File name:

Bombermania.exe.zip

Full analysis: https://app.any.run/tasks/7b0e3fa5-bc06-442e-a00e-924988d22562
Verdict: Malicious activity
Analysis date: March 02, 2024, 16:55:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v5.1 to extract, compression method=AES Encrypted
MD5:

E5459C4864695FDA631FB328B024CE61

SHA1:

14C17C4446F03DCAE11CA4BA4EBF81A0F35028D1

SHA256:

46EE42FB79A161BF3763E8E34A047018BD16D8572F8D31C2CDECAE3D2E7A57A8

SSDEEP:

49152:MrT6tmScfov2NB2orgfSvt4q/CRPdbLZ1k5iIdLu/k4mCwgFPWEe+YdS:M/6Fnv2NBzMOtqlvZ1FqDgFPZe+AS

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3700)
      • Bombermania.exe (PID: 2036)
      • _Bombermania.exe (PID: 3936)
      • is-4USA6.tmp (PID: 1836)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Bombermania.exe (PID: 2036)
      • _Bombermania.exe (PID: 3936)
      • is-4USA6.tmp (PID: 1836)
    • Process drops legitimate windows executable

      • is-4USA6.tmp (PID: 1836)
    • Reads the Windows owner or organization settings

      • is-4USA6.tmp (PID: 1836)
  • INFO

    • Checks supported languages

      • Bombermania.exe (PID: 2036)
      • Bombermania.exe (PID: 2752)
      • _Bombermania.exe (PID: 3936)
      • is-4USA6.tmp (PID: 1836)
    • Manual execution by a user

      • _Bombermania.exe (PID: 3948)
      • Bombermania.exe (PID: 2036)
      • Bombermania.exe (PID: 2752)
      • _Bombermania.exe (PID: 3936)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3700)
    • Create files in a temporary directory

      • Bombermania.exe (PID: 2752)
      • _Bombermania.exe (PID: 3936)
      • is-4USA6.tmp (PID: 1836)
      • Bombermania.exe (PID: 2036)
    • Reads the computer name

      • is-4USA6.tmp (PID: 1836)
    • Creates files in the program directory

      • is-4USA6.tmp (PID: 1836)
    • Creates a software uninstall entry

      • is-4USA6.tmp (PID: 1836)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 819
ZipBitFlag: 0x0001
ZipCompression: Unknown (99)
ZipModifyDate: 2007:09:24 15:39:30
ZipCRC: 0x00000000
ZipCompressedSize: 2747913
ZipUncompressedSize: 2801690
ZipFileName: Bombermania.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
6
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe bombermania.exe bombermania.exe no specs _bombermania.exe no specs _bombermania.exe is-4usa6.tmp

Process information

PID
CMD
Path
Indicators
Parent process
1836"C:\Users\admin\AppData\Local\Temp\is-D5TME.tmp\is-4USA6.tmp" /SL4 $B024E C:\Users\admin\AppData\Local\Temp\Bombermania.exe\_Bombermania.exe 2384405 50688 C:\Users\admin\AppData\Local\Temp\is-D5TME.tmp\is-4USA6.tmp
_Bombermania.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\is-d5tme.tmp\is-4usa6.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2036"C:\Users\admin\AppData\Local\Temp\Bombermania.exe\Bombermania.exe" C:\Users\admin\AppData\Local\Temp\Bombermania.exe\Bombermania.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\bombermania.exe\bombermania.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2752"C:\Users\admin\AppData\Local\Temp\Bombermania.exe\Bombermania.exe" C:\Users\admin\AppData\Local\Temp\Bombermania.exe\Bombermania.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\bombermania.exe\bombermania.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
3700"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Bombermania.exe.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3936"C:\Users\admin\AppData\Local\Temp\Bombermania.exe\_Bombermania.exe" C:\Users\admin\AppData\Local\Temp\Bombermania.exe\_Bombermania.exe
explorer.exe
User:
admin
Company:
Just Free Games
Integrity Level:
HIGH
Description:
Bombermania Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\bombermania.exe\_bombermania.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3948"C:\Users\admin\AppData\Local\Temp\Bombermania.exe\_Bombermania.exe" C:\Users\admin\AppData\Local\Temp\Bombermania.exe\_Bombermania.exeexplorer.exe
User:
admin
Company:
Just Free Games
Integrity Level:
MEDIUM
Description:
Bombermania Setup
Exit code:
3221226540
Version:
Modules
Images
c:\users\admin\appdata\local\temp\bombermania.exe\_bombermania.exe
c:\windows\system32\ntdll.dll
Total events
6 234
Read events
6 208
Write events
26
Delete events
0

Modification events

(PID) Process:(3700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3700) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Bombermania.exe.zip
(PID) Process:(3700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
10
Suspicious files
6
Text files
22
Unknown types
11

Dropped files

PID
Process
Filename
Type
2036Bombermania.exeC:\Users\admin\AppData\Local\Temp\Bombermania.exe\MultipurposeAgent_MyFileNameReport.xmlxml
MD5:BE5498E027E346DAFCF835B8FAE15FAF
SHA256:A5E471A56F5663957BF242E5C25D11739995FA75FDFC3261ADB48870FFE627E3
2036Bombermania.exeC:\Users\admin\AppData\Local\Temp\Bombermania.exe\OnStartup.xmlxml
MD5:6F6E56B9F9755B4B8C1F09E48C1B61A5
SHA256:4B07F2452780C190F54673618A9CCB7FFDEE69B21BE5231C0DC17D824D10ACB0
2036Bombermania.exeC:\Users\admin\AppData\Local\Temp\Bombermania.exe\OnStartup_FallBack.xmlxml
MD5:623DADBF038A827D7DFA0E631C3BC0E0
SHA256:DA73A0A830FCED711A3FF1941E3DCC8C6786D1B1308CD5852F0F0F6B768DD5A8
2036Bombermania.exeC:\Users\admin\AppData\Local\Temp\Bombermania.exe\UninstallPartII.xmlxml
MD5:514BB2B46BF58A41392D58062F86C0BF
SHA256:A04E3251EC95D7CD9A619CF183D9ED99FD6B18190F53A0CE72607D257BD4A2D5
2036Bombermania.exeC:\Users\admin\AppData\Local\Temp\Bombermania.exe\Instructions.xmlxml
MD5:06686DE253BF5BCA9B3FD61DAE44EEF2
SHA256:78730E10B80DA6E7B5306059BB77869928E0655A1E2A049E8F1A43A93452C05B
2752Bombermania.exeC:\Users\admin\AppData\Local\Temp\Bombermania.exe\Instructions.xmlxml
MD5:06686DE253BF5BCA9B3FD61DAE44EEF2
SHA256:78730E10B80DA6E7B5306059BB77869928E0655A1E2A049E8F1A43A93452C05B
2036Bombermania.exeC:\Users\admin\AppData\Local\Temp\Bombermania.exe\UninstallPartI.xmlxml
MD5:F8DA0FDA97735DD86E697BE9F8534F19
SHA256:9C1A8636ECB5E8F49F88B316DCBF81F2B6803B9905E3C6865AAA6E92805695FC
2036Bombermania.exeC:\Users\admin\AppData\Local\Temp\Bombermania.exe\ErrorsLogFile.txttext
MD5:A45022034C145D20F6CF697BC3C6901C
SHA256:F0ADA8D0655408E38843CE0D4DC2F1688F660D56CEA4D9618ED773111FD907CF
3936_Bombermania.exeC:\Users\admin\AppData\Local\Temp\is-D5TME.tmp\is-4USA6.tmpexecutable
MD5:E84DE69F85741B96C7755124D725F754
SHA256:F8A9ACFC4DBBC58DEAD29730E266726D1650437B76A73F6D2FF1A91949CA395F
1836is-4USA6.tmpC:\Users\admin\AppData\Local\Temp\is-AMHTR.tmp\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info