File name:

AL71_Keyboard_Setup_v2.0_20231220.exe

Full analysis: https://app.any.run/tasks/02b02b42-34ac-4422-965b-4a1aeb9e3c22
Verdict: Malicious activity
Analysis date: February 16, 2024, 10:05:18
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

E6762BEA0036669B1D1B67935C56EA27

SHA1:

FFD62A6598A66FBF7F2332ACDEAA59D54427C032

SHA256:

D6C83A47288282B5EAAD98649FA7A5F6044587F809B6A08CE255E89C4E574249

SSDEEP:

98304:eFuvFc0ZZA3bl7Nxt3O0+16EcGdS5kTJDw6TG1299Y3BzHpYRJRg0ZXYb4qLScFb:/15+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • AL71_Keyboard_Setup_v2.0_20231220.exe (PID: 3732)
      • AL71_Keyboard_Setup_v2.0_20231220.tmp (PID: 3772)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • AL71_Keyboard_Setup_v2.0_20231220.exe (PID: 3732)
      • AL71_Keyboard_Setup_v2.0_20231220.tmp (PID: 3772)
    • Process drops legitimate windows executable

      • AL71_Keyboard_Setup_v2.0_20231220.tmp (PID: 3772)
    • Reads the Windows owner or organization settings

      • AL71_Keyboard_Setup_v2.0_20231220.tmp (PID: 3772)
  • INFO

    • Create files in a temporary directory

      • AL71_Keyboard_Setup_v2.0_20231220.exe (PID: 3732)
      • AL71_Keyboard_Setup_v2.0_20231220.tmp (PID: 3772)
    • Checks supported languages

      • AL71_Keyboard_Setup_v2.0_20231220.tmp (PID: 3772)
      • AL71_Keyboard_Setup_v2.0_20231220.exe (PID: 3732)
      • OemDrv.exe (PID: 2332)
      • wmpnscfg.exe (PID: 4008)
    • Reads the computer name

      • AL71_Keyboard_Setup_v2.0_20231220.tmp (PID: 3772)
      • OemDrv.exe (PID: 2332)
      • wmpnscfg.exe (PID: 4008)
    • Creates files in the program directory

      • AL71_Keyboard_Setup_v2.0_20231220.tmp (PID: 3772)
    • Creates files or folders in the user directory

      • AL71_Keyboard_Setup_v2.0_20231220.tmp (PID: 3772)
    • Creates a software uninstall entry

      • AL71_Keyboard_Setup_v2.0_20231220.tmp (PID: 3772)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 4008)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (81.5)
.exe | Win32 Executable Delphi generic (10.5)
.exe | Win32 Executable (generic) (3.3)
.exe | Win16/32 Executable Delphi generic (1.5)
.exe | Generic Win/DOS Executable (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2009:08:15 19:29:32+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 86016
InitializedDataSize: 177664
UninitializedDataSize: -
EntryPoint: 0x163c4
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription:
FileVersion:
LegalCopyright:
ProductName:
ProductVersion:
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start al71_keyboard_setup_v2.0_20231220.exe al71_keyboard_setup_v2.0_20231220.tmp oemdrv.exe no specs wmpnscfg.exe no specs al71_keyboard_setup_v2.0_20231220.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1384"C:\Users\admin\AppData\Local\Temp\AL71_Keyboard_Setup_v2.0_20231220.exe" C:\Users\admin\AppData\Local\Temp\AL71_Keyboard_Setup_v2.0_20231220.exeexplorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Exit code:
3221226540
Version:
Modules
Images
c:\users\admin\appdata\local\temp\al71_keyboard_setup_v2.0_20231220.exe
c:\windows\system32\ntdll.dll
2332"C:\Program Files\AL71 Keyboard\OemDrv.exe"C:\Program Files\AL71 Keyboard\OemDrv.exeAL71_Keyboard_Setup_v2.0_20231220.tmp
User:
admin
Integrity Level:
HIGH
Exit code:
0
Version:
1, 0, 0, 0
Modules
Images
c:\program files\al71 keyboard\oemdrv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msimg32.dll
3732"C:\Users\admin\AppData\Local\Temp\AL71_Keyboard_Setup_v2.0_20231220.exe" C:\Users\admin\AppData\Local\Temp\AL71_Keyboard_Setup_v2.0_20231220.exe
explorer.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\al71_keyboard_setup_v2.0_20231220.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3772"C:\Users\admin\AppData\Local\Temp\is-VIAJR.tmp\AL71_Keyboard_Setup_v2.0_20231220.tmp" /SL5="$F0170,1556493,264704,C:\Users\admin\AppData\Local\Temp\AL71_Keyboard_Setup_v2.0_20231220.exe" C:\Users\admin\AppData\Local\Temp\is-VIAJR.tmp\AL71_Keyboard_Setup_v2.0_20231220.tmp
AL71_Keyboard_Setup_v2.0_20231220.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1048.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-viajr.tmp\al71_keyboard_setup_v2.0_20231220.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
4008"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
2 796
Read events
2 782
Write events
14
Delete events
0

Modification events

(PID) Process:(3772) AL71_Keyboard_Setup_v2.0_20231220.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{371D8FE0-CC41-48CA-8D07-76AC10304785}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
5.3.4 (u)
(PID) Process:(3772) AL71_Keyboard_Setup_v2.0_20231220.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{371D8FE0-CC41-48CA-8D07-76AC10304785}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files\AL71 Keyboard
(PID) Process:(3772) AL71_Keyboard_Setup_v2.0_20231220.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{371D8FE0-CC41-48CA-8D07-76AC10304785}_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files\AL71 Keyboard\
(PID) Process:(3772) AL71_Keyboard_Setup_v2.0_20231220.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{371D8FE0-CC41-48CA-8D07-76AC10304785}_is1
Operation:writeName:Inno Setup: Icon Group
Value:
AL71 Keyboard
(PID) Process:(3772) AL71_Keyboard_Setup_v2.0_20231220.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{371D8FE0-CC41-48CA-8D07-76AC10304785}_is1
Operation:writeName:Inno Setup: User
Value:
admin
(PID) Process:(3772) AL71_Keyboard_Setup_v2.0_20231220.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{371D8FE0-CC41-48CA-8D07-76AC10304785}_is1
Operation:writeName:DisplayName
Value:
AL71 Keyboard
(PID) Process:(3772) AL71_Keyboard_Setup_v2.0_20231220.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{371D8FE0-CC41-48CA-8D07-76AC10304785}_is1
Operation:writeName:UninstallString
Value:
"C:\Program Files\AL71 Keyboard\unins000.exe"
(PID) Process:(3772) AL71_Keyboard_Setup_v2.0_20231220.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{371D8FE0-CC41-48CA-8D07-76AC10304785}_is1
Operation:writeName:QuietUninstallString
Value:
"C:\Program Files\AL71 Keyboard\unins000.exe" /SILENT
(PID) Process:(3772) AL71_Keyboard_Setup_v2.0_20231220.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{371D8FE0-CC41-48CA-8D07-76AC10304785}_is1
Operation:writeName:DisplayVersion
Value:
2.0
(PID) Process:(3772) AL71_Keyboard_Setup_v2.0_20231220.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{371D8FE0-CC41-48CA-8D07-76AC10304785}_is1
Operation:writeName:NoModify
Value:
1
Executable files
13
Suspicious files
4
Text files
298
Unknown types
2

Dropped files

PID
Process
Filename
Type
3772AL71_Keyboard_Setup_v2.0_20231220.tmpC:\Users\admin\AppData\Local\Temp\is-GIGIT.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
3772AL71_Keyboard_Setup_v2.0_20231220.tmpC:\Program Files\AL71 Keyboard\unins000.exeexecutable
MD5:A405D85CD212167F00117411426385E2
SHA256:382818D063C2AEC7DA6A16D92F560FECCD3DE5A12DF93AA6D09F6ADC8DE54603
3772AL71_Keyboard_Setup_v2.0_20231220.tmpC:\Users\admin\AppData\Local\Temp\is-GIGIT.tmp\InitSetup.dllexecutable
MD5:3BB4A9FD05F14CC833291F7332565843
SHA256:72F5CFE575253EAFF31E27CE8F70B4CAAA079D2C42A4130515EECF7F0967115D
3772AL71_Keyboard_Setup_v2.0_20231220.tmpC:\Program Files\AL71 Keyboard\Cartoon\is-8BC9P.tmptext
MD5:DE7ED1FC8CDD4D96339B753B53C6A483
SHA256:C40425C75C0EA30FFC277C6E266AAC6D392116786E020FE6A614B92FD19D289F
3772AL71_Keyboard_Setup_v2.0_20231220.tmpC:\Program Files\AL71 Keyboard\Cartoon\fixon_unit.txttext
MD5:56944019D793CECCF18B55214DD3BC29
SHA256:DC512DC9659F157829F8878C904D47AF78AA96048BCAF5ADE8389CDFE11E83D2
3772AL71_Keyboard_Setup_v2.0_20231220.tmpC:\Program Files\AL71 Keyboard\Cartoon\breath_unit.txttext
MD5:DE7ED1FC8CDD4D96339B753B53C6A483
SHA256:C40425C75C0EA30FFC277C6E266AAC6D392116786E020FE6A614B92FD19D289F
3772AL71_Keyboard_Setup_v2.0_20231220.tmpC:\Program Files\AL71 Keyboard\Cartoon\is-S7E8S.tmptext
MD5:56944019D793CECCF18B55214DD3BC29
SHA256:DC512DC9659F157829F8878C904D47AF78AA96048BCAF5ADE8389CDFE11E83D2
3772AL71_Keyboard_Setup_v2.0_20231220.tmpC:\Program Files\AL71 Keyboard\Cartoon\flower_unit.txttext
MD5:ADF19B9B1C8CF06E276F560CFC703CD1
SHA256:E8ACE4319A670CAB1FECA8D04C60B6197FA9141F9732509199E75AE93A680135
3732AL71_Keyboard_Setup_v2.0_20231220.exeC:\Users\admin\AppData\Local\Temp\is-VIAJR.tmp\AL71_Keyboard_Setup_v2.0_20231220.tmpexecutable
MD5:AE4FFC736F84DE1C5BECB1680C27D046
SHA256:F0ED44C0988844A30F1B76D0DC035BF92F37936C0AAA7445F908D721CC4E5CA9
3772AL71_Keyboard_Setup_v2.0_20231220.tmpC:\Program Files\AL71 Keyboard\is-EPI91.tmpexecutable
MD5:A405D85CD212167F00117411426385E2
SHA256:382818D063C2AEC7DA6A16D92F560FECCD3DE5A12DF93AA6D09F6ADC8DE54603
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted

DNS requests

No data

Threats

No threats detected
Process
Message
AL71_Keyboard_Setup_v2.0_20231220.tmp
InitSetup: Remove Folder OK.