Static | ZeroBOX

PE Compile Time

2090-02-16 01:26:39

PDB Path

C:\Users\Administrator\Desktop\razgon.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000057d4 0x00005800 6.10317111676
.rsrc 0x00008000 0x00039964 0x00039a00 3.90644163261
.reloc 0x00042000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00040cc4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00040cc4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00040cc4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00040cc4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00040cc4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00040cc4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00040cc4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00040cc4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00040cc4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00040cc4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00040cc4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00040cc4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00040cc4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00040cc4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0004112c 0x000000ca LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000411f8 0x0000037c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00041574 0x000003ed LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
.a3B Ja3Ba
.a3B ja3Ba
ZsW[ /sW[a
YgK> >gK>a
)Ou 8)Oua
nwI%
^1Xp p1Xpa
s5Y ub
w Ui??Yf +
s5Y ub
!a QO/
b MrrXa
;BZ
maf Q+
GXf hL
"Jk9
;BZ
!a QO/
X o&a0a
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
v4.0.30319
#Strings
IEnumerable`1
List`1
Func`2
WindowsFormsApp36
<Module>
DisableEventsPARAMFLAGFHASCUSTDATA
INVOCATIONFLAGSCONTAINSSTACKPOINTERSHASHVALUE
setNaNSymbolInternalMemberTypeE
DeferredDisposableLifetimeCOREREMOTING
IActivatorUI
WrappedExceptionI
getFieldNamesVTBOOL
dRK9+qqbHTWVsptnSEbG6Wg1uTM
ThrowIfCancellationRequestedCMSUSAGEPATTERN
System.IO
AssemblyTitleAttributeIMPDEFAULT
GetFilesetIV
GetDomainX
MethodOnTypeBuilderInstantiationNULLPUBLICKEY
GetCultureInfoByIetfLanguageTaggetQuota
mscorlib
System.Collections.Generic
AllocCoTaskMemWaitAsync
IsCurrentActivityActiveSetCreationTimeUtc
get_Id
SEPDateOrOffsetGetVarIndexOfMemId
Thread
IMessageVersionAdded
getStatusIsSealed
KeyValuePairComparatorgetIsEnabled
GetArgumentsetIsSecured
PinnedBufferMemoryStreamMarkUsed
get_Elapsed
ScheduledExclusivewReserved
Synchronized
DefaultInterfaceAttributeIsInvalid
ContinuationTaskgetImplementedClsid
StringToHGlobalAutoNewGuid
CreatePermissionField
DispatchExceptionRemoveAtEnd
set_IsBackground
GetMethod
GetDeploymentPropertygetHardwareDevice
TranslateIObjectReference
ThaiBuddhistEraGetHashCode
AlwaysMode
getConstructionExceptionUIFamilyCodePage
UIContextGetReplyMessage
AddRange
Invoke
Enumerable
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
FlushWriteAsyncdGetHashFromHandle
SetterRuntimeArgumentHandle
DefineGlobalMethodStageComponentFile
FUNCDISPATCHGetHashFromAssemblyFile
Console
set_WindowStyle
ProcessWindowStyle
get_Name
set_FileName
CallConvStdcallgetFrameworkName
get_FullName
FromOADateIAssemblyName
getSetActorAsReferenceWhenCopyingClaimsIdentitySurname
getFeatureManageVolume
WriteLine
NativeCalendarNamegetScope
getInvariantCulturegetXsdType
getLockedAuditRuleType
ValueType
TimeSpanIsInstanceOfType
get_DeclaringType
SecurityProtocolType
VTDISPATCHsetExceptionType
TripleDESsetProviderType
System.Core
CreationTimeFailIgnore
get_Culture
set_Culture
ToFileTimeCurrentCulture
MethodBase
ApplicationSettingsBase
AlgorithmTypeOptimizeDefaultCase
Dispose
IdentityReferenceTimeSpanParse
Reverse
setPMDesignatorgetAsDate
CngAlgorithmIDSurrogate
SafeSerializationEventArgsAddSerializedState
EditorBrowsableState
getOutputEncodingTristate
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
HasElementTypeAssemblyTargetedPatchBandAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
ChunkNumberIsByRefLikeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
SpinCountStructLayoutAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
WriteByte
AsyncCausalityOperationgetHasValue
AccessDeniedCallbackObjectgetReferenceCountValue
razgon.exe
CommonProgramFilesXTrimToSize
ScavengeSetBufferSize
GetRuntimeBaseDefinitiongetIsParamDef
getOaepSHACompatibilityFlag
DependentOSMetadataMinorVersionPreserveSig
System.Threading
getHandlerOffsetISCIIEncoding
SingleDomaingetCurrentEncoding
System.Runtime.Versioning
EventResetModeMuiMapping
EnumerateFileSystemInfosResourceTypeIdString
SetWinContextInIDispatchAttributeMakeString
ContractAbbreviatorAttributeCompleting
getIsReadyOpenExisting
Stopwatch
setChildrenSetCachePath
get_ExecutablePath
ReadOnlyDictionaryValueEnumeratorsetWindowWidth
CMSASSEMBLYDEPLOYMENTFLAGBEFOREAPPLICATIONSTARTUPPtrToStringUni
setCurrencyPositivePatternIClientChannelSinkStack
InTypeCountMaskSink
outStringBuilderStackBuilderSink
UnsafeDeserializeNormal
GetFactorySuppliedEvidenceIsVirtual
System.ComponentModel
getRenewOnCallTimeCountedMbcsXml
CriticalHandleZeroOrMinusOneIsInvalidHashElementXml
set_SecurityProtocol
CMSFILEHASHALGORITHMMDCustomPropertyImpl
MemoryStream
Program
AddPermissionGetCelestialStem
System
KeysNormalizedgetAlgorithm
optionsHasClaim
Random
ErrorImportAsItanium
CategoryMembershipEntryFieldIdgetNewEnum
TimeSpan
LunisolarCalendarTimeZoneToken
OnePermissionToken
EmptyCAHolderremoveEventWritten
SetterKerbSmartCardLogon
razgon
DecrementRevision
ISecurityEncodableMinorVersion
getExecutionsetSkipVerification
Application
System.Configuration
System.Globalization
System.Reflection
AsUintSafeArrayRankMismatchException
ClassesRootContextMarshalException
getCustomAttributeEncodedArgumentTargetException
ArraysetDigitSubstitution
MethodInfo
EnqueueTimeZoneInfo
AccessRightTypesetCultureInfo
MemberInfo
ProcessStartInfo
AccessDeniedCallbackEphemerisCorrectionAlgorithmMap
GetItemSep
getCurrentSizeRecordArrayElementFixup
System.Linq
ReadBlockAsyncopExclusiveOr
ContextInlineLunarCalendar
FileIOPermissionStar
LoaderInformationgetFormatJapaneseFirstYearAsANumber
AnsiBSTRMarshalerSerializedStreamHeader
Binder
get_ResourceManager
PARAMFLAGNONEResourceFallbackManager
ServicePointManager
System.CodeDom.Compiler
ResumedEditAndContinueHelper
OneWayAttributeEnumHelper
StlocSArgMapper
getArrayValueDelegateWrapper
ObjectUrtTaskAwaiter
JapaneseCalendarResourceWriter
AccountComputersSidPositionPointer
ScrollLockOnBitConverter
WriteIntPtrconverter
ResourceTableMappingFinalStringMappedCultureNameResourceSetPair
RawEvidenceEnumeratorFor
StrongNameKeyInstallSymLanguageVendor
WindowsFormsApp36.MarkUsedConsoleColor
FirstPMDesignator
.cctor
ControlCDelegateDatagetIsConstructor
DetachablesetEventHandleIntPtr
ConvertTimeBySystemTimeZoneIdLPTStr
System.Diagnostics
InitialTasksFlowActivityIds
get_TotalSeconds
GetMethods
bodyWithEverythingFromEventKeywords
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
WindowsFormsApp36.Properties.Resources.resources
DebuggingModes
GetFunctionPointerForDelegategetShadowCopyDirectories
WindowsFormsApp36.Properties
setAppDomainManagerAssemblyContingentProperties
GetExportedTypes
InteropTotalMinutes
VectorToListAdapterDeriveBytes
NextBytes
BindingFlags
GetObjectParamAllFlags
WindowsBuiltInRoleAssemblyLoadEventArgs
TokenRestrictedDeviceClaimAttributesITracingStatusChangedEventArgs
System.Windows.Forms
methodInfos
DnsCreateAnySchemeAccess
IsAmbiguousTimeRegistryPermissionAccess
GetCurrentProcess
getClipboardsetNativeDigits
DGetDocuments
set_Arguments
getTypeInformationIsAnonymous
AppendWrapNonExceptionThrows
Concat
SystemAclAutoInheritedSystemAuditCallbackObject
ControlAppDomainThreadPoolEnqueueWorkObject
System.Net
ToFourDigitYearsetDefaultGrantSet
get_Default
FirstOrDefault
WebClient
actionCallElement
OpenWriteCleanupWorkListElement
SetObservedSecurityDocument
IsUnknownSurrogateGetCurrent
GetEnumValuesScheduledConcurrent
ReportEventIsEvent
OrdinalgetSpinCount
SetTraitsSyncRoot
ThreadStart
IMonikerRest
IsServerGCText
PropertiesgetIllogicalCallContext
BadSignatureIApplicationContext
NotationAppContext
HasCreationContextHostContext
IsCompatibilitySwitchSetgetUtcNow
SubscribeCodePageIndex
getIsBitProcessstartIndex
ParseMonday
get_Assembly
WindowsFormsApp36.IOCompletionCallbackDeclaredOnly
SynchronizationLockExceptionVisibleOnly
FallbackBufferEnsureByteCapacity
op_Equality
op_Inequality
UnauthenticatedPrincipalsetPriority
GetClassIDHasSecurity
ObjectCreationDelegateCommonObjectSecurity
TypeBuilderInstantiationIsDirty
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
1Copyright
2021 Razer Inc. All rights reserved.
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
1.0.191.235
$85358bc8-870c-45d4-99c3-f0e536ae69c4
WrapNonExceptionThrows
Razer Inc.
Razer Installer
C:\Users\Administrator\Desktop\razgon.pdb
_CorExeMain
mscoree.dll
dblH>o
5+,9;@v
}U(?@h
~/@hwm
k(A1lc
Yl/uDue
i6|+Evc
ei:<_'
)|JS4h
#h8HU
.Y[0YB
2be?/]r
{MqnV`
GLR/Zb
CA&DoWX
Rj>*?2;w~l8H'Pd
l6}/=n
[Y+_j
s(AXtJ>
m^K1]|+D
Ul17|3E
{i%Yvq
uU*a1x
}^K!)L
z HM3p
,l<;E*.
\ZyY$#
SVtBV`
cfC*Q^
$$)IUu
=7d0{m
+0g>`I
<?xml version="1.0" encoding="utf-8"?>
<assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
</requestedPrivileges>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}" />
</application>
</compatibility>
<application xmlns="urn:schemas-microsoft-com:asm.v3">
<windowsSettings>
<dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
<longPathAware xmlns="http://schemas.microsoft.com/SMI/2016/WindowsSettings">true</longPathAware>
</windowsSettings>
</application>
</assembly>
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
131022120000Z
281022120000Z0r1
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Code Signing CA0
p1f3q>
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
4http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0O
https://www.digicert.com/CPS0
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Code Signing CA0
200611000000Z
210702120000Z0}1
Washington1
Bellevue1"0
Skylum Software USA, Inc.1"0
Skylum Software USA, Inc.0
/http://crl3.digicert.com/sha2-assured-cs-g1.crl05
/http://crl4.digicert.com/sha2-assured-cs-g1.crl0L
https://www.digicert.com/CPS0
http://ocsp.digicert.com0N
Bhttp://cacerts.digicert.com/DigiCertSHA2AssuredIDCodeSigningCA.crt0
t \XJp
New Jersey1
Jersey City1
The USERTRUST Network1.0,
%USERTrust RSA Certification Authority0
190502000000Z
380118235959Z0}1
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA0
?http://crl.usertrust.com/USERTrustRSACertificationAuthority.crl0v
3http://crt.usertrust.com/USERTrustRSAAddTrustCA.crt0%
http://ocsp.usertrust.com0
rRj;B7|
[C]e=P
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA0
201023000000Z
320122235959Z0
Greater Manchester1
Salford1
Sectigo Limited1,0*
#Sectigo RSA Time Stamping Signer #20
https://sectigo.com/CPS0D
3http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t
3http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#
http://ocsp.sectigo.com0
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Code Signing CA
rO!tCC
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA
210604120840Z0?
z%\YdwS
LvZ0cq$2
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
Razer Inc.
FileDescription
FileVersion
1.0.191.235
InternalName
razgon.exe
LegalCopyright
Copyright
2021 Razer Inc. All rights reserved.
LegalTrademarks
OriginalFilename
razgon.exe
ProductName
Razer Installer
ProductVersion
1.0.191.235
Assembly Version
1.0.191.235
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic Clean
MicroWorld-eScan Clean
FireEye Clean
CAT-QuickHeal Clean
McAfee Clean
Malwarebytes Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.829760
BitDefenderTheta Gen:NN.ZemsilF.34084.qm1@ayu1@Kc
Cyren Clean
Symantec Clean
ESET-NOD32 Clean
Baidu Clean
TrendMicro-HouseCall Clean
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Trojan-Spy.MSIL.Stealer.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Clean
SentinelOne Static AI - Malicious PE
CMC Clean
Sophos Clean
APEX Malicious
GData Clean
Jiangmin Clean
MaxSecure Trojan.Malware.300983.susgen
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Clean
TACHYON Clean
Panda Clean
Zoner Clean
Tencent Clean
Yandex Clean
Ikarus Trojan-Downloader.MSIL.Agent
eGambit PE.Heur.InvalidSig
Fortinet Clean
Webroot Clean
Avast Clean
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.