File name:

RazerSynapseInstaller_V1.7.0.311.exe

Full analysis: https://app.any.run/tasks/cba6181b-c0b1-471a-8bf9-df3b483795c0
Verdict: Malicious activity
Analysis date: July 29, 2022, 11:24:50
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (console) Intel 80386, for MS Windows
MD5:

493E1FE8E3168E53B58DCD99F783B5A7

SHA1:

2EDE2C91CFCD6938F62382146CA60A345385C629

SHA256:

B5DF03D01755296F9651A022917181576F5D7B88DDF6843CAE19274E2AC1EB6B

SSDEEP:

196608:S926iZrVG5Jf8H8zz8HQho6YViaNGvKGm64vn+x:uDEkf8czz848emvw

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • RazerSynapseInstaller_V1.7.0.311.exe (PID: 3888)
      • RazerInstaller.exe (PID: 1292)
      • RazerInstaller.exe (PID: 3020)
    • Application was dropped or rewritten from another process

      • RazerInstaller.exe (PID: 2532)
      • RazerInstaller.exe (PID: 1292)
      • RazerInstaller.exe (PID: 3020)
      • RazerInstaller.exe (PID: 1712)
    • Loads dropped or rewritten executable

      • RazerInstaller.exe (PID: 2532)
      • werfault.exe (PID: 3232)
      • RazerInstaller.exe (PID: 1712)
  • SUSPICIOUS

    • Reads the computer name

      • RazerInstaller.exe (PID: 1292)
      • RazerInstaller.exe (PID: 2532)
      • RazerInstaller.exe (PID: 3020)
      • RazerInstaller.exe (PID: 1712)
    • Reads Environment values

      • RazerInstaller.exe (PID: 2532)
      • werfault.exe (PID: 3232)
      • RazerInstaller.exe (PID: 1712)
    • Creates files in the program directory

      • RazerInstaller.exe (PID: 2532)
      • werfault.exe (PID: 3232)
    • Drops a file with a compile date too recent

      • RazerSynapseInstaller_V1.7.0.311.exe (PID: 3888)
      • RazerInstaller.exe (PID: 1292)
      • RazerInstaller.exe (PID: 3020)
    • Checks supported languages

      • RazerSynapseInstaller_V1.7.0.311.exe (PID: 3888)
      • RazerInstaller.exe (PID: 1292)
      • RazerInstaller.exe (PID: 2532)
      • RazerSynapseInstaller_V1.7.0.311.exe (PID: 2648)
      • notepad++.exe (PID: 864)
      • RazerSynapseInstaller_V1.7.0.311.exe (PID: 3324)
      • RazerInstaller.exe (PID: 3020)
      • RazerInstaller.exe (PID: 1712)
      • RazerSynapseInstaller_V1.7.0.311.exe (PID: 4044)
    • Executable content was dropped or overwritten

      • RazerSynapseInstaller_V1.7.0.311.exe (PID: 3888)
      • RazerInstaller.exe (PID: 1292)
      • RazerInstaller.exe (PID: 3020)
  • INFO

    • Checks Windows Trust Settings

      • RazerInstaller.exe (PID: 2532)
      • RazerInstaller.exe (PID: 1712)
    • Checks supported languages

      • WISPTIS.EXE (PID: 948)
      • werfault.exe (PID: 3232)
      • explorer.exe (PID: 920)
      • WISPTIS.EXE (PID: 3840)
    • Reads the computer name

      • WISPTIS.EXE (PID: 948)
      • explorer.exe (PID: 920)
      • werfault.exe (PID: 3232)
      • WISPTIS.EXE (PID: 3840)
    • Reads settings of System Certificates

      • RazerInstaller.exe (PID: 2532)
      • RazerInstaller.exe (PID: 1712)
    • Manual execution by user

      • explorer.exe (PID: 920)
      • RazerSynapseInstaller_V1.7.0.311.exe (PID: 2648)
      • notepad++.exe (PID: 864)
      • RazerSynapseInstaller_V1.7.0.311.exe (PID: 3980)
      • RazerSynapseInstaller_V1.7.0.311.exe (PID: 3324)
      • RazerSynapseInstaller_V1.7.0.311.exe (PID: 4044)
    • Dropped object may contain Bitcoin addresses

      • RazerInstaller.exe (PID: 1712)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

ProductVersion: 1.7.0.311
ProductName: Razer Installer
OriginalFileName: Razer Installer.exe
LegalCopyright: Copyright © 2022 Razer Inc. All rights reserved.
InternalName: Razer Installer.exe
FileVersion: 1.7.0.311
CompanyName: Razer Inc.
CharacterSet: Unicode
LanguageCode: English (U.S.)
FileSubtype: -
ObjectFileType: Executable application
FileOS: Windows NT 32-bit
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 1.7.0.311
FileVersionNumber: 1.7.0.311
Subsystem: Windows command line
SubsystemVersion: 6
ImageVersion: -
OSVersion: 6
EntryPoint: 0x98b3
UninitializedDataSize: -
InitializedDataSize: 7973888
CodeSize: 147968
LinkerVersion: 14
PEType: PE32
TimeStamp: 2022:06:02 07:09:20+02:00
MachineType: Intel 386 or later, and compatibles

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date: 02-Jun-2022 05:09:20
Detected languages:
  • English - United States
Debug artifacts:
  • C:\jenkins\workspace\CommonTools\RazerInstaller_Master\SafeExtractor\Release\SafeExtractor.pdb
CompanyName: Razer Inc.
FileVersion: 1.7.0.311
InternalName: Razer Installer.exe
LegalCopyright: Copyright © 2022 Razer Inc. All rights reserved.
OriginalFilename: Razer Installer.exe
ProductName: Razer Installer
ProductVersion: 1.7.0.311

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000110

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 7
Time date stamp: 02-Jun-2022 05:09:20
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x00024169
0x00024200
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.66376
.rdata
0x00026000
0x0000F8F6
0x0000FA00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.49675
.data
0x00036000
0x000020C0
0x00001200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
3.817
.gfids
0x00039000
0x00000288
0x00000400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
2.66182
.tls
0x0003A000
0x00000009
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0.0203931
.rsrc
0x0003B000
0x00786300
0x00786400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
7.91075
.reloc
0x007C2000
0x00002574
0x00002600
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
6.52673

Resources

Title
Entropy
Size
Codepage
Language
Type
1
4.89623
392
UNKNOWN
English - United States
RT_MANIFEST
2
2.96891
67624
UNKNOWN
English - United States
RT_ICON
3
3.07406
38056
UNKNOWN
English - United States
RT_ICON
4
3.16626
26600
UNKNOWN
English - United States
RT_ICON
5
3.20563
21640
UNKNOWN
English - United States
RT_ICON
6
3.54238
16936
UNKNOWN
English - United States
RT_ICON
7
3.59474
13032
UNKNOWN
English - United States
RT_ICON
8
3.65651
9640
UNKNOWN
English - United States
RT_ICON
9
3.46338
6760
UNKNOWN
English - United States
RT_ICON
10
3.4811
5512
UNKNOWN
English - United States
RT_ICON

Imports

KERNEL32.dll
SHELL32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
78
Monitored processes
17
Malicious processes
7
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start razersynapseinstaller_v1.7.0.311.exe razerinstaller.exe razerinstaller.exe wisptis.exe no specs wisptis.exe no specs explorer.exe no specs razersynapseinstaller_v1.7.0.311.exe no specs razersynapseinstaller_v1.7.0.311.exe notepad++.exe razersynapseinstaller_v1.7.0.311.exe werfault.exe razersynapseinstaller_v1.7.0.311.exe razerinstaller.exe razerinstaller.exe wisptis.exe no specs wisptis.exe no specs razersynapseinstaller_v1.7.0.311.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
864"C:\Program Files\Notepad++\notepad++.exe" "C:\Users\admin\AppData\Local\Temp\RazerSynapseInstaller_V1.7.0.311.err"C:\Program Files\Notepad++\notepad++.exe
Explorer.EXE
User:
admin
Company:
Don HO don.h@free.fr
Integrity Level:
MEDIUM
Description:
Notepad++ : a free (GNU) source code editor
Exit code:
0
Version:
7.91
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\program files\notepad++\notepad++.exe
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
920"C:\Windows\explorer.exe" C:\Windows\explorer.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
948"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\SYSTEM32\WISPTIS.EXERazerInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Exit code:
24
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wisptis.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
1292C:\Windows\Installer\Razer\Installer\RazerInstaller.exeC:\Windows\Installer\Razer\Installer\RazerInstaller.exe
RazerSynapseInstaller_V1.7.0.311.exe
User:
admin
Integrity Level:
HIGH
Description:
Razer Installer
Exit code:
3489660927
Version:
1.7.0.311
Modules
Images
c:\windows\installer\razer\installer\razerinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1712"C:\Windows\Installer\Razer\Installer\App\RazerInstaller.exe" C:\Windows\Installer\Razer\Installer\App\RazerInstaller.exe
RazerInstaller.exe
User:
admin
Company:
Razer Inc.
Integrity Level:
HIGH
Description:
RazerInstaller
Exit code:
0
Version:
1.7.0.311
Modules
Images
c:\windows\installer\razer\installer\app\razerinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1852"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\SYSTEM32\WISPTIS.EXERazerInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wisptis.exe
c:\windows\system32\ntdll.dll
2532"C:\Windows\Installer\Razer\Installer\App\RazerInstaller.exe" C:\Windows\Installer\Razer\Installer\App\RazerInstaller.exe
RazerInstaller.exe
User:
admin
Company:
Razer Inc.
Integrity Level:
HIGH
Description:
RazerInstaller
Exit code:
3489660927
Version:
1.7.0.311
Modules
Images
c:\windows\installer\razer\installer\app\razerinstaller.exe
c:\windows\system32\mscoree.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2648"C:\Users\admin\AppData\Local\Temp\RazerSynapseInstaller_V1.7.0.311.exe" C:\Users\admin\AppData\Local\Temp\RazerSynapseInstaller_V1.7.0.311.exe
Explorer.EXE
User:
admin
Company:
Razer Inc.
Integrity Level:
HIGH
Exit code:
4294967295
Version:
1.7.0.311
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\razersynapseinstaller_v1.7.0.311.exe
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3020C:\Windows\Installer\Razer\Installer\RazerInstaller.exeC:\Windows\Installer\Razer\Installer\RazerInstaller.exe
RazerSynapseInstaller_V1.7.0.311.exe
User:
admin
Integrity Level:
HIGH
Description:
Razer Installer
Exit code:
0
Version:
1.7.0.311
Modules
Images
c:\windows\installer\razer\installer\razerinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3036"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\SYSTEM32\WISPTIS.EXERazerInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\wisptis.exe
Total events
10 304
Read events
10 138
Write events
165
Delete events
1

Modification events

(PID) Process:(1292) RazerInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1292) RazerInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1292) RazerInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1292) RazerInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2532) RazerInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
RazerInstaller.exe
(PID) Process:(2532) RazerInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2532) RazerInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2532) RazerInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2532) RazerInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(948) WISPTIS.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
WISPTIS.EXE
Executable files
321
Suspicious files
4
Text files
54
Unknown types
1

Dropped files

PID
Process
Filename
Type
3888RazerSynapseInstaller_V1.7.0.311.exeC:\Windows\Installer\Razer\Installer\RazerInstaller.exeexecutable
MD5:
SHA256:
1292RazerInstaller.exeC:\Windows\Installer\Razer\Installer\App\api-ms-win-core-console-l1-1-0.dll.tmpexecutable
MD5:11E55839FCB3A53BDFED2A27FB7D5E80
SHA256:F6BDC8FFD172B44F4D169707D9A457AEEF619872661229B8629EE4F15EEFFF0D
1292RazerInstaller.exeC:\Windows\Installer\Razer\Installer\App\api-ms-win-core-console-l1-1-0.dllexecutable
MD5:11E55839FCB3A53BDFED2A27FB7D5E80
SHA256:F6BDC8FFD172B44F4D169707D9A457AEEF619872661229B8629EE4F15EEFFF0D
1292RazerInstaller.exeC:\Windows\Installer\Razer\Installer\App\api-ms-win-core-datetime-l1-1-0.dll.tmpexecutable
MD5:9F3CF9F22836C32D988D7C7E0A977E1B
SHA256:7D588A5A958E32875D7BD346D1371E6EBFD9D5D2EDE47755942BADFC9C74E207
1292RazerInstaller.exeC:\Windows\Installer\Razer\Installer\App\api-ms-win-core-datetime-l1-1-0.dllexecutable
MD5:9F3CF9F22836C32D988D7C7E0A977E1B
SHA256:7D588A5A958E32875D7BD346D1371E6EBFD9D5D2EDE47755942BADFC9C74E207
1292RazerInstaller.exeC:\Windows\Installer\Razer\Installer\App\api-ms-win-core-debug-l1-1-0.dll.tmpexecutable
MD5:64978E199A7239D2C911876447A7F05B
SHA256:92B947F1D6236F86ED7E105CFF19E23C13D1968861426511B775905E1D26B47A
1292RazerInstaller.exeC:\Windows\Installer\Razer\Installer\App\api-ms-win-core-debug-l1-1-0.dllexecutable
MD5:64978E199A7239D2C911876447A7F05B
SHA256:92B947F1D6236F86ED7E105CFF19E23C13D1968861426511B775905E1D26B47A
1292RazerInstaller.exeC:\Windows\Installer\Razer\Installer\App\api-ms-win-core-file-l1-1-0.dll.tmpexecutable
MD5:D826D27C73D9F2420FB39FBE0745C7F0
SHA256:C0E5D482BD93BF71A73C01D0C1EC0722EA3260EBA1F4C87E797BAE334B5E9870
1292RazerInstaller.exeC:\Windows\Installer\Razer\Installer\App\api-ms-win-core-file-l1-1-0.dllexecutable
MD5:D826D27C73D9F2420FB39FBE0745C7F0
SHA256:C0E5D482BD93BF71A73C01D0C1EC0722EA3260EBA1F4C87E797BAE334B5E9870
1292RazerInstaller.exeC:\Windows\Installer\Razer\Installer\App\api-ms-win-core-heap-l1-1-0.dllexecutable
MD5:EE5C2FB7BC23BFD06FF32556CC7C3B4D
SHA256:EFC9F0E32BCE971900DDF66A1A9E68DAA3BFB2099A1BA9F24C6EE82DA2CBD6E8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
17
TCP/UDP connections
26
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1712
RazerInstaller.exe
HEAD
301
23.48.23.32:80
http://assets2.razerzone.com/images/razer-synapse/light_chroma_studio.png
US
whitelisted
1712
RazerInstaller.exe
HEAD
301
23.48.23.32:80
http://assets2.razerzone.com/images/razer-synapse/dark_chroma_studio.png
US
whitelisted
1712
RazerInstaller.exe
GET
301
23.48.23.32:80
http://assets2.razerzone.com/images/razer-synapse/light_chroma_studio.png
US
whitelisted
1712
RazerInstaller.exe
GET
301
23.48.23.32:80
http://assets2.razerzone.com/images/razer-synapse/lifestyle_chroma_studio.png
US
whitelisted
1712
RazerInstaller.exe
HEAD
301
23.48.23.32:80
http://assets2.razerzone.com/images/razer-synapse/lifestyle_macros.png
US
whitelisted
1712
RazerInstaller.exe
GET
301
23.48.23.32:80
http://assets2.razerzone.com/images/razer-synapse/dark_macros.png
US
whitelisted
1712
RazerInstaller.exe
GET
301
23.48.23.32:80
http://assets2.razerzone.com/images/razer-synapse/light_macros.png
US
whitelisted
1712
RazerInstaller.exe
GET
301
23.48.23.32:80
http://assets2.razerzone.com/images/razer-synapse/dark_chroma_studio.png
US
whitelisted
1712
RazerInstaller.exe
HEAD
301
23.48.23.32:80
http://assets2.razerzone.com/images/razer-synapse/dark_macros.png
US
whitelisted
1712
RazerInstaller.exe
GET
301
23.48.23.32:80
http://assets2.razerzone.com/images/razer-synapse/lifestyle_macros.png
US
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2532
RazerInstaller.exe
23.48.23.8:443
manifest.razerapi.com
TRUE INTERNET Co.,Ltd.
US
suspicious
3232
werfault.exe
20.189.173.20:443
watson.microsoft.com
Microsoft Corporation
US
suspicious
1712
RazerInstaller.exe
23.48.23.31:443
discovery.razerapi.com
TRUE INTERNET Co.,Ltd.
US
suspicious
2532
RazerInstaller.exe
23.48.23.5:443
manifest.razerapi.com
TRUE INTERNET Co.,Ltd.
US
suspicious
1712
RazerInstaller.exe
23.48.23.5:443
manifest.razerapi.com
TRUE INTERNET Co.,Ltd.
US
suspicious
1712
RazerInstaller.exe
23.48.23.38:443
synapse-3-webservice.razerzone.com
TRUE INTERNET Co.,Ltd.
US
suspicious
1712
RazerInstaller.exe
23.48.23.11:443
cdn.razersynapse.com
TRUE INTERNET Co.,Ltd.
US
suspicious
1712
RazerInstaller.exe
23.48.23.32:443
assets2.razerzone.com
TRUE INTERNET Co.,Ltd.
US
suspicious
2532
RazerInstaller.exe
23.48.23.61:443
discovery.razerapi.com
TRUE INTERNET Co.,Ltd.
US
suspicious
23.48.23.46:443
assets.razerzone.com
TRUE INTERNET Co.,Ltd.
US
suspicious

DNS requests

Domain
IP
Reputation
discovery.razerapi.com
  • 23.48.23.61
  • 23.48.23.31
suspicious
synapse-3-webservice.razerzone.com
  • 23.48.23.35
  • 23.48.23.38
suspicious
manifest.razerapi.com
  • 23.48.23.8
  • 23.48.23.5
malicious
ctldl.windowsupdate.com
  • 8.249.61.254
  • 8.241.45.126
  • 8.249.63.254
  • 8.238.176.254
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared
watson.microsoft.com
  • 20.189.173.20
whitelisted
cdn.razersynapse.com
  • 23.48.23.11
  • 23.48.23.7
whitelisted
assets.razerzone.com
  • 23.48.23.46
  • 23.48.23.24
whitelisted
assets2.razerzone.com
  • 23.48.23.32
  • 23.48.23.64
whitelisted

Threats

No threats detected
Process
Message
RazerInstaller.exe
RzKitty: DetectManager()
RazerInstaller.exe
RzKitty: hWnd ok
RazerInstaller.exe
log4net:ERROR Could not create Appender [RollingLogFileAppender] of type [log4net.Appender.RollingFileAppender,log4net]. Reported error follows.
RazerInstaller.exe
System.InvalidCastException: Unable to cast object of type 'log4net.Appender.RollingFileAppender' to type 'log4net.Appender.IAppender'. at log4net.Repository.Hierarchy.XmlHierarchyConfigurator.ParseAppender(XmlElement appenderElement)
RazerInstaller.exe
log4net:ERROR Appender named [RollingLogFileAppender] not found.
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\SciLexer.dll
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\updater\gup.exe
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled