File name:

Imminent.Monitor.3.9.0.0-Crack-YQ8.rar

Full analysis: https://app.any.run/tasks/14350b86-e6e6-4b08-987d-aeb7046d13f2
Verdict: Malicious activity
Analysis date: October 16, 2021, 02:00:44
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

F7E737811F8DE3F9A60612C61ECBD912

SHA1:

17377AD1C012D7615D2C2AF152E885D1D7C17A63

SHA256:

DF3ABE8E705A7B0EA353072D9582E90049256288135C0E7376CC389185EB1A69

SSDEEP:

98304:P2J+2Ec/jo6g+TPkFaStTg5BnnX7+6mVq:Wb7zsTg5Z7F+q

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3588)
      • Imminent Monitor 3.9.exe (PID: 996)
    • Application was dropped or rewritten from another process

      • Imminent Monitor 3.9.exe (PID: 996)
      • ImminentBuilder.exe (PID: 3756)
    • Starts Visual C# compiler

      • Imminent Monitor 3.9.exe (PID: 996)
    • Drops executable file immediately after starts

      • csc.exe (PID: 3228)
      • csc.exe (PID: 3856)
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 3196)
      • Imminent Monitor 3.9.exe (PID: 996)
      • ImminentBuilder.exe (PID: 3756)
    • Checks supported languages

      • WinRAR.exe (PID: 3196)
      • Imminent Monitor 3.9.exe (PID: 996)
      • csc.exe (PID: 3228)
      • cvtres.exe (PID: 1640)
      • csc.exe (PID: 3856)
      • cvtres.exe (PID: 872)
      • ImminentBuilder.exe (PID: 3756)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3196)
      • csc.exe (PID: 3228)
      • csc.exe (PID: 3856)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 3196)
    • Drops a file with a compile date too recent

      • csc.exe (PID: 3228)
      • csc.exe (PID: 3856)
    • Reads Environment values

      • Imminent Monitor 3.9.exe (PID: 996)
  • INFO

    • Manual execution by user

      • Imminent Monitor 3.9.exe (PID: 996)
      • ImminentBuilder.exe (PID: 3756)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 161
UncompressedSize: 84
OperatingSystem: Win32
ModifyDate: 2015:02:09 13:35:24
PackingMethod: Normal
ArchivedFileName: Imminent.Monitor.3.9.0.0-Crack-YQ8\8C1A0000.log
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
8
Malicious processes
4
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs imminent monitor 3.9.exe no specs csc.exe cvtres.exe no specs csc.exe cvtres.exe no specs imminentbuilder.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
872C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RESD6CB.tmp" "c:\Users\admin\AppData\Local\Temp\CSCD6CA.tmp"C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.execsc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft� Resource File To COFF Object Conversion Utility
Exit code:
0
Version:
8.00.50727.5003 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\cvtres.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptsp.dll
996"C:\Users\admin\Desktop\Imminent.Monitor.3.9.0.0-Crack-YQ8\Imminent Monitor 3.9.exe" C:\Users\admin\Desktop\Imminent.Monitor.3.9.0.0-Crack-YQ8\Imminent Monitor 3.9.exeExplorer.EXE
User:
admin
Company:
Imminent Methods
Integrity Level:
MEDIUM
Description:
Imminent Monitor
Exit code:
0
Version:
3.9.0.0
Modules
Images
c:\users\admin\desktop\imminent.monitor.3.9.0.0-crack-yq8\imminent monitor 3.9.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1640C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RESCCE8.tmp" "c:\Users\admin\AppData\Local\Temp\CSCCCE7.tmp"C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.execsc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft� Resource File To COFF Object Conversion Utility
Exit code:
0
Version:
8.00.50727.5003 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\cvtres.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptsp.dll
3196"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Imminent.Monitor.3.9.0.0-Crack-YQ8.rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3228"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\dmcanwld.cmdline"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe
Imminent Monitor 3.9.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Visual C# Command Line Compiler
Exit code:
0
Version:
8.0.50727.5483 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\csc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3588"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\system32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3756"C:\Users\admin\Desktop\Imminent.Monitor.3.9.0.0-Crack-YQ8\Builder\ImminentBuilder.exe" C:\Users\admin\Desktop\Imminent.Monitor.3.9.0.0-Crack-YQ8\Builder\ImminentBuilder.exeExplorer.EXE
User:
admin
Company:
Microsoft
Integrity Level:
MEDIUM
Description:
Builder
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\imminent.monitor.3.9.0.0-crack-yq8\builder\imminentbuilder.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3856"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\i14bqjad.cmdline"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe
Imminent Monitor 3.9.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Visual C# Command Line Compiler
Exit code:
0
Version:
8.0.50727.5483 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\csc.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
2 784
Read events
2 757
Write events
27
Delete events
0

Modification events

(PID) Process:(3196) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3196) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3196) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\171\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3196) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Imminent.Monitor.3.9.0.0-Crack-YQ8.rar
(PID) Process:(3196) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3196) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3196) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3196) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3196) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(3196) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
10
Suspicious files
0
Text files
411
Unknown types
8

Dropped files

PID
Process
Filename
Type
3196WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3196.32456\Imminent.Monitor.3.9.0.0-Crack-YQ8\CRACK INFO.txttext
MD5:
SHA256:
3196WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3196.32456\Imminent.Monitor.3.9.0.0-Crack-YQ8\readme.txttext
MD5:
SHA256:
3196WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3196.32456\Imminent.Monitor.3.9.0.0-Crack-YQ8\8C1A0000.logtext
MD5:1163D1A6F35590B0DD53D66D949D9D7B
SHA256:78D8EA61E188FFB6F82064713895B2C4A056D41468EDE27178AC53DC1C218461
3196WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3196.32456\Imminent.Monitor.3.9.0.0-Crack-YQ8\Builder\dnlib.dllexecutable
MD5:FB1EF0C4EBDCC61C23C809B01B8AE6C8
SHA256:51B88F4042F301204D5E6C31A822A53C69918C82B1604DF67D97D879E95C1268
3196WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3196.32456\Imminent.Monitor.3.9.0.0-Crack-YQ8\Builder\ImminentBuilder.exeexecutable
MD5:1B04AC944849488AD543636E1FD02DE7
SHA256:FEE4CE020777D27BF561A3C914619FCF77A4B7E1EC9202AD93461CED38C91C5B
3196WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3196.32456\Imminent.Monitor.3.9.0.0-Crack-YQ8\Builder\Vestris.ResourceLib.dllexecutable
MD5:3048628799C10059424491E174851F91
SHA256:FADCF9B9F02B540B33C31817445456DC36E8AB2A066DFC3E63256B9706638399
3196WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3196.32456\Imminent.Monitor.3.9.0.0-Crack-YQ8\loader.logtext
MD5:8BCF05365B0B48E11F694F89BCF413F2
SHA256:6AE863196E1AE95B6219882F75FDE8EA4DCB1D8EF4124F20D1E0B9B85A2831CF
3196WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3196.32456\Imminent.Monitor.3.9.0.0-Crack-YQ8\Imminent Monitor 3.9.exeexecutable
MD5:67EB6B75152046AEA39083F45D4E9492
SHA256:9078149DC6EE62AEA91749BA2DB9ABA15C9518F92BFE709B3BBA8523F92CD2E8
3196WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3196.32456\Imminent.Monitor.3.9.0.0-Crack-YQ8\ClientPlugin.dllexecutable
MD5:2B02DE4647260361B18DE39DF5AF1AC6
SHA256:94E757AAF2F333D53EB0DD4F941FBD445D36FC27383201D60B3C1073CAC20EC1
3196WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3196.32456\Imminent.Monitor.3.9.0.0-Crack-YQ8\PluginCompiler.exeexecutable
MD5:540ACCC16897D3039F610AD6CEF9B673
SHA256:937D40D109C7B0AA6246639A8F3D5893C6DD62DEC94816B2CF5A0E89BE2BE325
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info