File name:

FortiClientVPNOnlineInstaller.exe

Full analysis: https://app.any.run/tasks/1c798628-0eca-40a6-b512-deef8f1899b2
Verdict: Malicious activity
Analysis date: August 09, 2024, 16:42:16
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

11BFC265FC53AC4756E4EF2759CA10EB

SHA1:

E3D2BF11618C39DFD036BB33EA96AA5F989FED25

SHA256:

2E520FAA2B71BA56643153B77C2908C0D6DA34A2F6F9ABAA7CBADAB9278DC99E

SSDEEP:

98304:Fvs0nKhLE+vtgITiwgX672SJGqa1sI8XOcup2xvHdXPSmU8mdLRhQCX:c/2nL0a

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Drops the executable file immediately after the start

      • FortiClientVPNOnlineInstaller.exe (PID: 6512)
      • msiexec.exe (PID: 4936)
      • FortiClientVPN.exe (PID: 4404)
    • Checks Windows Trust Settings

      • FortiClientVPNOnlineInstaller.exe (PID: 6612)
      • FortiClientVPN.exe (PID: 4404)
      • msiexec.exe (PID: 4936)
    • Reads security settings of Internet Explorer

      • FortiClientVPNOnlineInstaller.exe (PID: 6512)
      • FortiClientVPN.exe (PID: 4404)
      • FortiClientVPNOnlineInstaller.exe (PID: 6612)
    • Reads the date of Windows installation

      • FortiClientVPNOnlineInstaller.exe (PID: 6512)
    • Application launched itself

      • FortiClientVPNOnlineInstaller.exe (PID: 6512)
    • Connects to the server without a host name

      • FortiClientVPNOnlineInstaller.exe (PID: 6612)
    • Executable content was dropped or overwritten

      • FortiClientVPN.exe (PID: 4404)
    • Reads the Windows owner or organization settings

      • FortiClientVPN.exe (PID: 4404)
      • msiexec.exe (PID: 4936)
    • Creates/Modifies COM task schedule object

      • FortiClientVPNOnlineInstaller.exe (PID: 6612)
  • INFO

    • Checks supported languages

      • FortiClientVPNOnlineInstaller.exe (PID: 6512)
      • FortiClientVPNOnlineInstaller.exe (PID: 6612)
      • FortiClientVPN.exe (PID: 4404)
      • msiexec.exe (PID: 1680)
      • msiexec.exe (PID: 4936)
      • msiexec.exe (PID: 5144)
    • Reads the computer name

      • FortiClientVPNOnlineInstaller.exe (PID: 6512)
      • FortiClientVPN.exe (PID: 4404)
      • msiexec.exe (PID: 4936)
      • msiexec.exe (PID: 1680)
      • msiexec.exe (PID: 5144)
      • FortiClientVPNOnlineInstaller.exe (PID: 6612)
    • Reads Environment values

      • FortiClientVPNOnlineInstaller.exe (PID: 6512)
      • FortiClientVPNOnlineInstaller.exe (PID: 6612)
      • msiexec.exe (PID: 1680)
      • msiexec.exe (PID: 5144)
    • Create files in a temporary directory

      • FortiClientVPNOnlineInstaller.exe (PID: 6512)
      • FortiClientVPNOnlineInstaller.exe (PID: 6612)
      • FortiClientVPN.exe (PID: 4404)
    • Process checks whether UAC notifications are on

      • FortiClientVPNOnlineInstaller.exe (PID: 6512)
    • Process checks computer location settings

      • FortiClientVPNOnlineInstaller.exe (PID: 6512)
    • Reads the software policy settings

      • FortiClientVPNOnlineInstaller.exe (PID: 6612)
      • FortiClientVPN.exe (PID: 4404)
      • msiexec.exe (PID: 4936)
    • Checks proxy server information

      • FortiClientVPNOnlineInstaller.exe (PID: 6612)
    • Creates files or folders in the user directory

      • FortiClientVPNOnlineInstaller.exe (PID: 6612)
    • Creates files in the program directory

      • FortiClientVPN.exe (PID: 4404)
    • Application launched itself

      • msiexec.exe (PID: 4936)
    • Reads the machine GUID from the registry

      • FortiClientVPN.exe (PID: 4404)
      • msiexec.exe (PID: 4936)
      • FortiClientVPNOnlineInstaller.exe (PID: 6612)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 4936)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:05:31 22:26:46+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.37
CodeSize: 1854464
InitializedDataSize: 951296
UninitializedDataSize: -
EntryPoint: 0x6fd60
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
144
Monitored processes
6
Malicious processes
0
Suspicious processes
3

Behavior graph

Click at the process to see the details
start forticlientvpnonlineinstaller.exe no specs forticlientvpnonlineinstaller.exe forticlientvpn.exe msiexec.exe msiexec.exe no specs msiexec.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1680C:\Windows\System32\MsiExec.exe -Embedding ED6627F54D1F1BBD84CC98A66A7D0CDD CC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4404C:\Users\admin\AppData\Local\Temp\FortiClientVPN.exeC:\Users\admin\AppData\Local\Temp\FortiClientVPN.exe
FortiClientVPNOnlineInstaller.exe
User:
admin
Company:
Fortinet Inc.
Integrity Level:
HIGH
Description:
FortiClient Installer
Version:
7.4.0.1658
Modules
Images
c:\users\admin\appdata\local\temp\forticlientvpn.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
4936C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
5144C:\Windows\System32\MsiExec.exe -Embedding 1B728FA05314D6220CB60EBEB3891977C:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6512"C:\Users\admin\AppData\Local\Temp\FortiClientVPNOnlineInstaller.exe" C:\Users\admin\AppData\Local\Temp\FortiClientVPNOnlineInstaller.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\forticlientvpnonlineinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ncrypt.dll
6612"C:\Users\admin\AppData\Local\Temp\FortiClientVPNOnlineInstaller.exe" C:\Users\admin\AppData\Local\Temp\FortiClientVPNOnlineInstaller.exe
FortiClientVPNOnlineInstaller.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\appdata\local\temp\forticlientvpnonlineinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ncrypt.dll
Total events
16 478
Read events
16 464
Write events
14
Delete events
0

Modification events

(PID) Process:(6512) FortiClientVPNOnlineInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(6512) FortiClientVPNOnlineInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(6512) FortiClientVPNOnlineInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(6512) FortiClientVPNOnlineInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(6612) FortiClientVPNOnlineInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{8052F904-874D-4d28-9380-AA9BDBF13AFD}\InProcServer32
Operation:writeName:ThreadingModel
Value:
diskcopy.dll
(PID) Process:(6612) FortiClientVPNOnlineInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{8052F904-874D-4d28-9380-AA9BDBF13AFD}\InProcServer32
Operation:writeName:AppID
Value:
{822BD7EE-3E73-4E7A-B461-20771A805A3F}
(PID) Process:(4404) FortiClientVPN.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{618736E0-3C3D-11CF-810C-00AA00389B71}\TypeLib
Operation:writeName:Version
Value:
1.1
(PID) Process:(4404) FortiClientVPN.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{618736E0-3C3D-11CF-810C-00AA00389B71}\TypeLib
Operation:writeName:Version
Value:
1.1
(PID) Process:(4404) FortiClientVPN.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Volatile\00\MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{03022430-ABC4-11D0-BDE2-00AA001A1953}\TypeLib
Operation:writeName:Version
Value:
1.1
(PID) Process:(4404) FortiClientVPN.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{03022430-ABC4-11D0-BDE2-00AA001A1953}\TypeLib
Operation:writeName:Version
Value:
1.1
Executable files
14
Suspicious files
10
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
6612FortiClientVPNOnlineInstaller.exeC:\Users\admin\AppData\Local\Temp\FortiClientVPN.exe
MD5:
SHA256:
4404FortiClientVPN.exeC:\Users\admin\AppData\Local\Temp\FCT_{625BC4BA-AC3E-4E4B-9996-EEED9D4287C3}\{AE4EB063-2C6D-4C39-A70D-A73113447DFF}\FortiClient.msi
MD5:
SHA256:
4404FortiClientVPN.exeC:\ProgramData\Applications\Cache\{0DC51760-4FB7-41F3-8967-D3DEC9D320EB}\7.4.0.1658\FortiClient.msi
MD5:
SHA256:
4936msiexec.exeC:\Windows\Installer\100a72.msi
MD5:
SHA256:
6612FortiClientVPNOnlineInstaller.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141binary
MD5:C33C2BD00840C9E726FAAB692CED1189
SHA256:5EDA0E13AA6955CB288E589570AAAA697B5C52047D09D4666B1797A717807AEA
6612FortiClientVPNOnlineInstaller.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEBbinary
MD5:518B87639452F467AC1BEF6B0507547E
SHA256:340FBE324B109D2C30F4F970E1C8DD6E7B07D52679CB1E6F324AF0F6EA3493F3
6612FortiClientVPNOnlineInstaller.exeC:\Users\admin\AppData\Local\Temp\obj_1_a06640__unpackedtext
MD5:4041077399DE378FCB24391D28DBBD65
SHA256:CA8628A9BEE40D677CEBFF9CB7D0EE97E8E276481E4B77E2FF6015C05DC8C0A1
6612FortiClientVPNOnlineInstaller.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8EC9B1D0ABBD7F98B401D425828828CE_052D619A1738623B01B6A412349193C8binary
MD5:3930DE28BB2B50DF0DE14F3B1E2707C3
SHA256:D9BBFAD643BF8483905C26F1782F6943265AB2DCA3B077EDEFA12972C8FD20EF
6612FortiClientVPNOnlineInstaller.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141binary
MD5:F500B62505C34811EDF3A2985DCA048A
SHA256:D15218C976ECA86368C94F41342579ADFDFA84D3DAB64FB42CC03FD64D0723AF
6612FortiClientVPNOnlineInstaller.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8EC9B1D0ABBD7F98B401D425828828CE_052D619A1738623B01B6A412349193C8binary
MD5:2309B8BEDA56D928610CBBC483AEFD5E
SHA256:85F063F4627B4C6498D4DB3CDE2EDAAB9084E945497A4777314223B89E6F2F20
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
60
DNS requests
20
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5924
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6612
FortiClientVPNOnlineInstaller.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
5924
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6968
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
7020
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6612
FortiClientVPNOnlineInstaller.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
6612
FortiClientVPNOnlineInstaller.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAhi3%2F7G6TMr%2BpOy8YeGNkI%3D
unknown
whitelisted
6612
FortiClientVPNOnlineInstaller.exe
POST
200
173.243.138.76:80
http://173.243.138.76/fdsupdate
unknown
unknown
6612
FortiClientVPNOnlineInstaller.exe
POST
200
173.243.138.76:80
http://173.243.138.76/fdsupdate
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
1184
RUXIMICS.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
2120
MoUsoCoreWorker.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2680
svchost.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6612
FortiClientVPNOnlineInstaller.exe
173.243.138.76:80
forticlient.fortinet.net
FORTINET
US
unknown
4
System
192.168.100.255:137
whitelisted
2680
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5336
SearchApp.exe
184.86.251.27:443
www.bing.com
Akamai International B.V.
DE
unknown
5336
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 172.217.23.110
whitelisted
forticlient.fortinet.net
  • 173.243.138.76
  • 208.184.237.75
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
  • 20.73.194.208
whitelisted
www.bing.com
  • 184.86.251.27
  • 184.86.251.22
  • 184.86.251.19
  • 2.23.209.179
  • 2.23.209.176
  • 2.23.209.177
  • 2.23.209.149
  • 2.23.209.182
  • 2.23.209.133
  • 2.23.209.140
  • 2.23.209.150
  • 2.23.209.158
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.71
  • 20.190.159.2
  • 40.126.31.69
  • 40.126.31.67
  • 20.190.159.68
  • 20.190.159.64
  • 20.190.159.4
  • 40.126.31.71
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
th.bing.com
  • 184.86.251.19
  • 184.86.251.22
  • 184.86.251.7
  • 184.86.251.27
  • 2.23.209.158
  • 2.23.209.185
  • 2.23.209.176
  • 2.23.209.179
  • 2.23.209.187
  • 2.23.209.189
  • 2.23.209.177
  • 2.23.209.133
  • 2.23.209.182
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted
arc.msn.com
  • 20.199.58.43
whitelisted

Threats

No threats detected
No debug info