File name: | 3.5.5_45574.exe |
Full analysis: | https://app.any.run/tasks/b2e4d180-8d9a-4194-b2b4-3da5538e5058 |
Verdict: | Malicious activity |
Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
Analysis date: | September 24, 2020, 17:14:44 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
MD5: | 6C3895A4678CB4488BFC45D75F9FC023 |
SHA1: | 3BB15238F9EBAB1EB2CAE2B58C1D2C5A3043981B |
SHA256: | 434C8EE819904AC7AF5ADBFAB526234B2CB94536F547E55E05E855886932BCF8 |
SSDEEP: | 49152:ugNWMpJ3jQtc1syiAhm8tr40UnWTbXUAvWLMD:ugWzc1nDh/unrAD |
.exe | | | UPX compressed Win32 Executable (43.5) |
---|---|---|
.exe | | | Win32 EXE Yoda's Crypter (42.7) |
.exe | | | Win32 Executable (generic) (7.2) |
.exe | | | Generic Win/DOS Executable (3.2) |
.exe | | | DOS Executable Generic (3.2) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2020:02:11 03:26:32+01:00 |
PEType: | PE32 |
LinkerVersion: | 14 |
CodeSize: | 1933312 |
InitializedDataSize: | 126976 |
UninitializedDataSize: | 3461120 |
EntryPoint: | 0x524e20 |
OSVersion: | 5.1 |
ImageVersion: | - |
SubsystemVersion: | 5.1 |
Subsystem: | Windows GUI |
FileVersionNumber: | 3.5.5.45574 |
ProductVersionNumber: | 3.5.5.45574 |
FileFlagsMask: | 0x002b |
FileFlags: | Special build |
FileOS: | Unknown (0) |
ObjectFileType: | Unknown |
FileSubtype: | - |
LanguageCode: | English (U.S.) |
CharacterSet: | Windows, Latin1 |
CompanyName: | BitTorrent Inc. |
FileDescription: | µTorrent |
FileVersion: | 3.5.5.45574 |
InternalName: | uTorrent.exe |
OriginalFileName: | uTorrent.exe |
LegalCopyright: | ©2019 BitTorrent, Inc. All Rights Reserved. |
ProductName: | µTorrent |
ProductVersion: | 3.5.5.45574 |
SpecialBuild: | stable34 stable |
Architecture: | IMAGE_FILE_MACHINE_I386 |
---|---|
Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Compilation Date: | 11-Feb-2020 02:26:32 |
Detected languages: |
|
CompanyName: | BitTorrent Inc. |
FileDescription: | µTorrent |
FileVersion: | 3.5.5.45574 |
InternalName: | uTorrent.exe |
OriginalFilename: | uTorrent.exe |
LegalCopyright: | ©2019 BitTorrent, Inc. All Rights Reserved. |
ProductName: | µTorrent |
ProductVersion: | 3.5.5.45574 |
SpecialBuild: | stable34 stable |
Magic number: | MZ |
---|---|
Bytes on last page of file: | 0x0090 |
Pages in file: | 0x0003 |
Relocations: | 0x0000 |
Size of header: | 0x0004 |
Min extra paragraphs: | 0x0000 |
Max extra paragraphs: | 0xFFFF |
Initial SS value: | 0x0000 |
Initial SP value: | 0x00B8 |
Checksum: | 0x0000 |
Initial IP value: | 0x0000 |
Initial CS value: | 0x0000 |
Overlay number: | 0x0000 |
OEM identifier: | 0x0000 |
OEM information: | 0x0000 |
Address of NE header: | 0x00000150 |
Signature: | PE |
---|---|
Machine: | IMAGE_FILE_MACHINE_I386 |
Number of sections: | 3 |
Time date stamp: | 11-Feb-2020 02:26:32 |
Pointer to Symbol Table: | 0x00000000 |
Number of symbols: | 0 |
Size of Optional Header: | 0x00E0 |
Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
UPX0 | 0x00001000 | 0x0034D000 | 0x00000000 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
UPX1 | 0x0034E000 | 0x001D8000 | 0x001D7C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.99986 |
.rsrc | 0x00526000 | 0x0001F000 | 0x0001EE00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.00632 |
Title | Entropy | Size | Codepage | Language | Type |
---|---|---|---|---|---|
1 | 5.11079 | 1835 | UNKNOWN | Swedish - Sweden | RT_MANIFEST |
2 | 7.81404 | 1003 | UNKNOWN | Swedish - Sweden | RT_HTML |
3 | 5.63952 | 62 | UNKNOWN | Swedish - Sweden | RT_GROUP_ICON |
4 | 7.97738 | 9640 | UNKNOWN | English - United States | RT_ICON |
5 | 4.22193 | 20 | UNKNOWN | Swedish - Sweden | RT_GROUP_ICON |
6 | 7.97881 | 9640 | UNKNOWN | English - United States | RT_ICON |
7 | 7.98292 | 9640 | UNKNOWN | English - United States | RT_ICON |
8 | 7.98008 | 9640 | UNKNOWN | English - United States | RT_ICON |
9 | 7.97937 | 9640 | UNKNOWN | English - United States | RT_ICON |
10 | 6.54557 | 114 | UNKNOWN | Swedish - Sweden | RT_DIALOG |
ADVAPI32.dll |
COMCTL32.dll |
COMDLG32.dll |
DNSAPI.dll |
GDI32.dll |
IPHLPAPI.DLL |
KERNEL32.DLL |
MSIMG32.dll |
OLEAUT32.dll |
PSAPI.DLL |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1560 | "C:\Users\admin\AppData\Roaming\uTorrent\updates\3.5.5_45574\utorrentie.exe" uTorrent_2400_02C30488_768547211 µTorrent4823DF041B09 uTorrent | C:\Users\admin\AppData\Roaming\uTorrent\updates\3.5.5_45574\utorrentie.exe | uTorrent.exe | ||||||||||||
User: admin Company: BitTorrent Inc. Integrity Level: LOW Description: WebHelper Exit code: 0 Version: 1.0.0 Modules
| |||||||||||||||
1740 | "C:\Users\admin\AppData\Roaming\uTorrent\helper\helper.exe" 49909 --hval MZIAuFkdzFPJsw3g -- -pid 2400 -version 45574 | C:\Users\admin\AppData\Roaming\uTorrent\helper\helper.exe | uTorrent.exe | ||||||||||||
User: admin Company: BitTorrent Inc. Integrity Level: MEDIUM Description: µTorrent Helper Exit code: 0 Version: 2.0.8.602 Modules
| |||||||||||||||
1896 | "C:\Users\admin\AppData\Roaming\uTorrent\updates\3.5.5_45574\utorrentie.exe" uTorrent_2400_02C305B8_652158345 µTorrent4823DF041B09 uTorrent | C:\Users\admin\AppData\Roaming\uTorrent\updates\3.5.5_45574\utorrentie.exe | — | uTorrent.exe | |||||||||||
User: admin Company: BitTorrent Inc. Integrity Level: LOW Description: WebHelper Exit code: 0 Version: 1.0.0 Modules
| |||||||||||||||
2400 | uTorrent.exe /NOINSTALL /BRINGTOFRONT | C:\Users\admin\AppData\Roaming\uTorrent\uTorrent.exe | 3.5.5_45574.exe | ||||||||||||
User: admin Company: BitTorrent Inc. Integrity Level: MEDIUM Description: µTorrent Exit code: 0 Version: 3.5.5.45574 Modules
| |||||||||||||||
2412 | "C:\Users\admin\AppData\Roaming\uTorrent\updates\3.5.5_45574\utorrentie.exe" uTorrent_2400_02C303F0_1768063582 µTorrent4823DF041B09 uTorrent | C:\Users\admin\AppData\Roaming\uTorrent\updates\3.5.5_45574\utorrentie.exe | uTorrent.exe | ||||||||||||
User: admin Company: BitTorrent Inc. Integrity Level: LOW Description: WebHelper Exit code: 0 Version: 1.0.0 Modules
| |||||||||||||||
2584 | "C:\Windows\system32\taskmgr.exe" /4 | C:\Windows\system32\taskmgr.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Task Manager Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
3088 | "C:\Users\admin\AppData\Roaming\uTorrent\updates\3.5.5_45574\utorrentie.exe" uTorrent_2400_02C305B8_1739611211 µTorrent4823DF041B09 uTorrent | C:\Users\admin\AppData\Roaming\uTorrent\updates\3.5.5_45574\utorrentie.exe | uTorrent.exe | ||||||||||||
User: admin Company: BitTorrent Inc. Integrity Level: LOW Description: WebHelper Exit code: 0 Version: 1.0.0 Modules
| |||||||||||||||
3368 | "C:\Users\admin\AppData\Local\Temp\3.5.5_45574.exe" | C:\Users\admin\AppData\Local\Temp\3.5.5_45574.exe | explorer.exe | ||||||||||||
User: admin Company: BitTorrent Inc. Integrity Level: MEDIUM Description: µTorrent Exit code: 1 Version: 3.5.5.45574 Modules
| |||||||||||||||
3380 | "C:\Users\admin\AppData\Roaming\uTorrent\updates\3.5.5_45574\utorrentie.exe" uTorrent_2400_02C305B8_1829157235 µTorrent4823DF041B09 uTorrent | C:\Users\admin\AppData\Roaming\uTorrent\updates\3.5.5_45574\utorrentie.exe | uTorrent.exe | ||||||||||||
User: admin Company: BitTorrent Inc. Integrity Level: LOW Description: WebHelper Exit code: 0 Version: 1.0.0 Modules
| |||||||||||||||
3540 | "C:\Users\admin\AppData\Local\Temp\3.5.5_45574.exe" /PERFORMINSTALL 128 "C:\Users\admin\AppData\Roaming\uTorrent" 4219920603 /HYDRA_EXCEPTION | C:\Users\admin\AppData\Local\Temp\3.5.5_45574.exe | 3.5.5_45574.exe | ||||||||||||
User: admin Company: BitTorrent Inc. Integrity Level: HIGH Description: µTorrent Exit code: 1 Version: 3.5.5.45574 Modules
|
(PID) Process: | (3368) 3.5.5_45574.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (3368) 3.5.5_45574.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
Operation: | write | Name: | CachePrefix |
Value: | |||
(PID) Process: | (3368) 3.5.5_45574.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
(PID) Process: | (3368) 3.5.5_45574.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
(PID) Process: | (3368) 3.5.5_45574.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
(PID) Process: | (3368) 3.5.5_45574.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 1 | |||
(PID) Process: | (3540) 3.5.5_45574.exe | Key: | HKEY_CURRENT_USER\Software\BitTorrent |
Operation: | write | Name: | computerID |
Value: DBE086FB319200B8591DCC53C9B30DE05158036CDEC3A658 | |||
(PID) Process: | (3540) 3.5.5_45574.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
(PID) Process: | (3540) 3.5.5_45574.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
Operation: | write | Name: | SavedLegacySettings |
Value: 46000000A3000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000 | |||
(PID) Process: | (3540) 3.5.5_45574.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 0 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3368 | 3.5.5_45574.exe | C:\Users\admin\AppData\Local\Temp\uttD741.tmp | — | |
MD5:— | SHA256:— | |||
3368 | 3.5.5_45574.exe | C:\Users\admin\AppData\Roaming\uTorrent\settings.dat.new | — | |
MD5:— | SHA256:— | |||
3540 | 3.5.5_45574.exe | C:\Users\admin\AppData\Local\Temp\utt403C.tmp | — | |
MD5:— | SHA256:— | |||
3540 | 3.5.5_45574.exe | C:\Users\admin\AppData\Local\Temp\utt48E8.tmp.new | — | |
MD5:— | SHA256:— | |||
3540 | 3.5.5_45574.exe | C:\Users\admin\AppData\Roaming\uTorrent\toolbar.benc.new | — | |
MD5:— | SHA256:— | |||
3368 | 3.5.5_45574.exe | C:\Users\admin\AppData\Local\Temp\utt7C0E.tmp | — | |
MD5:— | SHA256:— | |||
3368 | 3.5.5_45574.exe | C:\Users\admin\AppData\Local\Temp\utt7C9C.tmp | — | |
MD5:— | SHA256:— | |||
2400 | uTorrent.exe | C:\Users\admin\AppData\Local\Temp\utt915A.tmp | — | |
MD5:— | SHA256:— | |||
2400 | uTorrent.exe | C:\Users\admin\AppData\Roaming\uTorrent\settings.dat.new | — | |
MD5:— | SHA256:— | |||
3368 | 3.5.5_45574.exe | C:\Users\admin\AppData\Roaming\uTorrent\settings.dat | binary | |
MD5:— | SHA256:— |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3540 | 3.5.5_45574.exe | GET | — | 67.215.246.203:80 | http://update.utorrent.com/installstats.php?cl=uTorrent&v=111915526&h=MZIAuFkdzFPJsw3g&w=1DB10106&bu=0&pr=0&cmp=0&ocmp=0&showtbexists&pid=3540&cau=0&tbe=0&cd=0&view=win32 | US | — | — | whitelisted |
3540 | 3.5.5_45574.exe | GET | 200 | 67.215.246.203:80 | http://update.utorrent.com/installstats.php?cl=uTorrent&v=111915526&h=MZIAuFkdzFPJsw3g&w=1DB10106&bu=0&pr=0&cmp=0&ocmp=0&showtorrentoffer&pid=3540&cau=0&toroffer=0&torofferid=<NULL>&view=win32 | US | — | — | whitelisted |
2400 | uTorrent.exe | GET | — | 178.79.242.147:80 | http://apps.bittorrent.com/utorrent-onboarding/player.btapp | DE | — | — | whitelisted |
3540 | 3.5.5_45574.exe | GET | 200 | 67.215.246.203:80 | http://update.utorrent.com/installstats.php?cl=uTorrent&v=111915526&h=MZIAuFkdzFPJsw3g&w=1DB10106&bu=0&pr=0&cmp=0&ocmp=0&showinstall&pid=3540&cau=0&au=0&view=win32 | US | — | — | whitelisted |
3540 | 3.5.5_45574.exe | GET | 200 | 67.215.246.203:80 | http://update.utorrent.com/installstats.php?cl=uTorrent&v=111915526&h=MZIAuFkdzFPJsw3g&w=1DB10106&bu=0&pr=0&cmp=0&ocmp=0&installresult&pid=3540&cau=0&installresult=0&exit=1&au=0&ic=1&view=win32 | US | — | — | whitelisted |
3540 | 3.5.5_45574.exe | GET | 200 | 67.215.246.203:80 | http://update.utorrent.com/installstats.php?cl=uTorrent&v=111915526&h=MZIAuFkdzFPJsw3g&w=1DB10106&bu=0&pr=0&cmp=0&ocmp=0&wizardcomplete&pid=3540&cau=0&view=win32 | US | — | — | whitelisted |
3540 | 3.5.5_45574.exe | GET | 200 | 67.215.246.203:80 | http://update.utorrent.com/installstats.php?cl=uTorrent&v=111915526&h=MZIAuFkdzFPJsw3g&w=1DB10106&bu=0&pr=0&cmp=0&ocmp=0&showwarning&pid=3540&cau=0&view=win32 | US | — | — | whitelisted |
3368 | 3.5.5_45574.exe | POST | — | 54.225.194.96:80 | http://i-50.b-000.xyz.bench.utorrent.com/e?i=50 | US | — | — | whitelisted |
3368 | 3.5.5_45574.exe | POST | — | 54.235.208.27:80 | http://i-50.b-000.xyz.bench.utorrent.com/e?i=50 | US | — | — | whitelisted |
3368 | 3.5.5_45574.exe | POST | — | 54.197.251.114:80 | http://i-50.b-000.xyz.bench.utorrent.com/e?i=50 | US | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
3368 | 3.5.5_45574.exe | 23.21.43.186:80 | i-50.b-000.xyz.bench.utorrent.com | Amazon.com, Inc. | US | malicious |
3368 | 3.5.5_45574.exe | 54.243.113.215:80 | i-50.b-000.xyz.bench.utorrent.com | Amazon.com, Inc. | US | suspicious |
3368 | 3.5.5_45574.exe | 67.215.238.66:80 | download-lb.utorrent.com | QuadraNet, Inc | US | suspicious |
3368 | 3.5.5_45574.exe | 54.197.251.114:80 | i-50.b-000.xyz.bench.utorrent.com | Amazon.com, Inc. | US | whitelisted |
3368 | 3.5.5_45574.exe | 54.235.208.27:80 | i-50.b-000.xyz.bench.utorrent.com | Amazon.com, Inc. | US | whitelisted |
3368 | 3.5.5_45574.exe | 54.225.194.96:80 | i-50.b-000.xyz.bench.utorrent.com | Amazon.com, Inc. | US | whitelisted |
3368 | 3.5.5_45574.exe | 107.20.217.71:80 | i-50.b-000.xyz.bench.utorrent.com | Amazon.com, Inc. | US | suspicious |
3540 | 3.5.5_45574.exe | 67.215.246.203:80 | update.utorrent.com | QuadraNet, Inc | US | suspicious |
3368 | 3.5.5_45574.exe | 67.215.246.203:80 | update.utorrent.com | QuadraNet, Inc | US | suspicious |
2400 | uTorrent.exe | 98.143.146.7:80 | utorrent.com | QuadraNet, Inc | US | suspicious |
Domain | IP | Reputation |
---|---|---|
router.bittorrent.com |
| shared |
router.utorrent.com |
| whitelisted |
i-50.b-000.xyz.bench.utorrent.com |
| whitelisted |
download-lb.utorrent.com |
| whitelisted |
dns.msftncsi.com |
| shared |
i-21.b-45574.ut.bench.utorrent.com |
| suspicious |
update.utorrent.com |
| whitelisted |
i-50.b-45574.ut.bench.utorrent.com |
| suspicious |
utorrent.com |
| whitelisted |
apps.bittorrent.com |
| whitelisted |
PID | Process | Class | Message |
---|---|---|---|
— | — | Misc activity | APP [PTsecurity] uTorrent Hydra Client |
— | — | Misc activity | APP [PTsecurity] P2P uTorrent Hydra Client |
— | — | Misc activity | APP [PTsecurity] P2P uTorrent Hydra Client |
— | — | Misc activity | APP [PTsecurity] uTorrent Hydra Client |
— | — | Misc activity | APP [PTsecurity] P2P uTorrent Hydra Client |
— | — | Misc activity | APP [PTsecurity] uTorrent Hydra Client |
— | — | Misc activity | APP [PTsecurity] P2P uTorrent Hydra Client |
— | — | Misc activity | APP [PTsecurity] uTorrent Hydra Client |
— | — | Misc activity | APP [PTsecurity] P2P uTorrent Hydra Client |
— | — | Misc activity | APP [PTsecurity] uTorrent Hydra Client |
Process | Message |
---|---|
helper.exe | Unknown property letter-spacing
|
helper.exe | Unknown property letter-spacing
|
helper.exe | Unknown property font-stretch
|
helper.exe | Unknown property font-stretch
|
helper.exe | Unknown property font-stretch
|
helper.exe | Unknown property font-stretch
|
helper.exe | Unknown property font-stretch
|
helper.exe | Unknown property font-stretch
|
helper.exe | Unknown property letter-spacing
|
helper.exe | Unknown property letter-spacing
|