| File name: | Imminent monitor.zip |
| Full analysis: | https://app.any.run/tasks/95ec06e7-d740-4c37-a539-542cd1239cd2 |
| Verdict: | Malicious activity |
| Analysis date: | October 19, 2023, 10:13:57 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | D9ED8F76EDBC2ED594F3E59B2623F420 |
| SHA1: | F769C8715371F8B546D0C5A0FD07646CDE986ABC |
| SHA256: | 16B9C5B8D68AC8FAC40A0FC29DD2E0175F3FA8CC7DEC82C3BC8E0DFBFD998AF3 |
| SSDEEP: | 98304:c3xktO7ZTqEHvu5nO/jHdMtbVdLYyz4pP7Bt3X6fsozVbfx0cHwM6bQlnQjOoDeM:Vyx6PU |
| .kmz | | | Google Earth saved working session (60) |
|---|---|---|
| .zip | | | ZIP compressed archive (40) |
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2013:08:20 16:13:12 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | Imminent Monitor/Imminent Monitor/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 328 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe6_ Global\UsGthrCtrlFltPipeMssGthrPipe6 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\System32\SearchProtocolHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Exit code: 0 Version: 7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211) Modules
| |||||||||||||||
| 1124 | ping 1.1.1.1 -n 1 -w 1000 | C:\Windows\System32\PING.EXE | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: TCP/IP Ping Command Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1824 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL "C:\Users\admin\Desktop\Imminent monitor.zip.kmz" | C:\Windows\System32\rundll32.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2360 | "C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe" /noconfig @"C:\Users\admin\AppData\Local\Temp\1ojuqi2d.cmdline" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe | — | Imminent Monitor.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Visual Basic Command Line Compiler Exit code: 0 Version: 8.0.50727.5483 Modules
| |||||||||||||||
| 2704 | "C:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\as.exe" | C:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\as.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Integrity Level: MEDIUM Description: Windows Sidebar Exit code: 0 Version: 1.0.7600.1638 Modules
| |||||||||||||||
| 2916 | "C:\Windows\System32\cmd.exe" /C ping 1.1.1.1 -n 1 -w 1000 > Nul & Del "C:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\as.exe" | C:\Windows\System32\cmd.exe | — | as.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3156 | "cmd" | C:\Windows\System32\cmd.exe | — | as.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3164 | "C:\Users\admin\AppData\Roaming\as\as.exe" | C:\Users\admin\AppData\Roaming\as\as.exe | as.exe | ||||||||||||
User: admin Company: Microsoft Integrity Level: MEDIUM Description: Windows Sidebar Exit code: 0 Version: 1.0.7600.1638 Modules
| |||||||||||||||
| 3568 | "C:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\Imminent Monitor.exe" | C:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\Imminent Monitor.exe | explorer.exe | ||||||||||||
User: admin Company: Imminent Methods Integrity Level: HIGH Description: Imminent Monitor Exit code: 0 Version: 2.0.1.9 Modules
| |||||||||||||||
| 3716 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Imminent monitor.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| (PID) Process: | (3716) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3716) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (3716) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3716) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3716) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3716) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3716) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3716) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (328) SearchProtocolHost.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\178\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3568) Imminent Monitor.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3716 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3716.44234\Imminent Monitor\Imminent Monitor\Mono.Cecil.dll | executable | |
MD5:9985CF809DC38A4E2ED822B121DAF5B3 | SHA256:AEE8B5036768F5131ADE20B62AF79042AD16CE1F54062312F6A3C17C9BF692B0 | |||
| 3716 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3716.44234\Imminent Monitor\Imminent Monitor\Interop.NATUPNPLib.dll | executable | |
MD5:65E7844A181842146443B03EC4B4308C | SHA256:63E1B910D742F614E5F74D6E5F91EC2AD6CB31EABE5087E60DE6ECFE2A8D66CC | |||
| 3716 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3716.44234\Imminent Monitor\Imminent Monitor\Stub.modified.vb | text | |
MD5:D82B715069F8F886069F4AB3C4DCFD42 | SHA256:DE6DAF8A391EE1DA74F1AB4B349EAC4A34DF75AE9DFED31BFB9063D308BCDAA7 | |||
| 3568 | Imminent Monitor.exe | C:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\Settings\Main Settings\Settings.xml | xml | |
MD5:D728D3DC6A9FA8B5E04D8640792D1C4B | SHA256:5BD75459E2F6F5C52F7447B46528530B19C774906D4F7CE7CF9F636B7442BDC2 | |||
| 3568 | Imminent Monitor.exe | C:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\AForge.Video.dll | executable | |
MD5:0BD34AA29C7EA4181900797395A6DA78 | SHA256:BAFA6ED04CA2782270074127A0498DDE022C2A9F4096C6BB2B8E3C08BB3D404D | |||
| 3568 | Imminent Monitor.exe | C:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\ae3e83e2fab3a7d8683d8eefabd1e74d.resources | binary | |
MD5:0C8F7C61C04013D916AA80465AB8FC56 | SHA256:0F9C7FCB604922CD478DC381D897767259B9F6F8351F5AFF41FB902322D95924 | |||
| 3568 | Imminent Monitor.exe | C:\Users\admin\AppData\Local\Temp\tmp66C1.tmp | binary | |
MD5:68C69BE3D7AE67C09A463DFE73B8CC59 | SHA256:C5605EF159AA07E7ECF8E00CC6893617233555A6D20D37C7E12F48025B5022D3 | |||
| 3568 | Imminent Monitor.exe | C:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\AForge.Video.DirectShow.dll | executable | |
MD5:17ED442E8485AC3F7DC5B3C089654A61 | SHA256:666D44798D94EAFA1ED21AF79E9BC0293FFD96F863AB5D87F78BCEE9EF9FFD6B | |||
| 3568 | Imminent Monitor.exe | C:\Users\admin\AppData\Local\Temp\tmp66D2.tmp | binary | |
MD5:1DC37EB0279692F842541C4996C91B79 | SHA256:91807AF318881024FB13C9D6121EFFF837AE74234DFB248B509BF40ACE4F058D | |||
| 3568 | Imminent Monitor.exe | C:\Users\admin\AppData\Local\Temp\1ojuqi2d.0.vb | text | |
MD5:9BF595610E5CA0260E0EB4AEA984BB6B | SHA256:7DC3FD79B218AB04CE9B04055B54AF4E04D7FD43442834FA181DE23E54EF9045 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3164 | as.exe | GET | 301 | 172.67.75.176:80 | http://freegeoip.net/json/ | unknown | — | — | unknown |
3164 | as.exe | GET | 200 | 172.67.75.176:80 | http://freegeoip.net/shutdown | unknown | html | 1.00 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2656 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3568 | Imminent Monitor.exe | 162.125.66.15:443 | dl.dropboxusercontent.com | DROPBOX | DE | malicious |
3164 | as.exe | 172.67.75.176:80 | freegeoip.net | CLOUDFLARENET | US | unknown |
Domain | IP | Reputation |
|---|---|---|
dl.dropboxusercontent.com |
| shared |
freegeoip.net |
| shared |
PID | Process | Class | Message |
|---|---|---|---|
3568 | Imminent Monitor.exe | Misc activity | ET INFO DropBox User Content Domain (dl .dropboxusercontent .com in TLS SNI) |
3568 | Imminent Monitor.exe | Misc activity | ET INFO DropBox User Content Download Access over SSL M2 |
1088 | svchost.exe | Device Retrieving External IP Address Detected | ET INFO External IP Lookup Domain (freegeiop .net in DNS lookup) |