File name:

Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.exe

Full analysis: https://app.any.run/tasks/accb3e9c-9350-4067-a294-29060d8e5c06
Verdict: Malicious activity
Analysis date: May 15, 2025, 20:30:52
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
inno
installer
delphi
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 10 sections
MD5:

80EA0520D39BED9F73DBBACD3CF989A0

SHA1:

F512D4683C18F74F9A6926FB9405013B20F6D4F7

SHA256:

377A4EDD32A49736676BB9D1AC1AD06308EDC385E02F07C6CF340003A4CF201D

SSDEEP:

98304:o+cD4dn4CYix6DMYfVwyV/kI19d4zLFMlmaUr2aNHiqZnNTrEyHEFAofkViVUhhJ:TL9Rulx594

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmp (PID: 1272)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.exe (PID: 4756)
      • Mouse Drive Beta.exe (PID: 6404)
      • Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmp (PID: 1272)
    • The process drops C-runtime libraries

      • Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmp (PID: 1272)
      • Mouse Drive Beta.exe (PID: 6404)
    • Process drops legitimate windows executable

      • Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmp (PID: 1272)
      • Mouse Drive Beta.exe (PID: 6404)
    • Reads the Windows owner or organization settings

      • Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmp (PID: 1272)
  • INFO

    • Create files in a temporary directory

      • Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.exe (PID: 4756)
      • Mouse Drive Beta.exe (PID: 6404)
      • Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmp (PID: 1272)
    • Checks supported languages

      • Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.exe (PID: 4756)
      • Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmp (PID: 1272)
      • Mouse Drive Beta.exe (PID: 6404)
    • Compiled with Borland Delphi (YARA)

      • Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.exe (PID: 4756)
      • Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmp (PID: 1272)
    • The sample compiled with english language support

      • Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmp (PID: 1272)
      • Mouse Drive Beta.exe (PID: 6404)
    • Creates files in the program directory

      • Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmp (PID: 1272)
    • Detects InnoSetup installer (YARA)

      • Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmp (PID: 1272)
      • Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.exe (PID: 4756)
    • Reads the computer name

      • Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmp (PID: 1272)
      • Mouse Drive Beta.exe (PID: 6404)
    • Reads the machine GUID from the registry

      • Mouse Drive Beta.exe (PID: 6404)
    • The sample compiled with chinese language support

      • Mouse Drive Beta.exe (PID: 6404)
    • Reads Environment values

      • Mouse Drive Beta.exe (PID: 6404)
    • Creates files or folders in the user directory

      • Mouse Drive Beta.exe (PID: 6404)
    • Creates a software uninstall entry

      • Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmp (PID: 1272)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:04:14 16:10:23+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 100864
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Redragon, Inc.
FileDescription: Redragon M916-PRO-1K Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Redragon M916-PRO-1K
ProductVersion: 1.0.0.4
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
137
Monitored processes
6
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start redragon_m916-pro-1k_v1.0.0.4_2024.07.04_setup.exe redragon_m916-pro-1k_v1.0.0.4_2024.07.04_setup.tmp sppextcomobj.exe no specs slui.exe no specs mouse drive beta.exe redragon_m916-pro-1k_v1.0.0.4_2024.07.04_setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1272"C:\Users\admin\AppData\Local\Temp\is-1A4IB.tmp\Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmp" /SL5="$8034A,6564697,843776,C:\Users\admin\AppData\Local\Temp\Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.exe" C:\Users\admin\AppData\Local\Temp\is-1A4IB.tmp\Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmp
Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.exe
User:
admin
Company:
Redragon, Inc.
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-1a4ib.tmp\redragon_m916-pro-1k_v1.0.0.4_2024.07.04_setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
4428C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
4688"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4756"C:\Users\admin\AppData\Local\Temp\Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.exe" C:\Users\admin\AppData\Local\Temp\Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.exe
explorer.exe
User:
admin
Company:
Redragon, Inc.
Integrity Level:
HIGH
Description:
Redragon M916-PRO-1K Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\redragon_m916-pro-1k_v1.0.0.4_2024.07.04_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6404"C:\Program Files (x86)\Redragon M916-PRO-1K\Mouse Drive Beta.exe"C:\Program Files (x86)\Redragon M916-PRO-1K\Mouse Drive Beta.exe
Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmp
User:
admin
Integrity Level:
HIGH
Version:
1.0.0.4
Modules
Images
c:\program files (x86)\redragon m916-pro-1k\mouse drive beta.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
6972"C:\Users\admin\AppData\Local\Temp\Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.exe" C:\Users\admin\AppData\Local\Temp\Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.exeexplorer.exe
User:
admin
Company:
Redragon, Inc.
Integrity Level:
MEDIUM
Description:
Redragon M916-PRO-1K Setup
Exit code:
3221226540
Version:
Modules
Images
c:\users\admin\appdata\local\temp\redragon_m916-pro-1k_v1.0.0.4_2024.07.04_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
Total events
561
Read events
529
Write events
31
Delete events
1

Modification events

(PID) Process:(1272) Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Compx\Redragon\Redragon M916-PRO-1K
Operation:writeName:LanguageIndex
Value:
00
(PID) Process:(1272) Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.myp\OpenWithProgids
Operation:writeName:RedragonM916-PRO-1KFile.myp
Value:
(PID) Process:(1272) Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\Mouse Drive Beta.exe\SupportedTypes
Operation:writeName:.myp
Value:
(PID) Process:(1272) Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Compx\Redragon\Redragon M916-PRO-1K
Operation:delete keyName:(default)
Value:
(PID) Process:(1272) Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Redragon M916-PRO-1K
Value:
"C:\Program Files (x86)\Redragon M916-PRO-1K\Mouse Drive Beta.exe"
(PID) Process:(1272) Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F4D3E6BD-B622-4CFE-AD65-8802EF3BDE06}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.2.1
(PID) Process:(1272) Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F4D3E6BD-B622-4CFE-AD65-8802EF3BDE06}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files (x86)\Redragon M916-PRO-1K
(PID) Process:(1272) Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F4D3E6BD-B622-4CFE-AD65-8802EF3BDE06}_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files (x86)\Redragon M916-PRO-1K\
(PID) Process:(1272) Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F4D3E6BD-B622-4CFE-AD65-8802EF3BDE06}_is1
Operation:writeName:Inno Setup: Icon Group
Value:
(Default)
(PID) Process:(1272) Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F4D3E6BD-B622-4CFE-AD65-8802EF3BDE06}_is1
Operation:writeName:Inno Setup: User
Value:
admin
Executable files
20
Suspicious files
3
Text files
275
Unknown types
0

Dropped files

PID
Process
Filename
Type
1272Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmpC:\Program Files (x86)\Redragon M916-PRO-1K\is-5IAD7.tmptext
MD5:47AB355BFAF0A23632CDFD84B1FD8910
SHA256:430E1039E10132337E3CE4312C7DA1549DAD8409941DF9D9B4098081ECC92061
1272Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmpC:\Program Files (x86)\Redragon M916-PRO-1K\is-LBP4K.tmpexecutable
MD5:2965F1C6A54F37EF069854F0699BC28E
SHA256:F6ACAFB1B7CB6596C90B51D0533746E9F4F72F2494429DD6F628F08B8EB4A093
4756Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.exeC:\Users\admin\AppData\Local\Temp\is-1A4IB.tmp\Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmpexecutable
MD5:125CDB3076B78F64010C6CC7AB47F425
SHA256:961C389859CC27F73AF201702E68C7859A22CAE20CEC9E1651972DE15AEA178E
1272Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmpC:\Users\admin\AppData\Local\Temp\is-6EL66.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
1272Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmpC:\Program Files (x86)\Redragon M916-PRO-1K\is-3AV3M.tmptext
MD5:BD6A8821883BDD6667CC9A957C6F63E8
SHA256:E19DDF965FED746D6177C7DFB2F3AD2D7801B7BCEF46C6C1E7C2F482286ADB73
1272Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmpC:\Program Files (x86)\Redragon M916-PRO-1K\Config.initext
MD5:47AB355BFAF0A23632CDFD84B1FD8910
SHA256:430E1039E10132337E3CE4312C7DA1549DAD8409941DF9D9B4098081ECC92061
1272Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmpC:\Program Files (x86)\Redragon M916-PRO-1K\is-0V1GJ.tmpxml
MD5:2F9C54D665997881051C4D0744BE8AFA
SHA256:2659ACC08171BCA60AE27D5BB12F75B5697CCFA789E4408FB547FF9B08E90931
1272Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmpC:\Program Files (x86)\Redragon M916-PRO-1K\is-655S0.tmpexecutable
MD5:44ACA650B84973BAAB976F1CB56AFB82
SHA256:234E8D894F94C2A4EE444A0187A8C68C5C7863CC0727AE561523A0904699E67C
1272Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmpC:\Program Files (x86)\Redragon M916-PRO-1K\driver_sensor.htext
MD5:BD6A8821883BDD6667CC9A957C6F63E8
SHA256:E19DDF965FED746D6177C7DFB2F3AD2D7801B7BCEF46C6C1E7C2F482286ADB73
1272Redragon_M916-PRO-1K_v1.0.0.4_2024.07.04_setup.tmpC:\Program Files (x86)\Redragon M916-PRO-1K\Mouse Drive Beta.exeexecutable
MD5:44ACA650B84973BAAB976F1CB56AFB82
SHA256:234E8D894F94C2A4EE444A0187A8C68C5C7863CC0727AE561523A0904699E67C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
18
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
104.124.11.58:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6372
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6372
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
104.124.11.58:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.160.64:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6372
SIHClient.exe
172.202.163.200:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
GB
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 104.124.11.58
  • 104.124.11.17
whitelisted
google.com
  • 142.250.186.142
whitelisted
www.microsoft.com
  • 2.23.246.101
  • 95.101.149.131
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.160.64
  • 20.190.160.132
  • 20.190.160.3
  • 20.190.160.67
  • 20.190.160.22
  • 20.190.160.2
  • 40.126.32.133
  • 40.126.32.74
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted

Threats

No threats detected
No debug info