download:

EpicGamesLauncherInstaller.msi

Full analysis: https://app.any.run/tasks/aceabcae-6ed5-489a-a573-b58996149c1f
Verdict: Malicious activity
Analysis date: February 03, 2019, 03:26:15
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Epic Games Launcher, Author: Epic Games, Inc., Keywords: Installer, Comments: This installer database contains the logic and data required to install Epic Games Launcher., Create Time/Date: Mon Oct 1 17:36:20 2018, Name of Creating Application: Windows Installer XML Toolset (3.8.1128.0), Security: 4, Template: Intel;1033,1042,1041,2052,1025,1031,1034,1036,1040,1045,1046,1049,1055, Last Saved By: Intel;1033,1042,1041,2052,1025,1031,1034,1036,1040,1045,1046,1049,1055, Revision Number: {0E63B233-DC24-442C-BD38-0B91D90FEC5B}1.1.167.0;{3D0533FC-387E-4032-8630-32AFBBC45770}1.1.167.0;{D0769F44-D459-450F-B084-CAE38062C75B}, Number of Pages: 405, Number of Characters: 0
MD5:

8B4F31FD2004DC56110D75C473223D4D

SHA1:

D608BFB4EEC073DF9A76CFE58877DCC86364D428

SHA256:

B72DBA5A5817D8D7E80F1CACC9CBD6CB51C97E6200FB0255603A3B07E5E2B80D

SSDEEP:

786432:DyxZMTunmx0OTP4GOXDh901UBN1oARZ10LNBQ/OY4:DyxUx0OTPlOY16LwLAR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • rundll32.exe (PID: 800)
      • rundll32.exe (PID: 2760)
      • DXSETUP.exe (PID: 3836)
    • Application was dropped or rewritten from another process

      • DXSETUP.exe (PID: 3836)
  • SUSPICIOUS

    • Uses RUNDLL32.EXE to load library

      • MsiExec.exe (PID: 3256)
      • MsiExec.exe (PID: 3864)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 3984)
      • rundll32.exe (PID: 2760)
      • msiexec.exe (PID: 3588)
    • Searches for installed software

      • DXSETUP.exe (PID: 3836)
      • DllHost.exe (PID: 612)
    • Creates files in the Windows directory

      • DXSETUP.exe (PID: 3836)
    • Modifies the open verb of a shell class

      • msiexec.exe (PID: 3588)
  • INFO

    • Application launched itself

      • msiexec.exe (PID: 3588)
    • Loads dropped or rewritten executable

      • MsiExec.exe (PID: 3256)
      • MsiExec.exe (PID: 3864)
    • Dropped object may contain Bitcoin addresses

      • msiexec.exe (PID: 3588)
    • Low-level read access rights to disk partition

      • vssvc.exe (PID: 3420)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 3588)
    • Creates files in the program directory

      • msiexec.exe (PID: 3588)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (95.3)
.doc | Microsoft Word document (old ver.) (3.2)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CodePage: Windows Latin 1 (Western European)
Title: Installation Database
Subject: Epic Games Launcher
Author: Epic Games, Inc.
Keywords: Installer
Comments: This installer database contains the logic and data required to install Epic Games Launcher.
Template: Intel;1033,1042,1041,2052,1025,1031,1034,1036,1040,1045,1046,1049,1055
RevisionNumber: {C8BBEC99-0936-4125-8774-7CB89871A72D}
CreateDate: 2018:10:01 16:32:32
ModifyDate: 2018:10:01 16:32:32
Pages: 405
Words: 2
Software: Windows Installer XML Toolset (3.8.1128.0)
Security: Read-only enforced
LastModifiedBy: Intel;1033,1042,1041,2052,1025,1031,1034,1036,1040,1045,1046,1049,1055
Characters: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
9
Malicious processes
2
Suspicious processes
4

Behavior graph

Click at the process to see the details
start drop and start msiexec.exe msiexec.exe msiexec.exe no specs rundll32.exe no specs msiexec.exe no specs rundll32.exe dxsetup.exe vssvc.exe no specs SPPSurrogate no specs

Process information

PID
CMD
Path
Indicators
Parent process
612C:\Windows\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801}C:\Windows\system32\DllHost.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
800rundll32.exe "C:\Users\admin\AppData\Local\Temp\MSID2C4.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_2413250 5 CustomActionManaged!CustomActionManaged.CustomActions.ValidatePathLengthC:\Windows\system32\rundll32.exeMsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2760rundll32.exe "C:\Windows\Installer\MSID88F.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_2414734 9 CustomActionManaged!CustomActionManaged.CustomActions.TelemetrySendStartC:\Windows\system32\rundll32.exe
MsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
3256C:\Windows\system32\MsiExec.exe -Embedding 7427C1B6F496FC38B6865C51C9A01B59 CC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3420C:\Windows\system32\vssvc.exeC:\Windows\system32\vssvc.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3588C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
3836"C:\Program Files\Epic Games\DirectXRedist\DXSETUP.exe" /silentC:\Program Files\Epic Games\DirectXRedist\DXSETUP.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft DirectX Setup
Exit code:
0
Version:
4.9.0.0904
Modules
Images
c:\program files\epic games\directxredist\dxsetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3864C:\Windows\system32\MsiExec.exe -Embedding 6BD47DA32571F329E127BBA70EE2C0A4C:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3984"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\EpicGamesLauncherInstaller.msi"C:\Windows\System32\msiexec.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
4 016
Read events
541
Write events
3 475
Delete events
0

Modification events

(PID) Process:(3984) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3588) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000_CLASSES\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3588) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
040E0000465C695670BBD401
(PID) Process:(3588) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
A1E0E6EDD15A7FA94F7F3C27CE4C2A69C5B7DD6D8E906F35FE25238F3732F5F2
(PID) Process:(3588) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(2760) rundll32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\rundll32_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(2760) rundll32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\rundll32_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(2760) rundll32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\rundll32_RASAPI32
Operation:writeName:FileTracingMask
Value:
4294901760
(PID) Process:(2760) rundll32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\rundll32_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
4294901760
(PID) Process:(2760) rundll32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\rundll32_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
Executable files
100
Suspicious files
2 695
Text files
376
Unknown types
27

Dropped files

PID
Process
Filename
Type
3984msiexec.exeC:\Users\admin\AppData\Local\Temp\MSIB4E9.tmp
MD5:
SHA256:
3984msiexec.exeC:\Users\admin\AppData\Local\Temp\MSID2B3.tmp
MD5:
SHA256:
800rundll32.exeC:\Users\admin\AppData\Local\Temp\MSID2C4.tmp-\CustomActionManaged.dll
MD5:
SHA256:
800rundll32.exeC:\Users\admin\AppData\Local\Temp\MSID2C4.tmp-\Microsoft.Deployment.WindowsInstaller.dll
MD5:
SHA256:
800rundll32.exeC:\Users\admin\AppData\Local\Temp\MSID2C4.tmp-\CustomAction.config
MD5:
SHA256:
3588msiexec.exeC:\Windows\Installer\24d429.msi
MD5:
SHA256:
3588msiexec.exeC:\Windows\Installer\MSID821.tmp
MD5:
SHA256:
2760rundll32.exeC:\Users\admin\AppData\Local\Temp\CabDD70.tmp
MD5:
SHA256:
2760rundll32.exeC:\Users\admin\AppData\Local\Temp\TarDD71.tmp
MD5:
SHA256:
2760rundll32.exeC:\Users\admin\AppData\Local\Temp\CabDDA1.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
3
DNS requests
3
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2760
rundll32.exe
GET
200
52.222.146.184:80
http://x.ss2.us/x.cer
US
der
1.27 Kb
whitelisted
2760
rundll32.exe
GET
200
104.107.217.217:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
NL
compressed
55.2 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2760
rundll32.exe
52.200.123.101:443
datarouter.ol.epicgames.com
Amazon.com, Inc.
US
unknown
2760
rundll32.exe
52.222.146.184:80
x.ss2.us
Amazon.com, Inc.
US
whitelisted
2760
rundll32.exe
104.107.217.217:80
www.download.windowsupdate.com
Akamai International B.V.
NL
whitelisted

DNS requests

Domain
IP
Reputation
datarouter.ol.epicgames.com
  • 52.200.123.101
  • 52.87.18.159
  • 34.230.183.16
  • 18.235.124.39
  • 52.22.81.26
  • 52.4.127.66
  • 34.194.135.124
  • 54.208.92.41
unknown
x.ss2.us
  • 52.222.146.184
  • 52.222.146.187
  • 52.222.146.19
  • 52.222.146.226
whitelisted
www.download.windowsupdate.com
  • 104.107.217.217
  • 104.107.217.239
whitelisted

Threats

No threats detected
Process
Message
DXSETUP.exe
DLL_PROCESS_ATTACH
DXSETUP.exe
DLL_PROCESS_ATTACH