| File name: | FortiClientVPNOnlineInstaller_6.4.exe |
| Full analysis: | https://app.any.run/tasks/a8643ef2-9591-4415-a8a3-cdc4cc096d0c |
| Verdict: | Suspicious activity |
| Analysis date: | August 04, 2020, 02:21:29 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 97956A511A07B33AAFE92D64C24B167E |
| SHA1: | 87EC3FB53071D6D92BE3B0ADB48EED5643F77ED3 |
| SHA256: | AFE48F9BFF6F95E93C5195D59301F2AEA28A54B6B1ABBE305B6CA08AD6835B5E |
| SSDEEP: | 49152:wGM4uYLUg3c2dpjBlSP9iPtjM7oB7jZdWSp:wGMeUAc2JlSiljrp |
| .exe | | | Win64 Executable (generic) (76.4) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) |
| .exe | | | Generic Win/DOS Executable (5.5) |
| .exe | | | DOS Executable Generic (5.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2020:05:11 23:51:24+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 14.16 |
| CodeSize: | 1334272 |
| InitializedDataSize: | 692736 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1198d0 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 6.4.0.1464 |
| ProductVersionNumber: | 6.4.0.1464 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| Comments: | - |
| CompanyName: | Fortinet Inc. |
| FileDescription: | FortiClient VPN Online Installation |
| FileVersion: | 6.4.0.1464 |
| InternalName: | FortiClientVPNInstaller |
| LegalCopyright: | 2020 Fortinet Inc. All rights reserved. |
| LegalTrademarks: | - |
| OriginalFileName: | FortiClientVPNInstaller.exe |
| PrivateBuild: | - |
| ProductName: | FortiClient VPN Online Installation |
| ProductVersion: | 6.4.0.1464 |
| SpecialBuild: | - |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 11-May-2020 21:51:24 |
| Detected languages: |
|
| Comments: | - |
| CompanyName: | Fortinet Inc. |
| FileDescription: | FortiClient VPN Online Installation |
| FileVersion: | 6.4.0.1464 |
| InternalName: | FortiClientVPNInstaller |
| LegalCopyright: | 2020 Fortinet Inc. All rights reserved. |
| LegalTrademarks: | - |
| OriginalFilename: | FortiClientVPNInstaller.exe |
| PrivateBuild: | - |
| ProductName: | FortiClient VPN Online Installation |
| ProductVersion: | 6.4.0.1464 |
| SpecialBuild: | - |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x00000138 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 6 |
| Time date stamp: | 11-May-2020 21:51:24 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x00145AEC | 0x00145C00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.98238 |
.rdata | 0x00147000 | 0x0006EE44 | 0x0006F000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.07117 |
.data | 0x001B6000 | 0x00008CE4 | 0x00002A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.54648 |
.didat | 0x001BF000 | 0x00000150 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.93696 |
.rsrc | 0x001C0000 | 0x000233A0 | 0x00023400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.42583 |
.reloc | 0x001E4000 | 0x0000DC78 | 0x0000DE00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.60709 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.24015 | 1251 | UNKNOWN | UNKNOWN | RT_MANIFEST |
2 | 2.21727 | 744 | UNKNOWN | UNKNOWN | RT_ICON |
7 | 3.30163 | 752 | UNKNOWN | French - Canada | RT_STRING |
8 | 3.342 | 982 | UNKNOWN | French - Canada | RT_STRING |
9 | 3.29553 | 2122 | UNKNOWN | French - Canada | RT_STRING |
10 | 3.18561 | 824 | UNKNOWN | French - Canada | RT_STRING |
100 | 5.1788 | 195 | UNKNOWN | UNKNOWN | REGISTRY |
101 | 3.25301 | 274 | UNKNOWN | French - Canada | RT_DIALOG |
201 | 1.51664 | 20 | UNKNOWN | UNKNOWN | RT_GROUP_ICON |
203 | 3.40661 | 678 | UNKNOWN | French - Canada | RT_DIALOG |
COMCTL32.dll (delay-loaded) |
CRYPT32.dll |
KERNEL32.dll |
OLEAUT32.dll |
PSAPI.DLL |
USER32.dll |
USERENV.dll |
VERSION.dll |
WS2_32.dll |
bcrypt.dll |
Title | Ordinal | Address |
|---|---|---|
BeginHttpRequest | 1 | 0x0005D290 |
BeginHttpResponse | 2 | 0x0005D320 |
FCP_add_param | 3 | 0x0005A540 |
FCP_append_objdata_ff | 4 | 0x0005A590 |
FCP_break_obj_header | 5 | 0x0005A8E0 |
FCP_breakup_data_item | 6 | 0x0005A9E0 |
FCP_calculate_obj_head_chksum | 7 | 0x0005C7A0 |
FCP_chk_partial_obj_files | 8 | 0x0005AA60 |
FCP_cleanup | 9 | 0x0005AD00 |
FCP_clear_object_storage | 10 | 0x0005AD10 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1444 | C:\Windows\system32\MsiExec.exe -Embedding 74E9124929A0A8965C4785B6A75F572E C | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1680 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2204 | FortiClientVPN.exe | C:\Users\admin\AppData\Local\Temp\FortiClientVPN.exe | FortiClientVPNOnlineInstaller_6.4.exe | ||||||||||||
User: admin Company: Fortinet Inc. Integrity Level: HIGH Description: FortiClient Installer Exit code: 0 Version: 6.4.0.1464 Modules
| |||||||||||||||
| 2336 | "C:\Users\admin\AppData\Local\Temp\FortiClientVPNOnlineInstaller_6.4.exe" | C:\Users\admin\AppData\Local\Temp\FortiClientVPNOnlineInstaller_6.4.exe | — | explorer.exe | |||||||||||
User: admin Company: Fortinet Inc. Integrity Level: MEDIUM Description: FortiClient VPN Online Installation Exit code: 0 Version: 6.4.0.1464 Modules
| |||||||||||||||
| 2756 | "C:\Users\admin\AppData\Local\Temp\FortiClientVPNOnlineInstaller_6.4.exe" | C:\Users\admin\AppData\Local\Temp\FortiClientVPNOnlineInstaller_6.4.exe | FortiClientVPNOnlineInstaller_6.4.exe | ||||||||||||
User: admin Company: Fortinet Inc. Integrity Level: HIGH Description: FortiClient VPN Online Installation Exit code: 0 Version: 6.4.0.1464 Modules
| |||||||||||||||
| (PID) Process: | (2336) FortiClientVPNOnlineInstaller_6.4.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2336) FortiClientVPNOnlineInstaller_6.4.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (2756) FortiClientVPNOnlineInstaller_6.4.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8052F904-874D-4d28-9380-AA9BDBF13AFD}\InProcServer32 |
| Operation: | write | Name: | (default) |
Value: diskcopy.dll | |||
| (PID) Process: | (2756) FortiClientVPNOnlineInstaller_6.4.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8052F904-874D-4d28-9380-AA9BDBF13AFD}\InProcServer32 |
| Operation: | write | Name: | ThreadingModel |
Value: diskcopy.dll | |||
| (PID) Process: | (2756) FortiClientVPNOnlineInstaller_6.4.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8052F904-874D-4d28-9380-AA9BDBF13AFD}\InProcServer32 |
| Operation: | write | Name: | AppID |
Value: {F1652C6E-0E9E-4019-9F79-0B0A31B1ED10} | |||
| (PID) Process: | (2756) FortiClientVPNOnlineInstaller_6.4.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\132\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2756) FortiClientVPNOnlineInstaller_6.4.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43 |
| Operation: | write | Name: | Blob |
Value: 04000000010000001000000087CE0B7B2A0E4900E158719B37A893720F00000001000000140000006DCA5BD00DCF1C0F327059D374B29CA6E3C50AA60300000001000000140000000563B8630D62D75ABBC8AB1E4BDFB5A899B24D431D00000001000000100000004F5F106930398D09107B40C3C7CA8F1C0B000000010000001200000044006900670069004300650072007400000014000000010000001400000045EBA2AFF492CB82312D518BA7A7219DF36DC80F6200000001000000200000003E9099B5015E8F486C00BCEA9D111EE721FABA355A89BCF1DF69561E3DC6325C5300000001000000230000003021301F06096086480186FD6C020130123010060A2B0601040182373C0101030200C0090000000100000034000000303206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B06010505070308190000000100000010000000749966CECC95C1874194CA7203F9B6202000000001000000BB030000308203B73082029FA00302010202100CE7E0E517D846FE8FE560FC1BF03039300D06092A864886F70D01010505003065310B300906035504061302555331153013060355040A130C446967694365727420496E6331193017060355040B13107777772E64696769636572742E636F6D312430220603550403131B4469676943657274204173737572656420494420526F6F74204341301E170D3036313131303030303030305A170D3331313131303030303030305A3065310B300906035504061302555331153013060355040A130C446967694365727420496E6331193017060355040B13107777772E64696769636572742E636F6D312430220603550403131B4469676943657274204173737572656420494420526F6F7420434130820122300D06092A864886F70D01010105000382010F003082010A0282010100AD0E15CEE443805CB187F3B760F97112A5AEDC269488AAF4CEF520392858600CF880DAA9159532613CB5B128848A8ADC9F0A0C83177A8F90AC8AE779535C31842AF60F98323676CCDEDD3CA8A2EF6AFB21F25261DF9F20D71FE2B1D9FE1864D2125B5FF9581835BC47CDA136F96B7FD4B0383EC11BC38C33D9D82F18FE280FB3A783D6C36E44C061359616FE599C8B766DD7F1A24B0D2BFF0B72DA9E60D08E9035C678558720A1CFE56D0AC8497C3198336C22E987D0325AA2BA138211ED39179D993A72A1E6FAA4D9D5173175AE857D22AE3F014686F62879C8B1DAE45717C47E1C0EB0B492A656B3BDB297EDAAA7F0B7C5A83F9516D0FFA196EB085F18774F0203010001A3633061300E0603551D0F0101FF040403020186300F0603551D130101FF040530030101FF301D0603551D0E0416041445EBA2AFF492CB82312D518BA7A7219DF36DC80F301F0603551D2304183016801445EBA2AFF492CB82312D518BA7A7219DF36DC80F300D06092A864886F70D01010505000382010100A20EBCDFE2EDF0E372737A6494BFF77266D832E4427562AE87EBF2D5D9DE56B39FCCCE1428B90D97605C124C58E4D33D834945589735691AA847EA56C679AB12D8678184DF7F093C94E6B8262C20BD3DB32889F75FFF22E297841FE965EF87E0DFC16749B35DEBB2092AEB26ED78BE7D3F2BF3B726356D5F8901B6495B9F01059BAB3D25C1CCB67FC2F16F86C6FA6468EB812D94EB42B7FA8C1EDD62F1BE5067B76CBDF3F11F6B0C3607167F377CA95B6D7AF112466083D72704BE4BCE97BEC3672A6811DF80E70C3366BF130D146EF37F1F63101EFA8D1B256D6C8FA5B76101B1D2A326A110719DADE2C3F9C39951B72B0708CE2EE650B2A7FA0A452FA2F0F2 | |||
| (PID) Process: | (2756) FortiClientVPNOnlineInstaller_6.4.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\Certificates\92C1588E85AF2201CE7915E8538B492F605B80C6 |
| Operation: | write | Name: | Blob |
Value: 03000000010000001400000092C1588E85AF2201CE7915E8538B492F605B80C6190000000100000010000000021DFB9B16B1303A97B0BF78CDA68E46040000000100000010000000B656376C3D2ACEBBA18849D604361BD50F0000000100000020000000E767799478F64A34B3F53FF3BB9057FE1768F4AB178041B0DCC0FF1E210CBA651400000001000000140000005AC4B97B2A0AA3A5EA7103C060F92DF665750E58180000000100000010000000749966CECC95C1874194CA7203F9B6202000000001000000340500003082053030820418A00302010202100409181B5FD5BB66755343B56F955008300D06092A864886F70D01010B05003065310B300906035504061302555331153013060355040A130C446967694365727420496E6331193017060355040B13107777772E64696769636572742E636F6D312430220603550403131B4469676943657274204173737572656420494420526F6F74204341301E170D3133313032323132303030305A170D3238313032323132303030305A3072310B300906035504061302555331153013060355040A130C446967694365727420496E6331193017060355040B13107777772E64696769636572742E636F6D3131302F0603550403132844696769436572742053484132204173737572656420494420436F6465205369676E696E6720434130820122300D06092A864886F70D01010105000382010F003082010A0282010100F8D3B31C7F0E11AF677707D30B314919CFD0FB4599B13ADB44F57FE5A89DDB32D771EA769D052EB78FFA9243C0A5F989D43719D7B6AAF09C86A5D825AC0E79283A7EE9D167D3C6FB2927C7D37B2394E4912396907782F9A18423661254335074B12826BB2469C2C252F214678A8945D42DA1A3E9882C2095AE1C4A8708DF0CF5E24D6018BEAAC4B2AE70316633713EAC70A2ABCE7FE97CCB92A1E53B311CCFEAF20AE457BB4AB5E974E62BFE6CCB7E7439360D90EFE4B54EA4A9EA6A0AAB84F3AC674EB5C4F78CD1202523EB08643E5296C1F20F12F4C58E0FC1A2E82C51F773BCBD85B1628373418207E4388B6A7320D00F64733C9E9FA633A9FD19DF2593D10203010001A38201CD308201C930120603551D130101FF040830060101FF020100300E0603551D0F0101FF04040302018630130603551D25040C300A06082B06010505070303307906082B06010505070101046D306B302406082B060105050730018618687474703A2F2F6F6373702E64696769636572742E636F6D304306082B060105050730028637687474703A2F2F636163657274732E64696769636572742E636F6D2F4469676943657274417373757265644944526F6F7443412E6372743081810603551D1F047A3078303AA038A0368634687474703A2F2F63726C342E64696769636572742E636F6D2F4469676943657274417373757265644944526F6F7443412E63726C303AA038A0368634687474703A2F2F63726C332E64696769636572742E636F6D2F4469676943657274417373757265644944526F6F7443412E63726C304F0603551D20044830463038060A6086480186FD6C000204302A302806082B06010505070201161C68747470733A2F2F7777772E64696769636572742E636F6D2F435053300A06086086480186FD6C03301D0603551D0E041604145AC4B97B2A0AA3A5EA7103C060F92DF665750E58301F0603551D2304183016801445EBA2AFF492CB82312D518BA7A7219DF36DC80F300D06092A864886F70D01010B050003820101003EEC0D5A24B3F322D115C82C7C252976A81D5D1C2D3A1AC4EF3061D77E0B60FDC33D0FC4AF8BFDEF2ADF205537B0E1F6D192750F51B46EA58E5AE25E24814E10A4EE3F718E630E134BADD75F4479F33614068AF79C464E5CFF90B11B070E9115FBBAAFB551C28D24AE24C6C7272AA129281A3A7128023C2E91A3C02511E29C1447A17A6868AF9BA75C205CD971B10C8FBBA8F8C512689FCF40CB4044A513F0E6640C25084232B2368A2402FE2F727E1CD7494596E8591DE9FA74646BB2EB6643DAB3B08CD5E90DDDF60120CE9931633D081A18B3819B4FC6931006FC0781FA8BDAF98249F7626EA153FA129418852E9291EA686C4432B266A1E718A49A6451EF | |||
| (PID) Process: | (2204) FortiClientVPN.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\132\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2756 | FortiClientVPNOnlineInstaller_6.4.exe | C:\Users\admin\AppData\Local\Temp\obj_1_a01796 | — | |
MD5:— | SHA256:— | |||
| 2756 | FortiClientVPNOnlineInstaller_6.4.exe | C:\Users\admin\AppData\Local\Temp\obj_1_a01796__unpacked | — | |
MD5:— | SHA256:— | |||
| 2756 | FortiClientVPNOnlineInstaller_6.4.exe | C:\Users\admin\AppData\Local\Temp\FortiClientVPN.exe | — | |
MD5:— | SHA256:— | |||
| 2204 | FortiClientVPN.exe | C:\Users\admin\AppData\Local\Temp\{43C27CA2-E6FD-4931-AB77-C66F9B1F5946}\FortiClientVPN.msi | — | |
MD5:— | SHA256:— | |||
| 2204 | FortiClientVPN.exe | C:\ProgramData\Applications\Cache\{43C27CA2-E6FD-4931-AB77-C66F9B1F5946}\6.4.0.1464\FortiClientVPN.msi | — | |
MD5:— | SHA256:— | |||
| 2204 | FortiClientVPN.exe | C:\Users\admin\AppData\Local\Temp\MSI2AC7.tmp | — | |
MD5:— | SHA256:— | |||
| 2756 | FortiClientVPNOnlineInstaller_6.4.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2989C0A878FE45C610C8177194428257 | binary | |
MD5:— | SHA256:— | |||
| 2204 | FortiClientVPN.exe | C:\ProgramData\Applications\Cache\{43C27CA2-E6FD-4931-AB77-C66F9B1F5946}\6.4.0.1464\{43C27CA2-E6FD-4931-AB77-C66F9B1F5946}.mst | binary | |
MD5:— | SHA256:— | |||
| 2204 | FortiClientVPN.exe | C:\Users\admin\AppData\Local\Temp\{3254170D-993C-48E5-9BA4-52CB2F259DB3}.tmp | binary | |
MD5:— | SHA256:— | |||
| 2756 | FortiClientVPNOnlineInstaller_6.4.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2989C0A878FE45C610C8177194428257 | der | |
MD5:B656376C3D2ACEBBA18849D604361BD5 | SHA256:51044706BD237B91B89B781337E6D62656C69F0FCFFBE8E43741367948127862 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2756 | FortiClientVPNOnlineInstaller_6.4.exe | POST | 200 | 173.243.138.108:80 | http://173.243.138.108/fdsupdate | US | binary | 960 b | suspicious |
2756 | FortiClientVPNOnlineInstaller_6.4.exe | POST | 200 | 173.243.138.108:80 | http://173.243.138.108/fdsupdate | US | binary | 69.5 Mb | suspicious |
2756 | FortiClientVPNOnlineInstaller_6.4.exe | POST | 200 | 173.243.138.108:80 | http://173.243.138.108/fdsupdate | US | binary | 40.4 Kb | suspicious |
2756 | FortiClientVPNOnlineInstaller_6.4.exe | GET | 200 | 104.18.10.39:80 | http://cacerts.digicert.com/DigiCertSHA2AssuredIDCodeSigningCA.crt | US | der | 1.30 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2756 | FortiClientVPNOnlineInstaller_6.4.exe | 173.243.138.108:80 | forticlient.fortinet.net | Fortinet Inc. | US | suspicious |
— | — | 104.18.10.39:80 | cacerts.digicert.com | Cloudflare Inc | US | shared |
Domain | IP | Reputation |
|---|---|---|
forticlient.fortinet.net |
| suspicious |
cacerts.digicert.com |
| whitelisted |
Process | Message |
|---|---|
FortiClientVPN.exe | Trace/s: Do Install
|
FortiClientVPN.exe | Trace/s: call ProcessSetupChain
|