download:

/installer/url/

Full analysis: https://app.any.run/tasks/29f4da85-0cd0-4ce9-a46b-ddc8fde88364
Verdict: Malicious activity
Analysis date: April 28, 2025, 23:54:16
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
themida
arch-exec
vmprotect
upx
aspack
nspack
neolite
mpress
fsg
pecompact
antivm
tsuloader
pepack
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 13 sections
MD5:

E0673FF5AE5D93A2FACEA44592864D07

SHA1:

C17D27F4A71D6E7126E5D468A76B23555E08BE64

SHA256:

D65A5DF5C2C3A6D0149FF0A916CA27E8E4461F2131981A18E23C7158737265A3

SSDEEP:

98304:moFJ3nIIYuie4l7VRBDKHJpFSpGElxVdyu+nTJQB3dv80yYd/ZTgBIt0tqDA3qgr:O48COo41vbu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the BIOS version

      • url.exe (PID: 7584)
      • GeoComplyUpdate.exe (PID: 7848)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • crash_handler.exe (PID: 7196)
      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • com.geocomply.internal-updater-microservice.exe (PID: 7576)
      • crash_handler.exe (PID: 7516)
      • crash_handler.exe (PID: 1676)
      • crash_handler.exe (PID: 780)
      • service.exe (PID: 5124)
      • crash_handler.exe (PID: 3784)
      • PlayerLocationIcon.exe (PID: 1056)
    • Executable content was dropped or overwritten

      • url.exe (PID: 7584)
      • GeoComplyUpdate.exe (PID: 7848)
    • Executes as Windows Service

      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • com.geocomply.internal-updater-microservice.exe (PID: 7576)
      • service.exe (PID: 5124)
    • There is functionality for VM detection VMWare (YARA)

      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • service.exe (PID: 5124)
    • Creates a software uninstall entry

      • GeoComplyUpdate.exe (PID: 7848)
  • INFO

    • Checks supported languages

      • url.exe (PID: 7584)
      • GeoComplyUpdate.exe (PID: 7848)
      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • crash_handler.exe (PID: 7196)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • crash_handler.exe (PID: 1676)
      • crash_handler.exe (PID: 7516)
      • com.geocomply.internal-updater-microservice.exe (PID: 7576)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • service.exe (PID: 5124)
      • crash_handler.exe (PID: 3784)
      • PlayerLocationIcon.exe (PID: 1056)
      • crash_handler.exe (PID: 780)
    • The sample compiled with english language support

      • url.exe (PID: 7584)
      • GeoComplyUpdate.exe (PID: 7848)
    • Creates files in the program directory

      • url.exe (PID: 7584)
      • GeoComplyUpdate.exe (PID: 7848)
      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • crash_handler.exe (PID: 7196)
      • crash_handler.exe (PID: 1676)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • crash_handler.exe (PID: 7516)
      • com.geocomply.internal-updater-microservice.exe (PID: 7576)
      • crash_handler.exe (PID: 3784)
      • crash_handler.exe (PID: 780)
      • service.exe (PID: 5124)
      • PlayerLocationIcon.exe (PID: 1056)
    • Process checks whether UAC notifications are on

      • url.exe (PID: 7584)
      • GeoComplyUpdate.exe (PID: 7848)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • crash_handler.exe (PID: 7196)
      • crash_handler.exe (PID: 1676)
      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • crash_handler.exe (PID: 7516)
      • com.geocomply.internal-updater-microservice.exe (PID: 7576)
      • service.exe (PID: 5124)
      • crash_handler.exe (PID: 3784)
      • crash_handler.exe (PID: 780)
    • Reads the computer name

      • url.exe (PID: 7584)
      • GeoComplyUpdate.exe (PID: 7848)
      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • com.geocomply.internal-updater-microservice.exe (PID: 7576)
      • service.exe (PID: 5124)
      • PlayerLocationIcon.exe (PID: 1056)
    • Create files in a temporary directory

      • url.exe (PID: 7584)
      • GeoComplyUpdate.exe (PID: 7848)
    • Themida protector has been detected

      • url.exe (PID: 7584)
      • GeoComplyUpdate.exe (PID: 7848)
      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • crash_handler.exe (PID: 7196)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • crash_handler.exe (PID: 1676)
      • crash_handler.exe (PID: 7516)
      • service.exe (PID: 5124)
      • crash_handler.exe (PID: 780)
      • crash_handler.exe (PID: 3784)
      • PlayerLocationIcon.exe (PID: 1056)
    • Reads the machine GUID from the registry

      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
    • Reads the software policy settings

      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
    • VMProtect protector has been detected

      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • service.exe (PID: 5124)
    • TSULoader has been detected

      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • service.exe (PID: 5124)
    • Creates files or folders in the user directory

      • PlayerLocationIcon.exe (PID: 1056)
    • FSG packer has been detected

      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • service.exe (PID: 5124)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
    • Pepack has been detected

      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • service.exe (PID: 5124)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
    • PECompact has been detected (YARA)

      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • service.exe (PID: 5124)
    • UPX packer has been detected

      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • service.exe (PID: 5124)
    • NsPack has been detected

      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • service.exe (PID: 5124)
    • Mpress packer has been detected

      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • service.exe (PID: 5124)
    • Aspack has been detected

      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • service.exe (PID: 5124)
    • Neolite packer has been detected

      • com.geocomply.process-scanner-microservice.exe (PID: 7252)
      • com.geocomply.vm-detector-microservice.exe (PID: 6808)
      • com.geocomply.wifi-scanner-microservice.exe (PID: 5352)
      • service.exe (PID: 5124)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:06:11 18:31:23+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 4054528
InitializedDataSize: 2247168
UninitializedDataSize: -
EntryPoint: 0xb8a058
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 4.1.0.0
ProductVersionNumber: 4.1.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: GeoComply
FileDescription: Player Location Check
FileVersion: 4.1.0.0
InternalName: Player Location Check
LegalCopyright: © 2024 GeoComply Solutions Inc.
OriginalFileName: Player Location Check.exe
ProductName: Player Location Check
ProductVersion: 4.1.0.0
Website: https://www.geocomply.com
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
154
Monitored processes
17
Malicious processes
13
Suspicious processes
0

Behavior graph

Click at the process to see the details
start url.exe geocomplyupdate.exe com.geocomply.process-scanner-microservice.exe no specs com.geocomply.vm-detector-microservice.exe no specs crash_handler.exe no specs com.geocomply.wifi-scanner-microservice.exe no specs crash_handler.exe no specs com.geocomply.internal-updater-microservice.exe no specs crash_handler.exe no specs service.exe no specs crash_handler.exe no specs crash_handler.exe no specs playerlocationicon.exe no specs explorer.exe no specs COpenControlPanel no specs slui.exe url.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
780"C:\Program Files (x86)\GeoComply\PlayerLocationCheck\CrashHandler\crash_handler.exe" --no-rate-limit "--database=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.internal-updater-microservice\crash_dumps" "--metrics-dir=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.internal-updater-microservice\crash_dumps" --url=https://sentry.geocomply.com:443/api/4/minidump/?sentry_client=sentry.native/0.6.2&sentry_key=fe16c1a9523e4ab0b3707ad66b0217dc "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.internal-updater-microservice\crash_dumps\02da2150-2906-4105-c708-235a736ff918.run\__sentry-event" "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.internal-updater-microservice\crash_dumps\02da2150-2906-4105-c708-235a736ff918.run\__sentry-breadcrumb1" "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.internal-updater-microservice\crash_dumps\02da2150-2906-4105-c708-235a736ff918.run\__sentry-breadcrumb2" --initial-client-data=0x470,0x474,0x478,0x46c,0x47c,0x1256ba8,0x1256bbc,0x1256bccC:\Program Files (x86)\GeoComply\PlayerLocationCheck\CrashHandler\crash_handler.execom.geocomply.internal-updater-microservice.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Modules
Images
c:\program files (x86)\geocomply\playerlocationcheck\crashhandler\crash_handler.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
1056"C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\PlayerLocationIcon.exe"C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\PlayerLocationIcon.exeservice.exe
User:
admin
Company:
GeoComply Solutions Inc.
Integrity Level:
MEDIUM
Description:
Player Location Tray Icon
Version:
4.1.0.3
Modules
Images
c:\program files (x86)\geocomply\playerlocationcheck\application\playerlocationicon.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\ole32.dll
c:\windows\syswow64\ucrtbase.dll
1676"C:\Program Files (x86)\GeoComply\PlayerLocationCheck\CrashHandler\crash_handler.exe" --no-rate-limit "--database=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.vm-detector-microservice\crash_dumps" "--metrics-dir=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.vm-detector-microservice\crash_dumps" --url=https://sentry.geocomply.com:443/api/4/minidump/?sentry_client=sentry.native/0.6.2&sentry_key=fe16c1a9523e4ab0b3707ad66b0217dc "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.vm-detector-microservice\crash_dumps\d60821cc-3fbf-46b9-a0d2-ad483cdde799.run\__sentry-event" "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.vm-detector-microservice\crash_dumps\d60821cc-3fbf-46b9-a0d2-ad483cdde799.run\__sentry-breadcrumb1" "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.vm-detector-microservice\crash_dumps\d60821cc-3fbf-46b9-a0d2-ad483cdde799.run\__sentry-breadcrumb2" --initial-client-data=0x470,0x474,0x478,0x46c,0x47c,0xfc6ba8,0xfc6bbc,0xfc6bccC:\Program Files (x86)\GeoComply\PlayerLocationCheck\CrashHandler\crash_handler.execom.geocomply.vm-detector-microservice.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Modules
Images
c:\program files (x86)\geocomply\playerlocationcheck\crashhandler\crash_handler.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
3784"C:\Program Files (x86)\GeoComply\PlayerLocationCheck\CrashHandler\crash_handler.exe" --no-rate-limit "--database=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\service\crash_dumps" "--metrics-dir=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\service\crash_dumps" --url=https://sentry.geocomply.com:443/api/4/minidump/?sentry_client=sentry.native/0.6.2&sentry_key=fe16c1a9523e4ab0b3707ad66b0217dc "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\service\crash_dumps\d7f3e066-2b40-4803-6717-d9b2d86c5783.run\__sentry-event" "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\service\crash_dumps\d7f3e066-2b40-4803-6717-d9b2d86c5783.run\__sentry-breadcrumb1" "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\service\crash_dumps\d7f3e066-2b40-4803-6717-d9b2d86c5783.run\__sentry-breadcrumb2" --initial-client-data=0x480,0x484,0x488,0x47c,0x48c,0x1940978,0x194098c,0x194099cC:\Program Files (x86)\GeoComply\PlayerLocationCheck\CrashHandler\crash_handler.exeservice.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Modules
Images
c:\program files (x86)\geocomply\playerlocationcheck\crashhandler\crash_handler.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
5124"C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\service.exe"C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\service.exeservices.exe
User:
SYSTEM
Company:
GeoComply Solutions Inc.
Integrity Level:
SYSTEM
Description:
Player Location Check Service
Version:
4.1.0.3
Modules
Images
c:\program files (x86)\geocomply\playerlocationcheck\application\service.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\ole32.dll
c:\windows\syswow64\ucrtbase.dll
5352"C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.wifi-scanner-microservice.exe"C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.wifi-scanner-microservice.exeservices.exe
User:
SYSTEM
Company:
GeoComply Solutions Inc.
Integrity Level:
SYSTEM
Description:
WiFi Scanner Micro Service
Version:
4.1.0.3
Modules
Images
c:\program files (x86)\geocomply\playerlocationcheck\application\com.geocomply.wifi-scanner-microservice.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\ole32.dll
c:\windows\syswow64\ucrtbase.dll
6468C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6808"C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.vm-detector-microservice.exe"C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.vm-detector-microservice.exeservices.exe
User:
SYSTEM
Company:
GeoComply Solutions Inc.
Integrity Level:
SYSTEM
Description:
VM Detector Micro Service
Version:
4.1.0.3
Modules
Images
c:\program files (x86)\geocomply\playerlocationcheck\application\com.geocomply.vm-detector-microservice.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\ole32.dll
c:\windows\syswow64\ucrtbase.dll
7196"C:\Program Files (x86)\GeoComply\PlayerLocationCheck\CrashHandler\crash_handler.exe" --no-rate-limit "--database=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.process-scanner-microservice\crash_dumps" "--metrics-dir=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.process-scanner-microservice\crash_dumps" --url=https://sentry.geocomply.com:443/api/4/minidump/?sentry_client=sentry.native/0.6.2&sentry_key=fe16c1a9523e4ab0b3707ad66b0217dc "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.process-scanner-microservice\crash_dumps\a33b9ec9-123e-4010-9d77-a0d92590098b.run\__sentry-event" "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.process-scanner-microservice\crash_dumps\a33b9ec9-123e-4010-9d77-a0d92590098b.run\__sentry-breadcrumb1" "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.process-scanner-microservice\crash_dumps\a33b9ec9-123e-4010-9d77-a0d92590098b.run\__sentry-breadcrumb2" --initial-client-data=0x4c8,0x4d0,0x4d4,0x4cc,0x4d8,0xca6ba8,0xca6bbc,0xca6bccC:\Program Files (x86)\GeoComply\PlayerLocationCheck\CrashHandler\crash_handler.execom.geocomply.process-scanner-microservice.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Modules
Images
c:\program files (x86)\geocomply\playerlocationcheck\crashhandler\crash_handler.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7252"C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.process-scanner-microservice.exe"C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.process-scanner-microservice.exeservices.exe
User:
SYSTEM
Company:
GeoComply Solutions Inc.
Integrity Level:
SYSTEM
Description:
Process Scanner Micro Service
Version:
4.1.0.3
Modules
Images
c:\program files (x86)\geocomply\playerlocationcheck\application\com.geocomply.process-scanner-microservice.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\ole32.dll
c:\windows\syswow64\ucrtbase.dll
Total events
78 219
Read events
78 178
Write events
40
Delete events
1

Modification events

(PID) Process:(7848) GeoComplyUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0753064-8D66-41A7-9F23-7691290387BF}
Operation:writeName:DisplayIcon
Value:
C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Update\GeoComplyUpdate.exe
(PID) Process:(7848) GeoComplyUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0753064-8D66-41A7-9F23-7691290387BF}
Operation:writeName:DisplayName
Value:
Player Location Check
(PID) Process:(7848) GeoComplyUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0753064-8D66-41A7-9F23-7691290387BF}
Operation:writeName:DisplayVersion
Value:
4.1.0.3
(PID) Process:(7848) GeoComplyUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0753064-8D66-41A7-9F23-7691290387BF}
Operation:writeName:Publisher
Value:
GeoComply
(PID) Process:(7848) GeoComplyUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0753064-8D66-41A7-9F23-7691290387BF}
Operation:writeName:UninstallString
Value:
"C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Update\GeoComplyUpdate.exe" /uninstall
(PID) Process:(7800) explorer.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:NodeSlots
Value:
02020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
(PID) Process:(7800) explorer.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:MRUListEx
Value:
0000000004000000030000000E000000100000000F0000000C0000000D0000000B000000050000000A000000090000000800000001000000070000000600000002000000FFFFFFFF
(PID) Process:(7800) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar
Operation:writeName:Locked
Value:
1
(PID) Process:(7800) explorer.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell
Operation:writeName:NavBar
Value:
000000000000000000000000000000008B000000870000003153505305D5CDD59C2E1B10939708002B2CF9AE6B0000005A000000007B00360044003800420042003300440033002D0039004400380037002D0034004100390031002D0041004200350036002D003400460033003000430046004600450046004500390046007D005F0057006900640074006800000013000000CC0000000000000000000000
(PID) Process:(7800) explorer.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\4\Shell\{0C3794F3-B545-43AA-A329-C37430C58D2A}
Operation:writeName:Rev
Value:
0
Executable files
20
Suspicious files
67
Text files
14
Unknown types
0

Dropped files

PID
Process
Filename
Type
7848GeoComplyUpdate.exeC:\Users\admin\AppData\Local\Temp\6679-83f9-2991-701a
MD5:
SHA256:
7584url.exeC:\Users\admin\AppData\Local\Temp\b14c-a62b-3238-38e5\Update\Update\upgrade.manifest.xmlxml
MD5:4CF0793D12D0008BCBDCBA4FA27C1BFB
SHA256:F8D78CE8D22951EB76E5BB0C36D063C589195ADE437F1B83259ABF930224DBCD
7584url.exeC:\Users\admin\AppData\Local\Temp\b14c-a62b-3238-38e5\Update\Update\GeoComplyUpdate.infxml
MD5:36959AF2697CD2A21DA0026E101ACFCE
SHA256:14F77206CB9FEB9E61CBC0A43CE9BAA11C53375A78237396812BD4F38E1A920F
7584url.exeC:\Users\admin\AppData\Local\Temp\c0d0-5d77-043c-af54compressed
MD5:590AFF6BCE7745ACBD32C8246EBA1017
SHA256:83358A10C4D8CD7045E0722C776A3C59BCC567718DE63D6BDD33A48270D55CB0
7848GeoComplyUpdate.exeC:\Users\admin\AppData\Local\Temp\465d-7428-a1b6-db4e\PlayerLocationCheck\Application\com.geocomply.process-scanner-microservice.exeexecutable
MD5:C6E6AA49F2E5390AC8AFB5E679FB053B
SHA256:FA7CF44C544944449FA0FA5C09026D157BBB7BA6C9362D10030EF509564A42D8
7584url.exeC:\Users\admin\AppData\Local\Temp\b14c-a62b-3238-38e5\Update\Update\manifest.xmlxml
MD5:FBA05CD6839EA3D5ACA9F68C5CD5257F
SHA256:FD13AAD581C9AC46D86F4A9FFDD6D6DAC5E8AA95A8362656ED2EB7AEF6DAE209
7848GeoComplyUpdate.exeC:\Program Files (x86)\GeoComply\PlayerLocationCheck\Update\GeoComplyUpdate.exeexecutable
MD5:57825971D603090D7500C4C96500966E
SHA256:5B5303C4DE53D0CD36B3396E290C2BDA4BA8688A3EEAD74E6DF39F4B53481067
7848GeoComplyUpdate.exeC:\ProgramData\GeoComply\Logs\GeoComplyUpdate_1654694004.db-journalbinary
MD5:3E33FAE8DB0A4197E2B348424B9E9E67
SHA256:4D5A69B257FE30FC96FA6EA68FF579A894F9EE2F26630A646EB59890ED0D732C
7848GeoComplyUpdate.exeC:\Users\admin\AppData\Local\Temp\465d-7428-a1b6-db4e\PlayerLocationCheck\manifest.xmlxml
MD5:3F0601683C3BCB0E4516F987C5DCFF7F
SHA256:915D8CF320CF5BDFFA4973AC0A1DE509FCD2902C521C0D88A9498815808BB48C
7848GeoComplyUpdate.exeC:\Users\admin\AppData\Local\Temp\465d-7428-a1b6-db4e\PlayerLocationCheck\Application\com.geocomply.internal-updater-microservice.exeexecutable
MD5:FD7307FE83D310EBFC585129FAFF8ABE
SHA256:B2C102AD34E6C022F0B8E2785A7DB350A8405348052BA4EACB5DB22828A3C946
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
70
DNS requests
23
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
8104
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
8104
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6480
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.28:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
7584
url.exe
34.195.184.53:443
ums.geocomply.com
AMAZON-AES
US
unknown
7584
url.exe
18.66.122.41:443
prod-downloads.geocomply.com
AMAZON-02
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
google.com
  • 142.250.185.142
whitelisted
crl.microsoft.com
  • 23.216.77.28
  • 23.216.77.6
  • 23.216.77.42
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
ums.geocomply.com
  • 34.195.184.53
unknown
prod-downloads.geocomply.com
  • 18.66.122.41
  • 18.66.122.29
  • 18.66.122.49
  • 18.66.122.84
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted
www.bing.com
  • 2.16.241.201
  • 2.16.241.218
whitelisted

Threats

No threats detected
No debug info