File name:

Download Nimble Tools Nimble Kick WiN Plugin Crack.exe

Full analysis: https://app.any.run/tasks/a2d1c2aa-2fa6-49f6-9e90-4083baa781ef
Verdict: Malicious activity
Analysis date: February 17, 2026, 21:42:33
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

84E772AC7047ED5298AA5B7442C42CB9

SHA1:

9D90CB5B98C4382EBA62693CA4137D2EF5B4A093

SHA256:

05469322BB6E9DABD14F399E66F35995B386D103DEC271D15DDA0AC043B9865F

SSDEEP:

1536:Uy3T4iSID7Mu2pTUfzM74mVvtfsOBct/pMZq9p1aNESDtXR:pkibD7Mu2pT+M7VVvtESc3M8pS5DtXR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • Download Nimble Tools Nimble Kick WiN Plugin Crack.exe (PID: 7896)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • Download Nimble Tools Nimble Kick WiN Plugin Crack.exe (PID: 7896)
    • Executes application which crashes

      • Download Nimble Tools Nimble Kick WiN Plugin Crack.exe (PID: 7896)
  • INFO

    • Checks supported languages

      • Download Nimble Tools Nimble Kick WiN Plugin Crack.exe (PID: 7896)
    • Reads security settings of Internet Explorer

      • Download Nimble Tools Nimble Kick WiN Plugin Crack.exe (PID: 7896)
    • Reads the computer name

      • Download Nimble Tools Nimble Kick WiN Plugin Crack.exe (PID: 7896)
    • Checks proxy server information

      • WerFault.exe (PID: 2864)
      • Download Nimble Tools Nimble Kick WiN Plugin Crack.exe (PID: 7896)
      • WerFault.exe (PID: 3400)
    • Creates files or folders in the user directory

      • Download Nimble Tools Nimble Kick WiN Plugin Crack.exe (PID: 7896)
      • WerFault.exe (PID: 2864)
      • WerFault.exe (PID: 3400)
    • Reads the machine GUID from the registry

      • Download Nimble Tools Nimble Kick WiN Plugin Crack.exe (PID: 7896)
    • Create files in a temporary directory

      • Download Nimble Tools Nimble Kick WiN Plugin Crack.exe (PID: 7896)
    • There is functionality for taking screenshot (YARA)

      • Download Nimble Tools Nimble Kick WiN Plugin Crack.exe (PID: 7896)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:07:02 02:09:48+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 27136
InitializedDataSize: 184832
UninitializedDataSize: 2048
EntryPoint: 0x3532
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
155
Monitored processes
6
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start download nimble tools nimble kick win  plugin crack.exe werfault.exe werfault.exe slui.exe no specs svchost.exe download nimble tools nimble kick win  plugin crack.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2292C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2864C:\WINDOWS\SysWOW64\WerFault.exe -u -p 7896 -s 1196C:\Windows\SysWOW64\WerFault.exe
Download Nimble Tools Nimble Kick WiN Plugin Crack.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
3400C:\WINDOWS\SysWOW64\WerFault.exe -u -p 7896 -s 2320C:\Windows\SysWOW64\WerFault.exe
Download Nimble Tools Nimble Kick WiN Plugin Crack.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
3508C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7896"C:\Users\admin\AppData\Local\Temp\Download Nimble Tools Nimble Kick WiN Plugin Crack.exe" C:\Users\admin\AppData\Local\Temp\Download Nimble Tools Nimble Kick WiN Plugin Crack.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
3221226525
Modules
Images
c:\users\admin\appdata\local\temp\download nimble tools nimble kick win plugin crack.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
8456"C:\Users\admin\AppData\Local\Temp\Download Nimble Tools Nimble Kick WiN Plugin Crack.exe" C:\Users\admin\AppData\Local\Temp\Download Nimble Tools Nimble Kick WiN Plugin Crack.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\download nimble tools nimble kick win plugin crack.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
Total events
8 438
Read events
8 424
Write events
8
Delete events
6

Modification events

(PID) Process:(2864) WerFault.exeKey:\REGISTRY\A\{9ac57a77-ecb6-2e29-24ad-b7d5e2a2c665}\Root\InventoryApplicationFile
Operation:writeName:WritePermissionsCheck
Value:
1
(PID) Process:(2864) WerFault.exeKey:\REGISTRY\A\{9ac57a77-ecb6-2e29-24ad-b7d5e2a2c665}\Root\InventoryApplicationFile\PermissionsCheckTestKey
Operation:delete keyName:(default)
Value:
(PID) Process:(2864) WerFault.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\IdentityCRL\ClockData
Operation:writeName:ClockTimeSeconds
Value:
D4E0946900000000
(PID) Process:(2864) WerFault.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\IdentityCRL\ClockData
Operation:writeName:TickCount
Value:
A1671E0000000000
(PID) Process:(3400) WerFault.exeKey:\REGISTRY\A\{d1f72370-20a9-a4ab-4d4f-9f02948aaafa}\Root\InventoryApplicationFile
Operation:writeName:WritePermissionsCheck
Value:
1
(PID) Process:(3400) WerFault.exeKey:\REGISTRY\A\{d1f72370-20a9-a4ab-4d4f-9f02948aaafa}\Root\InventoryApplicationFile\PermissionsCheckTestKey
Operation:delete keyName:(default)
Value:
Executable files
0
Suspicious files
1
Text files
0
Unknown types
21

Dropped files

PID
Process
Filename
Type
2864WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_Download Nimble _8a4fccdbf3e5ef80c1ad5596e34bc66edab11c_e2a8ab23_691a0076-604a-471b-b405-29107b45f8cc\Report.wer
MD5:
SHA256:
7896Download Nimble Tools Nimble Kick WiN Plugin Crack.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12binary
MD5:4F53605EE73BF1920F9E0FBA0D5AD6E1
SHA256:70361FC5BD4A7FBFA22050CCD859760C6116CF7D33BDE25CB161D909D05030DC
7896Download Nimble Tools Nimble Kick WiN Plugin Crack.exeC:\Users\admin\AppData\Local\Temp\nss52B3.tmp\System.dllbinary
MD5:4ADD245D4BA34B04F213409BFE504C07
SHA256:9111099EFE9D5C9B391DC132B2FAF0A3851A760D4106D5368E30AC744EB42706
3400WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_Download Nimble _38c5eb8585af4a9ec1899d0536c306ff9f76022_e2a8ab23_2343a5b2-0a31-4664-99ce-45571741e8bf\Report.wer
MD5:
SHA256:
7896Download Nimble Tools Nimble Kick WiN Plugin Crack.exeC:\Users\admin\AppData\Local\Temp\nss52B3.tmp\nsDialogs.dllbinary
MD5:1D8F01A83DDD259BC339902C1D33C8F1
SHA256:4B7D17DA290F41EBE244827CC295CE7E580DA2F7E9F7CC3EFC1ABC6898E3C9ED
7896Download Nimble Tools Nimble Kick WiN Plugin Crack.exeC:\Users\admin\AppData\Local\Temp\nss52B3.tmp\NSISdl.dllbinary
MD5:05F72D6A944E701217EF2EB2CC13E0EE
SHA256:AAB28914794A1CDDA4561E9F2AF3E006DBED220D9D6BFE049B56D0CB9B783648
7896Download Nimble Tools Nimble Kick WiN Plugin Crack.exeC:\Users\admin\AppData\Local\Temp\nss52B3.tmp\modern-wizard.bmpbinary
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
7896Download Nimble Tools Nimble Kick WiN Plugin Crack.exeC:\Users\admin\AppData\Local\Temp\nss52B3.tmp\INetC.dllbinary
MD5:40D7ECA32B2F4D29DB98715DD45BFAC5
SHA256:85E03805F90F72257DD41BFDAA186237218BBB0EC410AD3B6576A88EA11DCCB9
7896Download Nimble Tools Nimble Kick WiN Plugin Crack.exeC:\Users\admin\AppData\Local\Temp\nss52B3.tmp\starterbinary
MD5:D5B62821A2C414A32B888427CF2451A6
SHA256:45B7F88BF9E31CE74AF81FC0D87F02272036C833A44FAF945AF492CC2A9D90DE
7896Download Nimble Tools Nimble Kick WiN Plugin Crack.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12binary
MD5:A514277813F835F93DE6ABA4A5CB9345
SHA256:DDF6C2159BF1C34587C4EC791DE55A385145D326453BA2BDB06659D4A0D4BE88
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
30
TCP/UDP connections
37
DNS requests
25
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6768
MoUsoCoreWorker.exe
GET
304
51.104.136.2:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
US
whitelisted
9080
svchost.exe
GET
304
51.104.136.2:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/UpdateHealthTools?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&sampleId=s:95271487&appVer=10.0.19041.3626&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=SedimentPack&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
whitelisted
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQ3L3%2F%2Fa6ADK8NraY2GXzVaYrHG4AQUb6t%2B2v%2BXQ3LsO2d33oJhNYhHQoUCEzMAAAAGb6JMMcOVb6sAAAAAAAY%3D
US
binary
959 b
whitelisted
7728
SIHClient.exe
GET
304
135.232.92.137:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAjTxtAB8my1oj8MfWpz%2F7Y%3D
US
binary
313 b
whitelisted
7896
Download Nimble Tools Nimble Kick WiN Plugin Crack.exe
GET
302
188.114.96.3:443
https://rabbitsbird.info/pe/build.php?pe=n&sub=&source=3942&s1=57194526&title=RG93bmxvYWQgTmltYmxlIFRvb2xzIE5pbWJsZSBLaWNrIFdpTiAgUGx1Z2luIENyYWNr&ti=1771364563
US
binary
175 b
unknown
7728
SIHClient.exe
GET
200
20.165.94.54:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
US
whitelisted
7728
SIHClient.exe
GET
200
135.232.92.137:443
https://slscr.update.microsoft.com/sls/ping
US
whitelisted
7728
SIHClient.exe
GET
304
135.232.92.137:443
https://slscr.update.microsoft.com/SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
7896
Download Nimble Tools Nimble Kick WiN Plugin Crack.exe
GET
188.114.96.3:443
https://rabbitsbird.info/pe/output/setup_6290754.exe
US
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
9080
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
7524
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5568
SearchApp.exe
23.3.89.90:443
th.bing.com
AKAMAI-ASN1
NL
whitelisted
23.3.89.90:443
th.bing.com
AKAMAI-ASN1
NL
whitelisted
2.16.241.201:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
204.79.197.203:80
oneocsp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3412
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 51.104.136.2
whitelisted
self.events.data.microsoft.com
  • 20.189.173.3
whitelisted
www.bing.com
  • 2.16.241.201
  • 2.16.241.205
  • 2.16.241.218
  • 2.16.241.207
whitelisted
th.bing.com
  • 23.3.89.90
  • 23.3.89.89
  • 95.100.158.121
  • 23.3.89.98
  • 23.3.89.96
  • 23.3.89.121
  • 23.3.89.97
  • 23.3.89.104
  • 95.100.158.123
whitelisted
ocsp.digicert.com
  • 184.30.131.245
  • 162.159.142.9
  • 172.66.2.5
whitelisted
oneocsp.microsoft.com
  • 204.79.197.203
whitelisted
google.com
  • 142.251.141.142
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
housesice.space
  • 172.67.205.73
  • 104.21.37.71
unknown
rabbitsbird.info
  • 188.114.96.3
  • 188.114.97.3
malicious

Threats

PID
Process
Class
Message
9080
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
7896
Download Nimble Tools Nimble Kick WiN Plugin Crack.exe
Potentially Bad Traffic
SUSPICIOUS [ANY.RUN] NSIS INetC plugin User-Agent observed in HTTP request
7896
Download Nimble Tools Nimble Kick WiN Plugin Crack.exe
Potentially Bad Traffic
SUSPICIOUS [ANY.RUN] NSIS INetC plugin User-Agent observed in HTTP request
7896
Download Nimble Tools Nimble Kick WiN Plugin Crack.exe
A Network Trojan was detected
ET MALWARE Suspicious Download Setup_ exe
No debug info