| download: | EpicGamesLauncherInstaller.msi |
| Full analysis: | https://app.any.run/tasks/aceabcae-6ed5-489a-a573-b58996149c1f |
| Verdict: | Malicious activity |
| Analysis date: | February 03, 2019, 03:26:15 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Epic Games Launcher, Author: Epic Games, Inc., Keywords: Installer, Comments: This installer database contains the logic and data required to install Epic Games Launcher., Create Time/Date: Mon Oct 1 17:36:20 2018, Name of Creating Application: Windows Installer XML Toolset (3.8.1128.0), Security: 4, Template: Intel;1033,1042,1041,2052,1025,1031,1034,1036,1040,1045,1046,1049,1055, Last Saved By: Intel;1033,1042,1041,2052,1025,1031,1034,1036,1040,1045,1046,1049,1055, Revision Number: {0E63B233-DC24-442C-BD38-0B91D90FEC5B}1.1.167.0;{3D0533FC-387E-4032-8630-32AFBBC45770}1.1.167.0;{D0769F44-D459-450F-B084-CAE38062C75B}, Number of Pages: 405, Number of Characters: 0 |
| MD5: | 8B4F31FD2004DC56110D75C473223D4D |
| SHA1: | D608BFB4EEC073DF9A76CFE58877DCC86364D428 |
| SHA256: | B72DBA5A5817D8D7E80F1CACC9CBD6CB51C97E6200FB0255603A3B07E5E2B80D |
| SSDEEP: | 786432:DyxZMTunmx0OTP4GOXDh901UBN1oARZ10LNBQ/OY4:DyxUx0OTPlOY16LwLAR |
| .msi | | | Microsoft Windows Installer (95.3) |
|---|---|---|
| .doc | | | Microsoft Word document (old ver.) (3.2) |
| .msi | | | Microsoft Installer (100) |
| CodePage: | Windows Latin 1 (Western European) |
|---|---|
| Title: | Installation Database |
| Subject: | Epic Games Launcher |
| Author: | Epic Games, Inc. |
| Keywords: | Installer |
| Comments: | This installer database contains the logic and data required to install Epic Games Launcher. |
| Template: | Intel;1033,1042,1041,2052,1025,1031,1034,1036,1040,1045,1046,1049,1055 |
| RevisionNumber: | {C8BBEC99-0936-4125-8774-7CB89871A72D} |
| CreateDate: | 2018:10:01 16:32:32 |
| ModifyDate: | 2018:10:01 16:32:32 |
| Pages: | 405 |
| Words: | 2 |
| Software: | Windows Installer XML Toolset (3.8.1128.0) |
| Security: | Read-only enforced |
| LastModifiedBy: | Intel;1033,1042,1041,2052,1025,1031,1034,1036,1040,1045,1046,1049,1055 |
| Characters: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 612 | C:\Windows\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801} | C:\Windows\system32\DllHost.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: COM Surrogate Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 800 | rundll32.exe "C:\Users\admin\AppData\Local\Temp\MSID2C4.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_2413250 5 CustomActionManaged!CustomActionManaged.CustomActions.ValidatePathLength | C:\Windows\system32\rundll32.exe | — | MsiExec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2760 | rundll32.exe "C:\Windows\Installer\MSID88F.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_2414734 9 CustomActionManaged!CustomActionManaged.CustomActions.TelemetrySendStart | C:\Windows\system32\rundll32.exe | MsiExec.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3256 | C:\Windows\system32\MsiExec.exe -Embedding 7427C1B6F496FC38B6865C51C9A01B59 C | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3420 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3588 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3836 | "C:\Program Files\Epic Games\DirectXRedist\DXSETUP.exe" /silent | C:\Program Files\Epic Games\DirectXRedist\DXSETUP.exe | msiexec.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft DirectX Setup Exit code: 0 Version: 4.9.0.0904 Modules
| |||||||||||||||
| 3864 | C:\Windows\system32\MsiExec.exe -Embedding 6BD47DA32571F329E127BBA70EE2C0A4 | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3984 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\EpicGamesLauncherInstaller.msi" | C:\Windows\System32\msiexec.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3984) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3588) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000_CLASSES\Local Settings\MuiCache\5F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3588) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: 040E0000465C695670BBD401 | |||
| (PID) Process: | (3588) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: A1E0E6EDD15A7FA94F7F3C27CE4C2A69C5B7DD6D8E906F35FE25238F3732F5F2 | |||
| (PID) Process: | (3588) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (2760) rundll32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\rundll32_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (2760) rundll32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\rundll32_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (2760) rundll32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\rundll32_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: 4294901760 | |||
| (PID) Process: | (2760) rundll32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\rundll32_RASAPI32 |
| Operation: | write | Name: | ConsoleTracingMask |
Value: 4294901760 | |||
| (PID) Process: | (2760) rundll32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\rundll32_RASAPI32 |
| Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3984 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSIB4E9.tmp | — | |
MD5:— | SHA256:— | |||
| 3984 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSID2B3.tmp | — | |
MD5:— | SHA256:— | |||
| 800 | rundll32.exe | C:\Users\admin\AppData\Local\Temp\MSID2C4.tmp-\CustomActionManaged.dll | — | |
MD5:— | SHA256:— | |||
| 800 | rundll32.exe | C:\Users\admin\AppData\Local\Temp\MSID2C4.tmp-\Microsoft.Deployment.WindowsInstaller.dll | — | |
MD5:— | SHA256:— | |||
| 800 | rundll32.exe | C:\Users\admin\AppData\Local\Temp\MSID2C4.tmp-\CustomAction.config | — | |
MD5:— | SHA256:— | |||
| 3588 | msiexec.exe | C:\Windows\Installer\24d429.msi | — | |
MD5:— | SHA256:— | |||
| 3588 | msiexec.exe | C:\Windows\Installer\MSID821.tmp | — | |
MD5:— | SHA256:— | |||
| 2760 | rundll32.exe | C:\Users\admin\AppData\Local\Temp\CabDD70.tmp | — | |
MD5:— | SHA256:— | |||
| 2760 | rundll32.exe | C:\Users\admin\AppData\Local\Temp\TarDD71.tmp | — | |
MD5:— | SHA256:— | |||
| 2760 | rundll32.exe | C:\Users\admin\AppData\Local\Temp\CabDDA1.tmp | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2760 | rundll32.exe | GET | 200 | 52.222.146.184:80 | http://x.ss2.us/x.cer | US | der | 1.27 Kb | whitelisted |
2760 | rundll32.exe | GET | 200 | 104.107.217.217:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | NL | compressed | 55.2 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2760 | rundll32.exe | 52.200.123.101:443 | datarouter.ol.epicgames.com | Amazon.com, Inc. | US | unknown |
2760 | rundll32.exe | 52.222.146.184:80 | x.ss2.us | Amazon.com, Inc. | US | whitelisted |
2760 | rundll32.exe | 104.107.217.217:80 | www.download.windowsupdate.com | Akamai International B.V. | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
datarouter.ol.epicgames.com |
| unknown |
x.ss2.us |
| whitelisted |
www.download.windowsupdate.com |
| whitelisted |
Process | Message |
|---|---|
DXSETUP.exe | DLL_PROCESS_ATTACH |
DXSETUP.exe | DLL_PROCESS_ATTACH |