download:

/installer/url/

Full analysis: https://app.any.run/tasks/29f4da85-0cd0-4ce9-a46b-ddc8fde88364
Verdict: Malicious activity
Analysis date: April 28, 2025, 23:54:16
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
themida
arch-exec
vmprotect
upx
aspack
nspack
neolite
mpress
fsg
pecompact
antivm
tsuloader
pepack
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 13 sections
MD5:

E0673FF5AE5D93A2FACEA44592864D07

SHA1:

C17D27F4A71D6E7126E5D468A76B23555E08BE64

SHA256:

D65A5DF5C2C3A6D0149FF0A916CA27E8E4461F2131981A18E23C7158737265A3

SSDEEP:

98304:moFJ3nIIYuie4l7VRBDKHJpFSpGElxVdyu+nTJQB3dv80yYd/ZTgBIt0tqDA3qgr:O48COo41vbu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executes as Windows Service

      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • com.geocomply.internal-updater-microservice.exe (PID: 7576)
      • service.exe (PID: 5124)
    • Reads the BIOS version

      • url.exe (PID: 7584)
      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • crash_handler.exe (PID: 7196)
      • crash_handler.exe (PID: 1676)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • crash_handler.exe (PID: 7516)
      • com.geocomply.internal-updater-microservice.exe (PID: 7576)
      • crash_handler.exe (PID: 780)
      • service.exe (PID: 5124)
      • crash_handler.exe (PID: 3784)
      • PlayerLocationIcon.exe (PID: 1056)
      • GeoComplyUpdate.exe (PID: 7848)
    • Executable content was dropped or overwritten

      • url.exe (PID: 7584)
      • GeoComplyUpdate.exe (PID: 7848)
    • Creates a software uninstall entry

      • GeoComplyUpdate.exe (PID: 7848)
    • There is functionality for VM detection VMWare (YARA)

      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • service.exe (PID: 5124)
  • INFO

    • Checks supported languages

      • url.exe (PID: 7584)
      • GeoComplyUpdate.exe (PID: 7848)
      • crash_handler.exe (PID: 7196)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • com.geocomply.internal-updater-microservice.exe (PID: 7576)
      • crash_handler.exe (PID: 1676)
      • crash_handler.exe (PID: 7516)
      • crash_handler.exe (PID: 780)
      • service.exe (PID: 5124)
      • crash_handler.exe (PID: 3784)
      • PlayerLocationIcon.exe (PID: 1056)
      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
    • Themida protector has been detected

      • GeoComplyUpdate.exe (PID: 7848)
      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • url.exe (PID: 7584)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • crash_handler.exe (PID: 7196)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • crash_handler.exe (PID: 1676)
      • crash_handler.exe (PID: 7516)
      • service.exe (PID: 5124)
      • crash_handler.exe (PID: 780)
      • crash_handler.exe (PID: 3784)
      • PlayerLocationIcon.exe (PID: 1056)
    • Process checks whether UAC notifications are on

      • url.exe (PID: 7584)
      • GeoComplyUpdate.exe (PID: 7848)
      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • crash_handler.exe (PID: 7196)
      • crash_handler.exe (PID: 1676)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • crash_handler.exe (PID: 7516)
      • com.geocomply.internal-updater-microservice.exe (PID: 7576)
      • crash_handler.exe (PID: 780)
      • service.exe (PID: 5124)
      • crash_handler.exe (PID: 3784)
    • Creates files in the program directory

      • url.exe (PID: 7584)
      • GeoComplyUpdate.exe (PID: 7848)
      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • crash_handler.exe (PID: 7196)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • crash_handler.exe (PID: 1676)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • com.geocomply.internal-updater-microservice.exe (PID: 7576)
      • crash_handler.exe (PID: 780)
      • crash_handler.exe (PID: 7516)
      • service.exe (PID: 5124)
      • crash_handler.exe (PID: 3784)
      • PlayerLocationIcon.exe (PID: 1056)
    • The sample compiled with english language support

      • url.exe (PID: 7584)
      • GeoComplyUpdate.exe (PID: 7848)
    • Reads the computer name

      • url.exe (PID: 7584)
      • GeoComplyUpdate.exe (PID: 7848)
      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • com.geocomply.internal-updater-microservice.exe (PID: 7576)
      • PlayerLocationIcon.exe (PID: 1056)
      • service.exe (PID: 5124)
    • Create files in a temporary directory

      • url.exe (PID: 7584)
      • GeoComplyUpdate.exe (PID: 7848)
    • Reads the software policy settings

      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
    • Reads the machine GUID from the registry

      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
    • Creates files or folders in the user directory

      • PlayerLocationIcon.exe (PID: 1056)
    • VMProtect protector has been detected

      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • service.exe (PID: 5124)
    • TSULoader has been detected

      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • service.exe (PID: 5124)
    • Pepack has been detected

      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • service.exe (PID: 5124)
    • PECompact has been detected (YARA)

      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • service.exe (PID: 5124)
    • UPX packer has been detected

      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • service.exe (PID: 5124)
    • NsPack has been detected

      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • service.exe (PID: 5124)
    • Neolite packer has been detected

      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • service.exe (PID: 5124)
    • Mpress packer has been detected

      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • service.exe (PID: 5124)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
    • Aspack has been detected

      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • service.exe (PID: 5124)
    • FSG packer has been detected

      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • service.exe (PID: 5124)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:06:11 18:31:23+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 4054528
InitializedDataSize: 2247168
UninitializedDataSize: -
EntryPoint: 0xb8a058
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 4.1.0.0
ProductVersionNumber: 4.1.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: GeoComply
FileDescription: Player Location Check
FileVersion: 4.1.0.0
InternalName: Player Location Check
LegalCopyright: © 2024 GeoComply Solutions Inc.
OriginalFileName: Player Location Check.exe
ProductName: Player Location Check
ProductVersion: 4.1.0.0
Website: https://www.geocomply.com
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
154
Monitored processes
17
Malicious processes
13
Suspicious processes
0

Behavior graph

Click at the process to see the details
start url.exe geocomplyupdate.exe com.geocomply.process-scanner-microservice.exe no specs com.geocomply.vm-detector-microservice.exe no specs crash_handler.exe no specs com.geocomply.wifi-scanner-microservice.exe no specs crash_handler.exe no specs com.geocomply.internal-updater-microservice.exe no specs crash_handler.exe no specs service.exe no specs crash_handler.exe no specs crash_handler.exe no specs playerlocationicon.exe no specs explorer.exe no specs COpenControlPanel no specs slui.exe url.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
780"C:\Program Files (x86)\GeoComply\PlayerLocationCheck\CrashHandler\crash_handler.exe" --no-rate-limit "--database=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.internal-updater-microservice\crash_dumps" "--metrics-dir=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.internal-updater-microservice\crash_dumps" --url=https://sentry.geocomply.com:443/api/4/minidump/?sentry_client=sentry.native/0.6.2&sentry_key=fe16c1a9523e4ab0b3707ad66b0217dc "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.internal-updater-microservice\crash_dumps\02da2150-2906-4105-c708-235a736ff918.run\__sentry-event" "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.internal-updater-microservice\crash_dumps\02da2150-2906-4105-c708-235a736ff918.run\__sentry-breadcrumb1" "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.internal-updater-microservice\crash_dumps\02da2150-2906-4105-c708-235a736ff918.run\__sentry-breadcrumb2" --initial-client-data=0x470,0x474,0x478,0x46c,0x47c,0x1256ba8,0x1256bbc,0x1256bccC:\Program Files (x86)\GeoComply\PlayerLocationCheck\CrashHandler\crash_handler.execom.geocomply.internal-updater-microservice.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Modules
Images
c:\program files (x86)\geocomply\playerlocationcheck\crashhandler\crash_handler.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
1056"C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\PlayerLocationIcon.exe"C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\PlayerLocationIcon.exeservice.exe
User:
admin
Company:
GeoComply Solutions Inc.
Integrity Level:
MEDIUM
Description:
Player Location Tray Icon
Version:
4.1.0.3
Modules
Images
c:\program files (x86)\geocomply\playerlocationcheck\application\playerlocationicon.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\ole32.dll
c:\windows\syswow64\ucrtbase.dll
1676"C:\Program Files (x86)\GeoComply\PlayerLocationCheck\CrashHandler\crash_handler.exe" --no-rate-limit "--database=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.vm-detector-microservice\crash_dumps" "--metrics-dir=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.vm-detector-microservice\crash_dumps" --url=https://sentry.geocomply.com:443/api/4/minidump/?sentry_client=sentry.native/0.6.2&sentry_key=fe16c1a9523e4ab0b3707ad66b0217dc "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.vm-detector-microservice\crash_dumps\d60821cc-3fbf-46b9-a0d2-ad483cdde799.run\__sentry-event" "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.vm-detector-microservice\crash_dumps\d60821cc-3fbf-46b9-a0d2-ad483cdde799.run\__sentry-breadcrumb1" "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.vm-detector-microservice\crash_dumps\d60821cc-3fbf-46b9-a0d2-ad483cdde799.run\__sentry-breadcrumb2" --initial-client-data=0x470,0x474,0x478,0x46c,0x47c,0xfc6ba8,0xfc6bbc,0xfc6bccC:\Program Files (x86)\GeoComply\PlayerLocationCheck\CrashHandler\crash_handler.execom.geocomply.vm-detector-microservice.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Modules
Images
c:\program files (x86)\geocomply\playerlocationcheck\crashhandler\crash_handler.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
3784"C:\Program Files (x86)\GeoComply\PlayerLocationCheck\CrashHandler\crash_handler.exe" --no-rate-limit "--database=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\service\crash_dumps" "--metrics-dir=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\service\crash_dumps" --url=https://sentry.geocomply.com:443/api/4/minidump/?sentry_client=sentry.native/0.6.2&sentry_key=fe16c1a9523e4ab0b3707ad66b0217dc "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\service\crash_dumps\d7f3e066-2b40-4803-6717-d9b2d86c5783.run\__sentry-event" "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\service\crash_dumps\d7f3e066-2b40-4803-6717-d9b2d86c5783.run\__sentry-breadcrumb1" "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\service\crash_dumps\d7f3e066-2b40-4803-6717-d9b2d86c5783.run\__sentry-breadcrumb2" --initial-client-data=0x480,0x484,0x488,0x47c,0x48c,0x1940978,0x194098c,0x194099cC:\Program Files (x86)\GeoComply\PlayerLocationCheck\CrashHandler\crash_handler.exeservice.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Modules
Images
c:\program files (x86)\geocomply\playerlocationcheck\crashhandler\crash_handler.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
5124"C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\service.exe"C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\service.exeservices.exe
User:
SYSTEM
Company:
GeoComply Solutions Inc.
Integrity Level:
SYSTEM
Description:
Player Location Check Service
Version:
4.1.0.3
Modules
Images
c:\program files (x86)\geocomply\playerlocationcheck\application\service.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\ole32.dll
c:\windows\syswow64\ucrtbase.dll
5352"C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.wifi-scanner-microservice.exe"C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.wifi-scanner-microservice.exeservices.exe
User:
SYSTEM
Company:
GeoComply Solutions Inc.
Integrity Level:
SYSTEM
Description:
WiFi Scanner Micro Service
Version:
4.1.0.3
Modules
Images
c:\program files (x86)\geocomply\playerlocationcheck\application\com.geocomply.wifi-scanner-microservice.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\ole32.dll
c:\windows\syswow64\ucrtbase.dll
6468C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6808"C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.vm-detector-microservice.exe"C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.vm-detector-microservice.exeservices.exe
User:
SYSTEM
Company:
GeoComply Solutions Inc.
Integrity Level:
SYSTEM
Description:
VM Detector Micro Service
Version:
4.1.0.3
Modules
Images
c:\program files (x86)\geocomply\playerlocationcheck\application\com.geocomply.vm-detector-microservice.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\ole32.dll
c:\windows\syswow64\ucrtbase.dll
7196"C:\Program Files (x86)\GeoComply\PlayerLocationCheck\CrashHandler\crash_handler.exe" --no-rate-limit "--database=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.process-scanner-microservice\crash_dumps" "--metrics-dir=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.process-scanner-microservice\crash_dumps" --url=https://sentry.geocomply.com:443/api/4/minidump/?sentry_client=sentry.native/0.6.2&sentry_key=fe16c1a9523e4ab0b3707ad66b0217dc "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.process-scanner-microservice\crash_dumps\a33b9ec9-123e-4010-9d77-a0d92590098b.run\__sentry-event" "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.process-scanner-microservice\crash_dumps\a33b9ec9-123e-4010-9d77-a0d92590098b.run\__sentry-breadcrumb1" "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.process-scanner-microservice\crash_dumps\a33b9ec9-123e-4010-9d77-a0d92590098b.run\__sentry-breadcrumb2" --initial-client-data=0x4c8,0x4d0,0x4d4,0x4cc,0x4d8,0xca6ba8,0xca6bbc,0xca6bccC:\Program Files (x86)\GeoComply\PlayerLocationCheck\CrashHandler\crash_handler.execom.geocomply.process-scanner-microservice.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Modules
Images
c:\program files (x86)\geocomply\playerlocationcheck\crashhandler\crash_handler.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7252"C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.process-scanner-microservice.exe"C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.process-scanner-microservice.exeservices.exe
User:
SYSTEM
Company:
GeoComply Solutions Inc.
Integrity Level:
SYSTEM
Description:
Process Scanner Micro Service
Version:
4.1.0.3
Modules
Images
c:\program files (x86)\geocomply\playerlocationcheck\application\com.geocomply.process-scanner-microservice.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\ole32.dll
c:\windows\syswow64\ucrtbase.dll
Total events
78 219
Read events
78 178
Write events
40
Delete events
1

Modification events

(PID) Process:(7848) GeoComplyUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0753064-8D66-41A7-9F23-7691290387BF}
Operation:writeName:DisplayIcon
Value:
C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Update\GeoComplyUpdate.exe
(PID) Process:(7848) GeoComplyUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0753064-8D66-41A7-9F23-7691290387BF}
Operation:writeName:DisplayName
Value:
Player Location Check
(PID) Process:(7848) GeoComplyUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0753064-8D66-41A7-9F23-7691290387BF}
Operation:writeName:DisplayVersion
Value:
4.1.0.3
(PID) Process:(7848) GeoComplyUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0753064-8D66-41A7-9F23-7691290387BF}
Operation:writeName:Publisher
Value:
GeoComply
(PID) Process:(7848) GeoComplyUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0753064-8D66-41A7-9F23-7691290387BF}
Operation:writeName:UninstallString
Value:
"C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Update\GeoComplyUpdate.exe" /uninstall
(PID) Process:(7800) explorer.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:NodeSlots
Value:
02020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
(PID) Process:(7800) explorer.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:MRUListEx
Value:
0000000004000000030000000E000000100000000F0000000C0000000D0000000B000000050000000A000000090000000800000001000000070000000600000002000000FFFFFFFF
(PID) Process:(7800) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar
Operation:writeName:Locked
Value:
1
(PID) Process:(7800) explorer.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell
Operation:writeName:NavBar
Value:
000000000000000000000000000000008B000000870000003153505305D5CDD59C2E1B10939708002B2CF9AE6B0000005A000000007B00360044003800420042003300440033002D0039004400380037002D0034004100390031002D0041004200350036002D003400460033003000430046004600450046004500390046007D005F0057006900640074006800000013000000CC0000000000000000000000
(PID) Process:(7800) explorer.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\4\Shell\{0C3794F3-B545-43AA-A329-C37430C58D2A}
Operation:writeName:Rev
Value:
0
Executable files
20
Suspicious files
67
Text files
14
Unknown types
0

Dropped files

PID
Process
Filename
Type
7848GeoComplyUpdate.exeC:\Users\admin\AppData\Local\Temp\6679-83f9-2991-701a
MD5:
SHA256:
7584url.exeC:\ProgramData\GeoComply\Logs\url_4267941084.db-journalbinary
MD5:5409F944E0A76084FBD9BE2EB7AFD62F
SHA256:94DB852E87DC7ADE89E83AB0673ADE23133FC39EA01BBAE6339C81B154DFCFE7
7584url.exeC:\ProgramData\mntempbinary
MD5:CC41518F91D1DA5A4AD221D09C0BE3CA
SHA256:5CAF7A076CA1DCEB85CED68578BDA436E9045C56781FB7FC622A696A1DEEA5B6
7584url.exeC:\Users\admin\AppData\Local\Temp\b14c-a62b-3238-38e5\Update\Update\GeoComplyUpdate.exeexecutable
MD5:57825971D603090D7500C4C96500966E
SHA256:5B5303C4DE53D0CD36B3396E290C2BDA4BA8688A3EEAD74E6DF39F4B53481067
7584url.exeC:\Users\admin\AppData\Local\Temp\b14c-a62b-3238-38e5\Update\Update\upgrade.manifest.xmlxml
MD5:4CF0793D12D0008BCBDCBA4FA27C1BFB
SHA256:F8D78CE8D22951EB76E5BB0C36D063C589195ADE437F1B83259ABF930224DBCD
7584url.exeC:\Users\admin\AppData\Local\Temp\b14c-a62b-3238-38e5\Update\Update\GeoComplyUpdate.infxml
MD5:36959AF2697CD2A21DA0026E101ACFCE
SHA256:14F77206CB9FEB9E61CBC0A43CE9BAA11C53375A78237396812BD4F38E1A920F
7584url.exeC:\Windows\INF\machine.PNFbinary
MD5:4C103190BC521FF032845C1B5FDADC4F
SHA256:28C1DEE803488C32BF5229B05FB3F6DA8959A436BB17D331E68AFA61A3BE932F
7848GeoComplyUpdate.exeC:\Users\admin\AppData\Local\Temp\465d-7428-a1b6-db4e\PlayerLocationCheck\Application\com.geocomply.internal-updater-microservice.exeexecutable
MD5:FD7307FE83D310EBFC585129FAFF8ABE
SHA256:B2C102AD34E6C022F0B8E2785A7DB350A8405348052BA4EACB5DB22828A3C946
7848GeoComplyUpdate.exeC:\Program Files (x86)\GeoComply\PlayerLocationCheck\Update\GeoComplyUpdate.infxml
MD5:36959AF2697CD2A21DA0026E101ACFCE
SHA256:14F77206CB9FEB9E61CBC0A43CE9BAA11C53375A78237396812BD4F38E1A920F
7584url.exeC:\Users\admin\AppData\Local\Temp\b14c-a62b-3238-38e5\Update\Update\manifest.xmlxml
MD5:FBA05CD6839EA3D5ACA9F68C5CD5257F
SHA256:FD13AAD581C9AC46D86F4A9FFDD6D6DAC5E8AA95A8362656ED2EB7AEF6DAE209
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
70
DNS requests
23
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
8104
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
8104
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6480
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.28:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
7584
url.exe
34.195.184.53:443
ums.geocomply.com
AMAZON-AES
US
unknown
7584
url.exe
18.66.122.41:443
prod-downloads.geocomply.com
AMAZON-02
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
google.com
  • 142.250.185.142
whitelisted
crl.microsoft.com
  • 23.216.77.28
  • 23.216.77.6
  • 23.216.77.42
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
ums.geocomply.com
  • 34.195.184.53
unknown
prod-downloads.geocomply.com
  • 18.66.122.41
  • 18.66.122.29
  • 18.66.122.49
  • 18.66.122.84
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted
www.bing.com
  • 2.16.241.201
  • 2.16.241.218
whitelisted

Threats

No threats detected
No debug info