| File name: | FortiClientVPNOnlineInstaller.exe |
| Full analysis: | https://app.any.run/tasks/297d33d8-0229-491c-8b45-5ae393c88dde |
| Verdict: | Malicious activity |
| Analysis date: | September 11, 2024, 22:28:28 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 9BFA08538F94A78395B116666E90606B |
| SHA1: | 9C62F61ABDED758772DA22C16F825CDF40F00F92 |
| SHA256: | D4BA0B587CCCC005BC37AD17817FC4DBD123D357EB34DDF6B1DD63FA57343F2F |
| SSDEEP: | 98304:rvs0mnezVX9ZVXtE8A8srb9DC1a5L5hEipkrOJpj0+sFeG6weI/d11be5053/mPl:tOA1Vtg3 |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:10:04 15:30:59+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.36 |
| CodeSize: | 3064320 |
| InitializedDataSize: | 1102336 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xe36b0 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 304 | DrvInst.exe "2" "201" "ROOT\NET\0000" "C:\WINDOWS\INF\oem1.inf" "oem1.inf:3205552c47487a89:FTNT.ndi:2020.4.9.0:root\ftvnic_a," "41304937f" "00000000000000EC" | C:\Windows\System32\drvinst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 488 | C:\Windows\System32\MsiExec.exe -Embedding B8F0CC6D24E96C92153B1BC7186FCB2B C | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1964 | C:\WINDOWS\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2268 | DrvInst.exe "4" "1" "C:\Program Files\Common Files\Fortinet\FortiClient\ftvnic\ft_vnic.inf" "9" "43d6f8a63" "00000000000001CC" "WinSta0\Default" "00000000000001DC" "208" "C:\Program Files\Common Files\Fortinet\FortiClient\ftvnic" | C:\Windows\System32\drvinst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2492 | C:\WINDOWS\system32\DllHost.exe /Processid:{4D111E08-CBF7-4F12-A926-2C7920AF52FC} | C:\Windows\System32\dllhost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3332 | C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding | C:\Windows\System32\rundll32.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4404 | C:\Users\admin\AppData\Local\Temp\FortiClientVPN.exe | C:\Users\admin\AppData\Local\Temp\FortiClientVPN.exe | FortiClientVPNOnlineInstaller.exe | ||||||||||||
User: admin Company: Fortinet Inc. Integrity Level: HIGH Description: FortiClient Installer Version: 7.2.5.1053 Modules
| |||||||||||||||
| 4672 | C:\Windows\System32\MsiExec.exe -Embedding 32CA1C49927F6F21D474A19CFB7675E9 E Global\MSI0000 | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4976 | "C:\Users\admin\AppData\Local\Temp\FortiClientVPNOnlineInstaller.exe" | C:\Users\admin\AppData\Local\Temp\FortiClientVPNOnlineInstaller.exe | FortiClientVPNOnlineInstaller.exe | ||||||||||||
User: admin Integrity Level: HIGH Modules
| |||||||||||||||
| 5116 | DrvInst.exe "4" "1" "C:\Program Files\Common Files\Fortinet\FortiClient\FortiFilter\FortiFilter.inf" "9" "449c87ebf" "00000000000001EC" "WinSta0\Default" "000000000000020C" "208" "C:\Program Files\Common Files\Fortinet\FortiClient\FortiFilter" | C:\Windows\System32\drvinst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (4976) FortiClientVPNOnlineInstaller.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{8052F904-874D-4d28-9380-AA9BDBF13AFD}\InProcServer32 |
| Operation: | write | Name: | ThreadingModel |
Value: diskcopy.dll | |||
| (PID) Process: | (4976) FortiClientVPNOnlineInstaller.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{8052F904-874D-4d28-9380-AA9BDBF13AFD}\InProcServer32 |
| Operation: | write | Name: | AppID |
Value: {2AEFE8E0-3FE6-42C7-869D-FAE4E3C1635E} | |||
| (PID) Process: | (4404) FortiClientVPN.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{618736E0-3C3D-11CF-810C-00AA00389B71}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.1 | |||
| (PID) Process: | (4404) FortiClientVPN.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{618736E0-3C3D-11CF-810C-00AA00389B71}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.1 | |||
| (PID) Process: | (4404) FortiClientVPN.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Volatile\00\MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{03022430-ABC4-11D0-BDE2-00AA001A1953}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.1 | |||
| (PID) Process: | (4404) FortiClientVPN.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{03022430-ABC4-11D0-BDE2-00AA001A1953}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.1 | |||
| (PID) Process: | (1964) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: AC0700005C5095229A04DB01 | |||
| (PID) Process: | (1964) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: 15C3523769DD0FE7D8EF701C803580D17BA3B24B1F24D89A0D7E1B38F3646A6F | |||
| (PID) Process: | (1964) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (1964) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders |
| Operation: | write | Name: | C:\Config.Msi\ |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4976 | FortiClientVPNOnlineInstaller.exe | C:\Users\admin\AppData\Local\Temp\FortiClientVPN.exe | — | |
MD5:— | SHA256:— | |||
| 4404 | FortiClientVPN.exe | C:\Users\admin\AppData\Local\Temp\FCT_{625BC4BA-AC3E-4E4B-9996-EEED9D4287C3}\{D06E7ED1-0713-4068-8B34-44FD7B456822}\FortiClient.msi | — | |
MD5:— | SHA256:— | |||
| 4404 | FortiClientVPN.exe | C:\ProgramData\Applications\Cache\{0A2534F7-66F2-41DF-86A8-CBC5776C82D7}\7.2.5.1053\FortiClient.msi | — | |
MD5:— | SHA256:— | |||
| 5988 | FortiClientInstaller.exe | C:\Users\admin\AppData\Local\Temp\FCTInstall.log | — | |
MD5:— | SHA256:— | |||
| 1964 | msiexec.exe | C:\Windows\Installer\14e07b.msi | — | |
MD5:— | SHA256:— | |||
| 4404 | FortiClientVPN.exe | C:\Users\admin\AppData\Local\Temp\FCT_{625BC4BA-AC3E-4E4B-9996-EEED9D4287C3}\{D06E7ED1-0713-4068-8B34-44FD7B456822}\configuration.xml | xml | |
MD5:EA8A176DBAAA5CC38807513FC8E82F7C | SHA256:0B9D879350811936414F744CD253F967AF3F64D1636730BB9DAEBBF28238E36C | |||
| 4404 | FortiClientVPN.exe | C:\Users\admin\AppData\Local\Temp\~DFB6867A51155AA859.TMP | gmc | |
MD5:BF619EAC0CDF3F68D496EA9344137E8B | SHA256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560 | |||
| 4404 | FortiClientVPN.exe | C:\Users\admin\AppData\Local\Temp\FCT_{625BC4BA-AC3E-4E4B-9996-EEED9D4287C3}\{D06E7ED1-0713-4068-8B34-44FD7B456822}\orchestrator.json | binary | |
MD5:0C65A97CBC59D31BF3C3AE961A704B04 | SHA256:FF2F2DE6F37B9F664DD41320F0E808CF7E31175AB0FECE2013BF67512E919037 | |||
| 4976 | FortiClientVPNOnlineInstaller.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8EC9B1D0ABBD7F98B401D425828828CE_C8DC9B0584977A543F76D6BA952A7E66 | der | |
MD5:DA1B2457EB6E7798AE7D7C6C9F5DDE03 | SHA256:BB8B14021F58CD8CD3101EE944F1BCE0CF7596AC2ECFC3B3DDE43569063E7D49 | |||
| 4976 | FortiClientVPNOnlineInstaller.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8EC9B1D0ABBD7F98B401D425828828CE_C8DC9B0584977A543F76D6BA952A7E66 | binary | |
MD5:39B9C2A98C44AE9B4A1EB7F8E956CB6B | SHA256:4E1BA3D0AB5DD28B86CB9A4DD108DA2DAFA3D61ED8927F8E4E606C06A6E4BAD8 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4976 | FortiClientVPNOnlineInstaller.exe | POST | 200 | 208.184.237.75:80 | http://208.184.237.75/fdsupdate | unknown | — | — | unknown |
4976 | FortiClientVPNOnlineInstaller.exe | POST | 200 | 173.243.138.76:80 | http://173.243.138.76/fdsupdate | unknown | — | — | unknown |
7072 | svchost.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
1440 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
4976 | FortiClientVPNOnlineInstaller.exe | POST | 200 | 173.243.138.76:80 | http://173.243.138.76/fdsupdate | unknown | — | — | unknown |
2456 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
2456 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
4976 | FortiClientVPNOnlineInstaller.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D | unknown | — | — | whitelisted |
4976 | FortiClientVPNOnlineInstaller.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEA8ZK8C1K2FOF0Q2W4wIAOc%3D | unknown | — | — | whitelisted |
4976 | FortiClientVPNOnlineInstaller.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
7072 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6020 | RUXIMICS.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2120 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4976 | FortiClientVPNOnlineInstaller.exe | 208.184.237.75:80 | forticlient.fortinet.net | FORTINET | US | whitelisted |
4976 | FortiClientVPNOnlineInstaller.exe | 173.243.138.76:80 | forticlient.fortinet.net | FORTINET | US | whitelisted |
7072 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
7072 | svchost.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
2120 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3260 | svchost.exe | 40.115.3.253:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
forticlient.fortinet.net |
| whitelisted |
www.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
go.microsoft.com |
| whitelisted |