File name:

Imminent monitor.zip

Full analysis: https://app.any.run/tasks/95ec06e7-d740-4c37-a539-542cd1239cd2
Verdict: Malicious activity
Analysis date: October 19, 2023, 10:13:57
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
evasion
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

D9ED8F76EDBC2ED594F3E59B2623F420

SHA1:

F769C8715371F8B546D0C5A0FD07646CDE986ABC

SHA256:

16B9C5B8D68AC8FAC40A0FC29DD2E0175F3FA8CC7DEC82C3BC8E0DFBFD998AF3

SSDEEP:

98304:c3xktO7ZTqEHvu5nO/jHdMtbVdLYyz4pP7Bt3X6fsozVbfx0cHwM6bQlnQjOoDeM:Vyx6PU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Imminent Monitor.exe (PID: 3732)
      • Imminent Monitor.exe (PID: 3568)
      • as.exe (PID: 3164)
      • as.exe (PID: 2704)
    • Drops the executable file immediately after the start

      • Imminent Monitor.exe (PID: 3568)
      • as.exe (PID: 2704)
      • vbc.exe (PID: 2360)
    • Loads dropped or rewritten executable

      • Imminent Monitor.exe (PID: 3568)
    • Starts CMD.EXE for self-deleting

      • as.exe (PID: 2704)
  • SUSPICIOUS

    • Reads the Internet Settings

      • Imminent Monitor.exe (PID: 3568)
      • as.exe (PID: 2704)
      • as.exe (PID: 3164)
    • Reads settings of System Certificates

      • Imminent Monitor.exe (PID: 3568)
    • The process executes VB scripts

      • Imminent Monitor.exe (PID: 3568)
    • Starts itself from another location

      • as.exe (PID: 2704)
    • Starts CMD.EXE for commands execution

      • as.exe (PID: 2704)
      • as.exe (PID: 3164)
    • Runs PING.EXE to delay simulation

      • cmd.exe (PID: 2916)
    • Checks for external IP

      • as.exe (PID: 3164)
    • Detected use of alternative data streams (AltDS)

      • cmd.exe (PID: 3156)
  • INFO

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3716)
    • Checks supported languages

      • Imminent Monitor.exe (PID: 3568)
      • vbc.exe (PID: 2360)
      • cvtres.exe (PID: 3724)
      • as.exe (PID: 2704)
      • as.exe (PID: 3164)
    • Manual execution by a user

      • Imminent Monitor.exe (PID: 3732)
      • WinRAR.exe (PID: 3716)
      • Imminent Monitor.exe (PID: 3568)
      • as.exe (PID: 2704)
    • Reads the computer name

      • Imminent Monitor.exe (PID: 3568)
      • as.exe (PID: 2704)
      • as.exe (PID: 3164)
    • Reads the machine GUID from the registry

      • Imminent Monitor.exe (PID: 3568)
      • vbc.exe (PID: 2360)
      • cvtres.exe (PID: 3724)
      • as.exe (PID: 2704)
      • as.exe (PID: 3164)
    • Reads Environment values

      • Imminent Monitor.exe (PID: 3568)
      • as.exe (PID: 3164)
    • Creates files or folders in the user directory

      • Imminent Monitor.exe (PID: 3568)
      • as.exe (PID: 2704)
      • as.exe (PID: 3164)
    • Create files in a temporary directory

      • Imminent Monitor.exe (PID: 3568)
      • cvtres.exe (PID: 3724)
    • The process uses the downloaded file

      • cmd.exe (PID: 3156)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.kmz | Google Earth saved working session (60)
.zip | ZIP compressed archive (40)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2013:08:20 16:13:12
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Imminent Monitor/Imminent Monitor/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
56
Monitored processes
12
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start rundll32.exe no specs winrar.exe no specs searchprotocolhost.exe no specs imminent monitor.exe no specs imminent monitor.exe vbc.exe no specs cvtres.exe no specs as.exe no specs as.exe cmd.exe no specs ping.exe no specs cmd.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
328"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe6_ Global\UsGthrCtrlFltPipeMssGthrPipe6 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1124ping 1.1.1.1 -n 1 -w 1000 C:\Windows\System32\PING.EXEcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
TCP/IP Ping Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\ping.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
1824"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL "C:\Users\admin\Desktop\Imminent monitor.zip.kmz"C:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2360"C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe" /noconfig @"C:\Users\admin\AppData\Local\Temp\1ojuqi2d.cmdline"C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exeImminent Monitor.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Visual Basic Command Line Compiler
Exit code:
0
Version:
8.0.50727.5483
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2704"C:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\as.exe" C:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\as.exeexplorer.exe
User:
admin
Company:
Microsoft
Integrity Level:
MEDIUM
Description:
Windows Sidebar
Exit code:
0
Version:
1.0.7600.1638
Modules
Images
c:\users\admin\desktop\imminent monitor\imminent monitor\as.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2916"C:\Windows\System32\cmd.exe" /C ping 1.1.1.1 -n 1 -w 1000 > Nul & Del "C:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\as.exe"C:\Windows\System32\cmd.exeas.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3156"cmd"C:\Windows\System32\cmd.exeas.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\cmd.exe
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
3164"C:\Users\admin\AppData\Roaming\as\as.exe" C:\Users\admin\AppData\Roaming\as\as.exe
as.exe
User:
admin
Company:
Microsoft
Integrity Level:
MEDIUM
Description:
Windows Sidebar
Exit code:
0
Version:
1.0.7600.1638
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\roaming\as\as.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3568"C:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\Imminent Monitor.exe" C:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\Imminent Monitor.exe
explorer.exe
User:
admin
Company:
Imminent Methods
Integrity Level:
HIGH
Description:
Imminent Monitor
Exit code:
0
Version:
2.0.1.9
Modules
Images
c:\users\admin\desktop\imminent monitor\imminent monitor\imminent monitor.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3716"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Imminent monitor.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\windows\system32\kernel32.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
10 408
Read events
10 356
Write events
49
Delete events
3

Modification events

(PID) Process:(3716) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3716) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3716) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3716) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3716) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3716) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3716) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3716) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(328) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3568) Imminent Monitor.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
8
Suspicious files
6
Text files
7
Unknown types
0

Dropped files

PID
Process
Filename
Type
3568Imminent Monitor.exeC:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\ae3e83e2fab3a7d8683d8eefabd1e74d.resourcesbinary
MD5:0C8F7C61C04013D916AA80465AB8FC56
SHA256:0F9C7FCB604922CD478DC381D897767259B9F6F8351F5AFF41FB902322D95924
3716WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3716.44234\Imminent Monitor\Imminent Monitor\Imminent.Packer.dllexecutable
MD5:D1BB8C8EED5AC6FFB29C002643873A87
SHA256:D04DDD9EEF62640C22A5ABB6DCE4838257EAEA904AEDE5B9F4D82A63C9A0F19F
3716WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3716.44234\Imminent Monitor\Imminent Monitor\Stub.modified.vbtext
MD5:D82B715069F8F886069F4AB3C4DCFD42
SHA256:DE6DAF8A391EE1DA74F1AB4B349EAC4A34DF75AE9DFED31BFB9063D308BCDAA7
3568Imminent Monitor.exeC:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\AForge.Video.dllexecutable
MD5:0BD34AA29C7EA4181900797395A6DA78
SHA256:BAFA6ED04CA2782270074127A0498DDE022C2A9F4096C6BB2B8E3C08BB3D404D
3568Imminent Monitor.exeC:\Users\admin\AppData\Local\Temp\tmp66D2.tmpbinary
MD5:1DC37EB0279692F842541C4996C91B79
SHA256:91807AF318881024FB13C9D6121EFFF837AE74234DFB248B509BF40ACE4F058D
3568Imminent Monitor.exeC:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\f67169dfbf72c4ca285e9ee12e3e9ac5.resourcesbinary
MD5:BCE9D0187DE10F8391BC1130F44E4C94
SHA256:141B1AA4466C5CDD69194AC48DD5907C654BF8AC2241F5CAE428994F45184ED3
3568Imminent Monitor.exeC:\Users\admin\AppData\Local\Temp\1ojuqi2d.0.vbtext
MD5:9BF595610E5CA0260E0EB4AEA984BB6B
SHA256:7DC3FD79B218AB04CE9B04055B54AF4E04D7FD43442834FA181DE23E54EF9045
3568Imminent Monitor.exeC:\Users\admin\AppData\Roaming\1100497\8469527text
MD5:1A87E8DD2C23052BF937FA5E05FA3300
SHA256:E3256B9306DF600CD0482C35EA008202D63F94D1F6D7957AB517D069F48E10B0
3568Imminent Monitor.exeC:\Users\admin\AppData\Local\Temp\1ojuqi2d.cmdlinetext
MD5:EB6A88DD721F3FA5DE615420B564DAD2
SHA256:4485B1E70077C94F5F674F1C0C2423C1ADC370B4CC07E56FE7334AF8D0C01240
2360vbc.exeC:\Users\admin\AppData\Local\Temp\vbc6858.tmpbinary
MD5:C27701662C500EB7DE2906CDA177F649
SHA256:276E8580087FDE6E6955B1E70BAF9B640B2E1F1A588F99A002A70B93DFAD2F8F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
5
DNS requests
2
Threats
5

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3164
as.exe
GET
301
172.67.75.176:80
http://freegeoip.net/json/
unknown
unknown
3164
as.exe
GET
200
172.67.75.176:80
http://freegeoip.net/shutdown
unknown
html
1.00 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2656
svchost.exe
239.255.255.250:1900
whitelisted
3568
Imminent Monitor.exe
162.125.66.15:443
dl.dropboxusercontent.com
DROPBOX
DE
malicious
3164
as.exe
172.67.75.176:80
freegeoip.net
CLOUDFLARENET
US
unknown

DNS requests

Domain
IP
Reputation
dl.dropboxusercontent.com
  • 162.125.66.15
shared
freegeoip.net
  • 172.67.75.176
  • 104.26.14.73
  • 104.26.15.73
shared

Threats

PID
Process
Class
Message
3568
Imminent Monitor.exe
Misc activity
ET INFO DropBox User Content Domain (dl .dropboxusercontent .com in TLS SNI)
3568
Imminent Monitor.exe
Misc activity
ET INFO DropBox User Content Download Access over SSL M2
1088
svchost.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain (freegeiop .net in DNS lookup)
2 ETPRO signatures available at the full report
No debug info