URL:

http://llsw.download3.utorrent.com/3.5.5/utorrent.45790.installer.exe

Full analysis: https://app.any.run/tasks/72e6d313-dd09-4d17-ba14-97dfa261b7c8
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: October 04, 2020, 18:03:06
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
evasion
Indicators:
MD5:

9931E5E40A8EF5A66D04E50A9BC6E3D6

SHA1:

A41D64DFC0E97A8F700D50F12225738D6D73718E

SHA256:

11FE3A0B134714E8AA03D71637CE11CB96763B84C06562DD4568C40DAF30DFA5

SSDEEP:

3:N1KSJWSYLLDuRLKNLQLcWuRLWaXgXLNn:CSJVjRLwLQLcWuRLBXgXLN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • utorrent.45790.installer.exe (PID: 2480)
      • utorrent.45790.installer.exe (PID: 2488)
      • offer-91404593-1E1F-4BA6-8CB0-507560613B11.exe (PID: 1700)
      • uTorrent.exe (PID: 3976)
      • WebCompanionInstaller.exe (PID: 2292)
      • utorrentie.exe (PID: 3452)
      • utorrentie.exe (PID: 2376)
      • utorrentie.exe (PID: 2756)
      • helper.exe (PID: 3336)
      • WebCompanion.exe (PID: 2468)
    • Runs PING.EXE for delay simulation

      • mshta.exe (PID: 2628)
    • Changes the autorun value in the registry

      • mshta.exe (PID: 2628)
      • uTorrent.exe (PID: 3976)
      • WebCompanion.exe (PID: 2468)
    • Changes settings of System certificates

      • WebCompanionInstaller.exe (PID: 2292)
      • WebCompanion.exe (PID: 2468)
    • Downloads executable files from the Internet

      • uTorrent.exe (PID: 3976)
    • Changes internet zones settings

      • WebCompanionInstaller.exe (PID: 2292)
    • Loads dropped or rewritten executable

      • WebCompanion.exe (PID: 2468)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 824)
      • iexplore.exe (PID: 1336)
      • cscript.exe (PID: 2084)
      • mshta.exe (PID: 2628)
      • offer-91404593-1E1F-4BA6-8CB0-507560613B11.exe (PID: 1700)
      • uTorrent.exe (PID: 3976)
      • WebCompanionInstaller.exe (PID: 2292)
    • Creates files in the user directory

      • utorrent.45790.installer.exe (PID: 2480)
      • utorrent.45790.installer.exe (PID: 2488)
      • mshta.exe (PID: 2628)
      • uTorrent.exe (PID: 3976)
      • utorrentie.exe (PID: 3452)
      • utorrentie.exe (PID: 2376)
      • WebCompanionInstaller.exe (PID: 2292)
    • Starts MSHTA.EXE for opening HTA or HTMLS files

      • utorrent.45790.installer.exe (PID: 2480)
    • Executes scripts

      • mshta.exe (PID: 2628)
    • Reads Internet Cache Settings

      • utorrent.45790.installer.exe (PID: 2488)
      • utorrent.45790.installer.exe (PID: 2480)
      • mshta.exe (PID: 2628)
      • uTorrent.exe (PID: 3976)
      • utorrentie.exe (PID: 3452)
      • utorrentie.exe (PID: 2376)
      • utorrentie.exe (PID: 2756)
    • Application launched itself

      • utorrent.45790.installer.exe (PID: 2488)
    • Modifies the open verb of a shell class

      • mshta.exe (PID: 2628)
      • uTorrent.exe (PID: 3976)
    • Creates a software uninstall entry

      • mshta.exe (PID: 2628)
      • WebCompanionInstaller.exe (PID: 2292)
    • Checks for external IP

      • mshta.exe (PID: 2628)
    • Cleans NTFS data-stream (Zone Identifier)

      • utorrent.45790.installer.exe (PID: 2480)
    • Adds / modifies Windows certificates

      • WebCompanionInstaller.exe (PID: 2292)
      • WebCompanion.exe (PID: 2468)
    • Reads internet explorer settings

      • utorrentie.exe (PID: 3452)
      • utorrentie.exe (PID: 2376)
      • utorrentie.exe (PID: 2756)
    • Changes IE settings (feature browser emulation)

      • uTorrent.exe (PID: 3976)
    • Creates files in the program directory

      • WebCompanionInstaller.exe (PID: 2292)
      • WebCompanion.exe (PID: 2468)
    • Starts SC.EXE for service management

      • WebCompanionInstaller.exe (PID: 2292)
    • Uses NETSH.EXE for network configuration

      • cmd.exe (PID: 2780)
    • Starts CMD.EXE for commands execution

      • WebCompanionInstaller.exe (PID: 2292)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 1336)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 1336)
      • iexplore.exe (PID: 824)
    • Changes internet zones settings

      • iexplore.exe (PID: 1336)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 1336)
    • Changes settings of System certificates

      • iexplore.exe (PID: 1336)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 1336)
    • Reads internet explorer settings

      • mshta.exe (PID: 2628)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 1336)
      • WebCompanion.exe (PID: 2468)
    • Manual execution by user

      • uTorrent.exe (PID: 3976)
    • Dropped object may contain Bitcoin addresses

      • WebCompanionInstaller.exe (PID: 2292)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
73
Monitored processes
24
Malicious processes
9
Suspicious processes
2

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start drop and start drop and start drop and start drop and start iexplore.exe iexplore.exe utorrent.45790.installer.exe utorrent.45790.installer.exe mshta.exe cscript.exe no specs ping.exe no specs cscript.exe cscript.exe cscript.exe cscript.exe offer-91404593-1e1f-4ba6-8cb0-507560613b11.exe utorrent.exe webcompanioninstaller.exe utorrentie.exe utorrentie.exe helper.exe utorrentie.exe sc.exe no specs sc.exe no specs sc.exe no specs cmd.exe no specs netsh.exe no specs webcompanion.exe

Process information

PID
CMD
Path
Indicators
Parent process
824"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1336 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
948"C:\Windows\System32\cscript.exe" shell_scripts/shell_ping_after_close.js "http://i-50.b-000.XYZ.bench.utorrent.com/e?i=50&e=eyJldmVudE5hbWUiOiJoeWRyYTEiLCJhY3Rpb24iOiJodGFiZWdpbiIsInBpZCI6IjI0ODAiLCJoIjoiVWtMYjRtZk56enVhYXhzQyIsInYiOiIxMTE5MTU3NDIiLCJiIjo0NTc5MCwiY2wiOiJ1VG9ycmVudCIsIm9zYSI6IjMyIiwic2xuZyI6ImVuIiwiZGIiOiJJbnRlcm5ldCBFeHBsb3JlciIsImRidiI6IjExLjAiLCJpYnIiOlt7Im5hbWUiOiJGaXJlZm94IiwidmVyc2lvbiI6IjY4LjAiLCJleGVOYW1lIjoiZmlyZWZveCJ9LHsibmFtZSI6Ikdvb2dsZSBDaHJvbWUiLCJ2ZXJzaW9uIjoiNzUuMCIsImV4ZU5hbWUiOiJjaHJvbWUifSx7Im5hbWUiOiJJbnRlcm5ldCBFeHBsb3JlciIsInZlcnNpb24iOiIxMS4wIiwiZXhlTmFtZSI6ImlleHBsb3JlIn0seyJuYW1lIjoiT3BlcmEgSW50ZXJuZXQgQnJvd3NlciIsInZlcnNpb24iOiIxMi4xNSIsImV4ZU5hbWUiOiJvcGVyYSJ9XSwiaXAiOiI0NS45Mi4yMjguOCIsImNuIjoiTm9yd2F5IiwicGFja2lkIjoibGF2YXNvZnRfYmluZyJ9" C:\Windows\System32\cscript.exe
mshta.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Console Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\cscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1336"C:\Program Files\Internet Explorer\iexplore.exe" "http://llsw.download3.utorrent.com/3.5.5/utorrent.45790.installer.exe"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
1700"C:\Users\admin\AppData\Local\Temp\offer-91404593-1E1F-4BA6-8CB0-507560613B11.exe" --silent --partner=BT170902 --homepage=1 --search=1C:\Users\admin\AppData\Local\Temp\offer-91404593-1E1F-4BA6-8CB0-507560613B11.exe
cscript.exe
User:
admin
Company:
Lavasoft
Integrity Level:
HIGH
Description:
Web Companion Installer
Exit code:
0
Version:
6.0.2270.4122
Modules
Images
c:\users\admin\appdata\local\temp\offer-91404593-1e1f-4ba6-8cb0-507560613b11.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2084"C:\Windows\System32\cscript.exe" shell_scripts/shell_install_offer.js "C:/Users/admin/AppData/Local/Temp/HYD92A6.tmp.1601834609/sideLog.log" "lavasoft_bing" "http://webcompanion.com/nano_download.php?partner=BT170902" "--silent%20--partner%3DBT170902%20--homepage%3D1%20--search%3D1" "0" "admin" "admin"C:\Windows\System32\cscript.exe
mshta.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Console Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\cscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2124netsh http add urlacl url=http://+:9007/ user=EveryoneC:\Windows\system32\netsh.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
2132"sc.exe" Create "WCAssistantService" binPath= "C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe" DisplayName= "WC Assistant" start= autoC:\Windows\system32\sc.exeWebCompanionInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
A tool to aid in developing services for WindowsNT
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll
2144"C:\Windows\System32\cscript.exe" shell_scripts/shell_ping_after_close.js "http://i-50.b-000.XYZ.bench.utorrent.com/e?i=50&e=eyJldmVudE5hbWUiOiJoeWRyYTEiLCJhY3Rpb24iOiJvZmZlciIsInBpZCI6IjI0ODAiLCJoIjoiVWtMYjRtZk56enVhYXhzQyIsInYiOiIxMTE5MTU3NDIiLCJiIjo0NTc5MCwiY2wiOiJ1VG9ycmVudCIsIm9zYSI6IjMyIiwic2xuZyI6ImVuIiwiZGIiOiJJbnRlcm5ldCBFeHBsb3JlciIsImRidiI6IjExLjAiLCJpYnIiOlt7Im5hbWUiOiJGaXJlZm94IiwidmVyc2lvbiI6IjY4LjAiLCJleGVOYW1lIjoiZmlyZWZveCJ9LHsibmFtZSI6Ikdvb2dsZSBDaHJvbWUiLCJ2ZXJzaW9uIjoiNzUuMCIsImV4ZU5hbWUiOiJjaHJvbWUifSx7Im5hbWUiOiJJbnRlcm5ldCBFeHBsb3JlciIsInZlcnNpb24iOiIxMS4wIiwiZXhlTmFtZSI6ImlleHBsb3JlIn0seyJuYW1lIjoiT3BlcmEgSW50ZXJuZXQgQnJvd3NlciIsInZlcnNpb24iOiIxMi4xNSIsImV4ZU5hbWUiOiJvcGVyYSJ9XSwiaXAiOiI0NS45Mi4yMjguOCIsImNuIjoiTm9yd2F5Iiwib2ZmZXJ0eXBlIjoicHJpbWFyeSIsInByb3ZpZGVyIjoibGF2YXNvZnRfYmluZyIsIm9mZmVyIjoibGF2YXNvZnRfYmluZyIsIm9mZmVycmVzdWx0IjoxfQ==" C:\Windows\System32\cscript.exe
mshta.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Console Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\cscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2224"C:\Windows\System32\cscript.exe" shell_scripts/shell_ping_after_close.js "http://i-50.b-000.XYZ.bench.utorrent.com/e?i=50&e=eyJldmVudE5hbWUiOiJoeWRyYTEiLCJhY3Rpb24iOiJodGFTdWNjZXNzIiwicGlkIjoiMjQ4MCIsImgiOiJVa0xiNG1mTnp6dWFheHNDIiwidiI6IjExMTkxNTc0MiIsImIiOjQ1NzkwLCJjbCI6InVUb3JyZW50Iiwib3NhIjoiMzIiLCJzbG5nIjoiZW4iLCJkYiI6IkludGVybmV0IEV4cGxvcmVyIiwiZGJ2IjoiMTEuMCIsImliciI6W3sibmFtZSI6IkZpcmVmb3giLCJ2ZXJzaW9uIjoiNjguMCIsImV4ZU5hbWUiOiJmaXJlZm94In0seyJuYW1lIjoiR29vZ2xlIENocm9tZSIsInZlcnNpb24iOiI3NS4wIiwiZXhlTmFtZSI6ImNocm9tZSJ9LHsibmFtZSI6IkludGVybmV0IEV4cGxvcmVyIiwidmVyc2lvbiI6IjExLjAiLCJleGVOYW1lIjoiaWV4cGxvcmUifSx7Im5hbWUiOiJPcGVyYSBJbnRlcm5ldCBCcm93c2VyIiwidmVyc2lvbiI6IjEyLjE1IiwiZXhlTmFtZSI6Im9wZXJhIn1dLCJpcCI6IjQ1LjkyLjIyOC44IiwiY24iOiJOb3J3YXkiLCJwYWNraWQiOiJsYXZhc29mdF9iaW5nIn0=" C:\Windows\System32\cscript.exe
mshta.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Console Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\cscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2292.\WebCompanionInstaller.exe --partner=BT170902 --version=6.0.2270.4122 --prod --silent --partner=BT170902 --homepage=1 --search=1C:\Users\admin\AppData\Local\Temp\7zSE931.tmp\WebCompanionInstaller.exe
offer-91404593-1E1F-4BA6-8CB0-507560613B11.exe
User:
admin
Company:
Lavasoft
Integrity Level:
HIGH
Description:
Web Companion
Exit code:
0
Version:
6.0.2270.4122
Modules
Images
c:\users\admin\appdata\local\temp\7zse931.tmp\webcompanioninstaller.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
Total events
3 060
Read events
2 684
Write events
372
Delete events
4

Modification events

(PID) Process:(1336) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
3080153656
(PID) Process:(1336) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30841464
(PID) Process:(1336) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(1336) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1336) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1336) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(1336) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(1336) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
46000000A5000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(1336) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(1336) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
88
Suspicious files
56
Text files
147
Unknown types
19

Dropped files

PID
Process
Filename
Type
824iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\utorrent.45790.installer.exe.bfouln6.partial
MD5:
SHA256:
1336iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF837FBD4C58F7EF49.TMP
MD5:
SHA256:
1336iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\utorrent.45790.installer.exe.bfouln6.partial:Zone.Identifier
MD5:
SHA256:
2488utorrent.45790.installer.exeC:\Users\admin\AppData\Local\Temp\utt912E.tmp
MD5:
SHA256:
2488utorrent.45790.installer.exeC:\Users\admin\AppData\Roaming\uTorrent\settings.dat.new
MD5:
SHA256:
824iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\utorrent.45790.installer[1].exeexecutable
MD5:
SHA256:
1336iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{E35404F9-066B-11EB-85AF-12A9866C77DE}.datbinary
MD5:
SHA256:
2488utorrent.45790.installer.exeC:\Users\admin\AppData\Roaming\uTorrent\settings.datbinary
MD5:
SHA256:
2488utorrent.45790.installer.exeC:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\1f91d2d17ea675d4c2c3192e241743f9_90059c37-1320-41a4-b58d-2b75a9850d2fbinary
MD5:
SHA256:
1336iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\utorrent.45790.installer.exeexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
93
TCP/UDP connections
213
DNS requests
55
Threats
37

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2480
utorrent.45790.installer.exe
GET
98.143.146.7:80
http://utorrent.com/download/langpacks/dl.php?build=45790&ref=client&client=utorrent&sys_l=en&sel_l=-1&tk=stable34
US
whitelisted
2480
utorrent.45790.installer.exe
GET
178.79.242.19:80
http://www.utorrent.com/scripts/dl.php?build=45790&ref=client&client=utorrent&sys_l=en&sel_l=-1&tk=stable34
DE
whitelisted
824
iexplore.exe
GET
200
178.79.242.0:80
http://llsw.download3.utorrent.com/3.5.5/utorrent.45790.installer.exe
DE
executable
2.02 Mb
whitelisted
2084
cscript.exe
GET
200
104.17.177.102:80
http://webcompanion.com/nano_download.php?partner=BT170902
US
executable
500 Kb
malicious
3976
uTorrent.exe
GET
178.79.242.19:80
http://apps.bittorrent.com/utorrent-onboarding/player.btapp
DE
whitelisted
2488
utorrent.45790.installer.exe
POST
200
50.17.220.153:80
http://i-50.b-000.xyz.bench.utorrent.com/e?i=50
US
text
21 b
whitelisted
2480
utorrent.45790.installer.exe
POST
200
107.20.217.71:80
http://i-50.b-000.xyz.bench.utorrent.com/e?i=50
US
text
21 b
whitelisted
2488
utorrent.45790.installer.exe
GET
200
67.215.238.66:80
http://download-lb.utorrent.com/endpoint/hydra-ut/os/win7/track/stable/browser/ie/os-region/US/os-lang/en/os-ver/6.1/enc-ver/111915742/
US
compressed
761 Kb
whitelisted
2144
cscript.exe
GET
200
107.20.217.71:80
http://i-50.b-000.xyz.bench.utorrent.com/e?i=50&e=eyJldmVudE5hbWUiOiJoeWRyYTEiLCJhY3Rpb24iOiJvZmZlciIsInBpZCI6IjI0ODAiLCJoIjoiVWtMYjRtZk56enVhYXhzQyIsInYiOiIxMTE5MTU3NDIiLCJiIjo0NTc5MCwiY2wiOiJ1VG9ycmVudCIsIm9zYSI6IjMyIiwic2xuZyI6ImVuIiwiZGIiOiJJbnRlcm5ldCBFeHBsb3JlciIsImRidiI6IjExLjAiLCJpYnIiOlt7Im5hbWUiOiJGaXJlZm94IiwidmVyc2lvbiI6IjY4LjAiLCJleGVOYW1lIjoiZmlyZWZveCJ9LHsibmFtZSI6Ikdvb2dsZSBDaHJvbWUiLCJ2ZXJzaW9uIjoiNzUuMCIsImV4ZU5hbWUiOiJjaHJvbWUifSx7Im5hbWUiOiJJbnRlcm5ldCBFeHBsb3JlciIsInZlcnNpb24iOiIxMS4wIiwiZXhlTmFtZSI6ImlleHBsb3JlIn0seyJuYW1lIjoiT3BlcmEgSW50ZXJuZXQgQnJvd3NlciIsInZlcnNpb24iOiIxMi4xNSIsImV4ZU5hbWUiOiJvcGVyYSJ9XSwiaXAiOiI0NS45Mi4yMjguOCIsImNuIjoiTm9yd2F5Iiwib2ZmZXJ0eXBlIjoicHJpbWFyeSIsInByb3ZpZGVyIjoibGF2YXNvZnRfYmluZyIsIm9mZmVyIjoibGF2YXNvZnRfYmluZyIsIm9mZmVycmVzdWx0IjoxfQ==
US
text
21 b
whitelisted
2224
cscript.exe
GET
200
107.20.217.71:80
http://i-50.b-000.xyz.bench.utorrent.com/e?i=50&e=eyJldmVudE5hbWUiOiJoeWRyYTEiLCJhY3Rpb24iOiJodGFTdWNjZXNzIiwicGlkIjoiMjQ4MCIsImgiOiJVa0xiNG1mTnp6dWFheHNDIiwidiI6IjExMTkxNTc0MiIsImIiOjQ1NzkwLCJjbCI6InVUb3JyZW50Iiwib3NhIjoiMzIiLCJzbG5nIjoiZW4iLCJkYiI6IkludGVybmV0IEV4cGxvcmVyIiwiZGJ2IjoiMTEuMCIsImliciI6W3sibmFtZSI6IkZpcmVmb3giLCJ2ZXJzaW9uIjoiNjguMCIsImV4ZU5hbWUiOiJmaXJlZm94In0seyJuYW1lIjoiR29vZ2xlIENocm9tZSIsInZlcnNpb24iOiI3NS4wIiwiZXhlTmFtZSI6ImNocm9tZSJ9LHsibmFtZSI6IkludGVybmV0IEV4cGxvcmVyIiwidmVyc2lvbiI6IjExLjAiLCJleGVOYW1lIjoiaWV4cGxvcmUifSx7Im5hbWUiOiJPcGVyYSBJbnRlcm5ldCBCcm93c2VyIiwidmVyc2lvbiI6IjEyLjE1IiwiZXhlTmFtZSI6Im9wZXJhIn1dLCJpcCI6IjQ1LjkyLjIyOC44IiwiY24iOiJOb3J3YXkiLCJwYWNraWQiOiJsYXZhc29mdF9iaW5nIn0=
US
text
21 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2488
utorrent.45790.installer.exe
107.20.217.71:80
i-50.b-000.xyz.bench.utorrent.com
Amazon.com, Inc.
US
suspicious
2488
utorrent.45790.installer.exe
50.17.220.153:80
i-50.b-000.xyz.bench.utorrent.com
Amazon.com, Inc.
US
suspicious
2488
utorrent.45790.installer.exe
67.215.238.66:80
download-lb.utorrent.com
QuadraNet, Inc
US
suspicious
2480
utorrent.45790.installer.exe
107.20.217.71:80
i-50.b-000.xyz.bench.utorrent.com
Amazon.com, Inc.
US
suspicious
2628
mshta.exe
208.95.112.1:80
ip-api.com
IBURST
malicious
948
cscript.exe
107.20.217.71:80
i-50.b-000.xyz.bench.utorrent.com
Amazon.com, Inc.
US
suspicious
2224
cscript.exe
107.20.217.71:80
i-50.b-000.xyz.bench.utorrent.com
Amazon.com, Inc.
US
suspicious
2480
utorrent.45790.installer.exe
98.143.146.7:80
utorrent.com
QuadraNet, Inc
US
suspicious
2144
cscript.exe
107.20.217.71:80
i-50.b-000.xyz.bench.utorrent.com
Amazon.com, Inc.
US
suspicious
2084
cscript.exe
104.17.177.102:80
webcompanion.com
Cloudflare Inc
US
shared

DNS requests

Domain
IP
Reputation
llsw.download3.utorrent.com
  • 178.79.242.0
  • 95.140.236.128
whitelisted
router.bittorrent.com
  • 67.215.246.10
shared
router.utorrent.com
  • 82.221.103.244
whitelisted
i-50.b-000.xyz.bench.utorrent.com
  • 107.20.217.71
  • 23.21.139.158
  • 23.23.215.82
  • 23.23.85.1
  • 54.197.251.114
  • 174.129.255.167
  • 23.21.43.186
  • 54.235.208.27
  • 50.17.220.153
  • 107.22.246.37
  • 54.225.194.96
whitelisted
download-lb.utorrent.com
  • 67.215.238.66
whitelisted
ip-api.com
  • 208.95.112.1
malicious
utorrent.com
  • 98.143.146.7
whitelisted
webcompanion.com
  • 104.17.177.102
  • 104.17.178.102
malicious
www.utorrent.com
  • 178.79.242.19
whitelisted
i-21.b-45790.ut.bench.utorrent.com
  • 107.22.246.37
  • 54.243.113.215
  • 50.17.220.153
  • 23.21.43.186
  • 107.20.217.71
  • 174.129.255.167
  • 54.225.194.96
  • 23.21.139.158
suspicious

Threats

PID
Process
Class
Message
824
iexplore.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
2488
utorrent.45790.installer.exe
Misc activity
APP [PTsecurity] uTorrent Hydra Client
2488
utorrent.45790.installer.exe
Misc activity
APP [PTsecurity] P2P uTorrent Hydra Client
2488
utorrent.45790.installer.exe
Misc activity
APP [PTsecurity] uTorrent Hydra Client
2488
utorrent.45790.installer.exe
Misc activity
APP [PTsecurity] P2P uTorrent Hydra Client
2488
utorrent.45790.installer.exe
Misc activity
APP [PTsecurity] uTorrent Hydra Client
2488
utorrent.45790.installer.exe
Misc activity
APP [PTsecurity] P2P uTorrent Hydra Client
2488
utorrent.45790.installer.exe
Misc activity
APP [PTsecurity] uTorrent Hydra Client
2488
utorrent.45790.installer.exe
Misc activity
APP [PTsecurity] P2P uTorrent Hydra Client
2628
mshta.exe
Potential Corporate Privacy Violation
ET POLICY External IP Lookup ip-api.com
8 ETPRO signatures available at the full report
Process
Message
WebCompanionInstaller.exe
Detecting windows culture
WebCompanionInstaller.exe
10/4/2020 7:04:00 PM :-> Starting installer 6.0.2270.4122 with: .\WebCompanionInstaller.exe --partner=BT170902 --version=6.0.2270.4122 --prod --silent --partner=BT170902 --homepage=1 --search=1, Run as admin: True
WebCompanionInstaller.exe
Preparing for installing Web Companion
WebCompanionInstaller.exe
10/4/2020 7:04:01 PM :-> Generating Machine and Install Id ...
WebCompanionInstaller.exe
10/4/2020 7:04:01 PM :-> Machine Id and Install Id has been generated
WebCompanionInstaller.exe
10/4/2020 7:04:02 PM :-> Checking prerequisites ...
WebCompanionInstaller.exe
10/4/2020 7:04:02 PM :-> Antivirus not detected
WebCompanionInstaller.exe
10/4/2020 7:04:02 PM :-> vm_check False
WebCompanionInstaller.exe
10/4/2020 7:04:02 PM :-> reg_check :False
WebCompanionInstaller.exe
10/4/2020 7:04:03 PM :-> Installed .Net framework is V40