File name:

FortiClientVPNOnlineInstaller.exe

Full analysis: https://app.any.run/tasks/1c798628-0eca-40a6-b512-deef8f1899b2
Verdict: Malicious activity
Analysis date: August 09, 2024, 16:42:16
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

11BFC265FC53AC4756E4EF2759CA10EB

SHA1:

E3D2BF11618C39DFD036BB33EA96AA5F989FED25

SHA256:

2E520FAA2B71BA56643153B77C2908C0D6DA34A2F6F9ABAA7CBADAB9278DC99E

SSDEEP:

98304:Fvs0nKhLE+vtgITiwgX672SJGqa1sI8XOcup2xvHdXPSmU8mdLRhQCX:c/2nL0a

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • FortiClientVPNOnlineInstaller.exe (PID: 6612)
      • FortiClientVPN.exe (PID: 4404)
      • FortiClientVPNOnlineInstaller.exe (PID: 6512)
    • Checks Windows Trust Settings

      • FortiClientVPNOnlineInstaller.exe (PID: 6612)
      • FortiClientVPN.exe (PID: 4404)
      • msiexec.exe (PID: 4936)
    • Creates/Modifies COM task schedule object

      • FortiClientVPNOnlineInstaller.exe (PID: 6612)
    • Application launched itself

      • FortiClientVPNOnlineInstaller.exe (PID: 6512)
    • Connects to the server without a host name

      • FortiClientVPNOnlineInstaller.exe (PID: 6612)
    • Executable content was dropped or overwritten

      • FortiClientVPN.exe (PID: 4404)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 4936)
      • FortiClientVPN.exe (PID: 4404)
    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 4936)
      • FortiClientVPN.exe (PID: 4404)
      • FortiClientVPNOnlineInstaller.exe (PID: 6512)
    • Reads the date of Windows installation

      • FortiClientVPNOnlineInstaller.exe (PID: 6512)
  • INFO

    • Create files in a temporary directory

      • FortiClientVPNOnlineInstaller.exe (PID: 6512)
      • FortiClientVPNOnlineInstaller.exe (PID: 6612)
      • FortiClientVPN.exe (PID: 4404)
    • Process checks computer location settings

      • FortiClientVPNOnlineInstaller.exe (PID: 6512)
    • Reads Environment values

      • FortiClientVPNOnlineInstaller.exe (PID: 6512)
      • FortiClientVPNOnlineInstaller.exe (PID: 6612)
      • msiexec.exe (PID: 1680)
      • msiexec.exe (PID: 5144)
    • Process checks whether UAC notifications are on

      • FortiClientVPNOnlineInstaller.exe (PID: 6512)
    • Reads the machine GUID from the registry

      • FortiClientVPNOnlineInstaller.exe (PID: 6612)
      • FortiClientVPN.exe (PID: 4404)
      • msiexec.exe (PID: 4936)
    • Reads the computer name

      • FortiClientVPNOnlineInstaller.exe (PID: 6612)
      • msiexec.exe (PID: 4936)
      • FortiClientVPN.exe (PID: 4404)
      • msiexec.exe (PID: 1680)
      • msiexec.exe (PID: 5144)
      • FortiClientVPNOnlineInstaller.exe (PID: 6512)
    • Reads the software policy settings

      • FortiClientVPNOnlineInstaller.exe (PID: 6612)
      • FortiClientVPN.exe (PID: 4404)
      • msiexec.exe (PID: 4936)
    • Checks proxy server information

      • FortiClientVPNOnlineInstaller.exe (PID: 6612)
    • Creates files or folders in the user directory

      • FortiClientVPNOnlineInstaller.exe (PID: 6612)
    • Creates files in the program directory

      • FortiClientVPN.exe (PID: 4404)
    • Checks supported languages

      • msiexec.exe (PID: 4936)
      • FortiClientVPN.exe (PID: 4404)
      • msiexec.exe (PID: 1680)
      • msiexec.exe (PID: 5144)
      • FortiClientVPNOnlineInstaller.exe (PID: 6512)
      • FortiClientVPNOnlineInstaller.exe (PID: 6612)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 4936)
    • Application launched itself

      • msiexec.exe (PID: 4936)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:05:31 22:26:46+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.37
CodeSize: 1854464
InitializedDataSize: 951296
UninitializedDataSize: -
EntryPoint: 0x6fd60
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
144
Monitored processes
6
Malicious processes
0
Suspicious processes
3

Behavior graph

Click at the process to see the details
start forticlientvpnonlineinstaller.exe no specs forticlientvpnonlineinstaller.exe forticlientvpn.exe msiexec.exe msiexec.exe no specs msiexec.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1680C:\Windows\System32\MsiExec.exe -Embedding ED6627F54D1F1BBD84CC98A66A7D0CDD CC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4404C:\Users\admin\AppData\Local\Temp\FortiClientVPN.exeC:\Users\admin\AppData\Local\Temp\FortiClientVPN.exe
FortiClientVPNOnlineInstaller.exe
User:
admin
Company:
Fortinet Inc.
Integrity Level:
HIGH
Description:
FortiClient Installer
Version:
7.4.0.1658
Modules
Images
c:\users\admin\appdata\local\temp\forticlientvpn.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
4936C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
5144C:\Windows\System32\MsiExec.exe -Embedding 1B728FA05314D6220CB60EBEB3891977C:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6512"C:\Users\admin\AppData\Local\Temp\FortiClientVPNOnlineInstaller.exe" C:\Users\admin\AppData\Local\Temp\FortiClientVPNOnlineInstaller.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\forticlientvpnonlineinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ncrypt.dll
6612"C:\Users\admin\AppData\Local\Temp\FortiClientVPNOnlineInstaller.exe" C:\Users\admin\AppData\Local\Temp\FortiClientVPNOnlineInstaller.exe
FortiClientVPNOnlineInstaller.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\appdata\local\temp\forticlientvpnonlineinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ncrypt.dll
Total events
16 478
Read events
16 464
Write events
14
Delete events
0

Modification events

(PID) Process:(6512) FortiClientVPNOnlineInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(6512) FortiClientVPNOnlineInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(6512) FortiClientVPNOnlineInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(6512) FortiClientVPNOnlineInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(6612) FortiClientVPNOnlineInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{8052F904-874D-4d28-9380-AA9BDBF13AFD}\InProcServer32
Operation:writeName:ThreadingModel
Value:
diskcopy.dll
(PID) Process:(6612) FortiClientVPNOnlineInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{8052F904-874D-4d28-9380-AA9BDBF13AFD}\InProcServer32
Operation:writeName:AppID
Value:
{822BD7EE-3E73-4E7A-B461-20771A805A3F}
(PID) Process:(4404) FortiClientVPN.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{618736E0-3C3D-11CF-810C-00AA00389B71}\TypeLib
Operation:writeName:Version
Value:
1.1
(PID) Process:(4404) FortiClientVPN.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{618736E0-3C3D-11CF-810C-00AA00389B71}\TypeLib
Operation:writeName:Version
Value:
1.1
(PID) Process:(4404) FortiClientVPN.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Volatile\00\MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{03022430-ABC4-11D0-BDE2-00AA001A1953}\TypeLib
Operation:writeName:Version
Value:
1.1
(PID) Process:(4404) FortiClientVPN.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{03022430-ABC4-11D0-BDE2-00AA001A1953}\TypeLib
Operation:writeName:Version
Value:
1.1
Executable files
14
Suspicious files
10
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
6612FortiClientVPNOnlineInstaller.exeC:\Users\admin\AppData\Local\Temp\FortiClientVPN.exe
MD5:
SHA256:
4404FortiClientVPN.exeC:\Users\admin\AppData\Local\Temp\FCT_{625BC4BA-AC3E-4E4B-9996-EEED9D4287C3}\{AE4EB063-2C6D-4C39-A70D-A73113447DFF}\FortiClient.msi
MD5:
SHA256:
4404FortiClientVPN.exeC:\ProgramData\Applications\Cache\{0DC51760-4FB7-41F3-8967-D3DEC9D320EB}\7.4.0.1658\FortiClient.msi
MD5:
SHA256:
4936msiexec.exeC:\Windows\Installer\100a72.msi
MD5:
SHA256:
6612FortiClientVPNOnlineInstaller.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8EC9B1D0ABBD7F98B401D425828828CE_052D619A1738623B01B6A412349193C8binary
MD5:3930DE28BB2B50DF0DE14F3B1E2707C3
SHA256:D9BBFAD643BF8483905C26F1782F6943265AB2DCA3B077EDEFA12972C8FD20EF
6612FortiClientVPNOnlineInstaller.exeC:\Users\admin\AppData\Local\Temp\obj_1_a06640binary
MD5:0B889CD8FC6FA7628B87FAE8D184D426
SHA256:B4506DCFB95866967725C04526AB8A539BD4B3B689E76FAE019DB4E64587CAC0
6612FortiClientVPNOnlineInstaller.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEBbinary
MD5:E33A85EF892402BBE9DE308183DDC016
SHA256:E330E9D3928DBEAEE6F18C0C90D415C55FD68E49C3BB68AAB6AD4F375C95786F
6612FortiClientVPNOnlineInstaller.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEBbinary
MD5:518B87639452F467AC1BEF6B0507547E
SHA256:340FBE324B109D2C30F4F970E1C8DD6E7B07D52679CB1E6F324AF0F6EA3493F3
6612FortiClientVPNOnlineInstaller.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8EC9B1D0ABBD7F98B401D425828828CE_052D619A1738623B01B6A412349193C8binary
MD5:2309B8BEDA56D928610CBBC483AEFD5E
SHA256:85F063F4627B4C6498D4DB3CDE2EDAAB9084E945497A4777314223B89E6F2F20
4404FortiClientVPN.exeC:\Users\admin\AppData\Local\Temp\MSIEECB.tmpexecutable
MD5:32EFBFFDA3376EE49D78BAFF6BCE3CC5
SHA256:F64E2CAD4CDCC53694CA3DBD78B941039064D31EA5892D4DED3A533F0FED627A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
60
DNS requests
20
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6612
FortiClientVPNOnlineInstaller.exe
POST
200
173.243.138.76:80
http://173.243.138.76/fdsupdate
unknown
unknown
6612
FortiClientVPNOnlineInstaller.exe
POST
200
173.243.138.76:80
http://173.243.138.76/fdsupdate
unknown
unknown
6612
FortiClientVPNOnlineInstaller.exe
POST
200
173.243.138.76:80
http://173.243.138.76/fdsupdate
unknown
unknown
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5924
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5924
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7020
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6612
FortiClientVPNOnlineInstaller.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
6612
FortiClientVPNOnlineInstaller.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
6612
FortiClientVPNOnlineInstaller.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAhi3%2F7G6TMr%2BpOy8YeGNkI%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
1184
RUXIMICS.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
2120
MoUsoCoreWorker.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2680
svchost.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6612
FortiClientVPNOnlineInstaller.exe
173.243.138.76:80
forticlient.fortinet.net
FORTINET
US
unknown
4
System
192.168.100.255:137
whitelisted
2680
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5336
SearchApp.exe
184.86.251.27:443
www.bing.com
Akamai International B.V.
DE
unknown
5336
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 172.217.23.110
whitelisted
forticlient.fortinet.net
  • 173.243.138.76
  • 208.184.237.75
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
  • 20.73.194.208
whitelisted
www.bing.com
  • 184.86.251.27
  • 184.86.251.22
  • 184.86.251.19
  • 2.23.209.179
  • 2.23.209.176
  • 2.23.209.177
  • 2.23.209.149
  • 2.23.209.182
  • 2.23.209.133
  • 2.23.209.140
  • 2.23.209.150
  • 2.23.209.158
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.71
  • 20.190.159.2
  • 40.126.31.69
  • 40.126.31.67
  • 20.190.159.68
  • 20.190.159.64
  • 20.190.159.4
  • 40.126.31.71
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
th.bing.com
  • 184.86.251.19
  • 184.86.251.22
  • 184.86.251.7
  • 184.86.251.27
  • 2.23.209.158
  • 2.23.209.185
  • 2.23.209.176
  • 2.23.209.179
  • 2.23.209.187
  • 2.23.209.189
  • 2.23.209.177
  • 2.23.209.133
  • 2.23.209.182
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted
arc.msn.com
  • 20.199.58.43
whitelisted

Threats

No threats detected
No debug info