| URL: | http://www.oldversion.com/windows/utorrent-3-0-0-25406 |
| Full analysis: | https://app.any.run/tasks/7bc5b375-34ff-4f4f-b2eb-841986c937b8 |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | May 20, 2025, 13:20:09 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 0B9D8244E11482C2AAF43556305D2563 |
| SHA1: | 7E9C689606CBDE28081CDD9EC4539CD58C7E7FA9 |
| SHA256: | 20A6F14B2F29B7DD8C64834A9AD9811BDB06B433D8DE00A097D32023CBCD5DC4 |
| SSDEEP: | 3:N1KJS4AFL/KJMywuRIWooFVTn:Cc4EDKJzwuRjF5 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1072 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5708 -childID 8 -isForBrowser -prefsHandle 5628 -prefMapHandle 5632 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1312 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {6363ed08-2fb3-4d5b-a0c3-3953923c3158} 2432 "\\.\pipe\gecko-crash-server-pipe.2432" 1a990711690 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 1280 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5336 -childID 6 -isForBrowser -prefsHandle 5252 -prefMapHandle 5256 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1312 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {84224d54-2a0b-4808-9115-f6014c273563} 2432 "\\.\pipe\gecko-crash-server-pipe.2432" 1a989167bd0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 2432 | "C:\Program Files\Mozilla Firefox\firefox.exe" http://www.oldversion.com/windows/utorrent-3-0-0-25406 | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 4892 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5588 -childID 7 -isForBrowser -prefsHandle 5456 -prefMapHandle 5520 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1312 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {b214ef7a-68be-4cdc-bf97-63fea43dc347} 2432 "\\.\pipe\gecko-crash-server-pipe.2432" 1a990711d90 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 5512 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5528 | uTorrent.exe /NOINSTALL /BRINGTOFRONT | C:\Program Files (x86)\uTorrent\uTorrent.exe | 3.0.0.25406_utorrent_3.0.exe | ||||||||||||
User: admin Company: BitTorrent, Inc. Integrity Level: MEDIUM Description: µTorrent Exit code: 3221226525 Version: 3.0.0.25406 Modules
| |||||||||||||||
| 5956 | "C:\Program Files\Mozilla Firefox\firefox.exe" "http://www.oldversion.com/windows/utorrent-3-0-0-25406" | C:\Program Files\Mozilla Firefox\firefox.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 7208 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1832 -parentBuildID 20240213221259 -prefsHandle 1764 -prefMapHandle 1732 -prefsLen 31031 -prefMapSize 244583 -appDir "C:\Program Files\Mozilla Firefox\browser" - {1a6cda86-78d0-47e2-a212-8f4990f2c0a6} 2432 "\\.\pipe\gecko-crash-server-pipe.2432" 1a9ffded410 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 1 Version: 123.0 Modules
| |||||||||||||||
| 7304 | C:\WINDOWS\SysWOW64\DllHost.exe /Processid:{E2B3C97F-6AE1-41AC-817A-F6F92166D7DD} | C:\Windows\SysWOW64\dllhost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7312 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2076 -parentBuildID 20240213221259 -prefsHandle 2068 -prefMapHandle 2064 -prefsLen 31031 -prefMapSize 244583 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {1c94ce71-1361-42c2-8f67-7398b69d5790} 2432 "\\.\pipe\gecko-crash-server-pipe.2432" 1a9f877fd10 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| (PID) Process: | (2432) firefox.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (2432) firefox.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer |
| Operation: | write | Name: | SlowContextMenuEntries |
Value: 6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000 | |||
| (PID) Process: | (8772) 3.0.0.25406_utorrent_3.0.exe | Key: | HKEY_CLASSES_ROOT\FalconBetaAccount |
| Operation: | write | Name: | remote_access_client_id |
Value: 7033724789 | |||
| (PID) Process: | (8452) 3.0.0.25406_utorrent_3.0.exe | Key: | HKEY_CLASSES_ROOT\.torrent |
| Operation: | write | Name: | Content Type |
Value: application/x-bittorrent | |||
| (PID) Process: | (8452) 3.0.0.25406_utorrent_3.0.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-bittorrent |
| Operation: | write | Name: | Extension |
Value: .torrent | |||
| (PID) Process: | (8452) 3.0.0.25406_utorrent_3.0.exe | Key: | HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-bittorrent |
| Operation: | write | Name: | Extension |
Value: .torrent | |||
| (PID) Process: | (8452) 3.0.0.25406_utorrent_3.0.exe | Key: | HKEY_CLASSES_ROOT\.btsearch |
| Operation: | write | Name: | Content Type |
Value: application/x-bittorrentsearchdescription+xml | |||
| (PID) Process: | (8452) 3.0.0.25406_utorrent_3.0.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-bittorrentsearchdescription+xml |
| Operation: | write | Name: | Extension |
Value: .btsearch | |||
| (PID) Process: | (8452) 3.0.0.25406_utorrent_3.0.exe | Key: | HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-bittorrentsearchdescription+xml |
| Operation: | write | Name: | Extension |
Value: .btsearch | |||
| (PID) Process: | (8452) 3.0.0.25406_utorrent_3.0.exe | Key: | HKEY_CLASSES_ROOT\Magnet |
| Operation: | write | Name: | URL Protocol |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2432 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 2432 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 2432 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 2432 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\SiteSecurityServiceState.bin | binary | |
MD5:425D6F9178B4571DE211FD725A7B7B3B | SHA256:EFBC84E151773B522BCC004DAF50692AF38B74B7B06FAEF8FC997E48247502EB | |||
| 2432 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 2432 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite | — | |
MD5:— | SHA256:— | |||
| 2432 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 2432 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 2432 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs-1.js | text | |
MD5:14867AEDF0FA1F88FF57EFC43D95EA62 | SHA256:C4604D5BE1DC473735551308A33422AEE3C0289EADE19BB51AF04B0D3B8DC1AF | |||
| 2432 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
2432 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | whitelisted |
2432 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.216.77.6:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
2432 | firefox.exe | POST | 200 | 184.24.77.58:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
2432 | firefox.exe | POST | 200 | 184.24.77.52:80 | http://r10.o.lencr.org/ | unknown | — | — | whitelisted |
2432 | firefox.exe | POST | 200 | 184.24.77.52:80 | http://r10.o.lencr.org/ | unknown | — | — | whitelisted |
2432 | firefox.exe | GET | 200 | 3.215.56.8:80 | http://www.oldversion.com/windows/utorrent-3-0-0-25406 | unknown | — | — | whitelisted |
2432 | firefox.exe | POST | 200 | 142.250.186.35:80 | http://o.pki.goog/we2 | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 23.216.77.6:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
5496 | MoUsoCoreWorker.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
2104 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2432 | firefox.exe | 34.36.137.203:443 | contile.services.mozilla.com | — | — | whitelisted |
2432 | firefox.exe | 3.215.56.8:80 | www.oldversion.com | AMAZON-AES | US | unknown |
2432 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
www.oldversion.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2196 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com) |
2196 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com) |
2196 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com) |
2196 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
2196 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
2196 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
2432 | firefox.exe | Potential Corporate Privacy Violation | ET INFO HTTP POST contains pass= in cleartext |
2432 | firefox.exe | Potential Corporate Privacy Violation | ET INFO PE EXE or DLL Windows file download HTTP |
2432 | firefox.exe | Misc activity | ET INFO EXE - Served Attached HTTP |
8772 | 3.0.0.25406_utorrent_3.0.exe | Potential Corporate Privacy Violation | ET P2P Bittorrent P2P Client User-Agent (uTorrent) |