URL:

https://epicgames-download1.akamaized.net/Builds/UnrealEngineLauncher/Installers/Win32/EpicInstaller-10.17.0.msi?launcherfilename=EpicInstaller-10.17.0-fortnite.msi

Full analysis: https://app.any.run/tasks/5c44e2c1-a7da-44f5-a613-072d1340ce24
Verdict: Malicious activity
Analysis date: September 14, 2020, 06:21:48
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

23B59709EAF9FDF2B921FD800326F4F7

SHA1:

60C89007646B85ED4A60FECCC81F72E8D748EF83

SHA256:

974283FDA73685CFC3EBEA0AC9AD24F9C34F61C111B1918C5A898B66F1C07004

SSDEEP:

3:N8O08KVLnh/HIBijAlfATXgX27uOXIMbV7JEeLsAiNxEOXIMbV+durM:2IK3HIIjAxAcX2COX7x7KzfuOX7xi

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • rundll32.exe (PID: 2656)
      • rundll32.exe (PID: 3828)
      • DXSETUP.exe (PID: 2568)
      • rundll32.exe (PID: 2244)
      • EpicGamesLauncher.exe (PID: 2256)
      • rundll32.exe (PID: 4036)
    • Application was dropped or rewritten from another process

      • DXSETUP.exe (PID: 2568)
      • EpicGamesLauncher.exe (PID: 2256)
    • Changes settings of System certificates

      • DXSETUP.exe (PID: 2568)
  • SUSPICIOUS

    • Creates files in the Windows directory

      • DXSETUP.exe (PID: 2568)
    • Executed via COM

      • DllHost.exe (PID: 3056)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 2876)
      • rundll32.exe (PID: 3828)
      • rundll32.exe (PID: 2244)
      • rundll32.exe (PID: 4036)
      • DXSETUP.exe (PID: 2568)
    • Uses RUNDLL32.EXE to load library

      • MsiExec.exe (PID: 3088)
      • MsiExec.exe (PID: 1332)
    • Starts Microsoft Installer

      • iexplore.exe (PID: 2588)
    • Removes files from Windows directory

      • DXSETUP.exe (PID: 2568)
    • Uses ICACLS.EXE to modify access control list

      • MsiExec.exe (PID: 3016)
    • Reads the machine GUID from the registry

      • EpicGamesLauncher.exe (PID: 2256)
    • Adds / modifies Windows certificates

      • DXSETUP.exe (PID: 2568)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 2588)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 2588)
      • iexplore.exe (PID: 3644)
    • Changes internet zones settings

      • iexplore.exe (PID: 2588)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 3644)
      • iexplore.exe (PID: 2588)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 2588)
    • Manual execution by user

      • explorer.exe (PID: 3708)
    • Changes settings of System certificates

      • iexplore.exe (PID: 2588)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 2588)
    • Loads dropped or rewritten executable

      • MsiExec.exe (PID: 3088)
      • MsiExec.exe (PID: 1332)
      • MsiExec.exe (PID: 3016)
    • Creates files in the user directory

      • iexplore.exe (PID: 2588)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
58
Monitored processes
15
Malicious processes
4
Suspicious processes
4

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe msiexec.exe rundll32.exe no specs msiexec.exe no specs msiexec.exe no specs rundll32.exe dxsetup.exe SPPSurrogate no specs explorer.exe no specs msiexec.exe no specs icacls.exe no specs rundll32.exe epicgameslauncher.exe rundll32.exe

Process information

PID
CMD
Path
Indicators
Parent process
1332C:\Windows\system32\MsiExec.exe -Embedding 15E118527E8147DC00F54212A1DF4D29C:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2244rundll32.exe "C:\Windows\Installer\MSI89C6.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_1542671 30 CustomActionManaged!CustomActionManaged.CustomActions.SetStartupCmdlineArgsC:\Windows\system32\rundll32.exe
MsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2256"C:\Program Files\Epic Games\Launcher\Portal\Binaries\Win32\EpicGamesLauncher.exe" com.epicgames.launcher://fortniteC:\Program Files\Epic Games\Launcher\Portal\Binaries\Win32\EpicGamesLauncher.exe
msiexec.exe
User:
admin
Company:
Epic Games, Inc.
Integrity Level:
MEDIUM
Description:
EpicGamesLauncher
Exit code:
0
Modules
Images
c:\program files\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\winmm.dll
2568"C:\Program Files\Epic Games\DirectXRedist\DXSETUP.exe" /silentC:\Program Files\Epic Games\DirectXRedist\DXSETUP.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft DirectX Setup
Exit code:
0
Version:
4.9.0.0904
Modules
Images
c:\program files\epic games\directxredist\dxsetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2588"C:\Program Files\Internet Explorer\iexplore.exe" https://epicgames-download1.akamaized.net/Builds/UnrealEngineLauncher/Installers/Win32/EpicInstaller-10.17.0.msi?launcherfilename=EpicInstaller-10.17.0-fortnite.msiC:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2656rundll32.exe "C:\Users\admin\AppData\Local\Temp\MSI8A74.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_1477250 5 CustomActionManaged!CustomActionManaged.CustomActions.ValidatePathLengthC:\Windows\system32\rundll32.exeMsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2876"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\Downloads\EpicInstaller-10.17.0-fortnite.msi" C:\Windows\System32\msiexec.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3016C:\Windows\system32\MsiExec.exe -Embedding 832AD0FCD4E954E9700E24F8055F7459 M Global\MSI0000C:\Windows\system32\MsiExec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3056C:\Windows\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801}C:\Windows\system32\DllHost.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3088C:\Windows\system32\MsiExec.exe -Embedding A4AA33DB763CC17CB1B6CF5E8553D949 CC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
1 210
Read events
1 040
Write events
165
Delete events
5

Modification events

(PID) Process:(2588) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
1873591722
(PID) Process:(2588) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30837343
(PID) Process:(2588) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2588) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2588) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2588) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2588) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2588) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2588) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2588) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
46000000A3000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
Executable files
13
Suspicious files
13
Text files
343
Unknown types
8

Dropped files

PID
Process
Filename
Type
3644iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\CabC68.tmp
MD5:
SHA256:
3644iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\TarC69.tmp
MD5:
SHA256:
3644iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\EpicInstaller-10.17.0-fortnite[1].msi
MD5:
SHA256:
3644iexplore.exeC:\Users\admin\Downloads\EpicInstaller-10.17.0-fortnite.msi.wqtcnee.partial
MD5:
SHA256:
2588iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF7FBD52F4992B8E0C.TMP
MD5:
SHA256:
2588iexplore.exeC:\Users\admin\Downloads\EpicInstaller-10.17.0-fortnite.msi.wqtcnee.partial:Zone.Identifier
MD5:
SHA256:
2588iexplore.exeC:\Users\admin\Downloads\EpicInstaller-10.17.0-fortnite.msi
MD5:
SHA256:
2876msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI7D43.tmp
MD5:
SHA256:
2876msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI8A54.tmp
MD5:
SHA256:
2656rundll32.exeC:\Users\admin\AppData\Local\Temp\MSI8A74.tmp-\CustomActionManaged.dll
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
17
DNS requests
9
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3644
iexplore.exe
GET
200
93.184.220.29:80
http://crl3.digicert.com/DigiCertGlobalRootCA.crl
US
der
631 b
whitelisted
2588
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D
US
der
1.47 Kb
whitelisted
2588
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D
US
der
1.47 Kb
whitelisted
1048
svchost.exe
GET
200
2.21.38.54:80
http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
FR
der
813 b
whitelisted
3644
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAtb9ltrp%2FvQiykNkEU33uA%3D
US
der
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3644
iexplore.exe
2.16.186.105:443
epicgames-download1.akamaized.net
Akamai International B.V.
whitelisted
3644
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3828
rundll32.exe
52.86.67.197:443
datarouter.ol.epicgames.com
Amazon.com, Inc.
US
unknown
2588
iexplore.exe
152.199.19.161:443
iecvlist.microsoft.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2588
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2588
iexplore.exe
204.79.197.200:443
ieonline.microsoft.com
Microsoft Corporation
US
whitelisted
1048
svchost.exe
2.21.38.54:80
www.microsoft.com
GTT Communications Inc.
FR
malicious
4036
rundll32.exe
34.237.117.11:443
datarouter.ol.epicgames.com
Amazon.com, Inc.
US
unknown
2256
EpicGamesLauncher.exe
34.237.117.11:443
datarouter.ol.epicgames.com
Amazon.com, Inc.
US
unknown

DNS requests

Domain
IP
Reputation
epicgames-download1.akamaized.net
  • 2.16.186.105
  • 2.16.186.56
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
crl3.digicert.com
  • 93.184.220.29
whitelisted
datarouter.ol.epicgames.com
  • 52.86.67.197
  • 23.23.43.12
  • 18.210.253.18
  • 52.7.165.73
  • 54.88.211.84
  • 35.170.111.251
  • 174.129.81.64
  • 100.24.222.252
  • 34.237.117.11
  • 54.145.237.163
  • 52.55.229.110
  • 54.161.190.252
  • 34.232.247.41
  • 52.87.92.96
unknown
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
ieonline.microsoft.com
  • 204.79.197.200
whitelisted
www.microsoft.com
  • 2.21.38.54
whitelisted

Threats

No threats detected
Process
Message
DXSETUP.exe
DLL_PROCESS_ATTACH
DXSETUP.exe
DLL_PROCESS_ATTACH
DXSETUP.exe
DLL_PROCESS_DETACH
DXSETUP.exe
DLL_PROCESS_DETACH
EpicGamesLauncher.exe
AppSettings: ForwardMessage: false
EpicGamesLauncher.exe
LogInit: Display: Command Line: "C:\Program Files\Epic Games\Launcher\Portal\Binaries\Win32\EpicGamesLauncher.exe" com.epicgames.launcher://fortnite -SaveToUserDir -Messaging
EpicGamesLauncher.exe
AppSettings: bAllowMultipleInstances: false
EpicGamesLauncher.exe
AppSettings: bDoesCompiledPlatformMatch: true
EpicGamesLauncher.exe
AppSettings: Version: 10.17.0-13657771+++Portal+Release-Live
EpicGamesLauncher.exe
LogInit: Base Directory: C:/Program Files/Epic Games/Launcher/Portal/Binaries/Win32/