File name:

FanDuel CT Player Location Check.exe

Full analysis: https://app.any.run/tasks/f58f0696-adf3-442c-980b-2aa15db0a50b
Verdict: Malicious activity
Analysis date: February 21, 2024, 15:16:18
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

95CD48619D0C022B68D74A541B9416C1

SHA1:

555BF9E14624F7BB8B8A06A0067BAFB8FD898DF2

SHA256:

D3AE92E9FF472BE443FA243FCC113F761E94A2B26173B4870314A6151CAE305C

SSDEEP:

98304:Rs0+7MMgCcW7YA7/5iCpKg/Xorvictlznl8/2Nh45K3ghZDPBFXnrUB01iB:IIB01G

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • FanDuel CT Player Location Check.exe (PID: 3672)
      • FanDuel CT Player Location Check.exe (PID: 2852)
  • SUSPICIOUS

    • Application launched itself

      • FanDuel CT Player Location Check.exe (PID: 3672)
    • Executes as Windows Service

      • service.exe (PID: 1824)
    • Creates a software uninstall entry

      • FanDuel CT Player Location Check.exe (PID: 2852)
    • Executable content was dropped or overwritten

      • FanDuel CT Player Location Check.exe (PID: 2852)
  • INFO

    • Reads the computer name

      • FanDuel CT Player Location Check.exe (PID: 3672)
      • FanDuel CT Player Location Check.exe (PID: 2852)
      • wmpnscfg.exe (PID: 3956)
      • service.exe (PID: 1824)
    • Reads the machine GUID from the registry

      • FanDuel CT Player Location Check.exe (PID: 2852)
      • service.exe (PID: 1740)
      • service.exe (PID: 1824)
    • Checks supported languages

      • FanDuel CT Player Location Check.exe (PID: 3672)
      • FanDuel CT Player Location Check.exe (PID: 2852)
      • wmpnscfg.exe (PID: 3956)
      • service.exe (PID: 1824)
      • service.exe (PID: 1740)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3956)
    • Create files in a temporary directory

      • FanDuel CT Player Location Check.exe (PID: 2852)
    • Creates files in the program directory

      • FanDuel CT Player Location Check.exe (PID: 2852)
      • service.exe (PID: 1824)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:07:15 12:35:01+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.25
CodeSize: 2542080
InitializedDataSize: 1026560
UninitializedDataSize: -
EntryPoint: 0x132913
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 3.0.2.59
ProductVersionNumber: 3.0.2.8
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: GeoComply
FileDescription: Player Location Check
FileVersion: 3.1.1.3
InternalName: Player Location Check
LegalCopyright: Copyright © 2020 GeoComply USA, Inc. All rights reserved.
OriginalFileName: Player Location Check.exe
ProductName: Player Location Check
ProductVersion: 3.1.1.3
Website: https://www.geocomply.com
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
7
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start fanduel ct player location check.exe no specs fanduel ct player location check.exe wmpnscfg.exe no specs service.exe no specs service.exe no specs schtasks.exe no specs schtasks.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1740"C:\Program Files\GeoComply\PlayerLocationCheck\Application\service.exe" /versionC:\Program Files\GeoComply\PlayerLocationCheck\Application\service.exeFanDuel CT Player Location Check.exe
User:
admin
Company:
GeoComply
Integrity Level:
HIGH
Description:
GeoComply GeoLocation Service
Exit code:
0
Version:
3.1.1.3
Modules
Images
c:\program files\geocomply\playerlocationcheck\application\service.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
1824"C:\Program Files\GeoComply\//PlayerLocationCheck///Application/service.exe"C:\Program Files\GeoComply\PlayerLocationCheck\Application\service.exeservices.exe
User:
SYSTEM
Company:
GeoComply
Integrity Level:
SYSTEM
Description:
GeoComply GeoLocation Service
Exit code:
0
Version:
3.1.1.3
Modules
Images
c:\program files\geocomply\playerlocationcheck\application\service.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
1860schtasks.exe /Create /RU "NT AUTHORITY\SYSTEM" /SC HOURLY /MO 1 /TN "GeoComply Update Task" /TR "\"C:\Program Files\GeoComply\\PlayerLocationCheck\Update\GeoComplyUpdate.exe\" /config=C:\Program Files\GeoComply\\PlayerLocationCheck\Update\GeoComplyUpdate.xml "C:\Windows\System32\schtasks.exeFanDuel CT Player Location Check.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
2852"C:\Users\admin\AppData\Local\Temp\FanDuel CT Player Location Check.exe" /runasadminC:\Users\admin\AppData\Local\Temp\FanDuel CT Player Location Check.exe
FanDuel CT Player Location Check.exe
User:
admin
Company:
GeoComply
Integrity Level:
HIGH
Description:
Player Location Check
Exit code:
0
Version:
3.1.1.3
Modules
Images
c:\users\admin\appdata\local\temp\fanduel ct player location check.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
c:\windows\system32\iphlpapi.dll
3068schtasks.exe /Delete /TN "GeoComply Update Task" /FC:\Windows\System32\schtasks.exeFanDuel CT Player Location Check.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
3672"C:\Users\admin\AppData\Local\Temp\FanDuel CT Player Location Check.exe" C:\Users\admin\AppData\Local\Temp\FanDuel CT Player Location Check.exeexplorer.exe
User:
admin
Company:
GeoComply
Integrity Level:
MEDIUM
Description:
Player Location Check
Exit code:
0
Version:
3.1.1.3
Modules
Images
c:\users\admin\appdata\local\temp\fanduel ct player location check.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
c:\windows\system32\iphlpapi.dll
3956"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
3 937
Read events
3 900
Write events
37
Delete events
0

Modification events

(PID) Process:(1824) service.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1740) service.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2852) FanDuel CT Player Location Check.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0753064-8D66-41A7-9F23-7691290387BF}
Operation:writeName:DisplayName
Value:
Player Location Check
(PID) Process:(2852) FanDuel CT Player Location Check.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0753064-8D66-41A7-9F23-7691290387BF}
Operation:writeName:DisplayIcon
Value:
C:\Program Files\GeoComply\PlayerLocationCheck\uninstall\0423bc1a-fda0-4510-a8e6-19090c7da560.exe,0
(PID) Process:(2852) FanDuel CT Player Location Check.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0753064-8D66-41A7-9F23-7691290387BF}
Operation:writeName:DisplayVersion
Value:
3.1.1.3
(PID) Process:(2852) FanDuel CT Player Location Check.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0753064-8D66-41A7-9F23-7691290387BF}
Operation:writeName:InstallLocation
Value:
C:\Program Files\GeoComply\
(PID) Process:(2852) FanDuel CT Player Location Check.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0753064-8D66-41A7-9F23-7691290387BF}
Operation:writeName:NoModify
Value:
1
(PID) Process:(2852) FanDuel CT Player Location Check.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0753064-8D66-41A7-9F23-7691290387BF}
Operation:writeName:NoRepair
Value:
1
(PID) Process:(2852) FanDuel CT Player Location Check.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0753064-8D66-41A7-9F23-7691290387BF}
Operation:writeName:Publisher
Value:
GeoComply
(PID) Process:(2852) FanDuel CT Player Location Check.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0753064-8D66-41A7-9F23-7691290387BF}
Operation:writeName:UninstallString
Value:
"C:\Program Files\GeoComply\PlayerLocationCheck\uninstall\0423bc1a-fda0-4510-a8e6-19090c7da560.exe" /uninstall
Executable files
11
Suspicious files
1
Text files
18
Unknown types
0

Dropped files

PID
Process
Filename
Type
2852FanDuel CT Player Location Check.exeC:\Users\admin\AppData\Local\Temp\tmp2852baaaaa\PlayerLocationCheck\Update\GeoComplyUpdate.inftext
MD5:87BA84BA03ADAB051016FE1994183D90
SHA256:F2379D32E9D62B222C1C8AA95C01D429AD670AAFFEF58A8557D74C4EEB93F633
2852FanDuel CT Player Location Check.exeC:\Users\admin\AppData\Local\Temp\tmp2852baaaaa\PlayerLocationCheck\Plugin\plugin.cfgxml
MD5:F93AD8F53FD5C1ADFA86D0403FD8F4E4
SHA256:3C070919A9239A1AE1E9379ACBEEBA4A3DD80232B08FB065235695D985FA5C1F
2852FanDuel CT Player Location Check.exeC:\Users\admin\AppData\Local\Temp\gc_plc_script.xmltext
MD5:335477BB762C5D4A8186C916D6FD9CBD
SHA256:78C0CA3F3B714AF0899508C635CC96A6269079F8643A3EEFB5C1E8572B418CCB
2852FanDuel CT Player Location Check.exeC:\Users\admin\AppData\Local\Temp\tmp2852baaaaa\PlayerLocationCheck\Update\upgrade.manifest.xmltext
MD5:376594EFD4F67327C5BD5AED3520708C
SHA256:8CF82E4ED00183B3E8096C00DFEAAA632EEE8BAD6445CCF5519D87B5167EF911
2852FanDuel CT Player Location Check.exeC:\Users\admin\AppData\Local\Temp\tmp2852baaaaa\PlayerLocationCheck\Application\PlayerLocationCheckTask.cmdtext
MD5:AD16BD03020B675244094EF769B5D318
SHA256:8846E1DA279248513A3B53A842731174858516AD62704B421EC72FF515B5208C
2852FanDuel CT Player Location Check.exeC:\Users\admin\AppData\Local\Temp\tmp2852baaaaa\PlayerLocationCheck\Application\service.xmltext
MD5:1EDF8636789B5C0A50A90C8E2E15ECFF
SHA256:83FEE2B5DAAFF59DC757D771FFC042CB2527DEE4BEA9A690239C88861BE2DF46
2852FanDuel CT Player Location Check.exeC:\Program Files\GeoComply\PlayerLocationCheck\Application\service.xmltext
MD5:1EDF8636789B5C0A50A90C8E2E15ECFF
SHA256:83FEE2B5DAAFF59DC757D771FFC042CB2527DEE4BEA9A690239C88861BE2DF46
2852FanDuel CT Player Location Check.exeC:\Users\admin\AppData\Local\Temp\tmp2852baaaaa\PlayerLocationCheck\Plugin\3.1.1.3\version.cfgxml
MD5:0B634E4DF98B44A373ADF5EDBB5FFCAC
SHA256:51E3986B2397DAB925571F28EBCB2BE1804F68E43C769FC867314D93615E622B
2852FanDuel CT Player Location Check.exeC:\Users\admin\AppData\Local\Temp\tmp2852baaaaa\PlayerLocationCheck\Plugin\3.1.1.3\gcapi\gc-sdk-clnt.dllexecutable
MD5:BA889BB6887B11D9F0D712419A9BCAC2
SHA256:67BF44717D800C54E1D0136DF7F4D6B6585A90CE6006C91047F37CA8291C522D
2852FanDuel CT Player Location Check.exeC:\Users\admin\AppData\Local\Temp\tmp2852aaaaaacompressed
MD5:007D355477B7A9C5B82377A777AC67BE
SHA256:877676528AFB3CC5ACA5243B038D24BEC3FFE0BAE79A7E386541E71786B0DE11
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
26
DNS requests
12
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2852
FanDuel CT Player Location Check.exe
GET
206
18.66.122.84:80
http://prod-downloads.geocomply.com/installer-packages/89AFE193-5BC0-4B1C-A4BC-CFB6F0E991EC/3.1.1.3/win/PROD-win-3.1.1.8-20221126-player-location-check-data.cab?Expires=1708530825&Signature=j7F9SPXdRlbbPcPWsT4lf-0Vi~~UilBZL6adSBqGwaur32NC-rq9U4s66d0jIi-5AQKBukSHFJEaGhBc9sV-v7Ozvz2H6jg48l9SJFL7KJQOCHDEFQjZykxRoxalSDGbBXNF4FkZepJrN2CtcfiIjmpVl4DHOdoIinewBdpyACEkK4Bnl5iPEJ1dtdn2qJDgFdSruRQDVKWcxDFu-lt0FJpVZj1kJtn0y-XRWKIOOQk~nQCt0JFBFw9L~g7qi09eHKi3DDQLSINuhpy-exExVqiAsUopZ29F~c19qoW6fKQZih~ejxRxteU3apyuAn~WFMQ6Zv4HrTavsCW7URP2rw__&Key-Pair-Id=APKAJAHZSWYHPOX2X2BQ
unknown
compressed
2.91 Mb
unknown
2852
FanDuel CT Player Location Check.exe
GET
206
18.66.122.41:80
http://prod-downloads.geocomply.com/installer-packages/89AFE193-5BC0-4B1C-A4BC-CFB6F0E991EC/3.1.1.3/win/PROD-win-3.1.1.8-20221126-player-location-check-data.cab?Expires=1708530825&Signature=j7F9SPXdRlbbPcPWsT4lf-0Vi~~UilBZL6adSBqGwaur32NC-rq9U4s66d0jIi-5AQKBukSHFJEaGhBc9sV-v7Ozvz2H6jg48l9SJFL7KJQOCHDEFQjZykxRoxalSDGbBXNF4FkZepJrN2CtcfiIjmpVl4DHOdoIinewBdpyACEkK4Bnl5iPEJ1dtdn2qJDgFdSruRQDVKWcxDFu-lt0FJpVZj1kJtn0y-XRWKIOOQk~nQCt0JFBFw9L~g7qi09eHKi3DDQLSINuhpy-exExVqiAsUopZ29F~c19qoW6fKQZih~ejxRxteU3apyuAn~WFMQ6Zv4HrTavsCW7URP2rw__&Key-Pair-Id=APKAJAHZSWYHPOX2X2BQ
unknown
binary
2.91 Mb
unknown
2852
FanDuel CT Player Location Check.exe
GET
206
18.66.122.49:80
http://prod-downloads.geocomply.com/installer-packages/89AFE193-5BC0-4B1C-A4BC-CFB6F0E991EC/3.1.1.3/win/PROD-win-3.1.1.8-20221126-player-location-check-data.cab?Expires=1708530825&Signature=j7F9SPXdRlbbPcPWsT4lf-0Vi~~UilBZL6adSBqGwaur32NC-rq9U4s66d0jIi-5AQKBukSHFJEaGhBc9sV-v7Ozvz2H6jg48l9SJFL7KJQOCHDEFQjZykxRoxalSDGbBXNF4FkZepJrN2CtcfiIjmpVl4DHOdoIinewBdpyACEkK4Bnl5iPEJ1dtdn2qJDgFdSruRQDVKWcxDFu-lt0FJpVZj1kJtn0y-XRWKIOOQk~nQCt0JFBFw9L~g7qi09eHKi3DDQLSINuhpy-exExVqiAsUopZ29F~c19qoW6fKQZih~ejxRxteU3apyuAn~WFMQ6Zv4HrTavsCW7URP2rw__&Key-Pair-Id=APKAJAHZSWYHPOX2X2BQ
unknown
binary
2.91 Mb
unknown
2852
FanDuel CT Player Location Check.exe
GET
206
18.66.122.29:80
http://prod-downloads.geocomply.com/installer-packages/89AFE193-5BC0-4B1C-A4BC-CFB6F0E991EC/3.1.1.3/win/PROD-win-3.1.1.8-20221126-player-location-check-data.cab?Expires=1708530825&Signature=j7F9SPXdRlbbPcPWsT4lf-0Vi~~UilBZL6adSBqGwaur32NC-rq9U4s66d0jIi-5AQKBukSHFJEaGhBc9sV-v7Ozvz2H6jg48l9SJFL7KJQOCHDEFQjZykxRoxalSDGbBXNF4FkZepJrN2CtcfiIjmpVl4DHOdoIinewBdpyACEkK4Bnl5iPEJ1dtdn2qJDgFdSruRQDVKWcxDFu-lt0FJpVZj1kJtn0y-XRWKIOOQk~nQCt0JFBFw9L~g7qi09eHKi3DDQLSINuhpy-exExVqiAsUopZ29F~c19qoW6fKQZih~ejxRxteU3apyuAn~WFMQ6Zv4HrTavsCW7URP2rw__&Key-Pair-Id=APKAJAHZSWYHPOX2X2BQ
unknown
binary
2.91 Mb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2852
FanDuel CT Player Location Check.exe
52.2.40.53:443
logger.geocomply.net
AMAZON-AES
US
unknown
2852
FanDuel CT Player Location Check.exe
34.194.204.84:443
ums.geocomply.com
AMAZON-AES
US
unknown
2852
FanDuel CT Player Location Check.exe
18.66.122.29:80
prod-downloads.geocomply.com
AMAZON-02
US
unknown
2852
FanDuel CT Player Location Check.exe
18.66.122.49:80
prod-downloads.geocomply.com
AMAZON-02
US
unknown
2852
FanDuel CT Player Location Check.exe
18.66.122.41:80
prod-downloads.geocomply.com
AMAZON-02
US
unknown
2852
FanDuel CT Player Location Check.exe
18.66.122.84:80
prod-downloads.geocomply.com
AMAZON-02
US
unknown
2852
FanDuel CT Player Location Check.exe
52.2.188.128:443
logger.geocomply.net
AMAZON-AES
US
unknown

DNS requests

Domain
IP
Reputation
logger.geocomply.net
  • 52.2.40.53
  • 52.2.188.128
unknown
ums.geocomply.com
  • 34.194.204.84
unknown
prod-downloads.geocomply.com
  • 18.66.122.84
  • 18.66.122.41
  • 18.66.122.29
  • 18.66.122.49
whitelisted

Threats

No threats detected
No debug info