FortiClientInstaller.exe

FortiClient Online Installation

Fortinet Technologies

This is a setup and installation application. The file has been seen being downloaded from dw.uptodown.com and multiple other hosts.
Publisher:
Fortinet Inc.  (signed by Fortinet Technologies)

Product:
FortiClient Online Installation

Version:
5.0.6.320

MD5:
a31eb8b4e284f4b4f196c6b4a0097e44

SHA-1:
4231883dc74835580663cc43adcd55b22fcd5495

SHA-256:
16563ad5d8c4ce71236c2fa2ceb7f40bda5adba42be99fb6d05644a2837d5d5c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/20/2024 5:07:14 AM UTC  (today)

File size:
487 KB (498,648 bytes)

Product version:
5.0.6.320

Copyright:
2013 Fortinet Inc. All rights reserved.

Original file name:
FortiClientInstaller.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\forticlientinstaller.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/18/2012 1:00:00 AM

Valid to:
8/22/2015 12:59:59 AM

Subject:
CN=Fortinet Technologies, OU=R&D, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Fortinet Technologies, L=Burnaby, S=British Columbia, C=CA

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
068A8678E09F4B3B5F74EB749451C6

File PE Metadata
Compilation timestamp:
10/1/2013 10:32:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:OQ4Tq2+oQuQKjiH0louKWHAFwpTpBU073FEggkUpRgnZ3:OQ4W29QuQKeUlodv1gnZ3

Entry address:
0xF4EB0

Entry point:
60, BE, 00, 70, 4C, 00, 8D, BE, 00, A0, F3, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Packer / compiler:
UPX 2.90LZMA]

Code size:
188 KB (192,512 bytes)

The file FortiClientInstaller.exe has been seen being distributed by the following 18 URLs.

https://dw.uptodown.com/dwn/BYe1-o7MtKuhnTQmNfM8sY-d1ZJ7E20q4kXlX0RMW1ZYqMptzyjY6ScfLCCFObf7cM5gdqqUN2GEUle2prpk59N0d5U3zd1H1o5PRok_4rB3HrnOr-DL5U8sTJWu5jWV/JhsIq8o4TyXdbAQKsQgyAEiom1LweWilKr6FTp0tAFhY-6FIzAFZLqTBzce5ngYDjqdgbQf69Eo3TrsiCA1xswy37Y61KMxHZAWUJPBnJ1BrtCyBHzDTwcTTiaOUmHW-/82MGfqMTEdq6eMMsW5uTXFBtzDqykAT_aUmKqWlLDLU4w7vGouEjVwVJwZbkbfrJr_B88nxpJfwsheDEXzLFH3hYSH76qTrhelbzCB-P0pLslLS44Uh0gtvX_SDnw1wg/.../

https://dw.uptodown.com/dwn/o6oez4FeHOt6V_ViTBb5myeP4r04R-A7_rcv6vJNM6ThrwaJP-9X7RCpAODrSfMh_m45OfxsJmIDtrfJwCd_tyd3Q-gZ6XMs0lk6NSTmCKTOA0VdLZu5sRibkBMLg9F4/PVk-hzv4pYWBauBWLBwLUuCjtXsU7XXr0-6zUkVWSLLczfyLTyboHJQkwDb0NZ7GcG_mPaYQEuB4AuwL96WOxYSoMWGXeGBiSl02hqYo4mpcjZZOg2w2xk19ETlSJB08/qjRzBscnyALGqcX9fuHgTKMLv-MXPglMGmh79ccoSLlcV0r0jQrr1QjN9hkHI9_phh_0-l6N_sjbsIHPqmT8XD1S0kyr9AUAUiX3uj0VMBvxUkFy4nCeWzXL0syVHlAl/.../

ftp://82.80.134.3/VPN ?”?×?§? ?”/.../FortiClientInstaller.exe

https://wrb01.asuswebstorage.com/webrelay/directdownload/.../?dis=10014&fi=1874208151

http://350.co.il/FortiClient.exe

https://dw.uptodown.com/dwn/MIlqjRvpS3slZmjQVvUzbbYFAkWi-VHKHfDqe6cS7XAaBg7H71KCKIQX8dgM7eJWp6xyb95CrZXLW3bX0w4nEG5J6I6pgKNpVRGpTTcWMZdrkzPeEbdYSWenT8YaZ1r1/b6miCMG8vFZgb2GZg3YedR8FK5LJMq3C8vQrPltasDcIT6Yt3WbOf6c6Ztud4LBtqdFV2LsBo2Enl9OZmTz1co0zzvyWXgVenrzIwV0PPz7mhKKwImMMsChJDJSXc2BW/yLqv5FqE3SDloBmF38IV9yN5Odg8Vgck84AeMUXyuZXs86uGfIQyrOWuQhe67pua3bJpwuWm_qyPEUs5IPIU8sgNr6jCnaGZOSwPWqvTIKAsnFxFbYNbHd4F0l6CfxHF/.../

https://dw.uptodown.com/dwn/MEpSps6VFULEHnOsrj9r0CscLsIcfE8peReb7sKv-fgc8vFE4iNNaWOLt4ximixj7jx3vM6XirDLZKMWdiHuFIWk8OlgRTL2JB81GafkW5xYlZUPMOFhl4oifVBy6S1_/MYU2d3DyiCtw3Pw-prJnouDhL3eUURJ4SManjjqlOEgyphgFWo6eLyRMHmzVTq297PHx0dzsrHtzuIaAoa_gWuxmua3-Kgg1BPr3pPxFIjFE0R2ktMemmC3II5QvgjC2/t9SFfyksYgkRqzqP_Rsx-2fPBjfYxcXI1zlUEZSdLob1gu-S-w3DUjsXXiGXFUPT3wOqucz4z5UYnJNNpDCTXIjlSgS0kBCh9P1AKrsF6KnIH4TuWs5JjtQ0dMjHzSI6/.../

http://www.download.hr/go.php?file=w10938&code=d1x4j6c0u2y9h7c4m6f0