| File name: | btweb_installer.exe |
| Full analysis: | https://app.any.run/tasks/0cf8c898-5655-4615-97ca-2c5627dcda06 |
| Verdict: | Malicious activity |
| Analysis date: | September 30, 2024, 21:09:16 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 2E8317080C5C77ABB49E50A39AF5B422 |
| SHA1: | A66808067A0E6C7DADFCB3E0CA29F63E12F1B654 |
| SHA256: | 060E08D028210F3597D2462A3B06F033E356575671D9DFE4DE2CDB521E635DF4 |
| SSDEEP: | 98304:B+cD4dnw2PXVUW33TWpPoDaO9Uus0tGL5sFhkLnehWJEVfltjtYedsvCIDoUdAyG:MfT |
| .exe | | | Inno Setup installer (67.7) |
|---|---|---|
| .exe | | | Win32 EXE PECompact compressed (generic) (25.6) |
| .exe | | | Win32 Executable (generic) (2.7) |
| .exe | | | Win16/32 Executable Delphi generic (1.2) |
| .exe | | | Generic Win/DOS Executable (1.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:02:15 14:54:16+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 741888 |
| InitializedDataSize: | 101376 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xb5eec |
| OSVersion: | 6.1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 6.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.5.0.8795 |
| ProductVersionNumber: | 1.5.0.8795 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | |
| FileDescription: | BitTorrent Web® |
| FileVersion: | 1.5.0.8795 |
| LegalCopyright: | ©2022 RainBerry Inc. All Rights Reserved |
| OriginalFileName: | |
| ProductName: | BitTorrent Web® |
| ProductVersion: | 1.5.0.8795 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1256 | .\UnifiedStub-installer.exe /silent | C:\Users\admin\AppData\Local\Temp\7zS02A2BA8F\UnifiedStub-installer.exe | w2obunan.exe | ||||||||||||
User: admin Company: Reason Software Company Inc. Integrity Level: HIGH Description: UnifiedStub Version: 6.0.6 Modules
| |||||||||||||||
| 1848 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | rsSyncSvc.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2036 | C:\WINDOWS\SysWOW64\WerFault.exe -u -p 3568 -s 1780 | C:\Windows\SysWOW64\WerFault.exe | btweb_installer.tmp | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Problem Reporting Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2144 | "C:\Users\admin\AppData\Local\Temp\btweb_installer.exe" /SPAWNWND=$1B03DC /NOTIFYWND=$A03F0 | C:\Users\admin\AppData\Local\Temp\btweb_installer.exe | btweb_installer.tmp | ||||||||||||
User: admin Company: Integrity Level: HIGH Description: BitTorrent Web® Exit code: 3221226525 Version: 1.5.0.8795 Modules
| |||||||||||||||
| 2876 | "C:\Users\admin\AppData\Local\Temp\is-7JJO9.tmp\component0.exe" -ip:"dui=bb926e54-e3ca-40fd-ae90-2764341e7792&dit=20240930210924&is_silent=true&oc=ZB_RAV_Cross_Tri_NCB&p=123d&a=100&b=&se=true" -vp:"dui=bb926e54-e3ca-40fd-ae90-2764341e7792&dit=20240930210924&oc=ZB_RAV_Cross_Tri_NCB&p=123d&a=100&oip=26&ptl=7&dta=true" -dp:"dui=bb926e54-e3ca-40fd-ae90-2764341e7792&dit=20240930210924&oc=ZB_RAV_Cross_Tri_NCB&p=123d&a=100" -i -v -d -se=true | C:\Users\admin\AppData\Local\Temp\is-7JJO9.tmp\component0.exe | btweb_installer.tmp | ||||||||||||
User: admin Company: Reason Software Company Inc. Integrity Level: HIGH Description: rsStubActivator Version: 1.6.1.0 Modules
| |||||||||||||||
| 3188 | C:\WINDOWS\SysWOW64\WerFault.exe -u -p 3568 -s 1776 | C:\Windows\SysWOW64\WerFault.exe | btweb_installer.tmp | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Problem Reporting Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3568 | "C:\Users\admin\AppData\Local\Temp\is-MF7EA.tmp\btweb_installer.tmp" /SL5="$A039A,2193577,844288,C:\Users\admin\AppData\Local\Temp\btweb_installer.exe" /SPAWNWND=$1B03DC /NOTIFYWND=$A03F0 | C:\Users\admin\AppData\Local\Temp\is-MF7EA.tmp\btweb_installer.tmp | btweb_installer.exe | ||||||||||||
User: admin Company: Integrity Level: HIGH Description: Setup/Uninstall Exit code: 3221226525 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 4540 | "C:\Users\admin\AppData\Local\Temp\is-7JJO9.tmp\btweb_install_rr.exe" /S | C:\Users\admin\AppData\Local\Temp\is-7JJO9.tmp\btweb_install_rr.exe | btweb_installer.tmp | ||||||||||||
User: admin Company: BitTorrent Limited Integrity Level: HIGH Description: BitTorrent Web Exit code: 0 Version: 1.4.0.5871 Modules
| |||||||||||||||
| 4712 | "C:\Program Files\ReasonLabs\Common\rsSyncSvc.exe" -pn:EPP -lpn:rav_antivirus -url:https://update.reasonsecurity.com/v2/live -bn:ReasonLabs -dt:10 | C:\Program Files\ReasonLabs\Common\rsSyncSvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Reason Software Company Inc. Integrity Level: SYSTEM Description: Reason Security Synchronize Service Version: 1.8.5.0 Modules
| |||||||||||||||
| 5244 | "C:\Program Files\ReasonLabs\Common\rsSyncSvc.exe" -i -bn:ReasonLabs -pn:EPP -lpn:rav_antivirus -url:https://update.reasonsecurity.com/v2/live -dt:10 | C:\Program Files\ReasonLabs\Common\rsSyncSvc.exe | — | UnifiedStub-installer.exe | |||||||||||
User: admin Company: Reason Software Company Inc. Integrity Level: HIGH Description: Reason Security Synchronize Service Exit code: 0 Version: 1.8.5.0 Modules
| |||||||||||||||
| (PID) Process: | (4540) btweb_install_rr.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\btweb |
| Operation: | write | Name: | UninstallString |
Value: "C:\Users\admin\AppData\Roaming\BitTorrent Web\Uninstall.exe" | |||
| (PID) Process: | (4540) btweb_install_rr.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\btweb |
| Operation: | write | Name: | QuietUninstallString |
Value: "C:\Users\admin\AppData\Roaming\BitTorrent Web\Uninstall.exe" /S | |||
| (PID) Process: | (4540) btweb_install_rr.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\btweb |
| Operation: | write | Name: | DisplayIcon |
Value: C:\Users\admin\AppData\Roaming\BitTorrent Web\uninstall.ico | |||
| (PID) Process: | (4540) btweb_install_rr.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\btweb |
| Operation: | write | Name: | DisplayName |
Value: BitTorrent Web | |||
| (PID) Process: | (4540) btweb_install_rr.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\btweb |
| Operation: | write | Name: | Publisher |
Value: BitTorrent Limited | |||
| (PID) Process: | (4540) btweb_install_rr.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\btweb |
| Operation: | write | Name: | DisplayVersion |
Value: 1.4.0 | |||
| (PID) Process: | (4540) btweb_install_rr.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\btweb |
| Operation: | write | Name: | NoModify |
Value: 1 | |||
| (PID) Process: | (4540) btweb_install_rr.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\btweb |
| Operation: | write | Name: | NoRepair |
Value: 1 | |||
| (PID) Process: | (4540) btweb_install_rr.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (4540) btweb_install_rr.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6956 | btweb_installer.exe | C:\Users\admin\AppData\Local\Temp\is-KA6H4.tmp\btweb_installer.tmp | executable | |
MD5:398B30ECE675AC5F192C8759747264CB | SHA256:66F73FE436210AF3FAE11D532439D51913A1D8C1D56D919049C8AFD3EA279F8E | |||
| 3568 | btweb_installer.tmp | C:\Users\admin\AppData\Local\Temp\is-7JJO9.tmp\license.rtf | text | |
MD5:8A708BF775DE14E5FBB16F6077B454D5 | SHA256:ECA753676C5C71D7BE141451CD6D1426A08ED5C254078BC585D9BA91395A971A | |||
| 4540 | btweb_install_rr.exe | C:\Users\admin\AppData\Local\Temp\nsz9FC8.tmp\UAC.dll | executable | |
MD5:ADB29E6B186DAA765DC750128649B63D | SHA256:2F7F8FC05DC4FD0D5CDA501B47E4433357E887BBFED7292C028D99C73B52DC08 | |||
| 3568 | btweb_installer.tmp | C:\Users\admin\AppData\Local\Temp\is-7JJO9.tmp\Logo.png | image | |
MD5:A047D3C01D1E469C5543D2679955149C | SHA256:CF090DEB874784E26829BBE05131CA859C88102F74019FE1B0162A63B412087A | |||
| 3568 | btweb_installer.tmp | C:\Users\admin\AppData\Local\Temp\is-7JJO9.tmp\_isetup\_setup64.tmp | executable | |
MD5:E4211D6D009757C078A9FAC7FF4F03D4 | SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95 | |||
| 4540 | btweb_install_rr.exe | C:\Users\admin\AppData\Roaming\BitTorrent Web\localization\fr.lang | text | |
MD5:11A3F9F9D7F238D2B1E8D7699DBAFF02 | SHA256:53656932C41719FCD2B809CC3FB84F40EC39DB344E527450D8A830E271E49A28 | |||
| 3568 | btweb_installer.tmp | C:\Users\admin\AppData\Local\Temp\is-7JJO9.tmp\is-EITQB.tmp | image | |
MD5:CD09F361286D1AD2622BA8A57B7613BD | SHA256:B92A31D4853D1B2C4E5B9D9624F40B439856D0C6A517E100978CBDE8D3C47DC8 | |||
| 3568 | btweb_installer.tmp | C:\Users\admin\AppData\Local\Temp\is-7JJO9.tmp\is-H9ACJ.tmp | executable | |
MD5:10358117981A96AEB9130F56C575D5C0 | SHA256:C77647A383542D7C7E6B08E5DA3F8358760FD030509AF840D01968DC845D7FB5 | |||
| 2144 | btweb_installer.exe | C:\Users\admin\AppData\Local\Temp\is-MF7EA.tmp\btweb_installer.tmp | executable | |
MD5:398B30ECE675AC5F192C8759747264CB | SHA256:66F73FE436210AF3FAE11D532439D51913A1D8C1D56D919049C8AFD3EA279F8E | |||
| 4540 | btweb_install_rr.exe | C:\Users\admin\AppData\Local\Temp\nsz9FC8.tmp\System.dll | executable | |
MD5:CFF85C549D536F651D4FB8387F1976F2 | SHA256:8DC562CDA7217A3A52DB898243DE3E2ED68B80E62DDCB8619545ED0B4E7F65A8 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2120 | MoUsoCoreWorker.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
5920 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5336 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
7000 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
7000 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
4540 | btweb_install_rr.exe | POST | 200 | 52.2.97.28:80 | http://i-4102.b-5871.btweb.bench.utorrent.com/e?i=4102 | unknown | — | — | whitelisted |
992 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
4540 | btweb_install_rr.exe | POST | 200 | 52.2.97.28:80 | http://i-4102.b-5871.btweb.bench.utorrent.com/e?i=4102 | unknown | — | — | whitelisted |
2036 | WerFault.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
1256 | UnifiedStub-installer.exe | GET | 200 | 204.79.197.203:80 | http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQ0NE46krjtIffEj0l00lckKsLufgQUJEWZoXeQKnzDyoOwbmQWhCr4LGcCEzMAAXxhE9usAbRsOHIAAAABfGE%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5000 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2120 | MoUsoCoreWorker.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3568 | btweb_installer.tmp | 18.245.62.11:443 | da8h2uy5f6k8n.cloudfront.net | — | US | whitelisted |
3568 | btweb_installer.tmp | 67.215.238.66:443 | download-lb.utorrent.com | ASN-QUADRANET-GLOBAL | US | whitelisted |
5000 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5920 | svchost.exe | 20.190.159.23:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
da8h2uy5f6k8n.cloudfront.net |
| whitelisted |
download-lb.utorrent.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
shield.reasonsecurity.com |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
4540 | btweb_install_rr.exe | Potentially Bad Traffic | ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla)) |
4540 | btweb_install_rr.exe | Potentially Bad Traffic | ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla)) |