File name:

Imminent.Monitor.3.9.0.0-Crack-YQ8.rar

Full analysis: https://app.any.run/tasks/14350b86-e6e6-4b08-987d-aeb7046d13f2
Verdict: Malicious activity
Analysis date: October 16, 2021, 02:00:44
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

F7E737811F8DE3F9A60612C61ECBD912

SHA1:

17377AD1C012D7615D2C2AF152E885D1D7C17A63

SHA256:

DF3ABE8E705A7B0EA353072D9582E90049256288135C0E7376CC389185EB1A69

SSDEEP:

98304:P2J+2Ec/jo6g+TPkFaStTg5BnnX7+6mVq:Wb7zsTg5Z7F+q

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • Imminent Monitor 3.9.exe (PID: 996)
      • SearchProtocolHost.exe (PID: 3588)
    • Drops executable file immediately after starts

      • csc.exe (PID: 3228)
      • csc.exe (PID: 3856)
    • Application was dropped or rewritten from another process

      • ImminentBuilder.exe (PID: 3756)
      • Imminent Monitor 3.9.exe (PID: 996)
    • Starts Visual C# compiler

      • Imminent Monitor 3.9.exe (PID: 996)
  • SUSPICIOUS

    • Checks supported languages

      • WinRAR.exe (PID: 3196)
      • Imminent Monitor 3.9.exe (PID: 996)
      • csc.exe (PID: 3228)
      • cvtres.exe (PID: 1640)
      • csc.exe (PID: 3856)
      • cvtres.exe (PID: 872)
      • ImminentBuilder.exe (PID: 3756)
    • Reads the computer name

      • Imminent Monitor 3.9.exe (PID: 996)
      • WinRAR.exe (PID: 3196)
      • ImminentBuilder.exe (PID: 3756)
    • Executable content was dropped or overwritten

      • csc.exe (PID: 3856)
      • csc.exe (PID: 3228)
      • WinRAR.exe (PID: 3196)
    • Drops a file with a compile date too recent

      • csc.exe (PID: 3228)
      • csc.exe (PID: 3856)
    • Reads Environment values

      • Imminent Monitor 3.9.exe (PID: 996)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 3196)
  • INFO

    • Manual execution by user

      • ImminentBuilder.exe (PID: 3756)
      • Imminent Monitor 3.9.exe (PID: 996)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 161
UncompressedSize: 84
OperatingSystem: Win32
ModifyDate: 2015:02:09 13:35:24
PackingMethod: Normal
ArchivedFileName: Imminent.Monitor.3.9.0.0-Crack-YQ8\8C1A0000.log
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
8
Malicious processes
4
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs imminent monitor 3.9.exe no specs csc.exe cvtres.exe no specs csc.exe cvtres.exe no specs imminentbuilder.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
872C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RESD6CB.tmp" "c:\Users\admin\AppData\Local\Temp\CSCD6CA.tmp"C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.execsc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft� Resource File To COFF Object Conversion Utility
Exit code:
0
Version:
8.00.50727.5003 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\cvtres.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptsp.dll
996"C:\Users\admin\Desktop\Imminent.Monitor.3.9.0.0-Crack-YQ8\Imminent Monitor 3.9.exe" C:\Users\admin\Desktop\Imminent.Monitor.3.9.0.0-Crack-YQ8\Imminent Monitor 3.9.exeExplorer.EXE
User:
admin
Company:
Imminent Methods
Integrity Level:
MEDIUM
Description:
Imminent Monitor
Exit code:
0
Version:
3.9.0.0
Modules
Images
c:\users\admin\desktop\imminent.monitor.3.9.0.0-crack-yq8\imminent monitor 3.9.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1640C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RESCCE8.tmp" "c:\Users\admin\AppData\Local\Temp\CSCCCE7.tmp"C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.execsc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft� Resource File To COFF Object Conversion Utility
Exit code:
0
Version:
8.00.50727.5003 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\cvtres.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptsp.dll
3196"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Imminent.Monitor.3.9.0.0-Crack-YQ8.rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3228"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\dmcanwld.cmdline"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe
Imminent Monitor 3.9.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Visual C# Command Line Compiler
Exit code:
0
Version:
8.0.50727.5483 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\csc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3588"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\system32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3756"C:\Users\admin\Desktop\Imminent.Monitor.3.9.0.0-Crack-YQ8\Builder\ImminentBuilder.exe" C:\Users\admin\Desktop\Imminent.Monitor.3.9.0.0-Crack-YQ8\Builder\ImminentBuilder.exeExplorer.EXE
User:
admin
Company:
Microsoft
Integrity Level:
MEDIUM
Description:
Builder
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\imminent.monitor.3.9.0.0-crack-yq8\builder\imminentbuilder.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3856"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\i14bqjad.cmdline"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe
Imminent Monitor 3.9.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Visual C# Command Line Compiler
Exit code:
0
Version:
8.0.50727.5483 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\csc.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
2 784
Read events
2 757
Write events
27
Delete events
0

Modification events

(PID) Process:(3196) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3196) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3196) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\171\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3196) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Imminent.Monitor.3.9.0.0-Crack-YQ8.rar
(PID) Process:(3196) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3196) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3196) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3196) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3196) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(3196) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
10
Suspicious files
0
Text files
411
Unknown types
8

Dropped files

PID
Process
Filename
Type
3196WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3196.32456\Imminent.Monitor.3.9.0.0-Crack-YQ8\CRACK INFO.txttext
MD5:
SHA256:
3196WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3196.32456\Imminent.Monitor.3.9.0.0-Crack-YQ8\Builder\Vestris.ResourceLib.dllexecutable
MD5:3048628799C10059424491E174851F91
SHA256:FADCF9B9F02B540B33C31817445456DC36E8AB2A066DFC3E63256B9706638399
3196WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3196.32456\Imminent.Monitor.3.9.0.0-Crack-YQ8\ClientPlugin.dllexecutable
MD5:2B02DE4647260361B18DE39DF5AF1AC6
SHA256:94E757AAF2F333D53EB0DD4F941FBD445D36FC27383201D60B3C1073CAC20EC1
3196WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3196.32456\Imminent.Monitor.3.9.0.0-Crack-YQ8\8C1A0000.logtext
MD5:1163D1A6F35590B0DD53D66D949D9D7B
SHA256:78D8EA61E188FFB6F82064713895B2C4A056D41468EDE27178AC53DC1C218461
3196WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3196.32456\Imminent.Monitor.3.9.0.0-Crack-YQ8\readme.txttext
MD5:
SHA256:
3196WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3196.32456\Imminent.Monitor.3.9.0.0-Crack-YQ8\Builder\dnlib.dllexecutable
MD5:FB1EF0C4EBDCC61C23C809B01B8AE6C8
SHA256:51B88F4042F301204D5E6C31A822A53C69918C82B1604DF67D97D879E95C1268
3196WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3196.32456\Imminent.Monitor.3.9.0.0-Crack-YQ8\Plugins\DisableWebcamLights.impbs
MD5:EF9E22457EB8581D51603DE1AAD87BD3
SHA256:9F6D7226856CF5D4EEBE724AE8CEB35BB4AFBBCA2140193F9540F8FAD6FBB501
3196WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3196.32456\Imminent.Monitor.3.9.0.0-Crack-YQ8\Resources\Images\Buttons\File Manager\buttonabort.pngimage
MD5:964D1AFCAA92B7B2EDA6B86513E511F8
SHA256:CEE7ED8601DE316A2B961D3D78B07CDFDD10BD04266D366CE5E77B425513F515
3196WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3196.32456\Imminent.Monitor.3.9.0.0-Crack-YQ8\Plugins\MultiTools.impbs
MD5:38DFCAA5FD03D0ABEB6102CD4742F60D
SHA256:C68763ED9B2B3171FD79AD2814414577393FA671428AF3E3DA201FA214B2C5E2
3196WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3196.32456\Imminent.Monitor.3.9.0.0-Crack-YQ8\Plugins\placeholder.bintext
MD5:7F6F0E25166FACE9F6C085D3E4C7ED1C
SHA256:4255D027413A8DAA922A312693254C40CEA390CBDCB7DEA5C21D8DDBA7AF7B3B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info