| File name: | EAappInstaller.exe |
| Full analysis: | https://app.any.run/tasks/a78d80a9-c355-4f57-9d62-d78c0ba9c2d6 |
| Verdict: | Malicious activity |
| Analysis date: | March 24, 2025, 17:56:58 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections |
| MD5: | 2FB5BB3062268AA54FDFE5372A191465 |
| SHA1: | 4152066B2127D475398F99DCBB8272EB7ACA5B6A |
| SHA256: | 0EECB0DABC69CD0C27BAA59A04E585CB6B71846A910B97E2D111A218FCE7F136 |
| SSDEEP: | 49152:zLN9SgkHLWqnivnuhHqvVYSCh6ymc/msdzZ+n5PY23PPZLl0QuwcZr5FrcNsO6N1:zLbkHLWqniKHqvCmc+sdzEn5r3P1GHwy |
| .exe | | | Win64 Executable (generic) (76.4) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) |
| .exe | | | Generic Win/DOS Executable (5.5) |
| .exe | | | DOS Executable Generic (5.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:09:17 05:33:38+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit, Removable run from swap, Net run from swap |
| PEType: | PE32 |
| LinkerVersion: | 14.16 |
| CodeSize: | 299008 |
| InitializedDataSize: | 266752 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x2df71 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 12.115.0.5372 |
| ProductVersionNumber: | 12.115.0.5372 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | Electronic Arts |
| FileDescription: | EA app |
| FileVersion: | 12.115.0.5372 |
| InternalName: | setup |
| LegalCopyright: | Copyright (c) Electronic Arts. All rights reserved. |
| OriginalFileName: | EAappInstaller.exe |
| ProductName: | EA app |
| ProductVersion: | 12.115.0.5372 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 672 | rundll32.exe "C:\WINDOWS\Installer\MSICE9B.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_1167031 12 juno-custom-actions!JunoCustomActions.JunoCustomActions.InitializeSession | C:\Windows\SysWOW64\rundll32.exe | msiexec.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 732 | "C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EACefSubProcess.exe" --type=gpu-process --no-sandbox --log-severity=warning --user-agent-product="Origin/10.6.0.00000 EAApp/13.423.0.5936 Chrome/109.0.5414.120" --lang=en-US --user-data-dir="C:\Users\admin\AppData\Local\Electronic Arts\EA Desktop\CEF" --enable-smooth-scrolling --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --log-file="C:\Users\admin\AppData\Local\Electronic Arts\EA Desktop\Logs\cef.log" --mojo-platform-channel-handle=2944 --field-trial-handle=2988,i,9721558536957328171,14261837841869201117,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:2 | C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EACefSubProcess.exe | — | EADesktop.exe | |||||||||||
User: admin Company: Electronic Arts Integrity Level: MEDIUM Description: EA Version: 13, 423, 0, 5936 Modules
| |||||||||||||||
| 736 | C:\WINDOWS\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801} | C:\Windows\System32\dllhost.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: COM Surrogate Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 904 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1764 | rundll32.exe "C:\WINDOWS\Installer\MSIE1D8.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_1171953 30 juno-custom-actions!JunoCustomActions.JunoCustomActions.CreateAdminWritableDirectories | C:\Windows\SysWOW64\rundll32.exe | msiexec.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2064 | "C:\Program Files\Electronic Arts\EA Desktop\VC\vc_redist-11.0.61030.x86.exe" /install /quiet /norestart /log "C:\ProgramData\EA Desktop\Logs\vc_redist-11.0.61030.x86.exe.log" | C:\Program Files\Electronic Arts\EA Desktop\VC\vc_redist-11.0.61030.x86.exe | — | EABackgroundService.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 Version: 11.0.61030.0 Modules
| |||||||||||||||
| 2240 | C:\WINDOWS\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2288 | rundll32.exe "C:\WINDOWS\Installer\MSI832C.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_1213281 63 juno-custom-actions!JunoCustomActions.JunoCustomActions.LaunchClient | C:\Windows\SysWOW64\rundll32.exe | msiexec.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2800 | "C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALauncher.exe" | C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALauncher.exe | — | rundll32.exe | |||||||||||
User: admin Company: Electronic Arts Integrity Level: HIGH Description: EA Exit code: 0 Version: 13, 423, 0, 5936 Modules
| |||||||||||||||
| 2908 | "C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\legacyPM\OriginLegacyCLI.exe" -register | C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\legacyPM\OriginLegacyCLI.exe | — | EABackgroundService.exe | |||||||||||
User: SYSTEM Company: Electronic Arts Integrity Level: SYSTEM Description: OriginLegacyCLI Exit code: 1 Version: 8,1,1,1591 Modules
| |||||||||||||||
| (PID) Process: | (4380) EAappInstaller.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (4380) EAappInstaller.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (4380) EAappInstaller.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (5256) EAappInstaller.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5d7078a4-7c9e-4ade-85bf-61c3856006ac} |
| Operation: | write | Name: | BundleCachePath |
Value: C:\ProgramData\Package Cache\{5d7078a4-7c9e-4ade-85bf-61c3856006ac}\EAappInstaller.exe | |||
| (PID) Process: | (5256) EAappInstaller.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5d7078a4-7c9e-4ade-85bf-61c3856006ac} |
| Operation: | write | Name: | BundleUpgradeCode |
Value: {ADF2591E-00D2-4FFF-9BF4-9CCDAE6BDC67} | |||
| (PID) Process: | (5256) EAappInstaller.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5d7078a4-7c9e-4ade-85bf-61c3856006ac} |
| Operation: | write | Name: | BundleAddonCode |
Value: | |||
| (PID) Process: | (5256) EAappInstaller.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5d7078a4-7c9e-4ade-85bf-61c3856006ac} |
| Operation: | write | Name: | BundleDetectCode |
Value: | |||
| (PID) Process: | (5256) EAappInstaller.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5d7078a4-7c9e-4ade-85bf-61c3856006ac} |
| Operation: | write | Name: | BundlePatchCode |
Value: | |||
| (PID) Process: | (5256) EAappInstaller.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5d7078a4-7c9e-4ade-85bf-61c3856006ac} |
| Operation: | write | Name: | BundleVersion |
Value: 13.423.0.5936 | |||
| (PID) Process: | (5256) EAappInstaller.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5d7078a4-7c9e-4ade-85bf-61c3856006ac} |
| Operation: | write | Name: | VersionMajor |
Value: 13 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7376 | EAappInstaller.exe | C:\Users\admin\AppData\Local\Temp\{5973E0BC-0E1C-4597-B168-CD77E15FC251}\.cr\EAappInstaller.exe | executable | |
MD5:2FB5BB3062268AA54FDFE5372A191465 | SHA256:0EECB0DABC69CD0C27BAA59A04E585CB6B71846A910B97E2D111A218FCE7F136 | |||
| 7400 | EAappInstaller.exe | C:\Users\admin\AppData\Local\Temp\{5FB57E89-7B21-421A-96BB-4821C05E23B5}\.ba\juno-bootstrapper-application.dll | binary | |
MD5:CC0312C685642CB8E1A038C645EFCE8D | SHA256:9C5EEC705F1C958127A027DC31B06242A5714B1A136A30A48A03B5D56ED6C39E | |||
| 7400 | EAappInstaller.exe | C:\Users\admin\AppData\Local\Temp\{5FB57E89-7B21-421A-96BB-4821C05E23B5}\.ba\version.dll | executable | |
MD5:E2EC4D53E85282276F93DB5026CB40D2 | SHA256:A68A2ADED6A2D2A3CC76C8580E726AB888DFB67BFB73966296A1B199B7D1A43D | |||
| 7400 | EAappInstaller.exe | C:\Users\admin\AppData\Local\Temp\{5FB57E89-7B21-421A-96BB-4821C05E23B5}\.be\EAappInstaller.exe | executable | |
MD5:2FB5BB3062268AA54FDFE5372A191465 | SHA256:0EECB0DABC69CD0C27BAA59A04E585CB6B71846A910B97E2D111A218FCE7F136 | |||
| 7400 | EAappInstaller.exe | C:\Users\admin\AppData\Local\Temp\{5FB57E89-7B21-421A-96BB-4821C05E23B5}\.ba\BootstrapperApplicationData.xml | binary | |
MD5:0EBFEB5D7036A4760D09409CDC752299 | SHA256:331EC4A01EDC8DDFB62126F21E42FB012282CA483287E5C501E605A683CDC0B1 | |||
| 7400 | EAappInstaller.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776 | binary | |
MD5:9D4E976D5EF164D4385E87BCC5D617CE | SHA256:C90172DC217A0086AFFD7A6294FC91A2ECE0D87271E5476C4465776B9A5258C3 | |||
| 7400 | EAappInstaller.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776 | binary | |
MD5:7D5F6AC28A8D523BFB00034688D4AED6 | SHA256:4A396FDEBDEB10FCB25F7C9AA26306588B332CC30EBAD664D2064145BBE19019 | |||
| 7400 | EAappInstaller.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\48[1].json | binary | |
MD5:6F05A7646023D86038C6079062A2E04E | SHA256:57CAD66036F153BA3AF2D8AD56CC76E44F76680210FD1B111C002C703D481F48 | |||
| 7400 | EAappInstaller.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B398B80134F72209547439DB21AB308D_A4CF52CCA82D7458083F7280801A3A04 | binary | |
MD5:C3B2E7057647C482D82920D6B089D0C2 | SHA256:74442205B68F9C71A9D4EB83EF34D32F31578339E2054DE44F6CFC234C60167D | |||
| 7400 | EAappInstaller.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B398B80134F72209547439DB21AB308D_A4CF52CCA82D7458083F7280801A3A04 | binary | |
MD5:23FC888B1FE1C3B977016A26582E7184 | SHA256:C6D47FC96BD8DF11F4BE3922B13D6D67D97ACFD64DBF5F36FAC94B649E8DDFE4 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 88.221.110.122:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | unknown |
5496 | MoUsoCoreWorker.exe | GET | 200 | 88.221.110.122:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | unknown |
— | — | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D | unknown | — | — | unknown |
— | — | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | unknown |
— | — | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQQX6Z6gAidtSefNc6DC0OInqPHDQQUD4BhHIIxYdUvKOeNRji0LOHG2eICEAmkqApTkBtUHrze5ePBmqo%3D | unknown | — | — | unknown |
6544 | svchost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | unknown |
7908 | backgroundTaskHost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | unknown |
4380 | EAappInstaller.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D | unknown | — | — | unknown |
4380 | EAappInstaller.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D | unknown | — | — | unknown |
4380 | EAappInstaller.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAZxNS3EwQO3Cucl6VRIY3Q%3D | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | unknown |
— | — | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | unknown |
2104 | svchost.exe | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | unknown |
5496 | MoUsoCoreWorker.exe | 88.221.110.122:80 | crl.microsoft.com | Akamai International B.V. | DE | unknown |
— | — | 88.221.110.122:80 | crl.microsoft.com | Akamai International B.V. | DE | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
5496 | MoUsoCoreWorker.exe | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | unknown |
— | — | 23.60.203.16:443 | autopatch.juno.ea.com | AKAMAI-AS | DE | unknown |
— | — | 184.30.131.245:80 | ocsp.digicert.com | AKAMAI-AS | US | unknown |
— | — | 23.196.246.72:443 | ratt.juno.ea.com | AKAMAI-AS | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
google.com |
| unknown |
crl.microsoft.com |
| unknown |
autopatch.juno.ea.com |
| unknown |
ocsp.digicert.com |
| unknown |
ratt.juno.ea.com |
| unknown |
pin-river.data.ea.com |
| unknown |
origin-a.akamaihd.net |
| unknown |
login.live.com |
| unknown |
client.wns.windows.com |
| unknown |
settings-win.data.microsoft.com |
| unknown |
Process | Message |
|---|---|
Setup.exe | The operation completed successfully.
|