download:

qBittorrent.html

Full analysis: https://app.any.run/tasks/0e7e9dd1-df53-4c2e-ab21-d2813d263121
Verdict: Malicious activity
Analysis date: August 05, 2019, 04:29:47
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: text/html
File info: HTML document, UTF-8 Unicode text, with very long lines
MD5:

510CB7FE88E8829774BA9333ABE6F72A

SHA1:

487007C6B3EC1D20D9CA4957CB7F4DCD2AE6CF28

SHA256:

0BFCDFCC93322166AA3A17811FEEAC2559EE04648366173EC1BF4F953BF5EA5A

SSDEEP:

1536:wzGDHSMGIwIRnXlIII26tFfL7BlKRVJz9WTYJ/x80EK9vTprJtoMz+rOvrFElMF8:wQXIEoPbo1+Z

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • qbittorrent_4.1.7_x64_setup.exe (PID: 2764)
      • qbittorrent_4.1.7_x64_setup.exe (PID: 2288)
      • qbittorrent_4.1.7_setup.exe (PID: 456)
      • qbittorrent_4.1.7_setup.exe (PID: 3840)
    • Application was dropped or rewritten from another process

      • qbittorrent_4.1.7_x64_setup.exe (PID: 2764)
      • qbittorrent_4.1.7_x64_setup.exe (PID: 2288)
      • qbittorrent_4.1.7_setup.exe (PID: 3840)
      • qbittorrent_4.1.7_setup.exe (PID: 456)
      • qbittorrent.exe (PID: 2620)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • chrome.exe (PID: 2380)
      • chrome.exe (PID: 3752)
      • qbittorrent_4.1.7_x64_setup.exe (PID: 2764)
      • qbittorrent_4.1.7_x64_setup.exe (PID: 2288)
      • chrome.exe (PID: 2308)
      • chrome.exe (PID: 916)
      • qbittorrent_4.1.7_setup.exe (PID: 3840)
      • qbittorrent_4.1.7_setup.exe (PID: 456)
    • Modifies files in Chrome extension folder

      • chrome.exe (PID: 3752)
    • Application launched itself

      • qbittorrent_4.1.7_x64_setup.exe (PID: 2764)
      • qbittorrent_4.1.7_setup.exe (PID: 3840)
    • Modifies the open verb of a shell class

      • qbittorrent_4.1.7_setup.exe (PID: 456)
      • qbittorrent_4.1.7_setup.exe (PID: 3840)
    • Creates a software uninstall entry

      • qbittorrent_4.1.7_setup.exe (PID: 456)
    • Creates files in the user directory

      • qbittorrent.exe (PID: 2620)
    • Creates files in the program directory

      • qbittorrent_4.1.7_setup.exe (PID: 456)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 1568)
      • chrome.exe (PID: 3752)
      • chrome.exe (PID: 2308)
    • Reads internet explorer settings

      • iexplore.exe (PID: 1992)
    • Changes internet zones settings

      • iexplore.exe (PID: 1568)
    • Manual execution by user

      • chrome.exe (PID: 3752)
      • chrome.exe (PID: 2308)
    • Reads Internet Cache Settings

      • chrome.exe (PID: 3752)
      • chrome.exe (PID: 2308)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.html | HyperText Markup Language (100)

EXIF

HTML

ContentType: text/html; charset=utf-8
HTTPEquivXUACompatible: IE=Edge
appleMobileWebAppCapable: yes
appleMobileWebAppStatusBarStyle: #033465
appleMobileWebAppTitle: FOSSHUB
appleMobileWebAppOrientations: portrait-any
formatDetection: date=no
viewport: user-scalable=no,initial-scale=1,maximum-scale=1,minimum-scale=1,width=device-width,height=device-height
language: en-US
Author: FOSSHUB
Distribution: global
Rating: safe for kids
dctermsRightsHolder: FOSSHUB
dctermsRights: All rights reserved.
dctermsDateCopyrighted: 2018
version: 1.0.2
Title: Download qBittorrent Free Software.
Description: Free, Open-Source, cross-platform torrent client based on the Qt toolkit and libtorrent-rasterbar library.
Abstract: Security Software Download.
Keywords: torrent, manager, alternative, Qt toolkit, libtorrent-rasterbar
news_keywords: torrent, manager, alternative, Qt toolkit, libtorrent-rasterbar
referrer: origin
Robots: index, follow
RevisitAfter: 1 day
themeColor: #ffffff
twitterCard: summary
twitterSite: @Foss_Hub
twitterCreator: @Foss_Hub
twitterDescription: Free, Open-Source, cross-platform torrent client based on the Qt toolkit and libtorrent-rasterbar library.
twitterTitle: qBittorrent
applicationName: FOSSHUB
msapplicationNavbuttonColor: #2b5797
msapplicationTileColor: #2b5797
msapplicationTileImage: qBittorrent
msapplicationTooltip: qBittorrent: Free software download for windows, linux, osx.
msapplicationWindow: width=1280;height=800
msapplicationSquare70x70logo: /media/favicon/mstile-70x70.png
msapplicationSquare150x150logo: /media/favicon/mstile-150x150.png
msapplicationWide310x150logo: /media/favicon/mstile-310x150.png
msapplicationSquare310x310logo: /media/favicon/mstile-310x310.png
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
91
Monitored processes
48
Malicious processes
7
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start iexplore.exe iexplore.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs qbittorrent_4.1.7_x64_setup.exe qbittorrent_4.1.7_x64_setup.exe chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs qbittorrent_4.1.7_setup.exe chrome.exe no specs qbittorrent_4.1.7_setup.exe qbittorrent.exe

Process information

PID
CMD
Path
Indicators
Parent process
276"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1036,2107547833900519239,14757768810025504302,131072 --enable-features=PasswordImport --gpu-preferences=KAAAAAAAAADgAAAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=5273248873501157299 --mojo-platform-channel-handle=1016 --ignored=" --type=renderer " /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
356"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=2876 --on-initialized-event-handle=312 --parent-handle=316 /prefetch:6C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
456"C:\Users\admin\Downloads\qbittorrent_4.1.7_setup.exe" /UAC:F01C2 /NCRC C:\Users\admin\Downloads\qbittorrent_4.1.7_setup.exe
qbittorrent_4.1.7_setup.exe
User:
admin
Company:
The qBittorrent project
Integrity Level:
HIGH
Description:
qBittorrent - A Bittorrent Client
Exit code:
0
Version:
4.1.7
Modules
Images
c:\users\admin\downloads\qbittorrent_4.1.7_setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
872"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1036,2107547833900519239,14757768810025504302,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=15730437143115757836 --mojo-platform-channel-handle=3356 --ignored=" --type=renderer " /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
900"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1036,2107547833900519239,14757768810025504302,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=5619904291624358441 --mojo-platform-channel-handle=3620 --ignored=" --type=renderer " /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
916"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1020,7792034887528170435,5955707041088931179,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=network --service-request-channel-token=3272876930818083432 --mojo-platform-channel-handle=1568 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1128"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1036,2107547833900519239,14757768810025504302,131072 --enable-features=PasswordImport --disable-gpu-sandbox --use-gl=disabled --gpu-preferences=KAAAAAAAAADgAAAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=5418743432392233312 --mojo-platform-channel-handle=2528 /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1344"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1020,7792034887528170435,5955707041088931179,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=14860661990741016247 --mojo-platform-channel-handle=3520 --ignored=" --type=renderer " /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1364"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1020,7792034887528170435,5955707041088931179,131072 --enable-features=PasswordImport --lang=en-US --no-sandbox --service-request-channel-token=16701940849319089298 --mojo-platform-channel-handle=3056 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1568"C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\admin\AppData\Local\Temp\qBittorrent.htmlC:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
2 791
Read events
2 538
Write events
243
Delete events
10

Modification events

(PID) Process:(1568) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(1568) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(1568) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(1568) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
Operation:writeName:SecuritySafe
Value:
1
(PID) Process:(1568) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(1568) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000092000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(1568) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
Operation:writeName:{B5210613-B739-11E9-9885-5254004A04AF}
Value:
0
(PID) Process:(1568) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Type
Value:
4
(PID) Process:(1568) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Count
Value:
2
(PID) Process:(1568) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Time
Value:
E30708000100050004001E000A00CB02
Executable files
21
Suspicious files
81
Text files
327
Unknown types
69

Dropped files

PID
Process
Filename
Type
1568iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\favicon[1].ico
MD5:
SHA256:
1568iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
1568iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF9878352669052551.TMP
MD5:
SHA256:
1568iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF972140D1AA5B0BC9.TMP
MD5:
SHA256:
1568iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF390F1F0EBE881D93.TMP
MD5:
SHA256:
3752chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\6215412d-2b10-4c69-9ed7-6882d4358432.tmp
MD5:
SHA256:
3752chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000020.dbtmp
MD5:
SHA256:
1568iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Last Active\{B5210616-B739-11E9-9885-5254004A04AF}.datbinary
MD5:
SHA256:
3752chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.oldtext
MD5:
SHA256:
3752chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.oldtext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
303
DNS requests
35
Threats
24

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2380
chrome.exe
GET
302
172.217.22.14:80
http://redirector.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvOWVmQUFXS041NV9ZVXlJVWwxbGc5TUM4dw/7519.422.0.3_pkedcjkdefgpdelpbcmbmeomcjbeemfm.crx
US
html
514 b
whitelisted
2620
qbittorrent.exe
GET
176.31.225.118:80
http://tracker.trackerfix.com/announce?info_hash=%23(%f8%9dU%d28%099%9e%f7-%0c%ad%a7J%0ey%f7%3a&peer_id=-qB4170-_lF0.qv(lo!b&port=8999&uploaded=0&downloaded=0&left=16384&corrupt=0&key=FEDB2163&event=started&numwant=200&compact=1&no_peer_id=1&supportcrypto=1&redundant=0
FR
suspicious
2620
qbittorrent.exe
GET
176.31.225.118:80
http://tracker.trackerfix.com/announce?info_hash=%23(%f8%9dU%d28%099%9e%f7-%0c%ad%a7J%0ey%f7%3a&peer_id=-qB4170-vPJO7P0*dXZ2&port=8999&uploaded=0&downloaded=0&left=278241037&corrupt=0&key=A65E37CF&event=started&numwant=200&compact=1&no_peer_id=1&supportcrypto=1&redundant=0
FR
suspicious
2380
chrome.exe
GET
200
173.194.139.6:80
http://r1---sn-aigzrn7k.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvOWVmQUFXS041NV9ZVXlJVWwxbGc5TUM4dw/7519.422.0.3_pkedcjkdefgpdelpbcmbmeomcjbeemfm.crx?cms_redirect=yes&mip=185.43.110.12&mm=28&mn=sn-aigzrn7k&ms=nvh&mt=1564979356&mv=m&mvi=0&pl=23&shardbypass=yes
US
crx
862 Kb
whitelisted
2620
qbittorrent.exe
GET
176.31.225.118:80
http://tracker.trackerfix.com/announce?info_hash=%23(%f8%9dU%d28%099%9e%f7-%0c%ad%a7J%0ey%f7%3a&peer_id=-qB4170-_lF0.qv(lo!b&port=8999&uploaded=0&downloaded=0&left=16384&corrupt=0&key=FEDB2163&event=started&numwant=200&compact=1&no_peer_id=1&supportcrypto=1&redundant=0
FR
suspicious
1568
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
104.19.196.151:445
cdnjs.cloudflare.com
Cloudflare Inc
US
shared
4
System
104.19.195.151:445
cdnjs.cloudflare.com
Cloudflare Inc
US
shared
4
System
104.19.197.151:445
cdnjs.cloudflare.com
Cloudflare Inc
US
shared
2380
chrome.exe
172.217.23.131:443
clientservices.googleapis.com
Google Inc.
US
whitelisted
4
System
104.19.195.151:139
cdnjs.cloudflare.com
Cloudflare Inc
US
shared
2380
chrome.exe
172.217.23.173:443
accounts.google.com
Google Inc.
US
whitelisted
2380
chrome.exe
172.217.18.10:443
fonts.googleapis.com
Google Inc.
US
whitelisted
2380
chrome.exe
172.217.22.99:443
www.google.com.ua
Google Inc.
US
whitelisted
4
System
104.19.198.151:445
cdnjs.cloudflare.com
Cloudflare Inc
US
shared
1568
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted

DNS requests

Domain
IP
Reputation
cdnjs.cloudflare.com
  • 104.19.196.151
  • 104.19.197.151
  • 104.19.198.151
  • 104.19.199.151
  • 104.19.195.151
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
clientservices.googleapis.com
  • 172.217.23.131
whitelisted
accounts.google.com
  • 172.217.23.173
shared
www.google.com.ua
  • 172.217.22.99
whitelisted
fonts.googleapis.com
  • 172.217.18.10
whitelisted
www.gstatic.com
  • 172.217.16.131
whitelisted
fonts.gstatic.com
  • 172.217.16.163
whitelisted
apis.google.com
  • 172.217.22.110
whitelisted
clients2.google.com
  • 172.217.22.46
whitelisted

Threats

PID
Process
Class
Message
Potential Corporate Privacy Violation
ET P2P BitTorrent DHT ping request
Potential Corporate Privacy Violation
ET P2P Vuze BT UDP Connection (5)
1064
svchost.exe
Potentially Bad Traffic
ET DNS Query for .to TLD
2620
qbittorrent.exe
Potential Corporate Privacy Violation
GPL P2P BitTorrent announce request
2620
qbittorrent.exe
Potential Corporate Privacy Violation
GPL P2P BitTorrent announce request
2620
qbittorrent.exe
Potential Corporate Privacy Violation
GPL P2P BitTorrent transfer
2620
qbittorrent.exe
Potential Corporate Privacy Violation
ET P2P BitTorrent peer sync
2620
qbittorrent.exe
Potential Corporate Privacy Violation
ET P2P BitTorrent peer sync
2620
qbittorrent.exe
Potential Corporate Privacy Violation
GPL P2P BitTorrent announce request
2620
qbittorrent.exe
Potential Corporate Privacy Violation
ET P2P BitTorrent peer sync
Process
Message
qbittorrent.exe
QObject::startTimer: Timers cannot have negative intervals