File name:

FortiClientVPNOnlineInstaller.exe

Full analysis: https://app.any.run/tasks/297d33d8-0229-491c-8b45-5ae393c88dde
Verdict: Malicious activity
Analysis date: September 11, 2024, 22:28:28
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

9BFA08538F94A78395B116666E90606B

SHA1:

9C62F61ABDED758772DA22C16F825CDF40F00F92

SHA256:

D4BA0B587CCCC005BC37AD17817FC4DBD123D357EB34DDF6B1DD63FA57343F2F

SSDEEP:

98304:rvs0mnezVX9ZVXtE8A8srb9DC1a5L5hEipkrOJpj0+sFeG6weI/d11be5053/mPl:tOA1Vtg3

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • FortiClientVPNOnlineInstaller.exe (PID: 6296)
      • FortiClientVPNOnlineInstaller.exe (PID: 4976)
      • FortiClientVPN.exe (PID: 4404)
    • Application launched itself

      • FortiClientVPNOnlineInstaller.exe (PID: 6296)
    • Creates/Modifies COM task schedule object

      • FortiClientVPNOnlineInstaller.exe (PID: 4976)
      • msiexec.exe (PID: 1964)
    • Connects to the server without a host name

      • FortiClientVPNOnlineInstaller.exe (PID: 4976)
    • Checks Windows Trust Settings

      • FortiClientVPNOnlineInstaller.exe (PID: 4976)
      • FortiClientVPN.exe (PID: 4404)
      • msiexec.exe (PID: 1964)
      • drvinst.exe (PID: 2268)
      • drvinst.exe (PID: 6200)
      • drvinst.exe (PID: 5116)
      • msiexec.exe (PID: 4672)
    • Executable content was dropped or overwritten

      • FortiClientVPN.exe (PID: 4404)
      • drvinst.exe (PID: 2268)
      • drvinst.exe (PID: 304)
      • drvinst.exe (PID: 6976)
      • drvinst.exe (PID: 5116)
      • drvinst.exe (PID: 6200)
    • Reads the Windows owner or organization settings

      • FortiClientVPN.exe (PID: 4404)
      • msiexec.exe (PID: 1964)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 1964)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 1964)
    • The process creates files with name similar to system file names

      • msiexec.exe (PID: 1964)
    • Creates files in the driver directory

      • drvinst.exe (PID: 2268)
      • msiexec.exe (PID: 4672)
      • msiexec.exe (PID: 1964)
      • drvinst.exe (PID: 6976)
      • drvinst.exe (PID: 5116)
      • drvinst.exe (PID: 6200)
    • Drops a system driver (possible attempt to evade defenses)

      • drvinst.exe (PID: 2268)
      • msiexec.exe (PID: 1964)
      • drvinst.exe (PID: 5116)
      • drvinst.exe (PID: 6200)
    • Creates or modifies Windows services

      • drvinst.exe (PID: 304)
      • drvinst.exe (PID: 6976)
    • Adds/modifies Windows certificates

      • msiexec.exe (PID: 4672)
  • INFO

    • Checks supported languages

      • FortiClientVPNOnlineInstaller.exe (PID: 6296)
      • FortiClientVPNOnlineInstaller.exe (PID: 4976)
      • msiexec.exe (PID: 1964)
      • msiexec.exe (PID: 488)
      • FortiClientVPN.exe (PID: 4404)
      • msiexec.exe (PID: 6532)
      • msiexec.exe (PID: 4672)
      • FortiClientInstaller.exe (PID: 5988)
      • drvinst.exe (PID: 2268)
      • drvinst.exe (PID: 304)
      • drvinst.exe (PID: 6200)
      • drvinst.exe (PID: 6976)
      • drvinst.exe (PID: 5116)
    • Create files in a temporary directory

      • FortiClientVPNOnlineInstaller.exe (PID: 6296)
      • FortiClientVPNOnlineInstaller.exe (PID: 4976)
      • FortiClientVPN.exe (PID: 4404)
      • FortiClientInstaller.exe (PID: 5988)
    • The process uses the downloaded file

      • FortiClientVPNOnlineInstaller.exe (PID: 6296)
    • Process checks whether UAC notifications are on

      • FortiClientVPNOnlineInstaller.exe (PID: 6296)
    • Reads the computer name

      • FortiClientVPNOnlineInstaller.exe (PID: 6296)
      • FortiClientVPNOnlineInstaller.exe (PID: 4976)
      • FortiClientVPN.exe (PID: 4404)
      • msiexec.exe (PID: 1964)
      • msiexec.exe (PID: 488)
      • FortiClientInstaller.exe (PID: 5988)
      • msiexec.exe (PID: 6532)
      • msiexec.exe (PID: 4672)
      • drvinst.exe (PID: 2268)
      • drvinst.exe (PID: 304)
      • drvinst.exe (PID: 6200)
      • drvinst.exe (PID: 6976)
      • drvinst.exe (PID: 5116)
    • Process checks computer location settings

      • FortiClientVPNOnlineInstaller.exe (PID: 6296)
    • Reads the software policy settings

      • FortiClientVPNOnlineInstaller.exe (PID: 4976)
      • FortiClientVPN.exe (PID: 4404)
      • msiexec.exe (PID: 1964)
      • drvinst.exe (PID: 2268)
      • drvinst.exe (PID: 6200)
      • drvinst.exe (PID: 5116)
      • msiexec.exe (PID: 4672)
    • Checks proxy server information

      • FortiClientVPNOnlineInstaller.exe (PID: 4976)
    • Reads the machine GUID from the registry

      • FortiClientVPNOnlineInstaller.exe (PID: 4976)
      • FortiClientVPN.exe (PID: 4404)
      • msiexec.exe (PID: 1964)
      • drvinst.exe (PID: 2268)
      • drvinst.exe (PID: 5116)
      • drvinst.exe (PID: 6200)
      • msiexec.exe (PID: 4672)
    • Creates files in the program directory

      • FortiClientVPN.exe (PID: 4404)
    • Creates files or folders in the user directory

      • FortiClientVPNOnlineInstaller.exe (PID: 4976)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 1964)
    • Reads Environment values

      • msiexec.exe (PID: 6532)
      • msiexec.exe (PID: 488)
    • Application launched itself

      • msiexec.exe (PID: 1964)
    • Manual execution by a user

      • FortiClientInstaller.exe (PID: 5988)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 1964)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:10:04 15:30:59+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.36
CodeSize: 3064320
InitializedDataSize: 1102336
UninitializedDataSize: -
EntryPoint: 0xe36b0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
148
Monitored processes
15
Malicious processes
7
Suspicious processes
3

Behavior graph

Click at the process to see the details
start forticlientvpnonlineinstaller.exe no specs forticlientvpnonlineinstaller.exe rundll32.exe no specs Shell Security Editor no specs forticlientvpn.exe msiexec.exe msiexec.exe no specs forticlientinstaller.exe no specs msiexec.exe no specs msiexec.exe no specs drvinst.exe drvinst.exe drvinst.exe drvinst.exe drvinst.exe

Process information

PID
CMD
Path
Indicators
Parent process
304DrvInst.exe "2" "201" "ROOT\NET\0000" "C:\WINDOWS\INF\oem1.inf" "oem1.inf:3205552c47487a89:FTNT.ndi:2020.4.9.0:root\ftvnic_a," "41304937f" "00000000000000EC"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
488C:\Windows\System32\MsiExec.exe -Embedding B8F0CC6D24E96C92153B1BC7186FCB2B CC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1964C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2268DrvInst.exe "4" "1" "C:\Program Files\Common Files\Fortinet\FortiClient\ftvnic\ft_vnic.inf" "9" "43d6f8a63" "00000000000001CC" "WinSta0\Default" "00000000000001DC" "208" "C:\Program Files\Common Files\Fortinet\FortiClient\ftvnic"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
2492C:\WINDOWS\system32\DllHost.exe /Processid:{4D111E08-CBF7-4F12-A926-2C7920AF52FC}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
3332C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
4404C:\Users\admin\AppData\Local\Temp\FortiClientVPN.exeC:\Users\admin\AppData\Local\Temp\FortiClientVPN.exe
FortiClientVPNOnlineInstaller.exe
User:
admin
Company:
Fortinet Inc.
Integrity Level:
HIGH
Description:
FortiClient Installer
Version:
7.2.5.1053
Modules
Images
c:\users\admin\appdata\local\temp\forticlientvpn.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
4672C:\Windows\System32\MsiExec.exe -Embedding 32CA1C49927F6F21D474A19CFB7675E9 E Global\MSI0000C:\Windows\System32\msiexec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4976"C:\Users\admin\AppData\Local\Temp\FortiClientVPNOnlineInstaller.exe" C:\Users\admin\AppData\Local\Temp\FortiClientVPNOnlineInstaller.exe
FortiClientVPNOnlineInstaller.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\appdata\local\temp\forticlientvpnonlineinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ncrypt.dll
5116DrvInst.exe "4" "1" "C:\Program Files\Common Files\Fortinet\FortiClient\FortiFilter\FortiFilter.inf" "9" "449c87ebf" "00000000000001EC" "WinSta0\Default" "000000000000020C" "208" "C:\Program Files\Common Files\Fortinet\FortiClient\FortiFilter"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
Total events
27 999
Read events
26 973
Write events
1 005
Delete events
21

Modification events

(PID) Process:(4976) FortiClientVPNOnlineInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{8052F904-874D-4d28-9380-AA9BDBF13AFD}\InProcServer32
Operation:writeName:ThreadingModel
Value:
diskcopy.dll
(PID) Process:(4976) FortiClientVPNOnlineInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{8052F904-874D-4d28-9380-AA9BDBF13AFD}\InProcServer32
Operation:writeName:AppID
Value:
{2AEFE8E0-3FE6-42C7-869D-FAE4E3C1635E}
(PID) Process:(4404) FortiClientVPN.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{618736E0-3C3D-11CF-810C-00AA00389B71}\TypeLib
Operation:writeName:Version
Value:
1.1
(PID) Process:(4404) FortiClientVPN.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{618736E0-3C3D-11CF-810C-00AA00389B71}\TypeLib
Operation:writeName:Version
Value:
1.1
(PID) Process:(4404) FortiClientVPN.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Volatile\00\MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{03022430-ABC4-11D0-BDE2-00AA001A1953}\TypeLib
Operation:writeName:Version
Value:
1.1
(PID) Process:(4404) FortiClientVPN.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{03022430-ABC4-11D0-BDE2-00AA001A1953}\TypeLib
Operation:writeName:Version
Value:
1.1
(PID) Process:(1964) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
AC0700005C5095229A04DB01
(PID) Process:(1964) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
15C3523769DD0FE7D8EF701C803580D17BA3B24B1F24D89A0D7E1B38F3646A6F
(PID) Process:(1964) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(1964) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Config.Msi\
Value:
Executable files
215
Suspicious files
113
Text files
11
Unknown types
5

Dropped files

PID
Process
Filename
Type
4976FortiClientVPNOnlineInstaller.exeC:\Users\admin\AppData\Local\Temp\FortiClientVPN.exe
MD5:
SHA256:
4404FortiClientVPN.exeC:\Users\admin\AppData\Local\Temp\FCT_{625BC4BA-AC3E-4E4B-9996-EEED9D4287C3}\{D06E7ED1-0713-4068-8B34-44FD7B456822}\FortiClient.msi
MD5:
SHA256:
4404FortiClientVPN.exeC:\ProgramData\Applications\Cache\{0A2534F7-66F2-41DF-86A8-CBC5776C82D7}\7.2.5.1053\FortiClient.msi
MD5:
SHA256:
5988FortiClientInstaller.exeC:\Users\admin\AppData\Local\Temp\FCTInstall.log
MD5:
SHA256:
1964msiexec.exeC:\Windows\Installer\14e07b.msi
MD5:
SHA256:
4404FortiClientVPN.exeC:\Users\admin\AppData\Local\Temp\FCT_{625BC4BA-AC3E-4E4B-9996-EEED9D4287C3}\{D06E7ED1-0713-4068-8B34-44FD7B456822}\configuration.xmlxml
MD5:EA8A176DBAAA5CC38807513FC8E82F7C
SHA256:0B9D879350811936414F744CD253F967AF3F64D1636730BB9DAEBBF28238E36C
4404FortiClientVPN.exeC:\Users\admin\AppData\Local\Temp\~DFB6867A51155AA859.TMPgmc
MD5:BF619EAC0CDF3F68D496EA9344137E8B
SHA256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
4404FortiClientVPN.exeC:\Users\admin\AppData\Local\Temp\FCT_{625BC4BA-AC3E-4E4B-9996-EEED9D4287C3}\{D06E7ED1-0713-4068-8B34-44FD7B456822}\orchestrator.jsonbinary
MD5:0C65A97CBC59D31BF3C3AE961A704B04
SHA256:FF2F2DE6F37B9F664DD41320F0E808CF7E31175AB0FECE2013BF67512E919037
4976FortiClientVPNOnlineInstaller.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8EC9B1D0ABBD7F98B401D425828828CE_C8DC9B0584977A543F76D6BA952A7E66der
MD5:DA1B2457EB6E7798AE7D7C6C9F5DDE03
SHA256:BB8B14021F58CD8CD3101EE944F1BCE0CF7596AC2ECFC3B3DDE43569063E7D49
4976FortiClientVPNOnlineInstaller.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8EC9B1D0ABBD7F98B401D425828828CE_C8DC9B0584977A543F76D6BA952A7E66binary
MD5:39B9C2A98C44AE9B4A1EB7F8E956CB6B
SHA256:4E1BA3D0AB5DD28B86CB9A4DD108DA2DAFA3D61ED8927F8E4E606C06A6E4BAD8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
44
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4976
FortiClientVPNOnlineInstaller.exe
POST
200
208.184.237.75:80
http://208.184.237.75/fdsupdate
unknown
unknown
4976
FortiClientVPNOnlineInstaller.exe
POST
200
173.243.138.76:80
http://173.243.138.76/fdsupdate
unknown
unknown
7072
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1440
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4976
FortiClientVPNOnlineInstaller.exe
POST
200
173.243.138.76:80
http://173.243.138.76/fdsupdate
unknown
unknown
2456
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2456
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4976
FortiClientVPNOnlineInstaller.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
4976
FortiClientVPNOnlineInstaller.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEA8ZK8C1K2FOF0Q2W4wIAOc%3D
unknown
whitelisted
4976
FortiClientVPNOnlineInstaller.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
7072
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6020
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4976
FortiClientVPNOnlineInstaller.exe
208.184.237.75:80
forticlient.fortinet.net
FORTINET
US
whitelisted
4976
FortiClientVPNOnlineInstaller.exe
173.243.138.76:80
forticlient.fortinet.net
FORTINET
US
whitelisted
7072
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
7072
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2120
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3260
svchost.exe
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.124.78.146
  • 20.73.194.208
whitelisted
google.com
  • 142.250.186.78
whitelisted
forticlient.fortinet.net
  • 208.184.237.75
  • 173.243.138.76
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
login.live.com
  • 40.126.32.72
  • 20.190.160.17
  • 40.126.32.74
  • 40.126.32.76
  • 20.190.160.22
  • 40.126.32.138
  • 20.190.160.20
  • 40.126.32.133
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
slscr.update.microsoft.com
  • 20.114.59.183
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.166.126.56
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted

Threats

No threats detected
No debug info