File name:

Bombermania.exe.zip

Full analysis: https://app.any.run/tasks/7e980ff7-e78e-40f2-85ec-54fe459cee97
Verdict: Malicious activity
Analysis date: March 02, 2024, 16:58:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v5.1 to extract, compression method=AES Encrypted
MD5:

E5459C4864695FDA631FB328B024CE61

SHA1:

14C17C4446F03DCAE11CA4BA4EBF81A0F35028D1

SHA256:

46EE42FB79A161BF3763E8E34A047018BD16D8572F8D31C2CDECAE3D2E7A57A8

SSDEEP:

49152:MrT6tmScfov2NB2orgfSvt4q/CRPdbLZ1k5iIdLu/k4mCwgFPWEe+YdS:M/6Fnv2NBzMOtqlvZ1FqDgFPZe+AS

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2160)
      • Bombermania.exe (PID: 3660)
      • _Bombermania.exe (PID: 2860)
      • is-FB505.tmp (PID: 2856)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • _Bombermania.exe (PID: 2860)
      • is-FB505.tmp (PID: 2856)
      • Bombermania.exe (PID: 3660)
    • Process drops legitimate windows executable

      • is-FB505.tmp (PID: 2856)
    • Reads the Windows owner or organization settings

      • is-FB505.tmp (PID: 2856)
  • INFO

    • Checks supported languages

      • _Bombermania.exe (PID: 2860)
      • is-FB505.tmp (PID: 2856)
      • Bombermania.exe (PID: 2792)
      • Bombermania.exe (PID: 2064)
      • Bombermania.exe (PID: 3660)
    • Create files in a temporary directory

      • _Bombermania.exe (PID: 2860)
      • is-FB505.tmp (PID: 2856)
      • Bombermania.exe (PID: 3660)
    • Manual execution by a user

      • _Bombermania.exe (PID: 2860)
      • Bombermania.exe (PID: 2792)
      • Bombermania.exe (PID: 2064)
      • msedge.exe (PID: 3020)
      • msedge.exe (PID: 2644)
      • Bombermania.exe (PID: 3660)
      • _Bombermania.exe (PID: 1876)
    • Creates a software uninstall entry

      • is-FB505.tmp (PID: 2856)
    • Creates files in the program directory

      • is-FB505.tmp (PID: 2856)
    • Application launched itself

      • msedge.exe (PID: 2644)
      • msedge.exe (PID: 3020)
    • Reads the computer name

      • is-FB505.tmp (PID: 2856)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2160)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 819
ZipBitFlag: 0x0001
ZipCompression: Unknown (99)
ZipModifyDate: 2007:09:24 15:39:30
ZipCRC: 0x00000000
ZipCompressedSize: 2747913
ZipUncompressedSize: 2801690
ZipFileName: Bombermania.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
74
Monitored processes
30
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe bombermania.exe _bombermania.exe no specs _bombermania.exe is-fb505.tmp bombermania.exe bombermania.exe msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1172"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3984 --field-trial-handle=1352,i,3731460321151840015,17695723696566496951,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1392"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=3596 --field-trial-handle=1352,i,3731460321151840015,17695723696566496951,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1408"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4056 --field-trial-handle=1352,i,3731460321151840015,17695723696566496951,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1556"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1652 --field-trial-handle=1352,i,3731460321151840015,17695723696566496951,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1796"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1264 --field-trial-handle=1352,i,3731460321151840015,17695723696566496951,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1860"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6a1ff598,0x6a1ff5a8,0x6a1ff5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1876"C:\Users\admin\AppData\Local\Temp\Bombermania.exe\_Bombermania.exe" C:\Users\admin\AppData\Local\Temp\Bombermania.exe\_Bombermania.exeexplorer.exe
User:
admin
Company:
Just Free Games
Integrity Level:
MEDIUM
Description:
Bombermania Setup
Exit code:
3221226540
Version:
Modules
Images
c:\users\admin\appdata\local\temp\bombermania.exe\_bombermania.exe
c:\windows\system32\ntdll.dll
2064"C:\Program Files\Bombermania\Bombermania.exe" C:\Program Files\Bombermania\Bombermania.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225477
Modules
Images
c:\program files\bombermania\bombermania.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2080"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4136 --field-trial-handle=1352,i,3731460321151840015,17695723696566496951,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2160"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Bombermania.exe.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
9 667
Read events
9 588
Write events
73
Delete events
6

Modification events

(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2160) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Bombermania.exe.zip
(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2160) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
11
Suspicious files
31
Text files
55
Unknown types
20

Dropped files

PID
Process
Filename
Type
3660Bombermania.exeC:\Users\admin\AppData\Local\Temp\Bombermania.exe\_Bombermania.exeexecutable
MD5:FE37B30358F0858A8EF4D8B874C8A96D
SHA256:77EDC8FD4A7EDD277BF6A61B6413804380DD89ED2D0E7B768EAE09EFC3393D9C
2160WinRAR.exeC:\Users\admin\AppData\Local\Temp\Bombermania.exe\Bombermania.exeexecutable
MD5:471D39A51A79F342033C5B0636C244DC
SHA256:1154535130D546EAA33BBC9051A9CB91E2B0E3A3991286C3D5B0A708110C9AA7
2856is-FB505.tmpC:\Program Files\Bombermania\unins000.exeexecutable
MD5:4E573E916D86107CFD08E9A3137173AE
SHA256:3715AC5FC0CD97F646A32767F76AFE27F4EC3C663C75031F807BD8486DACDA24
3660Bombermania.exeC:\Users\admin\AppData\Local\Temp\Bombermania.exe\ErrorsLogFile.txttext
MD5:9383541DE744D206D99567371301386B
SHA256:DE9D2E086D95823CA500E7270167295F8D840C9F9C350FE454FA9FF2D6F76DD9
3660Bombermania.exeC:\Users\admin\AppData\Local\Temp\Bombermania.exe\MultipurposeAgent_MyFileNameReport.xmlxml
MD5:1347BEE1E46356DFC95F1A4F0EAA889E
SHA256:5B76F35D8A9C77480B6B615361EBB04328255BDCBDE1F44FF5B234E427F7826A
2856is-FB505.tmpC:\Program Files\Bombermania\is-66E3K.tmpexecutable
MD5:4E573E916D86107CFD08E9A3137173AE
SHA256:3715AC5FC0CD97F646A32767F76AFE27F4EC3C663C75031F807BD8486DACDA24
2860_Bombermania.exeC:\Users\admin\AppData\Local\Temp\is-AGD6B.tmp\is-FB505.tmpexecutable
MD5:E84DE69F85741B96C7755124D725F754
SHA256:F8A9ACFC4DBBC58DEAD29730E266726D1650437B76A73F6D2FF1A91949CA395F
3660Bombermania.exeC:\Users\admin\AppData\Local\Temp\Bombermania.exe\OnStartup_FallBack.xmlxml
MD5:623DADBF038A827D7DFA0E631C3BC0E0
SHA256:DA73A0A830FCED711A3FF1941E3DCC8C6786D1B1308CD5852F0F0F6B768DD5A8
3660Bombermania.exeC:\Users\admin\AppData\Local\Temp\Bombermania.exe\OnStartup.xmlxml
MD5:6F6E56B9F9755B4B8C1F09E48C1B61A5
SHA256:4B07F2452780C190F54673618A9CCB7FFDEE69B21BE5231C0DC17D824D10ACB0
3660Bombermania.exeC:\Users\admin\AppData\Local\Temp\Bombermania.exe\Instructions.xmlxml
MD5:06686DE253BF5BCA9B3FD61DAE44EEF2
SHA256:78730E10B80DA6E7B5306059BB77869928E0655A1E2A049E8F1A43A93452C05B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
21
DNS requests
30
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2968
msedge.exe
GET
301
172.67.201.149:80
http://www.justfreegames.com/stats/bombermania.php?source=Bombermania_Desktop
unknown
unknown
2968
msedge.exe
GET
301
188.114.96.3:80
http://www.sunnygames.com/?source=Bombermania_Desktop
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2968
msedge.exe
172.67.201.149:80
www.justfreegames.com
CLOUDFLARENET
US
unknown
2644
msedge.exe
239.255.255.250:1900
unknown
2968
msedge.exe
13.107.21.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2968
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2968
msedge.exe
172.67.12.68:443
www.gametop.com
CLOUDFLARENET
US
unknown
2968
msedge.exe
104.16.57.101:443
static.cloudflareinsights.com
CLOUDFLARENET
unknown
2968
msedge.exe
104.17.2.184:443
challenges.cloudflare.com
CLOUDFLARENET
unknown

DNS requests

Domain
IP
Reputation
www.justfreegames.com
  • 172.67.201.149
whitelisted
edge.microsoft.com
  • 13.107.21.239
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
www.gametop.com
  • 172.67.12.68
whitelisted
static.cloudflareinsights.com
  • 104.16.57.101
whitelisted
challenges.cloudflare.com
  • 104.17.2.184
whitelisted
www.bing.com
  • 88.221.24.82
whitelisted
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com
  • 152.195.19.97
whitelisted
www.sunnygames.com
  • 188.114.96.3
unknown

Threats

PID
Process
Class
Message
2968
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare turnstile CAPTCHA challenge
2968
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare turnstile CAPTCHA challenge
Process
Message
msedge.exe
[0302/165914.049:ERROR:exception_handler_server.cc(527)] ConnectNamedPipe: The pipe is being closed. (0xE8)