

      • GeminiDesk.exe (PID: 8256)
    • Creates a software uninstall entry

      • GeminiDesk-Setup-8.2.0.exe (PID: 9056)
    • Launching a file from a Registry key

      • reg.exe (PID: 8444)
    • Node.js compiler has been detected

      • GeminiDesk.exe (PID: 8256)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 7284)
    • Checks current location (POWERSHELL)

      • powershell.exe (PID: 7284)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
213
Monitored processes
63
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs geminidesk-setup-8.2.0.exe cmd.exe no specs conhost.exe no specs tasklist.exe no specs find.exe no specs geminidesk.exe geminidesk.exe no specs geminidesk.exe geminidesk.exe no specs reg.exe conhost.exe no specs slui.exe geminidesk.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs geminidesk.exe no specs msedge.exe no specs msedge.exe no specs geminidesk.exe no specs geminidesk.exe no specs geminidesk.exe no specs geminidesk.exe no specs geminidesk.exe no specs msedge.exe no specs geminidesk.exe no specs geminidesk.exe no specs msedge.exe no specs msedge.exe no specs geminidesk.exe no specs geminidesk.exe no specs geminidesk.exe no specs geminidesk.exe no specs geminidesk.exe no specs cmd.exe no specs powershell.exe no specs conhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
508"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=5 --always-read-main-dll --field-trial-handle=3616,i,14390665461477782026,9669675705117314667,262144 --variations-seed-version --mojo-platform-channel-handle=3748 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1180"C:\Users\admin\AppData\Local\Programs\GeminiDesk\GeminiDesk.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\gemini-desk" --app-path="C:\Users\admin\AppData\Local\Programs\GeminiDesk\resources\app.asar" --enable-sandbox --remote-debugging-port=9222 --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=15 --field-trial-handle=1740,i,6097575927282639094,14102249765707534590,262144 --enable-features=PdfUseShowSaveFilePicker,ThirdPartyStoragePartitioning --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit --variations-seed-version --disable-logging --log-level=3 --v=0 --mojo-platform-channel-handle=5236 /prefetch:1C:\Users\admin\AppData\Local\Programs\GeminiDesk\GeminiDesk.exeGeminiDesk.exe
User:
admin
Company:
Hillel BH
Integrity Level:
LOW
Description:
GeminiDesk
Exit code:
0
Version:
8.2.0
Modules
Images
c:\users\admin\appdata\local\programs\geminidesk\geminidesk.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
1420"C:\Users\admin\AppData\Local\Programs\GeminiDesk\GeminiDesk.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\gemini-desk" --app-path="C:\Users\admin\AppData\Local\Programs\GeminiDesk\resources\app.asar" --remote-debugging-port=9222 --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=19 --field-trial-handle=1740,i,6097575927282639094,14102249765707534590,262144 --enable-features=PdfUseShowSaveFilePicker,ThirdPartyStoragePartitioning --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit --variations-seed-version --disable-logging --log-level=3 --v=0 --mojo-platform-channel-handle=5468 /prefetch:1C:\Users\admin\AppData\Local\Programs\GeminiDesk\GeminiDesk.exeGeminiDesk.exe
User:
admin
Company:
Hillel BH
Integrity Level:
LOW
Description:
GeminiDesk
Exit code:
0
Version:
8.2.0
Modules
Images
c:\users\admin\appdata\local\programs\geminidesk\geminidesk.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
2256"C:\Program Files (x86)\Microsoft\Edge\Application\133.0.3065.92\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5144,i,14390665461477782026,9669675705117314667,262144 --variations-seed-version --mojo-platform-channel-handle=5600 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\133.0.3065.92\identity_helper.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\identity_helper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2424"C:\Users\admin\AppData\Local\Programs\GeminiDesk\GeminiDesk.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\gemini-desk" --app-path="C:\Users\admin\AppData\Local\Programs\GeminiDesk\resources\app.asar" --enable-sandbox --remote-debugging-port=9222 --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=4 --field-trial-handle=1740,i,6097575927282639094,14102249765707534590,262144 --enable-features=PdfUseShowSaveFilePicker,ThirdPartyStoragePartitioning --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit --variations-seed-version --disable-logging --log-level=3 --v=0 --mojo-platform-channel-handle=2856 /prefetch:1C:\Users\admin\AppData\Local\Programs\GeminiDesk\GeminiDesk.exeGeminiDesk.exe
User:
admin
Company:
Hillel BH
Integrity Level:
LOW
Description:
GeminiDesk
Version:
8.2.0
Modules
Images
c:\users\admin\appdata\local\programs\geminidesk\geminidesk.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
2460"C:\Users\admin\AppData\Local\Programs\GeminiDesk\GeminiDesk.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\gemini-desk" --app-path="C:\Users\admin\AppData\Local\Programs\GeminiDesk\resources\app.asar" --enable-sandbox --remote-debugging-port=9222 --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=7 --field-trial-handle=1740,i,6097575927282639094,14102249765707534590,262144 --enable-features=PdfUseShowSaveFilePicker,ThirdPartyStoragePartitioning --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit --variations-seed-version --disable-logging --log-level=3 --v=0 --mojo-platform-channel-handle=4528 /prefetch:1C:\Users\admin\AppData\Local\Programs\GeminiDesk\GeminiDesk.exeGeminiDesk.exe
User:
admin
Company:
Hillel BH
Integrity Level:
LOW
Description:
GeminiDesk
Exit code:
0
Version:
8.2.0
Modules
Images
c:\users\admin\appdata\local\programs\geminidesk\geminidesk.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
2600"C:\Users\admin\AppData\Local\Programs\GeminiDesk\GeminiDesk.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --user-data-dir="C:\Users\admin\AppData\Roaming\gemini-desk" --field-trial-handle=1740,i,6097575927282639094,14102249765707534590,262144 --enable-features=PdfUseShowSaveFilePicker,ThirdPartyStoragePartitioning --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit --variations-seed-version --disable-logging --log-level=3 --v=0 --mojo-platform-channel-handle=5080 /prefetch:8C:\Users\admin\AppData\Local\Programs\GeminiDesk\GeminiDesk.exeGeminiDesk.exe
User:
admin
Company:
Hillel BH
Integrity Level:
MEDIUM
Description:
GeminiDesk
Version:
8.2.0
Modules
Images
c:\users\admin\appdata\local\programs\geminidesk\geminidesk.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2856"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=6 --always-read-main-dll --field-trial-handle=3572,i,14390665461477782026,9669675705117314667,262144 --variations-seed-version --mojo-platform-channel-handle=3628 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3008"C:\Users\admin\AppData\Local\Programs\GeminiDesk\GeminiDesk.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\gemini-desk" --app-path="C:\Users\admin\AppData\Local\Programs\GeminiDesk\resources\app.asar" --remote-debugging-port=9222 --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=20 --field-trial-handle=1740,i,6097575927282639094,14102249765707534590,262144 --enable-features=PdfUseShowSaveFilePicker,ThirdPartyStoragePartitioning --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit --variations-seed-version --disable-logging --log-level=3 --v=0 --mojo-platform-channel-handle=5288 /prefetch:1C:\Users\admin\AppData\Local\Programs\GeminiDesk\GeminiDesk.exeGeminiDesk.exe
User:
admin
Company:
Hillel BH
Integrity Level:
LOW
Description:
GeminiDesk
Version:
8.2.0
Modules
Images
c:\users\admin\appdata\local\programs\geminidesk\geminidesk.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
3104"C:\Users\admin\AppData\Local\Programs\GeminiDesk\GeminiDesk.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\gemini-desk" --app-path="C:\Users\admin\AppData\Local\Programs\GeminiDesk\resources\app.asar" --enable-sandbox --remote-debugging-port=9222 --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=9 --field-trial-handle=1740,i,6097575927282639094,14102249765707534590,262144 --enable-features=PdfUseShowSaveFilePicker,ThirdPartyStoragePartitioning --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit --variations-seed-version --disable-logging --log-level=3 --v=0 --mojo-platform-channel-handle=4212 /prefetch:1C:\Users\admin\AppData\Local\Programs\GeminiDesk\GeminiDesk.exeGeminiDesk.exe
User:
admin
Company:
Hillel BH
Integrity Level:
LOW
Description:
GeminiDesk
Version:
8.2.0
Modules
Images
c:\users\admin\appdata\local\programs\geminidesk\geminidesk.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
Total events
19 110
Read events
19 076
Write events
16
Delete events
18

Modification events

(PID) Process:(9056) GeminiDesk-Setup-8.2.0.exeKey:HKEY_CURRENT_USER\SOFTWARE\8a06cbf6-c39e-57e1-97f5-1137702cada2
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Local\Programs\GeminiDesk
(PID) Process:(9056) GeminiDesk-Setup-8.2.0.exeKey:HKEY_CURRENT_USER\SOFTWARE\8a06cbf6-c39e-57e1-97f5-1137702cada2
Operation:writeName:KeepShortcuts
Value:
true
(PID) Process:(9056) GeminiDesk-Setup-8.2.0.exeKey:HKEY_CURRENT_USER\SOFTWARE\8a06cbf6-c39e-57e1-97f5-1137702cada2
Operation:writeName:ShortcutName
Value:
GeminiDesk
(PID) Process:(9056) GeminiDesk-Setup-8.2.0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\8a06cbf6-c39e-57e1-97f5-1137702cada2
Operation:writeName:DisplayName
Value:
GeminiDesk 8.2.0
(PID) Process:(9056) GeminiDesk-Setup-8.2.0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\8a06cbf6-c39e-57e1-97f5-1137702cada2
Operation:writeName:UninstallString
Value:
"C:\Users\admin\AppData\Local\Programs\GeminiDesk\Uninstall GeminiDesk.exe" /currentuser
(PID) Process:(9056) GeminiDesk-Setup-8.2.0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\8a06cbf6-c39e-57e1-97f5-1137702cada2
Operation:writeName:QuietUninstallString
Value:
"C:\Users\admin\AppData\Local\Programs\GeminiDesk\Uninstall GeminiDesk.exe" /currentuser /S
(PID) Process:(9056) GeminiDesk-Setup-8.2.0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\8a06cbf6-c39e-57e1-97f5-1137702cada2
Operation:writeName:DisplayVersion
Value:
8.2.0
(PID) Process:(9056) GeminiDesk-Setup-8.2.0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\8a06cbf6-c39e-57e1-97f5-1137702cada2
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Local\Programs\GeminiDesk\uninstallerIcon.ico
(PID) Process:(9056) GeminiDesk-Setup-8.2.0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\8a06cbf6-c39e-57e1-97f5-1137702cada2
Operation:writeName:Publisher
Value:
Hillel BH
(PID) Process:(9056) GeminiDesk-Setup-8.2.0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\8a06cbf6-c39e-57e1-97f5-1137702cada2
Operation:writeName:NoModify
Value:
1
Executable files
25
Suspicious files
472
Text files
437
Unknown types
22

Dropped files

PID
Process
Filename
Type
7624msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RFfe17d.TMP
MD5:
SHA256:
7624msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old
MD5:
SHA256:
7624msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RFfe18d.TMP
MD5:
SHA256:
7624msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old
MD5:
SHA256:
7624msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RFfe18d.TMP
MD5:
SHA256:
7624msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
7624msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RFfe18d.TMP
MD5:
SHA256:
7624msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
7624msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RFfe1ac.TMP
MD5:
SHA256:
7624msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RFfe1ac.TMP
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
256
TCP/UDP connections
191
DNS requests
170
Threats
12

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7948
msedge.exe
GET
200
150.171.27.11:443
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
unknown
text
462 b
whitelisted
7948
msedge.exe
GET
200
150.171.27.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:QBFRVMi4nWQ518ukFSUVJSGPCjYi6JDFW9rwZLu9AtQ&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
unknown
whitelisted
7948
msedge.exe
GET
200
150.171.22.17:443
https://config.edge.skype.com/config/v1/Edge/133.0.3065.92?clientId=4489578223053569932&agents=EdgeFirstRun%2CEdgeFirstRunConfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=65&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1741678270&lafgdate=0
unknown
text
768 b
whitelisted
7948
msedge.exe
GET
200
104.18.22.222:443
https://copilot.microsoft.com/c/api/user/eligibility
unknown
25 b
whitelisted
7948
msedge.exe
GET
200
140.82.121.4:443
https://github.com/hillelkingqt/GeminiDesk/releases/tag/v8.2.0
unknown
html
128 Kb
unknown
7948
msedge.exe
GET
200
185.199.109.154:443
https://github.githubassets.com/assets/light-dac525bbd821.css
unknown
text
83.9 Kb
whitelisted
7948
msedge.exe
GET
200
185.199.109.154:443
https://github.githubassets.com/assets/keyboard-shortcuts-dialog.29aaeaafa90f007c6f61.module.css
unknown
1.72 Kb
whitelisted
7948
msedge.exe
GET
200
185.199.109.154:443
https://github.githubassets.com/assets/marketing-navigation.8284bdfe1ee4804a58c1.module.css
unknown
9.65 Kb
whitelisted
7948
msedge.exe
GET
200
185.199.109.154:443
https://github.githubassets.com/assets/light_high_contrast-56ccf4057897.css
unknown
text
84.4 Kb
whitelisted
7948
msedge.exe
GET
200
185.199.109.154:443
https://github.githubassets.com/assets/dark-784387e86ac0.css
unknown
text
83.7 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6300
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
6768
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2680
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
7948
msedge.exe
150.171.22.17:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7948
msedge.exe
150.171.27.11:80
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7948
msedge.exe
150.171.27.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7948
msedge.exe
140.82.121.4:443
github.com
GITHUB
US
whitelisted
7948
msedge.exe
104.18.22.222:443
copilot.microsoft.com
CLOUDFLARENET
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
whitelisted
google.com
  • 142.250.184.238
whitelisted
edge.microsoft.com
  • 150.171.27.11
  • 150.171.28.11
whitelisted
config.edge.skype.com
  • 150.171.22.17
whitelisted
github.com
  • 140.82.121.4
  • 140.82.121.3
whitelisted
copilot.microsoft.com
  • 104.18.22.222
  • 104.18.23.222
whitelisted
www.bing.com
  • 2.16.204.152
  • 2.16.204.146
  • 2.16.204.144
  • 2.16.204.147
  • 2.16.204.157
  • 2.16.204.160
  • 2.16.204.150
  • 2.16.204.143
  • 2.16.204.145
whitelisted
github.githubassets.com
  • 185.199.109.154
  • 185.199.108.154
  • 185.199.110.154
  • 185.199.111.154
whitelisted
avatars.githubusercontent.com
  • 185.199.109.133
  • 185.199.111.133
  • 185.199.110.133
  • 185.199.108.133
whitelisted
user-images.githubusercontent.com
  • 185.199.111.133
  • 185.199.108.133
  • 185.199.109.133
  • 185.199.110.133
whitelisted

Threats

PID
Process
Class
Message
7948
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access release user assets on GitHub
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
Potentially Bad Traffic
ET INFO PE EXE or DLL Windows file download HTTP
Misc activity
ET INFO EXE - Served Attached HTTP
2292
svchost.exe
Misc activity
ET INFO DNS Query to Online Application Hosting Domain (onrender .com)
2292
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Host dynamic web apps service (.onrender .com)
8256
GeminiDesk.exe
Misc activity
ET INFO Observed Online Application Hosting Domain (onrender .com in TLS SNI)
8276
GeminiDesk.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access release user assets on GitHub
8276
GeminiDesk.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
8276
GeminiDesk.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
No debug info