File name:

BummerLauncher.exe

Full analysis: https://app.any.run/tasks/b204538b-f52e-400d-8e48-024bf7735384
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: March 03, 2025, 07:48:01
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
loader
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows, 2 sections
MD5:

F7E1CB6F18B010C8D534C9A245EA000E

SHA1:

A6FACF39EBE8DF821E39A1411343FE6059B74F6C

SHA256:

5CEDB232A4290FC1D4FACAD1FFA0D4189DB906AE8CE04911B49D67F8907E8F7E

SSDEEP:

98304:g8/QuZB2HQJzDpSZYrTE8AwXhI0XOchs+TCIAdlJflB2bz14AWQxyTSYRHTgOPlk:dk

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Potential Corporate Privacy Violation

      • BummerLauncher.exe (PID: 7396)
    • Connects to unusual port

      • BummerLauncher.exe (PID: 7396)
    • Reads security settings of Internet Explorer

      • BummerLauncher.exe (PID: 7396)
    • Process requests binary or script from the Internet

      • BummerLauncher.exe (PID: 7396)
    • Executable content was dropped or overwritten

      • BummerLauncher.exe (PID: 7396)
  • INFO

    • Checks supported languages

      • BummerLauncher.exe (PID: 7396)
    • Reads the machine GUID from the registry

      • BummerLauncher.exe (PID: 7396)
    • Reads the computer name

      • BummerLauncher.exe (PID: 7396)
    • Create files in a temporary directory

      • BummerLauncher.exe (PID: 7396)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2059:07:18 15:49:14+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 48
CodeSize: 2076672
InitializedDataSize: 178688
UninitializedDataSize: -
EntryPoint: 0x0000
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: -
FileDescription: BummerLauncher
FileVersion: 1.0.0.0
InternalName: BummerLauncher.exe
LegalCopyright: Copyright © 2024
LegalTrademarks: -
OriginalFileName: BummerLauncher.exe
ProductName: BummerLauncher
ProductVersion: 1.0.0.0
AssemblyVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
139
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start bummerlauncher.exe sppextcomobj.exe no specs slui.exe no specs bummerlauncher.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
7300"C:\Users\admin\AppData\Local\Temp\BummerLauncher.exe" C:\Users\admin\AppData\Local\Temp\BummerLauncher.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
BummerLauncher
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\bummerlauncher.exe
c:\windows\system32\ntdll.dll
7396"C:\Users\admin\AppData\Local\Temp\BummerLauncher.exe" C:\Users\admin\AppData\Local\Temp\BummerLauncher.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
BummerLauncher
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\bummerlauncher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
7556C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7584"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
1 555
Read events
1 541
Write events
14
Delete events
0

Modification events

(PID) Process:(7396) BummerLauncher.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BummerLauncher_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(7396) BummerLauncher.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BummerLauncher_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(7396) BummerLauncher.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BummerLauncher_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(7396) BummerLauncher.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BummerLauncher_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(7396) BummerLauncher.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BummerLauncher_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(7396) BummerLauncher.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BummerLauncher_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(7396) BummerLauncher.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BummerLauncher_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(7396) BummerLauncher.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BummerLauncher_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(7396) BummerLauncher.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BummerLauncher_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(7396) BummerLauncher.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BummerLauncher_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
6
Suspicious files
0
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
7396BummerLauncher.exeC:\Users\admin\AppData\Local\Temp\BummerAC.exe
MD5:
SHA256:
7396BummerLauncher.exeC:\Users\admin\AppData\Local\Temp\GameAssembly.dll
MD5:
SHA256:
7396BummerLauncher.exeC:\Users\admin\AppData\Local\Temp\doorstop_config.initext
MD5:30706A5EE11709C50BEAD0093313047B
SHA256:2501FBAA65595FC5A9C1151FF113D37FA3E64D9AD486C01ED4CF0C05843DD9C9
7396BummerLauncher.exeC:\Users\admin\AppData\Local\Temp\UnityCrashHandler64.exeexecutable
MD5:A0E28B5D09D008DB5D10C6A4D6506856
SHA256:08FC865ED6D846AA73A6491936F1890F5026A355E9A4B689EC1F49E47CDA2B58
7396BummerLauncher.exeC:\Users\admin\AppData\Local\Temp\app.logtext
MD5:122B96253461D97E074476155C893CD5
SHA256:FBCBE1BDBE8DACD4EFA02E07369DA2D2339984537063338294C6A102F3C95AEF
7396BummerLauncher.exeC:\Users\admin\AppData\Local\Temp\.doorstop_versiontext
MD5:495063BEEAC89309A2247CE9C13ED292
SHA256:B4116D6E880009DC1440DDAB7EC054BCEA529AEA394EC5BAB7943B415A359281
7396BummerLauncher.exeC:\Users\admin\AppData\Local\Temp\baselib.dllexecutable
MD5:F4FA354EC58A335E5513300D58B21919
SHA256:E66DB63C0BEB860C19D0C668FC93FDBAC2842DAD5A5D487B03A45346F75F457D
7396BummerLauncher.exeC:\Users\admin\AppData\Local\Temp\BummerAC.Module.dllexecutable
MD5:A189095B724B0ACD71E49079BA752B65
SHA256:DC45AA2899747CB4B3871E1F27909E3A72FCEB73E35B66661EAF06BE7AC6B9BF
7396BummerLauncher.exeC:\Users\admin\AppData\Local\Temp\BummerAC.Load.dllexecutable
MD5:C4DEB790B27CFFDC840011180ABB0CB7
SHA256:ABDF084929D27A3DB2BF03E1F75DEEE926C87C1A40437D0445CA9B18663017F4
7396BummerLauncher.exeC:\Users\admin\AppData\Local\Temp\BummerAC.Updater.dllexecutable
MD5:0E759065B9FAAE699CF833F1E808657F
SHA256:476B59885B6734993A5D41EF7591696E10CE17696EAD32AA7B46AA6E3CD006E6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
20
DNS requests
13
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7396
BummerLauncher.exe
GET
200
150.241.113.82:36000
http://launcher.bummerrust.ru:36000/api/manifest
ES
text
77.5 Kb
unknown
7396
BummerLauncher.exe
GET
200
150.241.113.82:36000
http://launcher.bummerrust.ru:36000/api/getfile/.doorstop_version
ES
text
5 b
unknown
7396
BummerLauncher.exe
GET
200
150.241.113.82:36000
http://launcher.bummerrust.ru:36000/api/getfile/baselib.dll
ES
executable
390 Kb
unknown
7396
BummerLauncher.exe
GET
200
150.241.113.82:36000
http://launcher.bummerrust.ru:36000/api/getfile/BummerAC.Module.dll
ES
executable
59.0 Kb
unknown
7396
BummerLauncher.exe
GET
200
150.241.113.82:36000
http://launcher.bummerrust.ru:36000/api/getfile/BummerAC.Load.dll
ES
executable
55.0 Kb
unknown
6044
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
NL
binary
408 b
whitelisted
6044
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
NL
binary
419 b
whitelisted
7396
BummerLauncher.exe
GET
200
150.241.113.82:36000
http://launcher.bummerrust.ru:36000/api/getfile/BummerAC.Updater.dll
ES
executable
60.0 Kb
unknown
7396
BummerLauncher.exe
GET
150.241.113.82:36000
http://launcher.bummerrust.ru:36000/api/getfile/GameAssembly.dll
ES
unknown
7396
BummerLauncher.exe
GET
200
150.241.113.82:36000
http://launcher.bummerrust.ru:36000/api/getfile/doorstop_config.ini
ES
text
1.77 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4380
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
40.113.103.199:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
40.126.31.2:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7740
backgroundTaskHost.exe
20.199.58.43:443
arc.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6044
SIHClient.exe
52.149.20.212:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.104.136.2
whitelisted
google.com
  • 142.250.186.174
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
login.live.com
  • 40.126.31.2
  • 40.126.31.67
  • 40.126.31.73
  • 20.190.159.4
  • 20.190.159.68
  • 40.126.31.1
  • 40.126.31.128
  • 20.190.159.64
whitelisted
arc.msn.com
  • 20.199.58.43
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted
launcher.bummerrust.ru
  • 150.241.113.82
unknown

Threats

PID
Process
Class
Message
7396
BummerLauncher.exe
Potential Corporate Privacy Violation
ET INFO PE EXE or DLL Windows file download HTTP
7396
BummerLauncher.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
7396
BummerLauncher.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
No debug info