| File name: | Imminent monitor.zip |
| Full analysis: | https://app.any.run/tasks/95ec06e7-d740-4c37-a539-542cd1239cd2 |
| Verdict: | Malicious activity |
| Analysis date: | October 19, 2023, 10:13:57 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | D9ED8F76EDBC2ED594F3E59B2623F420 |
| SHA1: | F769C8715371F8B546D0C5A0FD07646CDE986ABC |
| SHA256: | 16B9C5B8D68AC8FAC40A0FC29DD2E0175F3FA8CC7DEC82C3BC8E0DFBFD998AF3 |
| SSDEEP: | 98304:c3xktO7ZTqEHvu5nO/jHdMtbVdLYyz4pP7Bt3X6fsozVbfx0cHwM6bQlnQjOoDeM:Vyx6PU |
| .kmz | | | Google Earth saved working session (60) |
|---|---|---|
| .zip | | | ZIP compressed archive (40) |
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2013:08:20 16:13:12 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | Imminent Monitor/Imminent Monitor/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 328 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe6_ Global\UsGthrCtrlFltPipeMssGthrPipe6 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\System32\SearchProtocolHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Exit code: 0 Version: 7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211) Modules
| |||||||||||||||
| 1124 | ping 1.1.1.1 -n 1 -w 1000 | C:\Windows\System32\PING.EXE | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: TCP/IP Ping Command Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1824 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL "C:\Users\admin\Desktop\Imminent monitor.zip.kmz" | C:\Windows\System32\rundll32.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2360 | "C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe" /noconfig @"C:\Users\admin\AppData\Local\Temp\1ojuqi2d.cmdline" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe | — | Imminent Monitor.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Visual Basic Command Line Compiler Exit code: 0 Version: 8.0.50727.5483 Modules
| |||||||||||||||
| 2704 | "C:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\as.exe" | C:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\as.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Integrity Level: MEDIUM Description: Windows Sidebar Exit code: 0 Version: 1.0.7600.1638 Modules
| |||||||||||||||
| 2916 | "C:\Windows\System32\cmd.exe" /C ping 1.1.1.1 -n 1 -w 1000 > Nul & Del "C:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\as.exe" | C:\Windows\System32\cmd.exe | — | as.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3156 | "cmd" | C:\Windows\System32\cmd.exe | — | as.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3164 | "C:\Users\admin\AppData\Roaming\as\as.exe" | C:\Users\admin\AppData\Roaming\as\as.exe | as.exe | ||||||||||||
User: admin Company: Microsoft Integrity Level: MEDIUM Description: Windows Sidebar Exit code: 0 Version: 1.0.7600.1638 Modules
| |||||||||||||||
| 3568 | "C:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\Imminent Monitor.exe" | C:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\Imminent Monitor.exe | explorer.exe | ||||||||||||
User: admin Company: Imminent Methods Integrity Level: HIGH Description: Imminent Monitor Exit code: 0 Version: 2.0.1.9 Modules
| |||||||||||||||
| 3716 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Imminent monitor.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| (PID) Process: | (3716) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3716) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (3716) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3716) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3716) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3716) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3716) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3716) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (328) SearchProtocolHost.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\178\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3568) Imminent Monitor.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3568 | Imminent Monitor.exe | C:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\ae3e83e2fab3a7d8683d8eefabd1e74d.resources | binary | |
MD5:0C8F7C61C04013D916AA80465AB8FC56 | SHA256:0F9C7FCB604922CD478DC381D897767259B9F6F8351F5AFF41FB902322D95924 | |||
| 3716 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3716.44234\Imminent Monitor\Imminent Monitor\Imminent.Packer.dll | executable | |
MD5:D1BB8C8EED5AC6FFB29C002643873A87 | SHA256:D04DDD9EEF62640C22A5ABB6DCE4838257EAEA904AEDE5B9F4D82A63C9A0F19F | |||
| 3716 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3716.44234\Imminent Monitor\Imminent Monitor\Stub.modified.vb | text | |
MD5:D82B715069F8F886069F4AB3C4DCFD42 | SHA256:DE6DAF8A391EE1DA74F1AB4B349EAC4A34DF75AE9DFED31BFB9063D308BCDAA7 | |||
| 3568 | Imminent Monitor.exe | C:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\AForge.Video.dll | executable | |
MD5:0BD34AA29C7EA4181900797395A6DA78 | SHA256:BAFA6ED04CA2782270074127A0498DDE022C2A9F4096C6BB2B8E3C08BB3D404D | |||
| 3568 | Imminent Monitor.exe | C:\Users\admin\AppData\Local\Temp\tmp66D2.tmp | binary | |
MD5:1DC37EB0279692F842541C4996C91B79 | SHA256:91807AF318881024FB13C9D6121EFFF837AE74234DFB248B509BF40ACE4F058D | |||
| 3568 | Imminent Monitor.exe | C:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\f67169dfbf72c4ca285e9ee12e3e9ac5.resources | binary | |
MD5:BCE9D0187DE10F8391BC1130F44E4C94 | SHA256:141B1AA4466C5CDD69194AC48DD5907C654BF8AC2241F5CAE428994F45184ED3 | |||
| 3568 | Imminent Monitor.exe | C:\Users\admin\AppData\Local\Temp\1ojuqi2d.0.vb | text | |
MD5:9BF595610E5CA0260E0EB4AEA984BB6B | SHA256:7DC3FD79B218AB04CE9B04055B54AF4E04D7FD43442834FA181DE23E54EF9045 | |||
| 3568 | Imminent Monitor.exe | C:\Users\admin\AppData\Roaming\1100497\8469527 | text | |
MD5:1A87E8DD2C23052BF937FA5E05FA3300 | SHA256:E3256B9306DF600CD0482C35EA008202D63F94D1F6D7957AB517D069F48E10B0 | |||
| 3568 | Imminent Monitor.exe | C:\Users\admin\AppData\Local\Temp\1ojuqi2d.cmdline | text | |
MD5:EB6A88DD721F3FA5DE615420B564DAD2 | SHA256:4485B1E70077C94F5F674F1C0C2423C1ADC370B4CC07E56FE7334AF8D0C01240 | |||
| 2360 | vbc.exe | C:\Users\admin\AppData\Local\Temp\vbc6858.tmp | binary | |
MD5:C27701662C500EB7DE2906CDA177F649 | SHA256:276E8580087FDE6E6955B1E70BAF9B640B2E1F1A588F99A002A70B93DFAD2F8F | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3164 | as.exe | GET | 301 | 172.67.75.176:80 | http://freegeoip.net/json/ | unknown | — | — | unknown |
3164 | as.exe | GET | 200 | 172.67.75.176:80 | http://freegeoip.net/shutdown | unknown | html | 1.00 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2656 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3568 | Imminent Monitor.exe | 162.125.66.15:443 | dl.dropboxusercontent.com | DROPBOX | DE | malicious |
3164 | as.exe | 172.67.75.176:80 | freegeoip.net | CLOUDFLARENET | US | unknown |
Domain | IP | Reputation |
|---|---|---|
dl.dropboxusercontent.com |
| shared |
freegeoip.net |
| shared |
PID | Process | Class | Message |
|---|---|---|---|
3568 | Imminent Monitor.exe | Misc activity | ET INFO DropBox User Content Domain (dl .dropboxusercontent .com in TLS SNI) |
3568 | Imminent Monitor.exe | Misc activity | ET INFO DropBox User Content Download Access over SSL M2 |
1088 | svchost.exe | Device Retrieving External IP Address Detected | ET INFO External IP Lookup Domain (freegeiop .net in DNS lookup) |