File name:

Imminent-Monitor-v3.9-main.zip

Full analysis: https://app.any.run/tasks/b302465a-dbbf-45cc-b255-991a7899e20e
Verdict: Malicious activity
Analysis date: June 18, 2023, 15:23:52
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

961CDD4F9D98A28C3C1127EE949E55A6

SHA1:

AB7E39E45BE4499568204AD39624A485ED23996B

SHA256:

922C1D4BB5B8FD60DEADEE19D1EE6E62FA68509D0828976B31606F49031A1B4C

SSDEEP:

98304:lhATE3rECTRlkKTo9b7di+b4ttMe355C2ZkEMb4YP/OxVQQvIpC/hjfBr6Yt:zl3ACTRk9bki4rpsE84YPeIpQrH

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Imminent Monitor 3.9.exe (PID: 2420)
    • Loads dropped or rewritten executable

      • Imminent Monitor 3.9.exe (PID: 2420)
    • Starts Visual C# compiler

      • Imminent Monitor 3.9.exe (PID: 2420)
  • SUSPICIOUS

    • Uses .NET C# to load dll

      • Imminent Monitor 3.9.exe (PID: 2420)
    • Executable content was dropped or overwritten

      • csc.exe (PID: 2980)
      • csc.exe (PID: 3228)
    • Reads Internet Explorer settings

      • Imminent Monitor 3.9.exe (PID: 2420)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2896)
    • Checks supported languages

      • Imminent Monitor 3.9.exe (PID: 2420)
      • csc.exe (PID: 2980)
      • cvtres.exe (PID: 3608)
      • cvtres.exe (PID: 3964)
      • csc.exe (PID: 3228)
    • The process checks LSA protection

      • Imminent Monitor 3.9.exe (PID: 2420)
      • csc.exe (PID: 2980)
      • cvtres.exe (PID: 3608)
      • csc.exe (PID: 3228)
      • cvtres.exe (PID: 3964)
    • Manual execution by a user

      • WinRAR.exe (PID: 2896)
      • Imminent Monitor 3.9.exe (PID: 2420)
    • Reads the computer name

      • Imminent Monitor 3.9.exe (PID: 2420)
    • Reads the machine GUID from the registry

      • Imminent Monitor 3.9.exe (PID: 2420)
      • csc.exe (PID: 2980)
      • cvtres.exe (PID: 3608)
      • csc.exe (PID: 3228)
      • cvtres.exe (PID: 3964)
    • Create files in a temporary directory

      • Imminent Monitor 3.9.exe (PID: 2420)
      • csc.exe (PID: 2980)
      • cvtres.exe (PID: 3608)
      • cvtres.exe (PID: 3964)
      • csc.exe (PID: 3228)
    • Reads Environment values

      • Imminent Monitor 3.9.exe (PID: 2420)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Imminent-Monitor-v3.9-main/
ZipUncompressedSize: -
ZipCompressedSize: -
ZipCRC: 0x00000000
ZipModifyDate: 2022:11:04 11:48:12
ZipCompression: None
ZipBitFlag: -
ZipRequiredVersion: 10
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
8
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe searchprotocolhost.exe no specs imminent monitor 3.9.exe no specs csc.exe cvtres.exe no specs csc.exe cvtres.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
956"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2420"C:\Users\admin\Desktop\Imminent Monitor v3.9\Imminent Monitor 3.9.exe" C:\Users\admin\Desktop\Imminent Monitor v3.9\Imminent Monitor 3.9.exeexplorer.exe
User:
admin
Company:
Imminent Methods
Integrity Level:
MEDIUM
Description:
Imminent Monitor
Exit code:
0
Version:
3.9.0.0
Modules
Images
c:\users\admin\desktop\imminent monitor v3.9\imminent monitor 3.9.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2844"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Imminent-Monitor-v3.9-main.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
2896"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Imminent-Monitor-v3.9-main\Imminent Monitor v3.9.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2980"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\unszbu2y.cmdline"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe
Imminent Monitor 3.9.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Visual C# Command Line Compiler
Exit code:
0
Version:
8.0.50727.5483 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\csc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3228"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\nnfmzbyi.cmdline"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe
Imminent Monitor 3.9.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Visual C# Command Line Compiler
Exit code:
0
Version:
8.0.50727.5483 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\csc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\ole32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3608C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RESB757.tmp" "c:\Users\admin\AppData\Local\Temp\CSCB756.tmp"C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.execsc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® Resource File To COFF Object Conversion Utility
Exit code:
0
Version:
8.00.50727.5003 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\cvtres.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptsp.dll
3964C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RESC041.tmp" "c:\Users\admin\AppData\Local\Temp\CSCC040.tmp"C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.execsc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® Resource File To COFF Object Conversion Utility
Exit code:
0
Version:
8.00.50727.5003 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\cvtres.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptsp.dll
Total events
3 097
Read events
3 055
Write events
42
Delete events
0

Modification events

(PID) Process:(2844) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2844) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2844) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2844) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2844) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2844) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2844) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2844) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2844) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(2844) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\Desktop
Executable files
13
Suspicious files
8
Text files
413
Unknown types
1

Dropped files

PID
Process
Filename
Type
2844WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2844.33358\Imminent-Monitor-v3.9-main\Imminent Monitor v3.9.zipcompressed
MD5:DFB2138BA9567F89ECC7EC2483E1DF0C
SHA256:6C7B6FAF5A493F036E6B69A0F4C9C7F1B86C068A56CE4D8D9A92C8EBDE0EAE99
2844WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2844.33358\Imminent-Monitor-v3.9-main\imminent.pngimage
MD5:87DFEFA97A605139ECD09656A6D2FFAA
SHA256:AD36AAA8BDF4834B0753A18F7C235E289963E455761980CA3D63F302FCADF598
2896WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2896.34207\Imminent Monitor v3.9\8C1A0000.logtext
MD5:1163D1A6F35590B0DD53D66D949D9D7B
SHA256:78D8EA61E188FFB6F82064713895B2C4A056D41468EDE27178AC53DC1C218461
2844WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2844.33358\Imminent-Monitor-v3.9-main\README.mdtext
MD5:0257AA01C51C4D56F923DD5A4C14DBB5
SHA256:9F590A7BFB413E67D81538C0CD35687D739EE1D295E23595754B2090456874FC
2896WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2896.34207\Imminent Monitor v3.9\Builder (Imminent Monitor 3.9.0.0)\dnlib.dllexecutable
MD5:FB1EF0C4EBDCC61C23C809B01B8AE6C8
SHA256:51B88F4042F301204D5E6C31A822A53C69918C82B1604DF67D97D879E95C1268
2896WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2896.34207\Imminent Monitor v3.9\loader.logtext
MD5:8BCF05365B0B48E11F694F89BCF413F2
SHA256:6AE863196E1AE95B6219882F75FDE8EA4DCB1D8EF4124F20D1E0B9B85A2831CF
2896WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2896.34207\Imminent Monitor v3.9\Imminent Monitor 3.9.exeexecutable
MD5:67EB6B75152046AEA39083F45D4E9492
SHA256:9078149DC6EE62AEA91749BA2DB9ABA15C9518F92BFE709B3BBA8523F92CD2E8
2896WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2896.34207\Imminent Monitor v3.9\LZLoader.dllexecutable
MD5:F93937B67A4A89EF91E122DDD30BB35C
SHA256:0245467395E61C0E873612F38705E47A4B72ACAAF0A3BA02EE65B20470488825
2896WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2896.34207\Imminent Monitor v3.9\Builder (Imminent Monitor 4.1.0.0)\IMBuilder.exeexecutable
MD5:E65CE31A56C1E6E691E0A6F8E2C46002
SHA256:D1A67435A7CFB6A06026EA515D8D5DFB25051D91E3F5BA2BDB80F2AD6D84400B
2896WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2896.34207\Imminent Monitor v3.9\Builder (Imminent Monitor 3.9.0.0)\ImminentBuilder.exeexecutable
MD5:1B04AC944849488AD543636E1FD02DE7
SHA256:FEE4CE020777D27BF561A3C914619FCF77A4B7E1EC9202AD93461CED38C91C5B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3992
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
1076
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info