File name:

Bombermania.exe.zip

Full analysis: https://app.any.run/tasks/7e980ff7-e78e-40f2-85ec-54fe459cee97
Verdict: Malicious activity
Analysis date: March 02, 2024, 16:58:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v5.1 to extract, compression method=AES Encrypted
MD5:

E5459C4864695FDA631FB328B024CE61

SHA1:

14C17C4446F03DCAE11CA4BA4EBF81A0F35028D1

SHA256:

46EE42FB79A161BF3763E8E34A047018BD16D8572F8D31C2CDECAE3D2E7A57A8

SSDEEP:

49152:MrT6tmScfov2NB2orgfSvt4q/CRPdbLZ1k5iIdLu/k4mCwgFPWEe+YdS:M/6Fnv2NBzMOtqlvZ1FqDgFPZe+AS

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2160)
      • Bombermania.exe (PID: 3660)
      • is-FB505.tmp (PID: 2856)
      • _Bombermania.exe (PID: 2860)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Bombermania.exe (PID: 3660)
      • _Bombermania.exe (PID: 2860)
      • is-FB505.tmp (PID: 2856)
    • Reads the Windows owner or organization settings

      • is-FB505.tmp (PID: 2856)
    • Process drops legitimate windows executable

      • is-FB505.tmp (PID: 2856)
  • INFO

    • Create files in a temporary directory

      • Bombermania.exe (PID: 3660)
      • is-FB505.tmp (PID: 2856)
      • _Bombermania.exe (PID: 2860)
    • Checks supported languages

      • Bombermania.exe (PID: 3660)
      • is-FB505.tmp (PID: 2856)
      • Bombermania.exe (PID: 2792)
      • Bombermania.exe (PID: 2064)
      • _Bombermania.exe (PID: 2860)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2160)
    • Manual execution by a user

      • _Bombermania.exe (PID: 1876)
      • Bombermania.exe (PID: 3660)
      • Bombermania.exe (PID: 2792)
      • Bombermania.exe (PID: 2064)
      • msedge.exe (PID: 3020)
      • msedge.exe (PID: 2644)
      • _Bombermania.exe (PID: 2860)
    • Creates files in the program directory

      • is-FB505.tmp (PID: 2856)
    • Reads the computer name

      • is-FB505.tmp (PID: 2856)
    • Creates a software uninstall entry

      • is-FB505.tmp (PID: 2856)
    • Application launched itself

      • msedge.exe (PID: 3020)
      • msedge.exe (PID: 2644)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 819
ZipBitFlag: 0x0001
ZipCompression: Unknown (99)
ZipModifyDate: 2007:09:24 15:39:30
ZipCRC: 0x00000000
ZipCompressedSize: 2747913
ZipUncompressedSize: 2801690
ZipFileName: Bombermania.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
74
Monitored processes
30
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe bombermania.exe _bombermania.exe no specs _bombermania.exe is-fb505.tmp bombermania.exe bombermania.exe msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1172"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3984 --field-trial-handle=1352,i,3731460321151840015,17695723696566496951,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1392"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=3596 --field-trial-handle=1352,i,3731460321151840015,17695723696566496951,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1408"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4056 --field-trial-handle=1352,i,3731460321151840015,17695723696566496951,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1556"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1652 --field-trial-handle=1352,i,3731460321151840015,17695723696566496951,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1796"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1264 --field-trial-handle=1352,i,3731460321151840015,17695723696566496951,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1860"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6a1ff598,0x6a1ff5a8,0x6a1ff5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1876"C:\Users\admin\AppData\Local\Temp\Bombermania.exe\_Bombermania.exe" C:\Users\admin\AppData\Local\Temp\Bombermania.exe\_Bombermania.exeexplorer.exe
User:
admin
Company:
Just Free Games
Integrity Level:
MEDIUM
Description:
Bombermania Setup
Exit code:
3221226540
Version:
Modules
Images
c:\users\admin\appdata\local\temp\bombermania.exe\_bombermania.exe
c:\windows\system32\ntdll.dll
2064"C:\Program Files\Bombermania\Bombermania.exe" C:\Program Files\Bombermania\Bombermania.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225477
Modules
Images
c:\program files\bombermania\bombermania.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2080"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4136 --field-trial-handle=1352,i,3731460321151840015,17695723696566496951,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2160"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Bombermania.exe.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
9 667
Read events
9 588
Write events
73
Delete events
6

Modification events

(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2160) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Bombermania.exe.zip
(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
11
Suspicious files
31
Text files
55
Unknown types
20

Dropped files

PID
Process
Filename
Type
3660Bombermania.exeC:\Users\admin\AppData\Local\Temp\Bombermania.exe\OnStartup_FallBack.xmlxml
MD5:623DADBF038A827D7DFA0E631C3BC0E0
SHA256:DA73A0A830FCED711A3FF1941E3DCC8C6786D1B1308CD5852F0F0F6B768DD5A8
3660Bombermania.exeC:\Users\admin\AppData\Local\Temp\Bombermania.exe\UninstallPartII.xmlxml
MD5:514BB2B46BF58A41392D58062F86C0BF
SHA256:A04E3251EC95D7CD9A619CF183D9ED99FD6B18190F53A0CE72607D257BD4A2D5
3660Bombermania.exeC:\Users\admin\AppData\Local\Temp\Bombermania.exe\OnStartup.xmlxml
MD5:6F6E56B9F9755B4B8C1F09E48C1B61A5
SHA256:4B07F2452780C190F54673618A9CCB7FFDEE69B21BE5231C0DC17D824D10ACB0
3660Bombermania.exeC:\Users\admin\AppData\Local\Temp\Bombermania.exe\MultipurposeAgent_MyFileNameReport.xmlxml
MD5:1347BEE1E46356DFC95F1A4F0EAA889E
SHA256:5B76F35D8A9C77480B6B615361EBB04328255BDCBDE1F44FF5B234E427F7826A
3660Bombermania.exeC:\Users\admin\AppData\Local\Temp\Bombermania.exe\UninstallPartI.xmlxml
MD5:F8DA0FDA97735DD86E697BE9F8534F19
SHA256:9C1A8636ECB5E8F49F88B316DCBF81F2B6803B9905E3C6865AAA6E92805695FC
2860_Bombermania.exeC:\Users\admin\AppData\Local\Temp\is-AGD6B.tmp\is-FB505.tmpexecutable
MD5:E84DE69F85741B96C7755124D725F754
SHA256:F8A9ACFC4DBBC58DEAD29730E266726D1650437B76A73F6D2FF1A91949CA395F
2856is-FB505.tmpC:\Program Files\Bombermania\unins000.exeexecutable
MD5:4E573E916D86107CFD08E9A3137173AE
SHA256:3715AC5FC0CD97F646A32767F76AFE27F4EC3C663C75031F807BD8486DACDA24
2856is-FB505.tmpC:\Program Files\Bombermania\is-66E3K.tmpexecutable
MD5:4E573E916D86107CFD08E9A3137173AE
SHA256:3715AC5FC0CD97F646A32767F76AFE27F4EC3C663C75031F807BD8486DACDA24
2856is-FB505.tmpC:\Program Files\Bombermania\is-2P1P8.tmptext
MD5:23675A2222DC5AB82BBA80ACA5854794
SHA256:B42AEC2D876D6AE56F9D1090844EBEF4B97127571227BDDEF84EAB55E40E530C
2856is-FB505.tmpC:\Program Files\Bombermania\is-JKOKC.tmptext
MD5:F13D60419C801C6219D47C21422F0A52
SHA256:83FB2DDA19EE2B79E3153883676BBCFE3AE45ACF0C5DB3115A669112C92F2812
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
21
DNS requests
30
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2968
msedge.exe
GET
301
172.67.201.149:80
http://www.justfreegames.com/stats/bombermania.php?source=Bombermania_Desktop
unknown
unknown
2968
msedge.exe
GET
301
188.114.96.3:80
http://www.sunnygames.com/?source=Bombermania_Desktop
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2968
msedge.exe
172.67.201.149:80
www.justfreegames.com
CLOUDFLARENET
US
unknown
2644
msedge.exe
239.255.255.250:1900
unknown
2968
msedge.exe
13.107.21.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2968
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2968
msedge.exe
172.67.12.68:443
www.gametop.com
CLOUDFLARENET
US
unknown
2968
msedge.exe
104.16.57.101:443
static.cloudflareinsights.com
CLOUDFLARENET
unknown
2968
msedge.exe
104.17.2.184:443
challenges.cloudflare.com
CLOUDFLARENET
unknown

DNS requests

Domain
IP
Reputation
www.justfreegames.com
  • 172.67.201.149
whitelisted
edge.microsoft.com
  • 13.107.21.239
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
www.gametop.com
  • 172.67.12.68
whitelisted
static.cloudflareinsights.com
  • 104.16.57.101
whitelisted
challenges.cloudflare.com
  • 104.17.2.184
whitelisted
www.bing.com
  • 88.221.24.82
whitelisted
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com
  • 152.195.19.97
whitelisted
www.sunnygames.com
  • 188.114.96.3
unknown

Threats

PID
Process
Class
Message
2968
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare turnstile CAPTCHA challenge
2968
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare turnstile CAPTCHA challenge
Process
Message
msedge.exe
[0302/165914.049:ERROR:exception_handler_server.cc(527)] ConnectNamedPipe: The pipe is being closed. (0xE8)