File name:

uTorrent.exe

Full analysis: https://app.any.run/tasks/9258acab-b59b-4d7f-b891-1d3679d2451a
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: August 08, 2020, 23:48:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
installer
adware
pua
lavasoft
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

26EA68F64166F1BFA4A2D435C3C91BD8

SHA1:

7F38EF9F08989E3DE8B9203F4B3FF21A6D3AB64F

SHA256:

4B2C89F6B9582C03277D5D5676226CAEA9AB115484A62370CB7855B9963A1B9A

SSDEEP:

98304:EG5QgQ7CuTkHvSHUwEt/1ytqVSh/DSSfqwHUhk7nuPKhsH:EG5AefPS0weUCw060H

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • installer.exe (PID: 2900)
      • GenericSetup.exe (PID: 2532)
    • Loads dropped or rewritten executable

      • GenericSetup.exe (PID: 2532)
    • Changes settings of System certificates

      • GenericSetup.exe (PID: 2532)
    • LAVASOFT was detected

      • installer.exe (PID: 2900)
  • SUSPICIOUS

    • Reads Environment values

      • GenericSetup.exe (PID: 2532)
    • Reads the Windows organization settings

      • GenericSetup.exe (PID: 2532)
    • Adds / modifies Windows certificates

      • GenericSetup.exe (PID: 2532)
    • Reads Windows owner or organization settings

      • GenericSetup.exe (PID: 2532)
    • Executable content was dropped or overwritten

      • uTorrent.exe (PID: 1908)
    • Searches for installed software

      • GenericSetup.exe (PID: 2532)
  • INFO

    • Reads settings of System Certificates

      • GenericSetup.exe (PID: 2532)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (29.8)
.exe | Win32 Executable MS Visual C++ (generic) (21.6)
.exe | Win64 Executable (generic) (19.1)
.exe | UPX compressed Win32 Executable (18.7)
.dll | Win32 Dynamic Link Library (generic) (4.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2011:04:18 20:54:06+02:00
PEType: PE32
LinkerVersion: 6
CodeSize: 104448
InitializedDataSize: 83968
UninitializedDataSize: -
EntryPoint: 0x148d4
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 3.5.5.45776
ProductVersionNumber: 3.5.5.45776
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileVersion: 3.5.5.45776
ProductVersion: 3.5.5.45776
CompanyName: BitTorrent Inc.
FileDescription: µTorrent
InternalName: uTorrent.exe
LegalCopyright: ©2020 BitTorrent, Inc. All Rights Reserved.
OriginalFileName: uTorrent.exe
ProductName: µTorrent
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
4
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start utorrent.exe #LAVASOFT installer.exe genericsetup.exe utorrent.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1908"C:\Users\admin\AppData\Local\Temp\uTorrent.exe" C:\Users\admin\AppData\Local\Temp\uTorrent.exe
explorer.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
HIGH
Description:
µTorrent
Exit code:
0
Version:
3.5.5.45776
Modules
Images
c:\users\admin\appdata\local\temp\utorrent.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2532"C:\Users\admin\AppData\Local\Temp\7zS477F531E\GenericSetup.exe" C:\Users\admin\AppData\Local\Temp\7zS477F531E\GenericSetup.exe C:\Users\admin\AppData\Local\Temp\7zS477F531E\GenericSetup.exe
installer.exe
User:
admin
Integrity Level:
HIGH
Description:
µTorrent
Exit code:
0
Version:
1.0.3.3337
Modules
Images
c:\users\admin\appdata\local\temp\7zs477f531e\genericsetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2868"C:\Users\admin\AppData\Local\Temp\uTorrent.exe" C:\Users\admin\AppData\Local\Temp\uTorrent.exeexplorer.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
MEDIUM
Description:
µTorrent
Exit code:
3221226540
Version:
3.5.5.45776
Modules
Images
c:\users\admin\appdata\local\temp\utorrent.exe
c:\systemroot\system32\ntdll.dll
2900.\installer.exeC:\Users\admin\AppData\Local\Temp\7zS477F531E\installer.exe
uTorrent.exe
User:
admin
Company:
adaware
Integrity Level:
HIGH
Description:
µTorrent
Exit code:
0
Version:
1.0.3.3337
Modules
Images
c:\users\admin\appdata\local\temp\7zs477f531e\installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
10 004
Read events
9 918
Write events
86
Delete events
0

Modification events

(PID) Process:(2900) installer.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager
Operation:writeName:PendingFileRenameOperations
Value:
\??\C:\Users\admin\AppData\Local\Temp\7zS477F531E\de\DevLib.resources.dll
(PID) Process:(2532) GenericSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2532) GenericSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2900) installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2900) installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2532) GenericSetup.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\137\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2532) GenericSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474
Operation:writeName:Blob
Value:
040000000100000010000000ACB694A59C17E0D791529BB19706A6E40F0000000100000014000000CE0E658AA3E847E467A147B3049191093D055E6F030000000100000014000000D4DE20D05E66FC53FE1A50882C78DB2852CAE4741D0000000100000010000000918AD43A9475F78BB5243DE886D8103C140000000100000014000000E59D5930824758CCACFA085436867B3AB5044DF062000000010000002000000016AF57A9F676B0AB126095AA5EBADEF22AB31119D644AC95CD4B93DBF3F26AEB0B0000000100000030000000440069006700690043006500720074002000420061006C00740069006D006F0072006500200052006F006F007400000009000000010000003E000000303C06082B0601050507030106082B0601050507030406082B0601050507030206082B0601050507030306082B0601050507030906082B0601050507030853000000010000006200000030603020060A2B06010401B13E01640130123010060A2B0601040182373C0101030200C0301F06096086480186FD6C020130123010060A2B0601040182373C0101030200C0301B060567810C010130123010060A2B0601040182373C0101030200C019000000010000001000000068CB42B035EA773E52EF50ECF50EC52920000000010000007B030000308203773082025FA0030201020204020000B9300D06092A864886F70D0101050500305A310B300906035504061302494531123010060355040A130942616C74696D6F726531133011060355040B130A43796265725472757374312230200603550403131942616C74696D6F7265204379626572547275737420526F6F74301E170D3030303531323138343630305A170D3235303531323233353930305A305A310B300906035504061302494531123010060355040A130942616C74696D6F726531133011060355040B130A43796265725472757374312230200603550403131942616C74696D6F7265204379626572547275737420526F6F7430820122300D06092A864886F70D01010105000382010F003082010A0282010100A304BB22AB983D57E826729AB579D429E2E1E89580B1B0E35B8E2B299A64DFA15DEDB009056DDB282ECE62A262FEB488DA12EB38EB219DC0412B01527B8877D31C8FC7BAB988B56A09E773E81140A7D1CCCA628D2DE58F0BA650D2A850C328EAF5AB25878A9A961CA967B83F0CD5F7F952132FC21BD57070F08FC012CA06CB9AE1D9CA337A77D6F8ECB9F16844424813D2C0C2A4AE5E60FEB6A605FCB4DD075902D459189863F5A563E0900C7D5DB2067AF385EAEBD403AE5E843E5FFF15ED69BCF939367275CF77524DF3C9902CB93DE5C923533F1F2498215C079929BDC63AECE76E863A6B97746333BD681831F0788D76BFFC9E8E5D2A86A74D90DC271A390203010001A3453043301D0603551D0E04160414E59D5930824758CCACFA085436867B3AB5044DF030120603551D130101FF040830060101FF020103300E0603551D0F0101FF040403020106300D06092A864886F70D01010505000382010100850C5D8EE46F51684205A0DDBB4F27258403BDF764FD2DD730E3A41017EBDA2929B6793F76F6191323B8100AF958A4D46170BD04616A128A17D50ABDC5BC307CD6E90C258D86404FECCCA37E38C637114FEDDD68318E4CD2B30174EEBE755E07481A7F70FF165C84C07985B805FD7FBE6511A30FC002B4F852373904D5A9317A18BFA02AF41299F7A34582E33C5EF59D9EB5C89E7C2EC8A49E4E08144B6DFD706D6B1A63BD64E61FB7CEF0F29F2EBB1BB7F250887392C2E2E3168D9A3202AB8E18DDE91011EE7E35AB90AF3E30947AD0333DA7650FF5FC8E9E62CF47442C015DBB1DB532D247D2382ED0FE81DC326A1EB5EE3CD5FCE7811D19C32442EA6339A9
Executable files
25
Suspicious files
0
Text files
20
Unknown types
0

Dropped files

PID
Process
Filename
Type
1908uTorrent.exeC:\Users\admin\AppData\Local\Temp\7zS477F531E\BundleConfig.jsontext
MD5:
SHA256:
1908uTorrent.exeC:\Users\admin\AppData\Local\Temp\7zS477F531E\Resources\FinishPage.htmlhtml
MD5:C80FA35AD16A8E6F6D02A003D408200C
SHA256:0C1C1704D0858BBF271EDEEF7C1A9C76126B90AF71A39D121D1159A3EE69599B
1908uTorrent.exeC:\Users\admin\AppData\Local\Temp\7zS477F531E\Resources\LicensePage.htmlhtml
MD5:2F4414A76546AE6BA2CC1B3C5102BD83
SHA256:8C8531CDF663FB92EE8E13FBFF63AF8A22017D424B8F58062B3E6F06050DD941
1908uTorrent.exeC:\Users\admin\AppData\Local\Temp\7zS477F531E\Resources\OfferPage.htmlhtml
MD5:CD971B3AC121709D874E11D6F5BBA960
SHA256:96304C4EF7192F521ADD5D9D630ED8AB75A3D45663D8641A7C3186519F88DC42
1908uTorrent.exeC:\Users\admin\AppData\Local\Temp\7zS477F531E\Resources\SettingPage1.htmlhtml
MD5:55A4C91743FD057A8C430767A32AC9A5
SHA256:361F60D1C7DE5B16C3C0FCA967A8B729D85AC19CA4BD847DBA8AAFB2CB5C8BBF
1908uTorrent.exeC:\Users\admin\AppData\Local\Temp\7zS477F531E\Resources\images\warning48x48.pngimage
MD5:D3361CF0D689A1B34D84F483D60BA9C9
SHA256:56739925AADA73F9489F9A6B72BFAAA92892B27D20F4D221380BA3EAE17F1442
1908uTorrent.exeC:\Users\admin\AppData\Local\Temp\7zS477F531E\Carrier.exeexecutable
MD5:
SHA256:
1908uTorrent.exeC:\Users\admin\AppData\Local\Temp\7zS477F531E\Resources\images\loader.gifimage
MD5:2B26F73D382AB69F3914A7D9FDA97B0F
SHA256:A6A0B05B1D5C52303DD3E9E2F9CDA1E688A490FBE84EA0D6E22A051AB6EFD643
1908uTorrent.exeC:\Users\admin\AppData\Local\Temp\7zS477F531E\Resources\tis\TranslateOfferTemplate.tistext
MD5:551029A3E046C5ED6390CC85F632A689
SHA256:7B8C76A85261C5F9E40E49F97E01A14320E9B224FF3D6AF8286632CA94CF96F8
1908uTorrent.exeC:\Users\admin\AppData\Local\Temp\7zS477F531E\Resources\WarningPage.htmlhtml
MD5:E4EAF0049346F0A54500F2E1D7162CDA
SHA256:D916648FFE60F3A0925EE8456D2153FFE9CBD616F6D1468F9DFC0BBCC5AB8D33
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
5
DNS requests
3
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2900
installer.exe
POST
200
104.18.87.101:80
http://flow.lavasoft.com/v1/event-stat?ProductID=IS&Type=StubStart
US
text
29 b
whitelisted
2900
installer.exe
POST
200
104.18.87.101:80
http://flow.lavasoft.com/v1/event-stat?ProductID=IS&Type=StubBundleStart
US
text
29 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2900
installer.exe
104.18.87.101:80
flow.lavasoft.com
Cloudflare Inc
US
shared
2532
GenericSetup.exe
104.16.235.79:443
sos.adaware.com
Cloudflare Inc
US
shared
2532
GenericSetup.exe
104.18.88.101:443
flow.lavasoft.com
Cloudflare Inc
US
shared

DNS requests

Domain
IP
Reputation
flow.lavasoft.com
  • 104.18.87.101
  • 104.18.88.101
whitelisted
sos.adaware.com
  • 104.16.235.79
  • 104.16.236.79
whitelisted

Threats

PID
Process
Class
Message
2900
installer.exe
A Network Trojan was detected
ET MALWARE Lavasoft PUA/Adware Client Install
Process
Message
GenericSetup.exe
at sciter:init-script.tis
GenericSetup.exe
at sciter:init-script.tis
GenericSetup.exe
GenericSetup.exe
GenericSetup.exe
file:resources/tis/TranslateOfferTemplate.tis(82) : warning :'async' does not contain any 'await'