Geek.exe

First submission 2024-10-17 20:09:11

File details

File type: PE32 executable (GUI) Intel 80386, for MS Windows
Mime type: application/x-dosexec
File size: 6855.48 KB (7020016 bytes)
Compile time: 2023-07-29 00:04:09
MD5: c0eeaaaae6a849152fe8e826a21b6054
SHA1: 58c4354bda3784f117c8ec3b5f217852033efbea
SHA256: ba619aed58332f8cf8fb93939e6986f9d8b3d0bae3ffa0348dbad5b43c186b19
Import Hash : ad779a1bb2e6ce5ca2839622084e8159
Sections 4 .text .rdata .data .rsrc
Directories 5 import resource debug tls security

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 39/77 VT report date: 2024-10-17 14:07:32
Malware Type 2 trojan hacktool
Threat Type 3 cryptz marte meterpreter

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://47.236.122.191/Geek.exe VirusTotal Report 47.236.122.191 VirusTotal Report 2024-10-17 20:09:11

PE Sections 1 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.text 0x1000 0x1e8333 1999872 ba8bda80cfa2a61bebe1c9efbc5b3e80d214e6db 33fd65819706fcaf64780ac15699040b
.rdata 0x1ea000 0x7211e 467456 cd6afa0c0dadbe469f7b81150c1e9267e845eeb4 43bbd8956d078106f0f04a8e1827c89b
.data 0x25d000 0x103bc 46592 9cc3ff0a456fbc9cebabbf0cd30cb165756ee298 a02bf9b9b1fb258f815dea04be6b2181
.rsrc 0x26e000 0x446d50 4484608 4b3078436f5a7031cab07b43266625f1cf0fef8c 3da5a26527c5b55aa805fb112e10a03b

PE Resources 14

Name Language Sublanguage Offset Size Data
BIN LANG_ENGLISH SUBLANG_ENGLISH_US 0x302c80 3865072
PNG LANG_NEUTRAL SUBLANG_NEUTRAL 0x2ed698 4883
XML LANG_NEUTRAL SUBLANG_NEUTRAL 0x2e9cd0 5709
RT_CURSOR LANG_NEUTRAL SUBLANG_NEUTRAL 0x2f2a78 3244
RT_BITMAP LANG_NEUTRAL SUBLANG_NEUTRAL 0x2f4808 1640
RT_ICON LANG_NEUTRAL SUBLANG_NEUTRAL 0x301b20 1736
RT_MENU LANG_ENGLISH SUBLANG_ENGLISH_US 0x2f2300 546
RT_DIALOG LANG_ENGLISH SUBLANG_ENGLISH_US 0x2f2528 346
RT_STRING LANG_ENGLISH SUBLANG_ENGLISH_US 0x6b3a98 166
RT_GROUP_CURSOR LANG_NEUTRAL SUBLANG_NEUTRAL 0x2f22e8 20
RT_GROUP_ICON LANG_NEUTRAL SUBLANG_NEUTRAL 0x301ac0 90
RT_VERSION LANG_NEUTRAL SUBLANG_NEUTRAL 0x2a9fc8 868
RT_MANIFEST LANG_ENGLISH SUBLANG_ENGLISH_US 0x6b2670 1792
None LANG_NEUTRAL SUBLANG_NEUTRAL 0x302228 22

Meta infos 10

LegalCopyright: Copyright (C) 2012-2023 Geek Uninstaller
InternalName: Geek Uninstaller
FileVersion: 1.5.2.165
CompanyName: Geek Uninstaller
OriginalFilename: geek.exe
ProductVersion: 1.5.2.165
FileDescription: Geek Uninstaller
Translation: 0x0000 0x04e4
Comments: https://geekuninstaller.com
ProductName: Geek-Uninstaller

Anti debug functions 13

FindWindowExW
FindWindowW
GetLastError
GetWindowThreadProcessId
IsDebuggerPresent
IsProcessorFeaturePresent
OutputDebugStringA
OutputDebugStringW
Process32FirstW
Process32NextW
RaiseException
TerminateProcess
UnhandledExceptionFilter

Anti debug functions 1

VMCheck.dll

File signature

MD5 SHA1 Block size Virtual Address
b8745877576dd6ef528e5be6a619ea4a f62ae92db17d9c5ce837b95322e1f697c40dbd72 20464 6999552

Strings analysis - File found

Log
%s_RemovalLog.log
.exe.log
Object
hhctrl.ocx
Data
cache.dat
XML
prefs.xml
AppXManifest.xml
*.xml
Linker File
*.lnk
Text
ghttps://geekuninstaller.com/update.txt
https://geekuninstaller.com/update.txt
Library
OLEACC.dll
LSHELL32.DLL
%Ts%Ts.dll
COMCTL32.dll
KERNEL32.dll
UxTheme.dll
USER32.dll
dwmapi.dll
avcuf64.dll
HComCtl32.dll
gdiplus.dll
COMDLG32.dll
ntdll.dll
geek.dll
dbghelp.dll
Ldwmapi.dll
ADVAPI32.dll
Yapi-ms-win-core-synch-l1-2-0.dll
mfcm140u.dll
AKERNEL32.dll
MAPI32.dll
api-ms-win-core-synch-l1-2-0.dll
combase.dll
d2d1.dll
WININET.dll
mscoree.dll
KernelBase.dll
Acomdlg32.dll
WCOMCTL32.DLL
@WININET.dll
MSIMG32.dll
ole32.dll
DWrite.dll
oledlg.dll
SHELL32.dll
VERSION.dll
SHLWAPI.dll
WINMM.dll
riched20.dll
OLEAUT32.dll
GDI32.dll
riched32.dll

Strings analysis - Possible IPs found 1

1.5.2.165

Strings analysis - Possible URLs found 22

http://crl.sectigo.com/SectigoPublicCodeSigningRootR46.crl0
http://crt.usertrust.com/USERTrustRSAAddTrustCA.crt0%
http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#
http://crt.sectigo.com/SectigoPublicCodeSigningCAR36.crt0#
http://www.google.com/search?q=%s&ie=UTF-8
http://schemas.microsoft.com/SMI/2005/WindowsSettings
https://geekuninstaller.com/update.txt
http://
https://geekuninstaller.com/
https://crystalidea.com/uninstall-tool?source=geek&campaign=app
http://crt.sectigo.com/SectigoPublicCodeSigningRootR46.p7c0#
http://ocsp.comodoca.com0
https://sectigo.com/CPS0
file://
http://crl.usertrust.com/USERTrustRSACertificationAuthority.crl0v
http://ocsp.usertrust.com0
https://geekuninstaller.com
http://ocsp.sectigo.com0
https://geekuninstaller.com/download/?version=%s
http://crl.sectigo.com/SectigoPublicCodeSigningCAR36.crl0y
http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t
http://crl.comodoca.com/AAACertificateServices.crl04

Import functions