File name:

Zuoya GMK67 Keyboard Setup.exe

Full analysis: https://app.any.run/tasks/48d93f82-6aaf-4d10-a6c5-2611b0722829
Verdict: Malicious activity
Analysis date: April 04, 2024, 11:21:18
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

6B1E5C7651C33030DA74DE2FF9190364

SHA1:

600DBAF2A899DC812F9C1A2465B99DB7D80C02AA

SHA256:

4C0DA3C450F93880ED7586617925DAE9B13DE1A8D62EBC738FF688DE06AB8178

SSDEEP:

98304:u+QqZ8frkK6xYSzEAOwrvHz3Ta2AJDv8UjY4KIaMSGaiPnbLNOguiRD5rkiR22nH:Df0MkjgBarmKxT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Zuoya GMK67 Keyboard Setup.exe (PID: 1692)
      • Zuoya GMK67 Keyboard Setup.exe (PID: 2792)
      • Zuoya GMK67 Keyboard Setup.tmp (PID: 1824)
  • SUSPICIOUS

    • Uses TASKKILL.EXE to kill process

      • Zuoya GMK67 Keyboard Setup.tmp (PID: 1824)
    • Reads security settings of Internet Explorer

      • Zuoya GMK67 Keyboard Setup.tmp (PID: 1824)
    • Process drops legitimate windows executable

      • Zuoya GMK67 Keyboard Setup.tmp (PID: 1824)
    • The process drops C-runtime libraries

      • Zuoya GMK67 Keyboard Setup.tmp (PID: 1824)
    • Non-standard symbols in registry

      • Zuoya GMK67 Keyboard Setup.tmp (PID: 1824)
    • Reads the Windows owner or organization settings

      • Zuoya GMK67 Keyboard Setup.tmp (PID: 1824)
    • Reads the Internet Settings

      • Zuoya GMK67 Keyboard Setup.tmp (PID: 1824)
  • INFO

    • Checks supported languages

      • Zuoya GMK67 Keyboard Setup.exe (PID: 1692)
      • Zuoya GMK67 Keyboard Setup.tmp (PID: 2860)
      • DeviceDriver.exe (PID: 2904)
      • Zuoya GMK67 Keyboard Setup.exe (PID: 2792)
      • Zuoya GMK67 Keyboard Setup.tmp (PID: 1824)
    • Create files in a temporary directory

      • Zuoya GMK67 Keyboard Setup.exe (PID: 2792)
      • Zuoya GMK67 Keyboard Setup.exe (PID: 1692)
    • Reads the computer name

      • Zuoya GMK67 Keyboard Setup.tmp (PID: 2860)
      • DeviceDriver.exe (PID: 2904)
      • Zuoya GMK67 Keyboard Setup.tmp (PID: 1824)
    • Creates files in the program directory

      • Zuoya GMK67 Keyboard Setup.tmp (PID: 1824)
    • Creates a software uninstall entry

      • Zuoya GMK67 Keyboard Setup.tmp (PID: 1824)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:06:03 08:09:11+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741376
InitializedDataSize: 100864
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: ZUOYO
FileDescription: ZUOYO GMK67 Driver Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: ZUOYO GMK67 Driver
ProductVersion: V1.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
6
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start zuoya gmk67 keyboard setup.exe no specs zuoya gmk67 keyboard setup.tmp no specs zuoya gmk67 keyboard setup.exe zuoya gmk67 keyboard setup.tmp no specs taskkill.exe no specs devicedriver.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1692"C:\Users\admin\AppData\Local\Temp\Zuoya GMK67 Keyboard Setup.exe" C:\Users\admin\AppData\Local\Temp\Zuoya GMK67 Keyboard Setup.exeexplorer.exe
User:
admin
Company:
ZUOYO
Integrity Level:
MEDIUM
Description:
ZUOYO GMK67 Driver Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\zuoya gmk67 keyboard setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1824"C:\Users\admin\AppData\Local\Temp\is-8JLSC.tmp\Zuoya GMK67 Keyboard Setup.tmp" /SL5="$100130,5559508,843264,C:\Users\admin\AppData\Local\Temp\Zuoya GMK67 Keyboard Setup.exe" /SPAWNWND=$16013E /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\is-8JLSC.tmp\Zuoya GMK67 Keyboard Setup.tmpZuoya GMK67 Keyboard Setup.exe
User:
admin
Company:
ZUOYO
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-8jlsc.tmp\zuoya gmk67 keyboard setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2792"C:\Users\admin\AppData\Local\Temp\Zuoya GMK67 Keyboard Setup.exe" /SPAWNWND=$16013E /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\Zuoya GMK67 Keyboard Setup.exe
Zuoya GMK67 Keyboard Setup.tmp
User:
admin
Company:
ZUOYO
Integrity Level:
HIGH
Description:
ZUOYO GMK67 Driver Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\zuoya gmk67 keyboard setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2860"C:\Users\admin\AppData\Local\Temp\is-1SATC.tmp\Zuoya GMK67 Keyboard Setup.tmp" /SL5="$E0170,5559508,843264,C:\Users\admin\AppData\Local\Temp\Zuoya GMK67 Keyboard Setup.exe" C:\Users\admin\AppData\Local\Temp\is-1SATC.tmp\Zuoya GMK67 Keyboard Setup.tmpZuoya GMK67 Keyboard Setup.exe
User:
admin
Company:
ZUOYO
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-1satc.tmp\zuoya gmk67 keyboard setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2904"C:\Program Files\ZUOYO GMK67 Driver\DeviceDriver.exe"C:\Program Files\ZUOYO GMK67 Driver\DeviceDriver.exeZuoya GMK67 Keyboard Setup.tmp
User:
admin
Integrity Level:
MEDIUM
Version:
1.0.1.1
Modules
Images
c:\program files\zuoyo gmk67 driver\devicedriver.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
3164"C:\Windows\System32\taskkill.exe" /f /im DeviceDriver.exeC:\Windows\System32\taskkill.exeZuoya GMK67 Keyboard Setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
Total events
4 385
Read events
4 341
Write events
38
Delete events
6

Modification events

(PID) Process:(1824) Zuoya GMK67 Keyboard Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
200700005A85E53C8286DA01
(PID) Process:(1824) Zuoya GMK67 Keyboard Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
5E399417E88D4D17BFF3AB5E137003AC3CF3661067B9BFB6E5BF89569C65089F
(PID) Process:(1824) Zuoya GMK67 Keyboard Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(1824) Zuoya GMK67 Keyboard Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1824) Zuoya GMK67 Keyboard Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1824) Zuoya GMK67 Keyboard Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1824) Zuoya GMK67 Keyboard Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1824) Zuoya GMK67 Keyboard Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files\ZUOYO GMK67 Driver\DeviceDriver.exe
(PID) Process:(1824) Zuoya GMK67 Keyboard Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
AACE1A11EC244067CDD8A9731D6320FE286D818942CE120D0DCB223EC8165520
(PID) Process:(1824) Zuoya GMK67 Keyboard Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.myp\OpenWithProgids
Operation:writeName:ZUOYOGMK67DriverFile.myp
Value:
Executable files
16
Suspicious files
11
Text files
236
Unknown types
0

Dropped files

PID
Process
Filename
Type
1692Zuoya GMK67 Keyboard Setup.exeC:\Users\admin\AppData\Local\Temp\is-1SATC.tmp\Zuoya GMK67 Keyboard Setup.tmpexecutable
MD5:
SHA256:
2792Zuoya GMK67 Keyboard Setup.exeC:\Users\admin\AppData\Local\Temp\is-8JLSC.tmp\Zuoya GMK67 Keyboard Setup.tmpexecutable
MD5:
SHA256:
1824Zuoya GMK67 Keyboard Setup.tmpC:\Program Files\ZUOYO GMK67 Driver\is-NCL0F.tmpexecutable
MD5:
SHA256:
1824Zuoya GMK67 Keyboard Setup.tmpC:\Program Files\ZUOYO GMK67 Driver\unins000.exeexecutable
MD5:
SHA256:
1824Zuoya GMK67 Keyboard Setup.tmpC:\Program Files\ZUOYO GMK67 Driver\is-MMSRH.tmpexecutable
MD5:
SHA256:
1824Zuoya GMK67 Keyboard Setup.tmpC:\Program Files\ZUOYO GMK67 Driver\DeviceDriver.exeexecutable
MD5:
SHA256:
1824Zuoya GMK67 Keyboard Setup.tmpC:\Program Files\ZUOYO GMK67 Driver\is-S9VG4.tmpxml
MD5:
SHA256:
1824Zuoya GMK67 Keyboard Setup.tmpC:\Program Files\ZUOYO GMK67 Driver\device.xmlxml
MD5:
SHA256:
1824Zuoya GMK67 Keyboard Setup.tmpC:\Program Files\ZUOYO GMK67 Driver\is-1TTPA.tmpexecutable
MD5:
SHA256:
1824Zuoya GMK67 Keyboard Setup.tmpC:\Program Files\ZUOYO GMK67 Driver\is-5IIIH.tmpexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
unknown
4
System
192.168.100.255:137
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info