| File name: | zuma-deluxe-1.0.exe |
| Full analysis: | https://app.any.run/tasks/410081e1-fabb-4d6a-99a6-0a9d12273431 |
| Verdict: | Malicious activity |
| Analysis date: | March 10, 2024, 12:04:22 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, InstallShield self-extracting archive |
| MD5: | 8B13A3EF51B432A08470C12896C069E8 |
| SHA1: | 15C14F18202D0F309F36F38BDC333C1A57E5DB66 |
| SHA256: | 54D7EF25B03F2D04D09F11D8614DF9C3B99BA55BE473DBE7FA1243DBF26855ED |
| SSDEEP: | 98304:n7gjE6xajoOOyY48GHQQ5rq81dspnCT0vUCVI+Med7LnPnLmWAK3/DjPLu7kybIX:repGEj/9m6RITw1pn |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2008:09:22 18:34:03+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 8 |
| CodeSize: | 290816 |
| InitializedDataSize: | 98304 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x31e80 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1776 | "C:\Users\admin\AppData\Local\Temp\zuma-deluxe-1.0.exe" | C:\Users\admin\AppData\Local\Temp\zuma-deluxe-1.0.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2692 | "C:\Program Files\PopCap Games\Zuma Deluxe\Zuma.exe" | C:\Program Files\PopCap Games\Zuma Deluxe\Zuma.exe | zuma-deluxe-1.0.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Zuma Exit code: 0 Version: 1, 0, 0, 1 Modules
| |||||||||||||||
| 3516 | "C:\ProgramData\PopCap Games\Zuma\popcapgame1.exe" -changedir="C:\Program Files\PopCap Games\Zuma Deluxe\" | C:\ProgramData\PopCap Games\Zuma\popcapgame1.exe | Zuma.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Zuma Exit code: 0 Version: 1, 0, 0, 1 Modules
| |||||||||||||||
| 4052 | "C:\Users\admin\AppData\Local\Temp\zuma-deluxe-1.0.exe" | C:\Users\admin\AppData\Local\Temp\zuma-deluxe-1.0.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| (PID) Process: | (1776) zuma-deluxe-1.0.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\GameUX\Games\{0ABD0415-76A0-4A15-B846-C18B919BF6D6} |
| Operation: | write | Name: | ConfigInstallType |
Value: 2 | |||
| (PID) Process: | (1776) zuma-deluxe-1.0.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\GameUX\Games\{0ABD0415-76A0-4A15-B846-C18B919BF6D6} |
| Operation: | write | Name: | ConfigApplicationPath |
Value: C:\Program Files\PopCap Games\Zuma Deluxe | |||
| (PID) Process: | (1776) zuma-deluxe-1.0.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\GameUX\Games\{0ABD0415-76A0-4A15-B846-C18B919BF6D6} |
| Operation: | write | Name: | ConfigGDFBinaryPath |
Value: C:\Program Files\PopCap Games\Zuma Deluxe\Zuma.exe | |||
| (PID) Process: | (1776) zuma-deluxe-1.0.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\GameUX\Games\{0ABD0415-76A0-4A15-B846-C18B919BF6D6} |
| Operation: | write | Name: | ApplicationId |
Value: {CF92B623-F090-4FDB-8BFB-2505D626CD46} | |||
| (PID) Process: | (1776) zuma-deluxe-1.0.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\GameUX\Games\{0ABD0415-76A0-4A15-B846-C18B919BF6D6} |
| Operation: | write | Name: | Title |
Value: Zuma™ Deluxe | |||
| (PID) Process: | (1776) zuma-deluxe-1.0.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\GameUX\Games\{0ABD0415-76A0-4A15-B846-C18B919BF6D6} |
| Operation: | write | Name: | RatingsInfo |
Value: <Ratings xmlns="urn:schemas-microsoft-com:GameDescription.v1">
<Rating ratingSystemID="{768BD93D-63BE-46A9-8994-0B53C4B5248F}" ratingID="{7A53B0BE-B92D-4e8a-A11F-8E6F9F3C575B}"/>
</Ratings> | |||
| (PID) Process: | (1776) zuma-deluxe-1.0.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\GameUX\Games\{0ABD0415-76A0-4A15-B846-C18B919BF6D6} |
| Operation: | write | Name: | Description |
Value: Unearth the ancient secrets of Zuma! Survive the hidden jungle temples... shoot magical balls to clear a deadly chain... avoid dangerous traps... and do it all before the chain reaches the golden skull. Be quick, or you'll be history in this action-packed challenge. | |||
| (PID) Process: | (1776) zuma-deluxe-1.0.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\GameUX\Games\{0ABD0415-76A0-4A15-B846-C18B919BF6D6} |
| Operation: | write | Name: | Type |
Value: 0 | |||
| (PID) Process: | (1776) zuma-deluxe-1.0.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1776) zuma-deluxe-1.0.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates |
| Operation: | delete value | Name: | 9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6 |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1776 | zuma-deluxe-1.0.exe | C:\Users\admin\AppData\Local\Temp\popcfg2\files.cab | — | |
MD5:— | SHA256:— | |||
| 1776 | zuma-deluxe-1.0.exe | C:\Users\admin\AppData\Local\Temp\popcfg2\defines.xml | text | |
MD5:33F72C59461C45073AF328AFD70C7A1D | SHA256:8B0A6448164795E044F47D3D4BBBEF5EE4A4208C160F746FD57BF58079C31F2C | |||
| 1776 | zuma-deluxe-1.0.exe | C:\Users\admin\AppData\Local\Temp\popcfg2\logo.bmp | image | |
MD5:1843D66328CEDC1CE60CB98F3D593F4A | SHA256:7F3E2F0EC8926E7911FE024271387657ADF8BDA95581C6235F995BE57FF56EA1 | |||
| 1776 | zuma-deluxe-1.0.exe | C:\Program Files\PopCap Games\Zuma Deluxe\drm\common\fonts\_Arial12Bold.png | image | |
MD5:863930D80A382BB4520ACC37C53D82F9 | SHA256:411C9B874945D4EB690A7D1DAB646B4A55CA0A054A78735D46D1B24D29299BD6 | |||
| 1776 | zuma-deluxe-1.0.exe | C:\Users\admin\AppData\Local\Temp\popcfg2\readme.html | html | |
MD5:A56B9138DAF1CE3AAB6845A186BE4972 | SHA256:C98E8EE14648AAEFD228E25683173FDE79DC928FE6C3EEB56B9D4F843BAE5CD5 | |||
| 1776 | zuma-deluxe-1.0.exe | C:\Program Files\PopCap Games\moregames.ico | image | |
MD5:E213A8D3DF54E8C1431CC9DEC3016DB1 | SHA256:2DD8378B031F18F67B20FC2354476395D00CEDFA1947CB29A9583C88FB14F589 | |||
| 1776 | zuma-deluxe-1.0.exe | C:\Users\admin\AppData\Local\Temp\popcfg2\props.xml | xml | |
MD5:ACF2E02C4FEDBF05762C4ACEEE1C1D4C | SHA256:EF7C8669907E7476C089339490023311D4EA430409AF242D6E50C92409A2B1DF | |||
| 1776 | zuma-deluxe-1.0.exe | C:\Program Files\PopCap Games\Zuma Deluxe\drm\common\drm.xml | xml | |
MD5:946A134DC587A63D6BD2118721221128 | SHA256:ECD9B35903EEC8B6C68C4775831023648A2B084C58762DEC715584DC57C7B22B | |||
| 1776 | zuma-deluxe-1.0.exe | C:\Users\admin\AppData\Local\Temp\popcfg2\install.xml | text | |
MD5:518587C14E2F1BE212D1DB1D017EAD0E | SHA256:E98558F3C178BBDEDD5ACA92E347BE4D8768F0A474081C04B1C9DE4DFDFF91AA | |||
| 1776 | zuma-deluxe-1.0.exe | C:\Users\admin\AppData\Local\Temp\popcfg2\product.bmp | image | |
MD5:2473C200DBCBA64785E26C765D9B0184 | SHA256:02158A1864BDF784BDE817FA8E418E4F20ECF17C0CF4AD4D1EE0578C29CB466D | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2692 | Zuma.exe | 49.13.77.253:80 | updates.popcap.com | Hetzner Online GmbH | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
updates.popcap.com |
| unknown |
dns.msftncsi.com |
| shared |
Process | Message |
|---|---|
Zuma.exe | Init Time: 0.040992
|
popcapgame1.exe | Product: Zuma
|
popcapgame1.exe | BuildNum: 0
|
popcapgame1.exe | BuildDate:
|
popcapgame1.exe | Application requests 640 x 480 [ 4: 3]
|
popcapgame1.exe | Desktop is 1280 x 720 [16: 9]
|
popcapgame1.exe | Display is 640 x 480 [ 4: 3]
|
popcapgame1.exe | Draw buffer is 640 x 480 [ 4: 3]
|
popcapgame1.exe | Resource Loading Time: 2047
|
Zuma.exe | Session seconds: 1 Minutes Left: 60
|