| File name: | utorrent_installer.exe |
| Full analysis: | https://app.any.run/tasks/d78754dd-1951-4caf-b2d4-c488367a0a54 |
| Verdict: | Malicious activity |
| Analysis date: | April 24, 2025, 18:27:34 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections |
| MD5: | DFC260AE851E48D6A012AE545CA4BB58 |
| SHA1: | 5C81201A0354D1CAD1A04CDCA255D6D1C29E99F9 |
| SHA256: | 401409E8DA7321FB94A1A8AC6217D2DD067007D29547257575C26A39F31E8931 |
| SSDEEP: | 98304:+GNMS/n45nef0Bw4paDYBsEL9yCBP9DGC+V0GBujawXkXCOBYVfWR8agAwBc3VsD:8V7hug |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2021:09:25 21:55:49+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 26112 |
| InitializedDataSize: | 141824 |
| UninitializedDataSize: | 2048 |
| EntryPoint: | 0x34f7 |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 3.6.0.47142 |
| ProductVersionNumber: | 3.6.0.47142 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | BitTorrent Limited |
| FileDescription: | utorrent |
| FileVersion: | 3.6.0.47142 |
| InternalName: | utorrent |
| LegalCopyright: | (c) 2023 BitTorrent Limited All Rights Reserved. |
| ProductName: | utorrent |
| ProductVersion: | 3.6.0.47142 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 668 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --no-appcompat-clear --mojo-platform-channel-handle=5584 --field-trial-handle=2256,i,17609831137579969687,2372729280543108135,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 736 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_xpay_wallet.mojom.EdgeXPayWalletService --lang=en-US --service-sandbox-type=utility --no-appcompat-clear --mojo-platform-channel-handle=3856 --field-trial-handle=2256,i,17609831137579969687,2372729280543108135,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 856 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5384 --field-trial-handle=2256,i,17609831137579969687,2372729280543108135,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 904 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3732 --field-trial-handle=2256,i,17609831137579969687,2372729280543108135,262144 --variations-seed-version /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1240 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_search_indexer.mojom.SearchIndexerInterfaceBroker --lang=en-US --service-sandbox-type=search_indexer --message-loop-type-ui --no-appcompat-clear --mojo-platform-channel-handle=4860 --field-trial-handle=2256,i,17609831137579969687,2372729280543108135,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1388 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=9 --mojo-platform-channel-handle=5224 --field-trial-handle=2256,i,17609831137579969687,2372729280543108135,262144 --variations-seed-version /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1660 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2660 --field-trial-handle=2256,i,17609831137579969687,2372729280543108135,262144 --variations-seed-version /prefetch:3 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2040 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=3944 --field-trial-handle=2256,i,17609831137579969687,2372729280543108135,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2236 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=2736 --field-trial-handle=2256,i,17609831137579969687,2372729280543108135,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2340 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=1488 --field-trial-handle=2256,i,17609831137579969687,2372729280543108135,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| (PID) Process: | (7436) utorrent.exe | Key: | HKEY_CLASSES_ROOT\FalconBetaAccount |
| Operation: | write | Name: | remote_access_client_id |
Value: 6360918805 | |||
| (PID) Process: | (7300) utorrent_installer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (7300) utorrent_installer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (7300) utorrent_installer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (7556) utorrent.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\BitTorrent |
| Operation: | write | Name: | computerID |
Value: 288D2D6268CF3363C0124DAE4ECA6FDDEE47E1815AE382FF | |||
| (PID) Process: | (7556) utorrent.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer |
| Operation: | write | Name: | SlowContextMenuEntries |
Value: 6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000 | |||
| (PID) Process: | (7556) utorrent.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (7556) utorrent.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (7556) utorrent.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (7852) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7436 | utorrent.exe | C:\Users\admin\AppData\Local\Temp\uttCB60.tmp | — | |
MD5:— | SHA256:— | |||
| 7556 | utorrent.exe | C:\Users\admin\AppData\Local\Temp\uttCF29.tmp | — | |
MD5:— | SHA256:— | |||
| 7300 | utorrent_installer.exe | C:\Users\admin\AppData\Local\Temp\nszC1CC.tmp\INetC.dll | executable | |
MD5:640BFF73A5F8E37B202D911E4749B2E9 | SHA256:C1E568E25EC111184DEB1B87CFDA4BFEC529B1ABEAB39B66539D998012F33502 | |||
| 7300 | utorrent_installer.exe | C:\Users\admin\AppData\Local\Temp\nszC1CC.tmp\System.dll | executable | |
MD5:CFF85C549D536F651D4FB8387F1976F2 | SHA256:8DC562CDA7217A3A52DB898243DE3E2ED68B80E62DDCB8619545ED0B4E7F65A8 | |||
| 7300 | utorrent_installer.exe | C:\Users\admin\AppData\Local\Temp\nszC1CC.tmp\bt_datachannel.dll | executable | |
MD5:DFCA05BEB0D6A31913C04B1314CA8B4A | SHA256:D4C4E05FADE7E76F4A2D0C9C58A6B9B82B761D9951FFDDD838C381549368E153 | |||
| 7556 | utorrent.exe | C:\Users\admin\AppData\Roaming\utorrent\toolbar_offer.benc | text | |
MD5:EB3DEFC30091C88B7097BB1FFE704583 | SHA256:C89B71F60C0F45E9CB57BCBF0587080972862EA9E370CCABED3A1786A65CD2A8 | |||
| 7436 | utorrent.exe | C:\Users\admin\AppData\Roaming\utorrent\updates\3.6.0_47142.exe | executable | |
MD5:B7F8A3909AD963D5B5260DACFA897E6E | SHA256:8837428A93C7EE46B9772D6C857E109E9BAA0F5B28450F87FFF7C0E8B87CF017 | |||
| 7556 | utorrent.exe | C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1693682860-607145093-2874071422-1001\a6ed7481bc2972bdd2af53f45a86d79e_bb926e54-e3ca-40fd-ae90-2764341e7792 | binary | |
MD5:3ACD7A67FDF4FB191C45E32B27A676F6 | SHA256:11061848A4C57DC9827CE3A73297F6E07E15AF2559D185B11133B47AC098EA83 | |||
| 7556 | utorrent.exe | C:\Users\admin\AppData\Roaming\utorrent\toolbar.benc | text | |
MD5:417E5709690D7499B46396F3B676BD69 | SHA256:960CF5D1103FCBB15FAB4B0FB1F81CF23C25B64C32B8DCA1FB96BC7875D1EE2B | |||
| 7556 | utorrent.exe | C:\Users\admin\AppData\Local\Temp\uttD91D.tmp | text | |
MD5:417E5709690D7499B46396F3B676BD69 | SHA256:960CF5D1103FCBB15FAB4B0FB1F81CF23C25B64C32B8DCA1FB96BC7875D1EE2B | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
7436 | utorrent.exe | POST | 200 | 44.209.208.153:80 | http://i-21.b-47142.ut.bench.utorrent.com/e?i=21 | unknown | — | — | whitelisted |
2104 | svchost.exe | GET | 200 | 2.19.11.105:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
2104 | svchost.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
7300 | utorrent_installer.exe | POST | 200 | 54.85.44.192:80 | http://i-6000.b-47142.ut.bench.utorrent.com/e?i=6000 | unknown | — | — | whitelisted |
7436 | utorrent.exe | POST | 200 | 44.209.208.153:80 | http://i-21.b-47142.ut.bench.utorrent.com/e?i=21 | unknown | — | — | whitelisted |
7556 | utorrent.exe | GET | 200 | 82.221.103.246:80 | http://update.utorrent.com/installoffer.php?h=aM8zY8ASTa5Oym_d&v=113358886&w=4A65000A&l=en&c=US&w64=1&db=other&cl=uTorrent&tsub=1&svp=4 | unknown | — | — | whitelisted |
7556 | utorrent.exe | GET | 200 | 82.221.103.245:80 | http://update.utorrent.li/installstats.php?cl=uTorrent&v=113358886&h=aM8zY8ASTa5Oym_d&w=4A65000A&bu=0&pr=0&cmp=0&ocmp=0&showtbexists&pid=7556&cau=0&lunv=0&tbe=0&view=win32 | unknown | — | — | whitelisted |
7556 | utorrent.exe | GET | 200 | 82.221.103.245:80 | http://update.utorrent.li/installstats.php?cl=uTorrent&v=113358886&h=aM8zY8ASTa5Oym_d&w=4A65000A&bu=0&pr=0&cmp=0&ocmp=0&showwarning&pid=7556&cau=0&lunv=0&view=win32 | unknown | — | — | whitelisted |
7436 | utorrent.exe | POST | 200 | 54.85.44.192:80 | http://i-50.b-47142.ut.bench.utorrent.com/e?i=50 | unknown | — | — | whitelisted |
— | — | GET | 401 | 13.107.6.158:443 | https://business.bing.com/api/v1/user/token/microsoftgraph?&clienttype=edge-omnibox | unknown | — | — | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
7300 | utorrent_installer.exe | 54.85.44.192:80 | i-6000.b-47142.ut.bench.utorrent.com | AMAZON-AES | US | whitelisted |
2104 | svchost.exe | 2.19.11.105:80 | crl.microsoft.com | Elisa Oyj | NL | whitelisted |
2104 | svchost.exe | 2.23.246.101:80 | www.microsoft.com | Ooredoo Q.S.C. | QA | whitelisted |
7436 | utorrent.exe | 44.209.208.153:80 | i-6000.b-47142.ut.bench.utorrent.com | AMAZON-AES | US | whitelisted |
2104 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
7556 | utorrent.exe | 82.221.103.246:80 | update.utorrent.com | Advania Island ehf | IS | whitelisted |
7436 | utorrent.exe | 54.85.44.192:80 | i-6000.b-47142.ut.bench.utorrent.com | AMAZON-AES | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
i-6000.b-47142.ut.bench.utorrent.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
router.bittorrent.com |
| whitelisted |
router.utorrent.com |
| whitelisted |
i-21.b-47142.ut.bench.utorrent.com |
| whitelisted |
update.utorrent.com |
| whitelisted |
i-50.b-47142.ut.bench.utorrent.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
7300 | utorrent_installer.exe | Potentially Bad Traffic | ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla)) |
7556 | utorrent.exe | Potential Corporate Privacy Violation | ET P2P Bittorrent P2P Client User-Agent (uTorrent) |
7556 | utorrent.exe | Potential Corporate Privacy Violation | ET P2P Bittorrent P2P Client User-Agent (uTorrent) |
7556 | utorrent.exe | Potential Corporate Privacy Violation | ET P2P Bittorrent P2P Client User-Agent (uTorrent) |
— | — | Potentially Bad Traffic | ET INFO Possible Chrome Plugin install |