File name:

btweb_installer.exe

Full analysis: https://app.any.run/tasks/0cf8c898-5655-4615-97ca-2c5627dcda06
Verdict: Malicious activity
Analysis date: September 30, 2024, 21:09:16
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

2E8317080C5C77ABB49E50A39AF5B422

SHA1:

A66808067A0E6C7DADFCB3E0CA29F63E12F1B654

SHA256:

060E08D028210F3597D2462A3B06F033E356575671D9DFE4DE2CDB521E635DF4

SSDEEP:

98304:B+cD4dnw2PXVUW33TWpPoDaO9Uus0tGL5sFhkLnehWJEVfltjtYedsvCIDoUdAyG:MfT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • btweb_installer.exe (PID: 2144)
      • w2obunan.exe (PID: 6688)
      • component0.exe (PID: 2876)
      • btweb_installer.exe (PID: 6956)
      • btweb_install_rr.exe (PID: 4540)
      • btweb_installer.tmp (PID: 3568)
      • UnifiedStub-installer.exe (PID: 1256)
    • Process drops legitimate windows executable

      • btweb_install_rr.exe (PID: 4540)
      • w2obunan.exe (PID: 6688)
      • UnifiedStub-installer.exe (PID: 1256)
    • Reads security settings of Internet Explorer

      • btweb_installer.tmp (PID: 5276)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • btweb_install_rr.exe (PID: 4540)
    • Executes as Windows Service

      • rsSyncSvc.exe (PID: 4712)
    • Drops a system driver (possible attempt to evade defenses)

      • UnifiedStub-installer.exe (PID: 1256)
    • The process drops C-runtime libraries

      • UnifiedStub-installer.exe (PID: 1256)
    • Drops 7-zip archiver for unpacking

      • UnifiedStub-installer.exe (PID: 1256)
    • Executes application which crashes

      • btweb_installer.tmp (PID: 3568)
  • INFO

    • Checks supported languages

      • btweb_installer.exe (PID: 6956)
      • btweb_installer.exe (PID: 2144)
      • btweb_installer.tmp (PID: 5276)
    • Create files in a temporary directory

      • btweb_installer.exe (PID: 6956)
      • btweb_installer.tmp (PID: 3568)
      • btweb_installer.exe (PID: 2144)
    • Process checks computer location settings

      • btweb_installer.tmp (PID: 5276)
    • Reads the computer name

      • btweb_installer.tmp (PID: 5276)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 101376
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 1.5.0.8795
ProductVersionNumber: 1.5.0.8795
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: BitTorrent Web®
FileVersion: 1.5.0.8795
LegalCopyright: ©2022 RainBerry Inc. All Rights Reserved
OriginalFileName:
ProductName: BitTorrent Web®
ProductVersion: 1.5.0.8795
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
146
Monitored processes
13
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start btweb_installer.exe btweb_installer.tmp no specs btweb_installer.exe btweb_installer.tmp btweb_install_rr.exe component0.exe w2obunan.exe unifiedstub-installer.exe rssyncsvc.exe no specs conhost.exe no specs rssyncsvc.exe no specs werfault.exe werfault.exe

Process information

PID
CMD
Path
Indicators
Parent process
1256.\UnifiedStub-installer.exe /silentC:\Users\admin\AppData\Local\Temp\7zS02A2BA8F\UnifiedStub-installer.exe
w2obunan.exe
User:
admin
Company:
Reason Software Company Inc.
Integrity Level:
HIGH
Description:
UnifiedStub
Version:
6.0.6
Modules
Images
c:\users\admin\appdata\local\temp\7zs02a2ba8f\unifiedstub-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1848\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exersSyncSvc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2036C:\WINDOWS\SysWOW64\WerFault.exe -u -p 3568 -s 1780C:\Windows\SysWOW64\WerFault.exe
btweb_installer.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
2144"C:\Users\admin\AppData\Local\Temp\btweb_installer.exe" /SPAWNWND=$1B03DC /NOTIFYWND=$A03F0 C:\Users\admin\AppData\Local\Temp\btweb_installer.exe
btweb_installer.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
BitTorrent Web®
Exit code:
3221226525
Version:
1.5.0.8795
Modules
Images
c:\users\admin\appdata\local\temp\btweb_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
2876"C:\Users\admin\AppData\Local\Temp\is-7JJO9.tmp\component0.exe" -ip:"dui=bb926e54-e3ca-40fd-ae90-2764341e7792&dit=20240930210924&is_silent=true&oc=ZB_RAV_Cross_Tri_NCB&p=123d&a=100&b=&se=true" -vp:"dui=bb926e54-e3ca-40fd-ae90-2764341e7792&dit=20240930210924&oc=ZB_RAV_Cross_Tri_NCB&p=123d&a=100&oip=26&ptl=7&dta=true" -dp:"dui=bb926e54-e3ca-40fd-ae90-2764341e7792&dit=20240930210924&oc=ZB_RAV_Cross_Tri_NCB&p=123d&a=100" -i -v -d -se=trueC:\Users\admin\AppData\Local\Temp\is-7JJO9.tmp\component0.exe
btweb_installer.tmp
User:
admin
Company:
Reason Software Company Inc.
Integrity Level:
HIGH
Description:
rsStubActivator
Version:
1.6.1.0
Modules
Images
c:\users\admin\appdata\local\temp\is-7jjo9.tmp\component0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3188C:\WINDOWS\SysWOW64\WerFault.exe -u -p 3568 -s 1776C:\Windows\SysWOW64\WerFault.exe
btweb_installer.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
3568"C:\Users\admin\AppData\Local\Temp\is-MF7EA.tmp\btweb_installer.tmp" /SL5="$A039A,2193577,844288,C:\Users\admin\AppData\Local\Temp\btweb_installer.exe" /SPAWNWND=$1B03DC /NOTIFYWND=$A03F0 C:\Users\admin\AppData\Local\Temp\is-MF7EA.tmp\btweb_installer.tmp
btweb_installer.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
3221226525
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-mf7ea.tmp\btweb_installer.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
4540"C:\Users\admin\AppData\Local\Temp\is-7JJO9.tmp\btweb_install_rr.exe" /SC:\Users\admin\AppData\Local\Temp\is-7JJO9.tmp\btweb_install_rr.exe
btweb_installer.tmp
User:
admin
Company:
BitTorrent Limited
Integrity Level:
HIGH
Description:
BitTorrent Web
Exit code:
0
Version:
1.4.0.5871
Modules
Images
c:\users\admin\appdata\local\temp\is-7jjo9.tmp\btweb_install_rr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4712"C:\Program Files\ReasonLabs\Common\rsSyncSvc.exe" -pn:EPP -lpn:rav_antivirus -url:https://update.reasonsecurity.com/v2/live -bn:ReasonLabs -dt:10C:\Program Files\ReasonLabs\Common\rsSyncSvc.exeservices.exe
User:
SYSTEM
Company:
Reason Software Company Inc.
Integrity Level:
SYSTEM
Description:
Reason Security Synchronize Service
Version:
1.8.5.0
Modules
Images
c:\program files\reasonlabs\common\rssyncsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
5244"C:\Program Files\ReasonLabs\Common\rsSyncSvc.exe" -i -bn:ReasonLabs -pn:EPP -lpn:rav_antivirus -url:https://update.reasonsecurity.com/v2/live -dt:10C:\Program Files\ReasonLabs\Common\rsSyncSvc.exeUnifiedStub-installer.exe
User:
admin
Company:
Reason Software Company Inc.
Integrity Level:
HIGH
Description:
Reason Security Synchronize Service
Exit code:
0
Version:
1.8.5.0
Modules
Images
c:\program files\reasonlabs\common\rssyncsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
14 207
Read events
14 080
Write events
83
Delete events
44

Modification events

(PID) Process:(4540) btweb_install_rr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\btweb
Operation:writeName:UninstallString
Value:
"C:\Users\admin\AppData\Roaming\BitTorrent Web\Uninstall.exe"
(PID) Process:(4540) btweb_install_rr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\btweb
Operation:writeName:QuietUninstallString
Value:
"C:\Users\admin\AppData\Roaming\BitTorrent Web\Uninstall.exe" /S
(PID) Process:(4540) btweb_install_rr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\btweb
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Roaming\BitTorrent Web\uninstall.ico
(PID) Process:(4540) btweb_install_rr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\btweb
Operation:writeName:DisplayName
Value:
BitTorrent Web
(PID) Process:(4540) btweb_install_rr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\btweb
Operation:writeName:Publisher
Value:
BitTorrent Limited
(PID) Process:(4540) btweb_install_rr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\btweb
Operation:writeName:DisplayVersion
Value:
1.4.0
(PID) Process:(4540) btweb_install_rr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\btweb
Operation:writeName:NoModify
Value:
1
(PID) Process:(4540) btweb_install_rr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\btweb
Operation:writeName:NoRepair
Value:
1
(PID) Process:(4540) btweb_install_rr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(4540) btweb_install_rr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
Executable files
409
Suspicious files
91
Text files
41
Unknown types
5

Dropped files

PID
Process
Filename
Type
6956btweb_installer.exeC:\Users\admin\AppData\Local\Temp\is-KA6H4.tmp\btweb_installer.tmpexecutable
MD5:398B30ECE675AC5F192C8759747264CB
SHA256:66F73FE436210AF3FAE11D532439D51913A1D8C1D56D919049C8AFD3EA279F8E
3568btweb_installer.tmpC:\Users\admin\AppData\Local\Temp\is-7JJO9.tmp\license.rtftext
MD5:8A708BF775DE14E5FBB16F6077B454D5
SHA256:ECA753676C5C71D7BE141451CD6D1426A08ED5C254078BC585D9BA91395A971A
4540btweb_install_rr.exeC:\Users\admin\AppData\Local\Temp\nsz9FC8.tmp\UAC.dllexecutable
MD5:ADB29E6B186DAA765DC750128649B63D
SHA256:2F7F8FC05DC4FD0D5CDA501B47E4433357E887BBFED7292C028D99C73B52DC08
3568btweb_installer.tmpC:\Users\admin\AppData\Local\Temp\is-7JJO9.tmp\Logo.pngimage
MD5:A047D3C01D1E469C5543D2679955149C
SHA256:CF090DEB874784E26829BBE05131CA859C88102F74019FE1B0162A63B412087A
3568btweb_installer.tmpC:\Users\admin\AppData\Local\Temp\is-7JJO9.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
4540btweb_install_rr.exeC:\Users\admin\AppData\Roaming\BitTorrent Web\localization\fr.langtext
MD5:11A3F9F9D7F238D2B1E8D7699DBAFF02
SHA256:53656932C41719FCD2B809CC3FB84F40EC39DB344E527450D8A830E271E49A28
3568btweb_installer.tmpC:\Users\admin\AppData\Local\Temp\is-7JJO9.tmp\is-EITQB.tmpimage
MD5:CD09F361286D1AD2622BA8A57B7613BD
SHA256:B92A31D4853D1B2C4E5B9D9624F40B439856D0C6A517E100978CBDE8D3C47DC8
3568btweb_installer.tmpC:\Users\admin\AppData\Local\Temp\is-7JJO9.tmp\is-H9ACJ.tmpexecutable
MD5:10358117981A96AEB9130F56C575D5C0
SHA256:C77647A383542D7C7E6B08E5DA3F8358760FD030509AF840D01968DC845D7FB5
2144btweb_installer.exeC:\Users\admin\AppData\Local\Temp\is-MF7EA.tmp\btweb_installer.tmpexecutable
MD5:398B30ECE675AC5F192C8759747264CB
SHA256:66F73FE436210AF3FAE11D532439D51913A1D8C1D56D919049C8AFD3EA279F8E
4540btweb_install_rr.exeC:\Users\admin\AppData\Local\Temp\nsz9FC8.tmp\System.dllexecutable
MD5:CFF85C549D536F651D4FB8387F1976F2
SHA256:8DC562CDA7217A3A52DB898243DE3E2ED68B80E62DDCB8619545ED0B4E7F65A8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
78
DNS requests
27
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2120
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5920
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
7000
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7000
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4540
btweb_install_rr.exe
POST
200
52.2.97.28:80
http://i-4102.b-5871.btweb.bench.utorrent.com/e?i=4102
unknown
whitelisted
992
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
4540
btweb_install_rr.exe
POST
200
52.2.97.28:80
http://i-4102.b-5871.btweb.bench.utorrent.com/e?i=4102
unknown
whitelisted
2036
WerFault.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1256
UnifiedStub-installer.exe
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQ0NE46krjtIffEj0l00lckKsLufgQUJEWZoXeQKnzDyoOwbmQWhCr4LGcCEzMAAXxhE9usAbRsOHIAAAABfGE%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5000
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
3568
btweb_installer.tmp
18.245.62.11:443
da8h2uy5f6k8n.cloudfront.net
US
whitelisted
3568
btweb_installer.tmp
67.215.238.66:443
download-lb.utorrent.com
ASN-QUADRANET-GLOBAL
US
whitelisted
5000
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5920
svchost.exe
20.190.159.23:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
google.com
  • 142.250.185.206
whitelisted
da8h2uy5f6k8n.cloudfront.net
  • 18.245.62.11
  • 18.245.62.217
  • 18.245.62.189
  • 18.245.62.213
whitelisted
download-lb.utorrent.com
  • 67.215.238.66
whitelisted
login.live.com
  • 20.190.159.23
  • 40.126.31.67
  • 20.190.159.73
  • 20.190.159.4
  • 40.126.31.73
  • 20.190.159.2
  • 40.126.31.69
  • 20.190.159.64
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
shield.reasonsecurity.com
  • 18.172.112.22
  • 18.172.112.11
  • 18.172.112.38
  • 18.172.112.34
unknown

Threats

PID
Process
Class
Message
4540
btweb_install_rr.exe
Potentially Bad Traffic
ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla))
4540
btweb_install_rr.exe
Potentially Bad Traffic
ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla))
No debug info