| download: | Process.exe |
| Full analysis: | https://app.any.run/tasks/297d101e-9f04-4216-98c9-f948413c468a |
| Verdict: | Malicious activity |
| Analysis date: | August 17, 2018, 06:37:43 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | text/html |
| File info: | HTML document, ASCII text |
| MD5: | A67A2513CEA5A40702CD9C8936B50850 |
| SHA1: | 67118FEC8D411A5A16A9E11EC51E064AE9C13785 |
| SHA256: | 1E89B9E03ECD42833D71F865BE1377733B0044841E69C3CDE0AE7C45E50946D5 |
| SSDEEP: | 24:Wlux+49snxeWZyoft9el9xmU4KdCgaKI9xmbGW0hOKdd9EP9xmnX1gKd3I9xmtib:qS+gmeWQolGmU4KdCga9mbB0hOKd/8mi |
| .htm/html | | | HyperText Markup Language with DOCTYPE (80.6) |
|---|---|---|
| .html | | | HyperText Markup Language (19.3) |
| Title: | Index of / |
|---|
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 868 | "C:\Users\admin\AppData\Roaming\uTorrent\updates\3.5.3_44494\utorrentie.exe" uTorrent_2208_003DC0D8_1207159716 µTorrent4823DF041B09 uTorrent | C:\Users\admin\AppData\Roaming\uTorrent\updates\3.5.3_44494\utorrentie.exe | uTorrent.exe | ||||||||||||
User: admin Company: BitTorrent Inc. Integrity Level: LOW Description: WebHelper Exit code: 0 Version: 1.0.0 Modules
| |||||||||||||||
| 1600 | "C:\Users\admin\AppData\Roaming\uTorrent\updates\3.5.3_44494.exe" /LAUNCHED | C:\Users\admin\AppData\Roaming\uTorrent\updates\3.5.3_44494.exe | uTorrent.exe | ||||||||||||
User: admin Company: BitTorrent Inc. Integrity Level: MEDIUM Description: µTorrent Exit code: 0 Version: 3.5.3.44494 Modules
| |||||||||||||||
| 1916 | "C:\Users\admin\AppData\Roaming\uTorrent\uTorrent.exe" | C:\Users\admin\AppData\Roaming\uTorrent\uTorrent.exe | explorer.exe | ||||||||||||
User: admin Company: BitTorrent Inc. Integrity Level: MEDIUM Description: µTorrent Exit code: 0 Version: 3.5.1.44332 Modules
| |||||||||||||||
| 2092 | "C:\Users\admin\AppData\Roaming\uTorrent\updates\3.5.3_44494\utorrentie.exe" uTorrent_2208_003DBF10_1298198349 µTorrent4823DF041B09 uTorrent | C:\Users\admin\AppData\Roaming\uTorrent\updates\3.5.3_44494\utorrentie.exe | uTorrent.exe | ||||||||||||
User: admin Company: BitTorrent Inc. Integrity Level: LOW Description: WebHelper Exit code: 0 Version: 1.0.0 Modules
| |||||||||||||||
| 2208 | "C:\Users\admin\AppData\Roaming\uTorrent\uTorrent.exe" /RELOCATED | C:\Users\admin\AppData\Roaming\uTorrent\uTorrent.exe | 3.5.3_44494.exe | ||||||||||||
User: admin Company: BitTorrent Inc. Integrity Level: MEDIUM Description: µTorrent Exit code: 0 Version: 3.5.3.44494 Modules
| |||||||||||||||
| 2500 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2784 CREDAT:71937 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 8.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2784 | "C:\Program Files\Internet Explorer\iexplore.exe" -nohome | C:\Program Files\Internet Explorer\iexplore.exe | uTorrent.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 8.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3288 | "C:\Windows\system32\ntvdm.exe" -i1 | C:\Windows\system32\ntvdm.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: NTVDM.EXE Exit code: 3221225786 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (1916) uTorrent.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1916) uTorrent.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (1916) uTorrent.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (1600) 3.5.3_44494.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent |
| Operation: | write | Name: | DisplayIcon |
Value: "C:\Users\admin\AppData\Roaming\uTorrent\uTorrent.exe",0 | |||
| (PID) Process: | (1600) 3.5.3_44494.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent |
| Operation: | write | Name: | DisplayName |
Value: µTorrent | |||
| (PID) Process: | (1600) 3.5.3_44494.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent |
| Operation: | write | Name: | DisplayVersion |
Value: 3.5.3.44494 | |||
| (PID) Process: | (1600) 3.5.3_44494.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent |
| Operation: | write | Name: | UninstallString |
Value: "C:\Users\admin\AppData\Roaming\uTorrent\uTorrent.exe" /UNINSTALL | |||
| (PID) Process: | (1600) 3.5.3_44494.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent |
| Operation: | write | Name: | InstallLocation |
Value: C:\Users\admin\AppData\Roaming\uTorrent | |||
| (PID) Process: | (1600) 3.5.3_44494.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent |
| Operation: | write | Name: | VersionMajor |
Value: 3 | |||
| (PID) Process: | (1600) 3.5.3_44494.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent |
| Operation: | write | Name: | MajorVersion |
Value: 3 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3288 | ntvdm.exe | C:\Users\admin\AppData\Local\Temp\scs33A3.tmp | — | |
MD5:— | SHA256:— | |||
| 3288 | ntvdm.exe | C:\Users\admin\AppData\Local\Temp\scs33A4.tmp | — | |
MD5:— | SHA256:— | |||
| 1916 | uTorrent.exe | C:\Users\admin\AppData\Local\Temp\CabFF21.tmp | — | |
MD5:— | SHA256:— | |||
| 1916 | uTorrent.exe | C:\Users\admin\AppData\Local\Temp\TarFF22.tmp | — | |
MD5:— | SHA256:— | |||
| 1916 | uTorrent.exe | C:\Users\admin\AppData\Local\Temp\CabFF33.tmp | — | |
MD5:— | SHA256:— | |||
| 1916 | uTorrent.exe | C:\Users\admin\AppData\Local\Temp\TarFF34.tmp | — | |
MD5:— | SHA256:— | |||
| 1916 | uTorrent.exe | C:\Users\admin\AppData\Local\Temp\Cab34C.tmp | — | |
MD5:— | SHA256:— | |||
| 1916 | uTorrent.exe | C:\Users\admin\AppData\Local\Temp\Tar34D.tmp | — | |
MD5:— | SHA256:— | |||
| 1600 | 3.5.3_44494.exe | C:\Users\admin\AppData\Local\Temp\uttAB9.tmp | — | |
MD5:— | SHA256:— | |||
| 1600 | 3.5.3_44494.exe | C:\Users\admin\AppData\Roaming\uTorrent\settings.dat.new | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2208 | uTorrent.exe | GET | 304 | 208.111.178.129:80 | http://apps.bittorrent.com/utorrent-onboarding/player.btapp?h=P-6naYMO2gvdMZkz&v=111652302&ol=en&ul=&tk=stable34&c=uTorrent | US | — | — | whitelisted |
2208 | uTorrent.exe | GET | 304 | 69.164.0.0:80 | http://apps.bittorrent.com/utorrent-onboarding/welcome-upsell.btapp?h=P-6naYMO2gvdMZkz&v=111652302&ol=en&ul=&tk=stable34&c=uTorrent | US | — | — | whitelisted |
2208 | uTorrent.exe | GET | — | 173.254.195.58:80 | http://update.bittorrent.com/time.php | US | — | — | whitelisted |
2208 | uTorrent.exe | GET | 200 | 208.111.171.129:80 | http://cdn.ap.bittorrent.com/control/feature/tags/ut.json | US | text | 2.11 Kb | shared |
2208 | uTorrent.exe | GET | 200 | 208.111.171.129:80 | http://cdn.ap.bittorrent.com/control/tags/ut.json | US | text | 8.30 Kb | shared |
2500 | iexplore.exe | GET | 200 | 178.79.251.1:80 | http://cdn.bitmedianetwork.com/network/r.html?u=ue1-8427979be7984a8ea13ffc1e9a9fcded&next=http://utorrent.com/prodnews&osv=1DB10106&iev=8&geo=US&lang=en&ver=3%2e5%2e3%2e1%2e44494 | GB | html | 1.20 Kb | suspicious |
2500 | iexplore.exe | GET | 200 | 178.79.251.1:80 | http://cdn.bitmedianetwork.com/network/5682.js | GB | text | 3.55 Kb | suspicious |
2092 | utorrentie.exe | GET | 200 | 178.79.251.129:80 | http://www.bt.co/assets/js/3p/ie8.js | GB | text | 7.34 Kb | whitelisted |
2500 | iexplore.exe | GET | 200 | 216.58.215.234:80 | http://ajax.googleapis.com/ajax/libs/jquery/1.4.0/jquery.min.js | US | text | 23.2 Kb | whitelisted |
2208 | uTorrent.exe | POST | 200 | 23.23.215.82:80 | http://i-29.b-44494.ut.bench.utorrent.com/e?i=29 | US | text | 21 b | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 62.210.104.54:28022 | — | Online S.a.s. | FR | unknown |
1916 | uTorrent.exe | 205.185.216.10:80 | www.download.windowsupdate.com | Highwinds Network Group, Inc. | US | whitelisted |
1916 | uTorrent.exe | 174.129.255.167:80 | i-31.b-44332.ut.bench.utorrent.com | Amazon.com, Inc. | US | whitelisted |
2208 | uTorrent.exe | 54.192.203.188:80 | now.bt.co | Amazon.com, Inc. | US | unknown |
2208 | uTorrent.exe | 208.111.178.129:80 | apps.bittorrent.com | Limelight Networks, Inc. | US | suspicious |
2208 | uTorrent.exe | 69.164.0.0:80 | apps.bittorrent.com | Limelight Networks, Inc. | US | suspicious |
2208 | uTorrent.exe | 52.85.183.24:80 | utclient.utorrent.com | Amazon.com, Inc. | US | unknown |
2208 | uTorrent.exe | 54.192.203.188:443 | now.bt.co | Amazon.com, Inc. | US | unknown |
2208 | uTorrent.exe | 82.221.103.244:6881 | router.utorrent.com | Thor Data Center ehf | IS | suspicious |
— | — | 67.215.246.10:6881 | router.bittorrent.com | QuadraNet, Inc | US | suspicious |
Domain | IP | Reputation |
|---|---|---|
www.download.windowsupdate.com |
| whitelisted |
router.utorrent.com |
| whitelisted |
router.bittorrent.com |
| shared |
i-31.b-44332.ut.bench.utorrent.com |
| malicious |
now.bt.co |
| whitelisted |
utclient.utorrent.com |
| shared |
apps.bittorrent.com |
| whitelisted |
www.bing.com |
| whitelisted |
cdn.bitmedianetwork.com |
| suspicious |
i-29.b-44494.ut.bench.utorrent.com |
| malicious |
PID | Process | Class | Message |
|---|---|---|---|
2208 | uTorrent.exe | Potential Corporate Privacy Violation | ET P2P BTWebClient UA uTorrent in use |
2208 | uTorrent.exe | Potential Corporate Privacy Violation | ET P2P BTWebClient UA uTorrent in use |
2208 | uTorrent.exe | Potential Corporate Privacy Violation | ET P2P BTWebClient UA uTorrent in use |
2208 | uTorrent.exe | Potential Corporate Privacy Violation | ET P2P BTWebClient UA uTorrent in use |
2208 | uTorrent.exe | Potential Corporate Privacy Violation | ET P2P BitTorrent DHT ping request |
2208 | uTorrent.exe | Potential Corporate Privacy Violation | ET P2P BTWebClient UA uTorrent in use |
2208 | uTorrent.exe | Potential Corporate Privacy Violation | ET P2P BTWebClient UA uTorrent in use |