| download: | /installer/url/ |
| Full analysis: | https://app.any.run/tasks/29f4da85-0cd0-4ce9-a46b-ddc8fde88364 |
| Verdict: | Malicious activity |
| Analysis date: | April 28, 2025, 23:54:16 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 13 sections |
| MD5: | E0673FF5AE5D93A2FACEA44592864D07 |
| SHA1: | C17D27F4A71D6E7126E5D468A76B23555E08BE64 |
| SHA256: | D65A5DF5C2C3A6D0149FF0A916CA27E8E4461F2131981A18E23C7158737265A3 |
| SSDEEP: | 98304:moFJ3nIIYuie4l7VRBDKHJpFSpGElxVdyu+nTJQB3dv80yYd/ZTgBIt0tqDA3qgr:O48COo41vbu |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:06:11 18:31:23+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.29 |
| CodeSize: | 4054528 |
| InitializedDataSize: | 2247168 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xb8a058 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 4.1.0.0 |
| ProductVersionNumber: | 4.1.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Unknown |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | GeoComply |
| FileDescription: | Player Location Check |
| FileVersion: | 4.1.0.0 |
| InternalName: | Player Location Check |
| LegalCopyright: | © 2024 GeoComply Solutions Inc. |
| OriginalFileName: | Player Location Check.exe |
| ProductName: | Player Location Check |
| ProductVersion: | 4.1.0.0 |
| Website: | https://www.geocomply.com |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 780 | "C:\Program Files (x86)\GeoComply\PlayerLocationCheck\CrashHandler\crash_handler.exe" --no-rate-limit "--database=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.internal-updater-microservice\crash_dumps" "--metrics-dir=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.internal-updater-microservice\crash_dumps" --url=https://sentry.geocomply.com:443/api/4/minidump/?sentry_client=sentry.native/0.6.2&sentry_key=fe16c1a9523e4ab0b3707ad66b0217dc "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.internal-updater-microservice\crash_dumps\02da2150-2906-4105-c708-235a736ff918.run\__sentry-event" "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.internal-updater-microservice\crash_dumps\02da2150-2906-4105-c708-235a736ff918.run\__sentry-breadcrumb1" "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.internal-updater-microservice\crash_dumps\02da2150-2906-4105-c708-235a736ff918.run\__sentry-breadcrumb2" --initial-client-data=0x470,0x474,0x478,0x46c,0x47c,0x1256ba8,0x1256bbc,0x1256bcc | C:\Program Files (x86)\GeoComply\PlayerLocationCheck\CrashHandler\crash_handler.exe | — | com.geocomply.internal-updater-microservice.exe | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Modules
| |||||||||||||||
| 1056 | "C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\PlayerLocationIcon.exe" | C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\PlayerLocationIcon.exe | — | service.exe | |||||||||||
User: admin Company: GeoComply Solutions Inc. Integrity Level: MEDIUM Description: Player Location Tray Icon Version: 4.1.0.3 Modules
| |||||||||||||||
| 1676 | "C:\Program Files (x86)\GeoComply\PlayerLocationCheck\CrashHandler\crash_handler.exe" --no-rate-limit "--database=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.vm-detector-microservice\crash_dumps" "--metrics-dir=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.vm-detector-microservice\crash_dumps" --url=https://sentry.geocomply.com:443/api/4/minidump/?sentry_client=sentry.native/0.6.2&sentry_key=fe16c1a9523e4ab0b3707ad66b0217dc "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.vm-detector-microservice\crash_dumps\d60821cc-3fbf-46b9-a0d2-ad483cdde799.run\__sentry-event" "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.vm-detector-microservice\crash_dumps\d60821cc-3fbf-46b9-a0d2-ad483cdde799.run\__sentry-breadcrumb1" "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.vm-detector-microservice\crash_dumps\d60821cc-3fbf-46b9-a0d2-ad483cdde799.run\__sentry-breadcrumb2" --initial-client-data=0x470,0x474,0x478,0x46c,0x47c,0xfc6ba8,0xfc6bbc,0xfc6bcc | C:\Program Files (x86)\GeoComply\PlayerLocationCheck\CrashHandler\crash_handler.exe | — | com.geocomply.vm-detector-microservice.exe | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Modules
| |||||||||||||||
| 3784 | "C:\Program Files (x86)\GeoComply\PlayerLocationCheck\CrashHandler\crash_handler.exe" --no-rate-limit "--database=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\service\crash_dumps" "--metrics-dir=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\service\crash_dumps" --url=https://sentry.geocomply.com:443/api/4/minidump/?sentry_client=sentry.native/0.6.2&sentry_key=fe16c1a9523e4ab0b3707ad66b0217dc "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\service\crash_dumps\d7f3e066-2b40-4803-6717-d9b2d86c5783.run\__sentry-event" "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\service\crash_dumps\d7f3e066-2b40-4803-6717-d9b2d86c5783.run\__sentry-breadcrumb1" "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\service\crash_dumps\d7f3e066-2b40-4803-6717-d9b2d86c5783.run\__sentry-breadcrumb2" --initial-client-data=0x480,0x484,0x488,0x47c,0x48c,0x1940978,0x194098c,0x194099c | C:\Program Files (x86)\GeoComply\PlayerLocationCheck\CrashHandler\crash_handler.exe | — | service.exe | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Modules
| |||||||||||||||
| 5124 | "C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\service.exe" | C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\service.exe | — | services.exe | |||||||||||
User: SYSTEM Company: GeoComply Solutions Inc. Integrity Level: SYSTEM Description: Player Location Check Service Version: 4.1.0.3 Modules
| |||||||||||||||
| 5352 | "C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.wifi-scanner-microservice.exe" | C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.wifi-scanner-microservice.exe | — | services.exe | |||||||||||
User: SYSTEM Company: GeoComply Solutions Inc. Integrity Level: SYSTEM Description: WiFi Scanner Micro Service Version: 4.1.0.3 Modules
| |||||||||||||||
| 6468 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6808 | "C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.vm-detector-microservice.exe" | C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.vm-detector-microservice.exe | — | services.exe | |||||||||||
User: SYSTEM Company: GeoComply Solutions Inc. Integrity Level: SYSTEM Description: VM Detector Micro Service Version: 4.1.0.3 Modules
| |||||||||||||||
| 7196 | "C:\Program Files (x86)\GeoComply\PlayerLocationCheck\CrashHandler\crash_handler.exe" --no-rate-limit "--database=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.process-scanner-microservice\crash_dumps" "--metrics-dir=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.process-scanner-microservice\crash_dumps" --url=https://sentry.geocomply.com:443/api/4/minidump/?sentry_client=sentry.native/0.6.2&sentry_key=fe16c1a9523e4ab0b3707ad66b0217dc "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.process-scanner-microservice\crash_dumps\a33b9ec9-123e-4010-9d77-a0d92590098b.run\__sentry-event" "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.process-scanner-microservice\crash_dumps\a33b9ec9-123e-4010-9d77-a0d92590098b.run\__sentry-breadcrumb1" "--attachment=C:\ProgramData\GeoComply\Player Location Check\4.1.0.3\com.geocomply.process-scanner-microservice\crash_dumps\a33b9ec9-123e-4010-9d77-a0d92590098b.run\__sentry-breadcrumb2" --initial-client-data=0x4c8,0x4d0,0x4d4,0x4cc,0x4d8,0xca6ba8,0xca6bbc,0xca6bcc | C:\Program Files (x86)\GeoComply\PlayerLocationCheck\CrashHandler\crash_handler.exe | — | com.geocomply.process-scanner-microservice.exe | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Modules
| |||||||||||||||
| 7252 | "C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.process-scanner-microservice.exe" | C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\com.geocomply.process-scanner-microservice.exe | — | services.exe | |||||||||||
User: SYSTEM Company: GeoComply Solutions Inc. Integrity Level: SYSTEM Description: Process Scanner Micro Service Version: 4.1.0.3 Modules
| |||||||||||||||
| (PID) Process: | (7848) GeoComplyUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0753064-8D66-41A7-9F23-7691290387BF} |
| Operation: | write | Name: | DisplayIcon |
Value: C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Update\GeoComplyUpdate.exe | |||
| (PID) Process: | (7848) GeoComplyUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0753064-8D66-41A7-9F23-7691290387BF} |
| Operation: | write | Name: | DisplayName |
Value: Player Location Check | |||
| (PID) Process: | (7848) GeoComplyUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0753064-8D66-41A7-9F23-7691290387BF} |
| Operation: | write | Name: | DisplayVersion |
Value: 4.1.0.3 | |||
| (PID) Process: | (7848) GeoComplyUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0753064-8D66-41A7-9F23-7691290387BF} |
| Operation: | write | Name: | Publisher |
Value: GeoComply | |||
| (PID) Process: | (7848) GeoComplyUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0753064-8D66-41A7-9F23-7691290387BF} |
| Operation: | write | Name: | UninstallString |
Value: "C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Update\GeoComplyUpdate.exe" /uninstall | |||
| (PID) Process: | (7800) explorer.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU |
| Operation: | write | Name: | NodeSlots |
Value: 02020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202 | |||
| (PID) Process: | (7800) explorer.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU |
| Operation: | write | Name: | MRUListEx |
Value: 0000000004000000030000000E000000100000000F0000000C0000000D0000000B000000050000000A000000090000000800000001000000070000000600000002000000FFFFFFFF | |||
| (PID) Process: | (7800) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar |
| Operation: | write | Name: | Locked |
Value: 1 | |||
| (PID) Process: | (7800) explorer.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell |
| Operation: | write | Name: | NavBar |
Value: 000000000000000000000000000000008B000000870000003153505305D5CDD59C2E1B10939708002B2CF9AE6B0000005A000000007B00360044003800420042003300440033002D0039004400380037002D0034004100390031002D0041004200350036002D003400460033003000430046004600450046004500390046007D005F0057006900640074006800000013000000CC0000000000000000000000 | |||
| (PID) Process: | (7800) explorer.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\4\Shell\{0C3794F3-B545-43AA-A329-C37430C58D2A} |
| Operation: | write | Name: | Rev |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7848 | GeoComplyUpdate.exe | C:\Users\admin\AppData\Local\Temp\6679-83f9-2991-701a | — | |
MD5:— | SHA256:— | |||
| 7584 | url.exe | C:\Users\admin\AppData\Local\Temp\b14c-a62b-3238-38e5\Update\Update\upgrade.manifest.xml | xml | |
MD5:4CF0793D12D0008BCBDCBA4FA27C1BFB | SHA256:F8D78CE8D22951EB76E5BB0C36D063C589195ADE437F1B83259ABF930224DBCD | |||
| 7584 | url.exe | C:\Users\admin\AppData\Local\Temp\b14c-a62b-3238-38e5\Update\Update\GeoComplyUpdate.inf | xml | |
MD5:36959AF2697CD2A21DA0026E101ACFCE | SHA256:14F77206CB9FEB9E61CBC0A43CE9BAA11C53375A78237396812BD4F38E1A920F | |||
| 7584 | url.exe | C:\Users\admin\AppData\Local\Temp\c0d0-5d77-043c-af54 | compressed | |
MD5:590AFF6BCE7745ACBD32C8246EBA1017 | SHA256:83358A10C4D8CD7045E0722C776A3C59BCC567718DE63D6BDD33A48270D55CB0 | |||
| 7848 | GeoComplyUpdate.exe | C:\Users\admin\AppData\Local\Temp\465d-7428-a1b6-db4e\PlayerLocationCheck\Application\com.geocomply.process-scanner-microservice.exe | executable | |
MD5:C6E6AA49F2E5390AC8AFB5E679FB053B | SHA256:FA7CF44C544944449FA0FA5C09026D157BBB7BA6C9362D10030EF509564A42D8 | |||
| 7584 | url.exe | C:\Users\admin\AppData\Local\Temp\b14c-a62b-3238-38e5\Update\Update\manifest.xml | xml | |
MD5:FBA05CD6839EA3D5ACA9F68C5CD5257F | SHA256:FD13AAD581C9AC46D86F4A9FFDD6D6DAC5E8AA95A8362656ED2EB7AEF6DAE209 | |||
| 7848 | GeoComplyUpdate.exe | C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Update\GeoComplyUpdate.exe | executable | |
MD5:57825971D603090D7500C4C96500966E | SHA256:5B5303C4DE53D0CD36B3396E290C2BDA4BA8688A3EEAD74E6DF39F4B53481067 | |||
| 7848 | GeoComplyUpdate.exe | C:\ProgramData\GeoComply\Logs\GeoComplyUpdate_1654694004.db-journal | binary | |
MD5:3E33FAE8DB0A4197E2B348424B9E9E67 | SHA256:4D5A69B257FE30FC96FA6EA68FF579A894F9EE2F26630A646EB59890ED0D732C | |||
| 7848 | GeoComplyUpdate.exe | C:\Users\admin\AppData\Local\Temp\465d-7428-a1b6-db4e\PlayerLocationCheck\manifest.xml | xml | |
MD5:3F0601683C3BCB0E4516F987C5DCFF7F | SHA256:915D8CF320CF5BDFFA4973AC0A1DE509FCD2902C521C0D88A9498815808BB48C | |||
| 7848 | GeoComplyUpdate.exe | C:\Users\admin\AppData\Local\Temp\465d-7428-a1b6-db4e\PlayerLocationCheck\Application\com.geocomply.internal-updater-microservice.exe | executable | |
MD5:FD7307FE83D310EBFC585129FAFF8ABE | SHA256:B2C102AD34E6C022F0B8E2785A7DB350A8405348052BA4EACB5DB22828A3C946 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5496 | MoUsoCoreWorker.exe | GET | 200 | 23.216.77.28:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
8104 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
8104 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
2924 | SearchApp.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
2924 | SearchApp.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
6480 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5496 | MoUsoCoreWorker.exe | 23.216.77.28:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
5496 | MoUsoCoreWorker.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2104 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3216 | svchost.exe | 172.211.123.249:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
7584 | url.exe | 34.195.184.53:443 | ums.geocomply.com | AMAZON-AES | US | unknown |
7584 | url.exe | 18.66.122.41:443 | prod-downloads.geocomply.com | AMAZON-02 | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
ums.geocomply.com |
| unknown |
prod-downloads.geocomply.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |