File name:

Imminent monitor.zip

Full analysis: https://app.any.run/tasks/95ec06e7-d740-4c37-a539-542cd1239cd2
Verdict: Malicious activity
Analysis date: October 19, 2023, 10:13:57
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
evasion
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

D9ED8F76EDBC2ED594F3E59B2623F420

SHA1:

F769C8715371F8B546D0C5A0FD07646CDE986ABC

SHA256:

16B9C5B8D68AC8FAC40A0FC29DD2E0175F3FA8CC7DEC82C3BC8E0DFBFD998AF3

SSDEEP:

98304:c3xktO7ZTqEHvu5nO/jHdMtbVdLYyz4pP7Bt3X6fsozVbfx0cHwM6bQlnQjOoDeM:Vyx6PU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Imminent Monitor.exe (PID: 3732)
      • Imminent Monitor.exe (PID: 3568)
      • as.exe (PID: 2704)
      • as.exe (PID: 3164)
    • Loads dropped or rewritten executable

      • Imminent Monitor.exe (PID: 3568)
    • Drops the executable file immediately after the start

      • vbc.exe (PID: 2360)
      • Imminent Monitor.exe (PID: 3568)
      • as.exe (PID: 2704)
    • Starts CMD.EXE for self-deleting

      • as.exe (PID: 2704)
  • SUSPICIOUS

    • Reads settings of System Certificates

      • Imminent Monitor.exe (PID: 3568)
    • The process executes VB scripts

      • Imminent Monitor.exe (PID: 3568)
    • Reads the Internet Settings

      • Imminent Monitor.exe (PID: 3568)
      • as.exe (PID: 2704)
      • as.exe (PID: 3164)
    • Starts CMD.EXE for commands execution

      • as.exe (PID: 2704)
      • as.exe (PID: 3164)
    • Runs PING.EXE to delay simulation

      • cmd.exe (PID: 2916)
    • Detected use of alternative data streams (AltDS)

      • cmd.exe (PID: 3156)
    • Starts itself from another location

      • as.exe (PID: 2704)
    • Checks for external IP

      • as.exe (PID: 3164)
  • INFO

    • Manual execution by a user

      • WinRAR.exe (PID: 3716)
      • Imminent Monitor.exe (PID: 3732)
      • Imminent Monitor.exe (PID: 3568)
      • as.exe (PID: 2704)
    • Checks supported languages

      • Imminent Monitor.exe (PID: 3568)
      • as.exe (PID: 2704)
      • vbc.exe (PID: 2360)
      • cvtres.exe (PID: 3724)
      • as.exe (PID: 3164)
    • Reads the computer name

      • Imminent Monitor.exe (PID: 3568)
      • as.exe (PID: 2704)
      • as.exe (PID: 3164)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3716)
    • Reads the machine GUID from the registry

      • Imminent Monitor.exe (PID: 3568)
      • as.exe (PID: 2704)
      • vbc.exe (PID: 2360)
      • cvtres.exe (PID: 3724)
      • as.exe (PID: 3164)
    • Reads Environment values

      • Imminent Monitor.exe (PID: 3568)
      • as.exe (PID: 3164)
    • Create files in a temporary directory

      • cvtres.exe (PID: 3724)
      • Imminent Monitor.exe (PID: 3568)
    • Creates files or folders in the user directory

      • Imminent Monitor.exe (PID: 3568)
      • as.exe (PID: 3164)
      • as.exe (PID: 2704)
    • The process uses the downloaded file

      • cmd.exe (PID: 3156)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.kmz | Google Earth saved working session (60)
.zip | ZIP compressed archive (40)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2013:08:20 16:13:12
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Imminent Monitor/Imminent Monitor/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
56
Monitored processes
12
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start rundll32.exe no specs winrar.exe no specs searchprotocolhost.exe no specs imminent monitor.exe no specs imminent monitor.exe vbc.exe no specs cvtres.exe no specs as.exe no specs as.exe cmd.exe no specs ping.exe no specs cmd.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
328"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe6_ Global\UsGthrCtrlFltPipeMssGthrPipe6 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1124ping 1.1.1.1 -n 1 -w 1000 C:\Windows\System32\PING.EXEcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
TCP/IP Ping Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\ping.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
1824"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL "C:\Users\admin\Desktop\Imminent monitor.zip.kmz"C:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2360"C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe" /noconfig @"C:\Users\admin\AppData\Local\Temp\1ojuqi2d.cmdline"C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exeImminent Monitor.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Visual Basic Command Line Compiler
Exit code:
0
Version:
8.0.50727.5483
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2704"C:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\as.exe" C:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\as.exeexplorer.exe
User:
admin
Company:
Microsoft
Integrity Level:
MEDIUM
Description:
Windows Sidebar
Exit code:
0
Version:
1.0.7600.1638
Modules
Images
c:\users\admin\desktop\imminent monitor\imminent monitor\as.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2916"C:\Windows\System32\cmd.exe" /C ping 1.1.1.1 -n 1 -w 1000 > Nul & Del "C:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\as.exe"C:\Windows\System32\cmd.exeas.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3156"cmd"C:\Windows\System32\cmd.exeas.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\cmd.exe
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
3164"C:\Users\admin\AppData\Roaming\as\as.exe" C:\Users\admin\AppData\Roaming\as\as.exe
as.exe
User:
admin
Company:
Microsoft
Integrity Level:
MEDIUM
Description:
Windows Sidebar
Exit code:
0
Version:
1.0.7600.1638
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\roaming\as\as.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3568"C:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\Imminent Monitor.exe" C:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\Imminent Monitor.exe
explorer.exe
User:
admin
Company:
Imminent Methods
Integrity Level:
HIGH
Description:
Imminent Monitor
Exit code:
0
Version:
2.0.1.9
Modules
Images
c:\users\admin\desktop\imminent monitor\imminent monitor\imminent monitor.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3716"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Imminent monitor.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\windows\system32\kernel32.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
10 408
Read events
10 356
Write events
49
Delete events
3

Modification events

(PID) Process:(3716) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3716) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3716) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3716) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3716) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3716) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3716) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3716) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(328) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3568) Imminent Monitor.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
8
Suspicious files
6
Text files
7
Unknown types
0

Dropped files

PID
Process
Filename
Type
3716WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3716.44234\Imminent Monitor\Imminent Monitor\Mono.Cecil.dllexecutable
MD5:9985CF809DC38A4E2ED822B121DAF5B3
SHA256:AEE8B5036768F5131ADE20B62AF79042AD16CE1F54062312F6A3C17C9BF692B0
3716WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3716.44234\Imminent Monitor\Imminent Monitor\Interop.NATUPNPLib.dllexecutable
MD5:65E7844A181842146443B03EC4B4308C
SHA256:63E1B910D742F614E5F74D6E5F91EC2AD6CB31EABE5087E60DE6ECFE2A8D66CC
3716WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3716.44234\Imminent Monitor\Imminent Monitor\Stub.modified.vbtext
MD5:D82B715069F8F886069F4AB3C4DCFD42
SHA256:DE6DAF8A391EE1DA74F1AB4B349EAC4A34DF75AE9DFED31BFB9063D308BCDAA7
3568Imminent Monitor.exeC:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\Settings\Main Settings\Settings.xmlxml
MD5:D728D3DC6A9FA8B5E04D8640792D1C4B
SHA256:5BD75459E2F6F5C52F7447B46528530B19C774906D4F7CE7CF9F636B7442BDC2
3568Imminent Monitor.exeC:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\AForge.Video.dllexecutable
MD5:0BD34AA29C7EA4181900797395A6DA78
SHA256:BAFA6ED04CA2782270074127A0498DDE022C2A9F4096C6BB2B8E3C08BB3D404D
3568Imminent Monitor.exeC:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\ae3e83e2fab3a7d8683d8eefabd1e74d.resourcesbinary
MD5:0C8F7C61C04013D916AA80465AB8FC56
SHA256:0F9C7FCB604922CD478DC381D897767259B9F6F8351F5AFF41FB902322D95924
3568Imminent Monitor.exeC:\Users\admin\AppData\Local\Temp\tmp66C1.tmpbinary
MD5:68C69BE3D7AE67C09A463DFE73B8CC59
SHA256:C5605EF159AA07E7ECF8E00CC6893617233555A6D20D37C7E12F48025B5022D3
3568Imminent Monitor.exeC:\Users\admin\Desktop\Imminent Monitor\Imminent Monitor\AForge.Video.DirectShow.dllexecutable
MD5:17ED442E8485AC3F7DC5B3C089654A61
SHA256:666D44798D94EAFA1ED21AF79E9BC0293FFD96F863AB5D87F78BCEE9EF9FFD6B
3568Imminent Monitor.exeC:\Users\admin\AppData\Local\Temp\tmp66D2.tmpbinary
MD5:1DC37EB0279692F842541C4996C91B79
SHA256:91807AF318881024FB13C9D6121EFFF837AE74234DFB248B509BF40ACE4F058D
3568Imminent Monitor.exeC:\Users\admin\AppData\Local\Temp\1ojuqi2d.0.vbtext
MD5:9BF595610E5CA0260E0EB4AEA984BB6B
SHA256:7DC3FD79B218AB04CE9B04055B54AF4E04D7FD43442834FA181DE23E54EF9045
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
5
DNS requests
2
Threats
5

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3164
as.exe
GET
301
172.67.75.176:80
http://freegeoip.net/json/
unknown
unknown
3164
as.exe
GET
200
172.67.75.176:80
http://freegeoip.net/shutdown
unknown
html
1.00 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2656
svchost.exe
239.255.255.250:1900
whitelisted
3568
Imminent Monitor.exe
162.125.66.15:443
dl.dropboxusercontent.com
DROPBOX
DE
malicious
3164
as.exe
172.67.75.176:80
freegeoip.net
CLOUDFLARENET
US
unknown

DNS requests

Domain
IP
Reputation
dl.dropboxusercontent.com
  • 162.125.66.15
shared
freegeoip.net
  • 172.67.75.176
  • 104.26.14.73
  • 104.26.15.73
shared

Threats

PID
Process
Class
Message
3568
Imminent Monitor.exe
Misc activity
ET INFO DropBox User Content Domain (dl .dropboxusercontent .com in TLS SNI)
3568
Imminent Monitor.exe
Misc activity
ET INFO DropBox User Content Download Access over SSL M2
1088
svchost.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain (freegeiop .net in DNS lookup)
2 ETPRO signatures available at the full report
No debug info