File name:

RzS3WizardPkgS3.exe

Full analysis: https://app.any.run/tasks/750b17f9-0ddb-4c71-bb5b-422ebbca7eb7
Verdict: Malicious activity
Analysis date: November 16, 2021, 06:03:23
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

063403DF1277ECC9ABD38DE3FF7BC9AF

SHA1:

D56053BFBEFDF7A69AA177F89F79ED687EF72E1B

SHA256:

FFBAD9333B728D25D9E6F86BCAED18CEB4F22FC9074A1D014C83776365879457

SSDEEP:

98304:wQV3hyxJmVO0kHskzhBO4db0ABfkGm+fdwB3A4KSsokcDlY2JXkFluPlSi7SPkh9:wK3ExJmIlzO4pbsGm0wBQ4fLLBPIujQg

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • RazerSynapseInstaller_ProdDiscoveryEndpoint.exe (PID: 2296)
      • RazerInstaller.exe (PID: 2056)
    • Changes the autorun value in the registry

      • RzS3WizardPkgS3.exe (PID: 3720)
    • Loads dropped or rewritten executable

      • RzS3WizardPkgS3.exe (PID: 3720)
      • RazerInstaller.exe (PID: 2576)
    • Application was dropped or rewritten from another process

      • RazerSynapseInstaller_ProdDiscoveryEndpoint.exe (PID: 2296)
      • RazerInstaller.exe (PID: 2056)
      • RazerInstaller.exe (PID: 2576)
  • SUSPICIOUS

    • Creates files in the program directory

      • RzS3WizardPkgS3.exe (PID: 3720)
      • RazerInstaller.exe (PID: 2576)
    • Drops a file that was compiled in debug mode

      • RzS3WizardPkgS3.exe (PID: 3720)
      • RazerInstaller.exe (PID: 2056)
    • Checks supported languages

      • RazerSynapseInstaller_ProdDiscoveryEndpoint.exe (PID: 2296)
      • RzS3WizardPkgS3.exe (PID: 3720)
      • nsD3BF.tmp (PID: 3384)
      • RazerInstaller.exe (PID: 2056)
      • RazerInstaller.exe (PID: 2576)
    • Reads the computer name

      • RzS3WizardPkgS3.exe (PID: 3720)
      • RazerInstaller.exe (PID: 2056)
      • RazerInstaller.exe (PID: 2576)
    • Executable content was dropped or overwritten

      • RzS3WizardPkgS3.exe (PID: 3720)
      • RazerSynapseInstaller_ProdDiscoveryEndpoint.exe (PID: 2296)
      • RazerInstaller.exe (PID: 2576)
      • RazerInstaller.exe (PID: 2056)
    • Creates a directory in Program Files

      • RzS3WizardPkgS3.exe (PID: 3720)
    • Starts application with an unusual extension

      • RzS3WizardPkgS3.exe (PID: 3720)
    • Drops a file with a compile date too recent

      • RazerInstaller.exe (PID: 2056)
    • Drops a file with too old compile date

      • RazerInstaller.exe (PID: 2056)
    • Reads Environment values

      • RazerInstaller.exe (PID: 2576)
  • INFO

    • Checks supported languages

      • WISPTIS.EXE (PID: 2240)
    • Reads the computer name

      • WISPTIS.EXE (PID: 2240)
    • Dropped object may contain Bitcoin addresses

      • RazerInstaller.exe (PID: 2576)
    • Reads settings of System Certificates

      • RazerInstaller.exe (PID: 2576)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:07:25 00:17:55+02:00
PEType: PE32
LinkerVersion: 6
CodeSize: 26112
InitializedDataSize: 141824
UninitializedDataSize: 2048
EntryPoint: 0x348f
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.2.0.36
ProductVersionNumber: 1.2.0.36
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: MiniInstaller for Razer Windows S3 Update
CompanyName: Razer Inc.
FileDescription: Razer S3 Wizard Package
FileVersion: 1.2.0.36
InternalName: Razer S3 Wizard Package
LegalCopyright: Copyright © 2021 Razer Inc. All rights reserved
OriginalFileName: RzS3WizardPkgS3.exe
ProductName: Razer S3 Wizard Package
ProductVersion: 1.2.0.36

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 24-Jul-2021 22:17:55
Detected languages:
  • English - United States
Comments: MiniInstaller for Razer Windows S3 Update
CompanyName: Razer Inc.
FileDescription: Razer S3 Wizard Package
FileVersion: 1.2.0.36
InternalName: Razer S3 Wizard Package
LegalCopyright: Copyright © 2021 Razer Inc. All rights reserved
OriginalFilename: RzS3WizardPkgS3.exe
ProductName: Razer S3 Wizard Package
ProductVersion: 1.2.0.36

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000D8

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 5
Time date stamp: 24-Jul-2021 22:17:55
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x00006411
0x00006600
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.40243
.rdata
0x00008000
0x00001398
0x00001400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.13775
.data
0x0000A000
0x00020338
0x00000600
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.0208
.ndata
0x0002B000
0x00010000
0x00000000
IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0
.rsrc
0x0003B000
0x00000BE0
0x00000C00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.59745

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.28908
841
UNKNOWN
English - United States
RT_MANIFEST
103
2.16096
20
UNKNOWN
English - United States
RT_GROUP_ICON
111
2.48825
96
UNKNOWN
English - United States
RT_DIALOG

Imports

ADVAPI32.dll
COMCTL32.dll
GDI32.dll
KERNEL32.dll
SHELL32.dll
USER32.dll
ole32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
8
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start drop and start rzs3wizardpkgs3.exe nsd3bf.tmp no specs razersynapseinstaller_proddiscoveryendpoint.exe razerinstaller.exe razerinstaller.exe wisptis.exe no specs wisptis.exe no specs rzs3wizardpkgs3.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2056C:\Windows\Installer\Razer\Installer\RazerInstaller.exe -c /showdeviceC:\Windows\Installer\Razer\Installer\RazerInstaller.exe
RazerSynapseInstaller_ProdDiscoveryEndpoint.exe
User:
admin
Integrity Level:
HIGH
Description:
Razer Installer
Exit code:
0
Version:
1.0.150.988
Modules
Images
c:\windows\installer\razer\installer\razerinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\sechost.dll
2240"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\SYSTEM32\WISPTIS.EXERazerInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Exit code:
24
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wisptis.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
2296"C:\Program Files\Razer\RzS3WizardS3\RazerSynapseInstaller_ProdDiscoveryEndpoint.exe" -c /showdeviceC:\Program Files\Razer\RzS3WizardS3\RazerSynapseInstaller_ProdDiscoveryEndpoint.exe
nsD3BF.tmp
User:
admin
Company:
Razer Inc.
Integrity Level:
HIGH
Exit code:
0
Version:
1.0.150.988
Modules
Images
c:\program files\razer\rzs3wizards3\razersynapseinstaller_proddiscoveryendpoint.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2576"C:\Windows\Installer\Razer\Installer\App\RazerInstaller.exe" /showdeviceC:\Windows\Installer\Razer\Installer\App\RazerInstaller.exe
RazerInstaller.exe
User:
admin
Company:
Razer Inc.
Integrity Level:
HIGH
Description:
RazerInstaller
Exit code:
0
Version:
1.0.150.988
Modules
Images
c:\windows\installer\razer\installer\app\razerinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3036"C:\Users\admin\AppData\Local\Temp\RzS3WizardPkgS3.exe" C:\Users\admin\AppData\Local\Temp\RzS3WizardPkgS3.exeExplorer.EXE
User:
admin
Company:
Razer Inc.
Integrity Level:
MEDIUM
Description:
Razer S3 Wizard Package
Exit code:
3221226540
Version:
1.2.0.36
Modules
Images
c:\users\admin\appdata\local\temp\rzs3wizardpkgs3.exe
c:\windows\system32\ntdll.dll
3072"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\SYSTEM32\WISPTIS.EXERazerInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wisptis.exe
c:\windows\system32\ntdll.dll
3384"C:\Users\admin\AppData\Local\Temp\nsbD3AE.tmp\nsD3BF.tmp" C:\Program Files\Razer\RzS3WizardS3\RazerSynapseInstaller_ProdDiscoveryEndpoint.exe -c /showdeviceC:\Users\admin\AppData\Local\Temp\nsbD3AE.tmp\nsD3BF.tmpRzS3WizardPkgS3.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsbd3ae.tmp\nsd3bf.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3720"C:\Users\admin\AppData\Local\Temp\RzS3WizardPkgS3.exe" C:\Users\admin\AppData\Local\Temp\RzS3WizardPkgS3.exe
Explorer.EXE
User:
admin
Company:
Razer Inc.
Integrity Level:
HIGH
Description:
Razer S3 Wizard Package
Exit code:
2
Version:
1.2.0.36
Modules
Images
c:\users\admin\appdata\local\temp\rzs3wizardpkgs3.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
Total events
4 866
Read events
4 756
Write events
109
Delete events
1

Modification events

(PID) Process:(3720) RzS3WizardPkgS3.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Operation:writeName:CleanUp RzS3Wizard
Value:
C:\Program Files\Razer\RzS3WizardS3\RzInstallerDeletionS3.vbs
(PID) Process:(2056) RazerInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2056) RazerInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2056) RazerInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2056) RazerInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2576) RazerInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
RazerInstaller.exe
(PID) Process:(2576) RazerInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2576) RazerInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2576) RazerInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2576) RazerInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
134
Suspicious files
0
Text files
40
Unknown types
0

Dropped files

PID
Process
Filename
Type
2296RazerSynapseInstaller_ProdDiscoveryEndpoint.exeC:\Windows\Installer\Razer\Installer\RazerInstaller.exeexecutable
MD5:
SHA256:
2056RazerInstaller.exeC:\Windows\Installer\Razer\Installer\App\api-ms-win-core-console-l1-1-0.dll.tmpexecutable
MD5:11E55839FCB3A53BDFED2A27FB7D5E80
SHA256:F6BDC8FFD172B44F4D169707D9A457AEEF619872661229B8629EE4F15EEFFF0D
3720RzS3WizardPkgS3.exeC:\Program Files\Razer\RzS3WizardS3\RzInstallerDeletionS3.vbstext
MD5:B226D0CDAB125BF26AC90F983154D8EB
SHA256:E66A7F022DD9271EE2010DC4FBF64D5B7BF4FAF87F314539E6BBAD7C9EBC3A5B
2056RazerInstaller.exeC:\Windows\Installer\Razer\Installer\App\api-ms-win-core-file-l1-1-0.dllexecutable
MD5:D826D27C73D9F2420FB39FBE0745C7F0
SHA256:C0E5D482BD93BF71A73C01D0C1EC0722EA3260EBA1F4C87E797BAE334B5E9870
2056RazerInstaller.exeC:\Windows\Installer\Razer\Installer\App\api-ms-win-core-datetime-l1-1-0.dllexecutable
MD5:9F3CF9F22836C32D988D7C7E0A977E1B
SHA256:7D588A5A958E32875D7BD346D1371E6EBFD9D5D2EDE47755942BADFC9C74E207
2056RazerInstaller.exeC:\Windows\Installer\Razer\Installer\App\api-ms-win-core-errorhandling-l1-1-0.dllexecutable
MD5:9D74D89F2679C0C5DDB35A1EF30BD182
SHA256:E207FFC6FEF144E5D393E79DE75F8F20D223F1AC33A011EEB822D30FA2031046
2056RazerInstaller.exeC:\Windows\Installer\Razer\Installer\App\api-ms-win-core-debug-l1-1-0.dll.tmpexecutable
MD5:64978E199A7239D2C911876447A7F05B
SHA256:92B947F1D6236F86ED7E105CFF19E23C13D1968861426511B775905E1D26B47A
2056RazerInstaller.exeC:\Windows\Installer\Razer\Installer\App\api-ms-win-core-datetime-l1-1-0.dll.tmpexecutable
MD5:9F3CF9F22836C32D988D7C7E0A977E1B
SHA256:7D588A5A958E32875D7BD346D1371E6EBFD9D5D2EDE47755942BADFC9C74E207
2056RazerInstaller.exeC:\Windows\Installer\Razer\Installer\App\api-ms-win-core-errorhandling-l1-1-0.dll.tmpexecutable
MD5:9D74D89F2679C0C5DDB35A1EF30BD182
SHA256:E207FFC6FEF144E5D393E79DE75F8F20D223F1AC33A011EEB822D30FA2031046
2056RazerInstaller.exeC:\Windows\Installer\Razer\Installer\App\api-ms-win-core-file-l1-2-0.dll.tmpexecutable
MD5:EC4F2CB68DCF7E96516EB284003BE8BB
SHA256:3816BBB7DD76D8FC6A7B83A0ED2F61B23DD5FC0843D3308EE077CB725D5C9088
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
22
DNS requests
10
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2576
RazerInstaller.exe
GET
301
2.16.107.98:80
http://assets2.razerzone.com/images/razer-synapse/dark_macros.png
unknown
whitelisted
2576
RazerInstaller.exe
HEAD
301
2.16.107.98:80
http://assets2.razerzone.com/images/razer-synapse/dark_chroma_studio.png
unknown
whitelisted
2576
RazerInstaller.exe
HEAD
301
2.16.107.98:80
http://assets2.razerzone.com/images/razer-synapse/dark_macros.png
unknown
whitelisted
2576
RazerInstaller.exe
GET
301
2.16.107.98:80
http://assets2.razerzone.com/images/razer-synapse/dark_chroma_studio.png
unknown
whitelisted
2576
RazerInstaller.exe
HEAD
301
2.16.107.98:80
http://assets2.razerzone.com/images/razer-synapse/light_chroma_studio.png
unknown
whitelisted
2576
RazerInstaller.exe
HEAD
301
2.16.107.98:80
http://assets2.razerzone.com/images/razer-synapse/lifestyle_macros.png
unknown
whitelisted
2576
RazerInstaller.exe
GET
301
2.16.107.98:80
http://assets2.razerzone.com/images/razer-synapse/light_chroma_studio.png
unknown
whitelisted
2576
RazerInstaller.exe
HEAD
301
2.16.107.98:80
http://assets2.razerzone.com/images/razer-synapse/light_macros.png
unknown
whitelisted
2576
RazerInstaller.exe
GET
301
2.16.107.98:80
http://assets2.razerzone.com/images/razer-synapse/dark_chroma_studio.png
unknown
whitelisted
2576
RazerInstaller.exe
GET
301
2.16.107.98:80
http://assets2.razerzone.com/images/razer-synapse/lifestyle_macros.png
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2576
RazerInstaller.exe
2.16.107.67:443
manifest.razerapi.com
Akamai International B.V.
whitelisted
2576
RazerInstaller.exe
2.16.107.51:443
cdn.razersynapse.com
Akamai International B.V.
suspicious
2576
RazerInstaller.exe
2.16.107.121:443
assets.razerzone.com
Akamai International B.V.
suspicious
2576
RazerInstaller.exe
2.16.107.98:443
assets2.razerzone.com
Akamai International B.V.
suspicious
2576
RazerInstaller.exe
2.16.107.98:80
assets2.razerzone.com
Akamai International B.V.
suspicious
2576
RazerInstaller.exe
2.16.107.50:443
assets.razerzone.com
Akamai International B.V.
suspicious
2576
RazerInstaller.exe
2.16.107.16:443
discovery.razerapi.com
Akamai International B.V.
suspicious
2576
RazerInstaller.exe
52.216.24.180:443
albedozero.s3.amazonaws.com
Amazon.com, Inc.
US
unknown
2576
RazerInstaller.exe
2.16.107.89:80
assets2.razerzone.com
Akamai International B.V.
suspicious
2576
RazerInstaller.exe
34.206.134.70:443
albedozero.razerapi.com
Amazon.com, Inc.
US
unknown

DNS requests

Domain
IP
Reputation
discovery.razerapi.com
  • 2.16.107.16
  • 2.16.107.17
suspicious
manifest.razerapi.com
  • 2.16.107.67
  • 2.16.107.104
malicious
cdn.razersynapse.com
  • 2.16.107.51
  • 2.16.107.10
whitelisted
assets.razerzone.com
  • 2.16.107.121
  • 2.16.107.50
whitelisted
assets2.razerzone.com
  • 2.16.107.98
  • 2.16.107.89
whitelisted
deals-assets-cdn.razerzone.com
  • 2.16.107.50
  • 2.16.107.35
whitelisted
albedozero.razerapi.com
  • 34.206.134.70
  • 52.206.176.62
  • 3.211.22.204
  • 34.239.90.110
  • 52.5.230.37
  • 34.201.195.122
  • 34.197.78.128
  • 54.86.120.132
unknown
albedozero.s3.amazonaws.com
  • 52.216.24.180
unknown

Threats

No threats detected
Process
Message
RazerInstaller.exe
RzKitty: DetectManager()
RazerInstaller.exe
RzKitty: hWnd ok
RazerInstaller.exe
RzKitty: RegisterDevNotify ok
RazerInstaller.exe
RzKitty: EnumBTLEAudioDevices start
RazerInstaller.exe
RzKitty: EnumBTLEAudioDevices done
RazerInstaller.exe
RzKitty: DetectMgr done
RazerInstaller.exe
log4net:ERROR XmlHierarchyConfigurator: Could not create Appender [RollingLogFileAppender] of type [log4net.Appender.RollingFileAppender,log4net]. Reported error follows.
RazerInstaller.exe
System.InvalidCastException: Unable to cast object of type 'log4net.Appender.RollingFileAppender' to type 'log4net.Appender.IAppender'. at log4net.Repository.Hierarchy.XmlHierarchyConfigurator.ParseAppender(XmlElement appenderElement)
RazerInstaller.exe
log4net:ERROR XmlHierarchyConfigurator: Appender named [RollingLogFileAppender] not found.