File name:

BitTorrent.Pro.7.10.5.Build.45785_Startcrack.com.exe

Full analysis: https://app.any.run/tasks/10f5614d-6c2b-41e0-b99a-13b80d59ecc7
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: November 05, 2020, 12:34:53
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
installer
adware
pua
lavasoft
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

7A0A22B2AD850668229C61B1469F086E

SHA1:

04B5DCEB5C924EF36437A628C100ED35939E579E

SHA256:

4BF0C75B494ED080BAC7FAADAADD3555D2D6BAD74D43C6FB8CBF21D7D00E41A8

SSDEEP:

98304:3G5QgDzoNTKoAFDFPL6Xy/r1C0CFav4i8ckad49QBOB5Y5oEUq36t:3G5XowoAF5vCJUQi96ie5Gos+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • GenericSetup.exe (PID: 2344)
    • Application was dropped or rewritten from another process

      • installer.exe (PID: 2520)
      • GenericSetup.exe (PID: 2344)
      • Carrier.exe (PID: 2924)
      • BitTorrent.exe (PID: 1968)
      • bittorrentie.exe (PID: 2932)
      • bittorrentie.exe (PID: 2500)
      • bittorrentie.exe (PID: 3532)
    • LAVASOFT was detected

      • installer.exe (PID: 2520)
    • Changes settings of System certificates

      • GenericSetup.exe (PID: 2344)
      • Carrier.exe (PID: 2924)
    • Changes the autorun value in the registry

      • Carrier.exe (PID: 2924)
      • BitTorrent.exe (PID: 1968)
    • Loads the Task Scheduler COM API

      • GenericSetup.exe (PID: 2344)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • BitTorrent.Pro.7.10.5.Build.45785_Startcrack.com.exe (PID: 3708)
      • Carrier.exe (PID: 2924)
      • BitTorrent.exe (PID: 1968)
    • Reads the Windows organization settings

      • GenericSetup.exe (PID: 2344)
    • Reads Environment values

      • GenericSetup.exe (PID: 2344)
    • Reads Windows owner or organization settings

      • GenericSetup.exe (PID: 2344)
    • Starts CMD.EXE for commands execution

      • GenericSetup.exe (PID: 2344)
    • Adds / modifies Windows certificates

      • GenericSetup.exe (PID: 2344)
    • Creates files in the user directory

      • Carrier.exe (PID: 2924)
      • BitTorrent.exe (PID: 1968)
      • bittorrentie.exe (PID: 2500)
      • bittorrentie.exe (PID: 3532)
    • Reads Internet Cache Settings

      • Carrier.exe (PID: 2924)
      • BitTorrent.exe (PID: 1968)
      • bittorrentie.exe (PID: 2932)
      • bittorrentie.exe (PID: 3532)
      • bittorrentie.exe (PID: 2500)
    • Modifies the open verb of a shell class

      • Carrier.exe (PID: 2924)
    • Executed via COM

      • DllHost.exe (PID: 3484)
    • Executed via Task Scheduler

      • cmd.exe (PID: 3600)
    • Creates a software uninstall entry

      • Carrier.exe (PID: 2924)
    • Changes IE settings (feature browser emulation)

      • BitTorrent.exe (PID: 1968)
    • Reads internet explorer settings

      • bittorrentie.exe (PID: 2932)
      • bittorrentie.exe (PID: 3532)
      • bittorrentie.exe (PID: 2500)
    • Searches for installed software

      • GenericSetup.exe (PID: 2344)
  • INFO

    • Reads settings of System Certificates

      • GenericSetup.exe (PID: 2344)
      • Carrier.exe (PID: 2924)
      • bittorrentie.exe (PID: 2500)
      • bittorrentie.exe (PID: 3532)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (36.8)
.exe | Win32 Executable MS Visual C++ (generic) (26.6)
.exe | Win64 Executable (generic) (23.6)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2011:04:18 20:54:06+02:00
PEType: PE32
LinkerVersion: 6
CodeSize: 104448
InitializedDataSize: 45568
UninitializedDataSize: -
EntryPoint: 0x148d4
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 7.10.5.45785
ProductVersionNumber: 7.10.5.45785
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileVersion: 7.10.5.45785
ProductVersion: 7.10.5.45785
CompanyName: BitTorrent Inc.
FileDescription: BitTorrent
InternalName: BitTorrent.exe
LegalCopyright: ©2020 BitTorrent, Inc. All Rights Reserved.
OriginalFileName: BitTorrent.exe
ProductName: BitTorrent
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
53
Monitored processes
12
Malicious processes
8
Suspicious processes
2

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start bittorrent.pro.7.10.5.build.45785_startcrack.com.exe #LAVASOFT installer.exe genericsetup.exe cmd.exe no specs carrier.exe HNetCfg.FwPolicy2 no specs cmd.exe no specs bittorrent.exe bittorrentie.exe bittorrentie.exe bittorrentie.exe bittorrent.pro.7.10.5.build.45785_startcrack.com.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1152"C:\Windows\system32\cmd.exe" /C ""C:\Users\admin\AppData\Local\Temp\7zSC7E3EDC4\Carrier.exe" /S /FORCEINSTALL 1110010101111110"C:\Windows\system32\cmd.exeGenericSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1188"C:\Users\admin\AppData\Local\Temp\BitTorrent.Pro.7.10.5.Build.45785_Startcrack.com.exe" C:\Users\admin\AppData\Local\Temp\BitTorrent.Pro.7.10.5.Build.45785_Startcrack.com.exeexplorer.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
MEDIUM
Description:
BitTorrent
Exit code:
3221226540
Version:
7.10.5.45785
Modules
Images
c:\users\admin\appdata\local\temp\bittorrent.pro.7.10.5.build.45785_startcrack.com.exe
c:\systemroot\system32\ntdll.dll
1968"C:\Users\admin\AppData\Roaming\BitTorrent\BitTorrent.exe" /RUNONSTARTUPC:\Users\admin\AppData\Roaming\BitTorrent\BitTorrent.exe
cmd.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
MEDIUM
Description:
BitTorrent
Exit code:
0
Version:
7.10.5.45785
Modules
Images
c:\users\admin\appdata\roaming\bittorrent\bittorrent.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
2344"C:\Users\admin\AppData\Local\Temp\7zSC7E3EDC4\GenericSetup.exe" C:\Users\admin\AppData\Local\Temp\7zSC7E3EDC4\GenericSetup.exe C:\Users\admin\AppData\Local\Temp\7zSC7E3EDC4\GenericSetup.exe
installer.exe
User:
admin
Company:
Adaware
Integrity Level:
HIGH
Description:
BitTorrent
Exit code:
3221225547
Version:
1.0.2.3368
Modules
Images
c:\users\admin\appdata\local\temp\7zsc7e3edc4\genericsetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2500"C:\Users\admin\AppData\Roaming\BitTorrent\updates\7.10.5_45785\bittorrentie.exe" BitTorrent_1968_01E337A8_541403748 BT4823DF041B09 BitTorrentC:\Users\admin\AppData\Roaming\BitTorrent\updates\7.10.5_45785\bittorrentie.exe
BitTorrent.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
LOW
Description:
WebHelper
Exit code:
0
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\roaming\bittorrent\updates\7.10.5_45785\bittorrentie.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2520.\installer.exeC:\Users\admin\AppData\Local\Temp\7zSC7E3EDC4\installer.exe
BitTorrent.Pro.7.10.5.Build.45785_Startcrack.com.exe
User:
admin
Company:
adaware
Integrity Level:
HIGH
Description:
BitTorrent
Exit code:
0
Version:
1.0.2.3368
Modules
Images
c:\users\admin\appdata\local\temp\7zsc7e3edc4\installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2924"C:\Users\admin\AppData\Local\Temp\7zSC7E3EDC4\Carrier.exe" /S /FORCEINSTALL 1110010101111110C:\Users\admin\AppData\Local\Temp\7zSC7E3EDC4\Carrier.exe
cmd.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
HIGH
Description:
BitTorrent
Exit code:
1
Version:
7.10.5.45785
Modules
Images
c:\users\admin\appdata\local\temp\7zsc7e3edc4\carrier.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
2932"C:\Users\admin\AppData\Roaming\BitTorrent\updates\7.10.5_45785\bittorrentie.exe" BitTorrent_1968_01E338D8_1510887404 BT4823DF041B09 BitTorrentC:\Users\admin\AppData\Roaming\BitTorrent\updates\7.10.5_45785\bittorrentie.exe
BitTorrent.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
LOW
Description:
WebHelper
Exit code:
0
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\roaming\bittorrent\updates\7.10.5_45785\bittorrentie.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3484C:\Windows\system32\DllHost.exe /Processid:{E2B3C97F-6AE1-41AC-817A-F6F92166D7DD}C:\Windows\system32\DllHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3532"C:\Users\admin\AppData\Roaming\BitTorrent\updates\7.10.5_45785\bittorrentie.exe" BitTorrent_1968_01E332E8_1193906570 BT4823DF041B09 BitTorrentC:\Users\admin\AppData\Roaming\BitTorrent\updates\7.10.5_45785\bittorrentie.exe
BitTorrent.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
LOW
Description:
WebHelper
Exit code:
0
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\roaming\bittorrent\updates\7.10.5_45785\bittorrentie.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
12 636
Read events
12 380
Write events
254
Delete events
2

Modification events

(PID) Process:(2520) installer.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager
Operation:writeName:PendingFileRenameOperations
Value:
\??\C:\Users\admin\AppData\Local\Temp\7zSC7E3EDC4\de\DevLib.resources.dll
(PID) Process:(2344) GenericSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2344) GenericSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2520) installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2520) installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2344) GenericSetup.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2344) GenericSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474
Operation:writeName:Blob
Value:
040000000100000010000000ACB694A59C17E0D791529BB19706A6E40F0000000100000014000000CE0E658AA3E847E467A147B3049191093D055E6F030000000100000014000000D4DE20D05E66FC53FE1A50882C78DB2852CAE4741D0000000100000010000000918AD43A9475F78BB5243DE886D8103C140000000100000014000000E59D5930824758CCACFA085436867B3AB5044DF062000000010000002000000016AF57A9F676B0AB126095AA5EBADEF22AB31119D644AC95CD4B93DBF3F26AEB0B0000000100000030000000440069006700690043006500720074002000420061006C00740069006D006F0072006500200052006F006F007400000009000000010000003E000000303C06082B0601050507030106082B0601050507030406082B0601050507030206082B0601050507030306082B0601050507030906082B0601050507030853000000010000006200000030603020060A2B06010401B13E01640130123010060A2B0601040182373C0101030200C0301F06096086480186FD6C020130123010060A2B0601040182373C0101030200C0301B060567810C010130123010060A2B0601040182373C0101030200C019000000010000001000000068CB42B035EA773E52EF50ECF50EC52920000000010000007B030000308203773082025FA0030201020204020000B9300D06092A864886F70D0101050500305A310B300906035504061302494531123010060355040A130942616C74696D6F726531133011060355040B130A43796265725472757374312230200603550403131942616C74696D6F7265204379626572547275737420526F6F74301E170D3030303531323138343630305A170D3235303531323233353930305A305A310B300906035504061302494531123010060355040A130942616C74696D6F726531133011060355040B130A43796265725472757374312230200603550403131942616C74696D6F7265204379626572547275737420526F6F7430820122300D06092A864886F70D01010105000382010F003082010A0282010100A304BB22AB983D57E826729AB579D429E2E1E89580B1B0E35B8E2B299A64DFA15DEDB009056DDB282ECE62A262FEB488DA12EB38EB219DC0412B01527B8877D31C8FC7BAB988B56A09E773E81140A7D1CCCA628D2DE58F0BA650D2A850C328EAF5AB25878A9A961CA967B83F0CD5F7F952132FC21BD57070F08FC012CA06CB9AE1D9CA337A77D6F8ECB9F16844424813D2C0C2A4AE5E60FEB6A605FCB4DD075902D459189863F5A563E0900C7D5DB2067AF385EAEBD403AE5E843E5FFF15ED69BCF939367275CF77524DF3C9902CB93DE5C923533F1F2498215C079929BDC63AECE76E863A6B97746333BD681831F0788D76BFFC9E8E5D2A86A74D90DC271A390203010001A3453043301D0603551D0E04160414E59D5930824758CCACFA085436867B3AB5044DF030120603551D130101FF040830060101FF020103300E0603551D0F0101FF040403020106300D06092A864886F70D01010505000382010100850C5D8EE46F51684205A0DDBB4F27258403BDF764FD2DD730E3A41017EBDA2929B6793F76F6191323B8100AF958A4D46170BD04616A128A17D50ABDC5BC307CD6E90C258D86404FECCCA37E38C637114FEDDD68318E4CD2B30174EEBE755E07481A7F70FF165C84C07985B805FD7FBE6511A30FC002B4F852373904D5A9317A18BFA02AF41299F7A34582E33C5EF59D9EB5C89E7C2EC8A49E4E08144B6DFD706D6B1A63BD64E61FB7CEF0F29F2EBB1BB7F250887392C2E2E3168D9A3202AB8E18DDE91011EE7E35AB90AF3E30947AD0333DA7650FF5FC8E9E62CF47442C015DBB1DB532D247D2382ED0FE81DC326A1EB5EE3CD5FCE7811D19C32442EA6339A9
(PID) Process:(2344) GenericSetup.exeKey:HKEY_CURRENT_USER\Software\Opera Stable Offer
Operation:writeName:LastTimeOfferShown
Value:
1604579767
(PID) Process:(2924) Carrier.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2924) Carrier.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3B1EFD3A66EA28B16697394703A72CA340A05BD5
Operation:writeName:Blob
Value:
040000000100000010000000A266BB7DCC38A562631361BBF61DD11B140000000100000014000000D5F656CB8FE8A25C6268D13D94905BD7CE9A18C40300000001000000140000003B1EFD3A66EA28B16697394703A72CA340A05BD50B00000001000000540000004D006900630072006F0073006F0066007400200052006F006F007400200043006500720074006900660069006300610074006500200041007500740068006F00720069007400790020003200300031003000000069000000010000000E000000300C060A2B0601040182373C03020F000000010000002000000008FBA831C08544208F5208686B991CA1B2CFC510E7301784DDF1EB5BF03932391900000001000000100000003C70FAEA25600CE3B2CC5F0B222ED6292000000001000000F1050000308205ED308203D5A003020102021028CC3A25BFBA44AC449A9B586B4339AA300D06092A864886F70D01010B0500308188310B3009060355040613025553311330110603550408130A57617368696E67746F6E3110300E060355040713075265646D6F6E64311E301C060355040A13154D6963726F736F667420436F72706F726174696F6E31323030060355040313294D6963726F736F667420526F6F7420436572746966696361746520417574686F726974792032303130301E170D3130303632333231353732345A170D3335303632333232303430315A308188310B3009060355040613025553311330110603550408130A57617368696E67746F6E3110300E060355040713075265646D6F6E64311E301C060355040A13154D6963726F736F667420436F72706F726174696F6E31323030060355040313294D6963726F736F667420526F6F7420436572746966696361746520417574686F72697479203230313030820222300D06092A864886F70D01010105000382020F003082020A0282020100B9089E28E4E4EC064E5068B341C57BEBAEB68EAF81BA22441F6534694CBE704017F2167BE279FD86ED0D39F41BA8AD92901ECB3D768F5AD9B591102E3C058D8A6D2454E71FED56AD83B4509C15A51774885920FC08C58476D368D46F2878CE5CB8F3509044FFE3635FBEA19A2C961504D607FE1E8421E0423111C4283694CF50A4629EC9D6AB7100B25B0CE696D40A2496F5FFC6D5B71BD7CBB72162AF12DCA15D37E31AFB1A4698C09BC0E7631F2A0893027E1E6A8EF29F1889E42285A2B1845740FFF50ED86F9CEDE2453101CD17E97FB08145E3AA214026A172AAA74F3C01057EEE8358B15E06639962917882B70D930C246AB41BDB27EC5F95043F934A30F59718B3A7F919A793331D01C8DB22525CD725C946F9A2FB875943BE9B62B18D2D86441A46AC78617E3009FAAE89C4412A2266039139459CC78B0CA8CA0D2FFB52EA0CF76333239DFEB01FAD67D6A75003C6047063B52CB1865A43B7FBAEF96E296E21214126068CC9C3EEB0C28593A1B985D9E6326C4B4C3FD65DA3E5B59D77C39CC055B77400E3B838AB839750E19A42241DC6C0A330D11A5AC85234F773F1C7181F33AD7AECCB4160F3239420C24845AC5C51C62E80C2E27715BD8587ED369D9691EE00B5A370EC9FE38D80688376BAAF5D70522216E266FBBAB3C5C2F73E2F77A6CADEC1A6C6484CC3375123D327D7B84E7096F0A14476AF78CF9AE166130203010001A351304F300B0603551D0F040403020186300F0603551D130101FF040530030101FF301D0603551D0E04160414D5F656CB8FE8A25C6268D13D94905BD7CE9A18C4301006092B06010401823715010403020100300D06092A864886F70D01010B05000382020100ACA5968CBFBBAEA6F6D7718743315688FD1C32715B35B7D4F091F2AF37E214F1F30226053E16147F14BAB84FFB89B2B2E7D409CC6DB95B3B64657066B7F2B15ADF1A02F3F551B8676D79F3BF567BE484B92B1E9B409C2634F947189869D81CD7B6D1BF8F61C267C4B5EF60438E101B3649E420CAADA7C1B1276509F8CDF55B2AD08433F3EF1FF2F59C0B589337A075A0DE72DE6C752A6622F58C0630569F40B930AA40771582D78BECC0D3B2BD83C5770C1EAEAF1953A04D79719F0FAF30CE67F9D62CCC22417A07F2974218CE59791055DE6F10E4B8DA836640160968235B972E269A02BB578CC5B8BA69623280899EA1FDC0927C7B2B3319842A63C5006862FA9F478D997A453AA7E9EDEE6942B5F3819B4756107BFC7036841873EAEFF9974D9E3323DD260BBA2AB73F44DC8327FFBD61592B11B7CA4FDBC58B0C1C31AE32F8F8B942F77FDC619A76B15A04E1113D6645B71871BEC92485D6F3D4BA41345D122D25B98DA613486D4BB0077D99930961817457268AAB69E3E4D9C788CC24D8EC52245C1EBC9114E296DEEB0ADA9EDD5FB35BDBD482ECC620508725403AFBC7EECDFE33E56EC3840955032539C0E9355D6531A8F6BFA009CD29C7B336322EDC95F383C15ACF8B8DF6EAB321F8A4ED1E310EB64C11AB600BA412232217A3366482910412E0AB6F1ECB500561B440FF598671D1D533697CA9738A38D7640CF169
Executable files
28
Suspicious files
59
Text files
123
Unknown types
25

Dropped files

PID
Process
Filename
Type
3708BitTorrent.Pro.7.10.5.Build.45785_Startcrack.com.exeC:\Users\admin\AppData\Local\Temp\7zSC7E3EDC4\BundleConfig.jsontext
MD5:
SHA256:
3708BitTorrent.Pro.7.10.5.Build.45785_Startcrack.com.exeC:\Users\admin\AppData\Local\Temp\7zSC7E3EDC4\Resources\InstallingPage.htmlhtml
MD5:
SHA256:
3708BitTorrent.Pro.7.10.5.Build.45785_Startcrack.com.exeC:\Users\admin\AppData\Local\Temp\7zSC7E3EDC4\Resources\style.csstext
MD5:
SHA256:
3708BitTorrent.Pro.7.10.5.Build.45785_Startcrack.com.exeC:\Users\admin\AppData\Local\Temp\7zSC7E3EDC4\GenericSetup.exeexecutable
MD5:
SHA256:
3708BitTorrent.Pro.7.10.5.Build.45785_Startcrack.com.exeC:\Users\admin\AppData\Local\Temp\7zSC7E3EDC4\GenericSetup.exe.configxml
MD5:C5BB4979EE79C1A681C76AFEA65C95ED
SHA256:54F1667525366C3C0F21949B406F62097FF9C5B4982A188A1AE5A3B61AE9A59C
3708BitTorrent.Pro.7.10.5.Build.45785_Startcrack.com.exeC:\Users\admin\AppData\Local\Temp\7zSC7E3EDC4\app.icoimage
MD5:CC7413942399B5B595C7FDFB23C5FFB6
SHA256:0DE7EA049E24950671C1282C07C141FB10459BBE5BFB160EBB25C6730BCFD349
3708BitTorrent.Pro.7.10.5.Build.45785_Startcrack.com.exeC:\Users\admin\AppData\Local\Temp\7zSC7E3EDC4\Resources\OfferPage.htmlhtml
MD5:EFCC32263936E44529D5EC75DE571046
SHA256:C336A27CF694C523B5C6BF045CD5F01799F5CD4340986496B54FDD687873DEDE
3708BitTorrent.Pro.7.10.5.Build.45785_Startcrack.com.exeC:\Users\admin\AppData\Local\Temp\7zSC7E3EDC4\Resources\images\loader.gifimage
MD5:2B26F73D382AB69F3914A7D9FDA97B0F
SHA256:A6A0B05B1D5C52303DD3E9E2F9CDA1E688A490FBE84EA0D6E22A051AB6EFD643
3708BitTorrent.Pro.7.10.5.Build.45785_Startcrack.com.exeC:\Users\admin\AppData\Local\Temp\7zSC7E3EDC4\Resources\FinishPage.htmlhtml
MD5:3BF1735583BBEA98BE9021D18F74A576
SHA256:A1A2C3AAAC73220795EC17935142C40E2833B2F21660109886F07DDD26F2A88E
3708BitTorrent.Pro.7.10.5.Build.45785_Startcrack.com.exeC:\Users\admin\AppData\Local\Temp\7zSC7E3EDC4\Resources\LicensePage.htmlhtml
MD5:AC0370806A6CC40B31BE57837AF9FBFA
SHA256:46C598EBC80E32943F7EE8A409C1415647845DEA0EC698061EC9533A470D8523
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
58
TCP/UDP connections
167
DNS requests
55
Threats
10

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1968
BitTorrent.exe
GET
304
67.27.159.126:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
whitelisted
2924
Carrier.exe
GET
200
82.221.103.246:80
http://update.utorrent.li/installstats.php?cl=BitTorrent&v=256619225&h=Rg0UvXHc3wutxj-9&w=1DB10106&bu=0&pr=0&cmp=291&ocmp=291&installresult&pid=2924&cau=0&installresult=0&exit=1&au=0&ic=1&view=win32
IS
whitelisted
1968
BitTorrent.exe
GET
173.254.195.58:80
http://update.bittorrent.com/time.php
US
whitelisted
1968
BitTorrent.exe
GET
178.79.242.147:80
http://apps.bittorrent.com/utorrent-onboarding/player.btapp
DE
whitelisted
1968
BitTorrent.exe
GET
178.79.242.147:80
http://cdn.ap.bittorrent.com/control/tags/bt.json
DE
shared
2924
Carrier.exe
GET
200
82.221.103.246:80
http://update.utorrent.li/installstats.php?cl=BitTorrent&v=256619225&h=Rg0UvXHc3wutxj-9&w=1DB10106&bu=0&pr=0&cmp=291&ocmp=291&showinstall&pid=2924&cau=0&au=0&view=win32
IS
whitelisted
1968
BitTorrent.exe
GET
200
178.79.242.147:80
http://cdn.ap.bittorrent.com/control/feature/tags/bt.json
DE
text
2.19 Kb
shared
2932
bittorrentie.exe
GET
200
178.79.242.181:80
http://video.trontv.com/partners/didomi/client-cmp-bt.min.html?langs=en
DE
html
7.52 Kb
suspicious
2520
installer.exe
POST
200
104.18.87.101:80
http://flow.lavasoft.com/v1/event-stat?ProductID=IS&Type=StubStart
US
text
29 b
whitelisted
2924
Carrier.exe
GET
200
67.27.159.126:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
57.5 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
223.231.79.99:52458
Bharti Airtel Ltd. AS for GPRS Service
IN
unknown
2520
installer.exe
104.18.87.101:80
flow.lavasoft.com
Cloudflare Inc
US
shared
2344
GenericSetup.exe
104.16.235.79:443
sos.adaware.com
Cloudflare Inc
US
shared
2344
GenericSetup.exe
104.18.88.101:443
flow.lavasoft.com
Cloudflare Inc
US
shared
2344
GenericSetup.exe
104.18.88.101:80
flow.lavasoft.com
Cloudflare Inc
US
shared
2924
Carrier.exe
82.221.103.246:80
update.utorrent.li
Thor Data Center ehf
IS
suspicious
1968
BitTorrent.exe
67.27.159.126:80
www.download.windowsupdate.com
Level 3 Communications, Inc.
US
suspicious
1968
BitTorrent.exe
23.21.43.186:80
i-21.b-45785.bt.bench.utorrent.com
Amazon.com, Inc.
US
malicious
1968
BitTorrent.exe
178.79.242.147:80
apps.bittorrent.com
Limelight Networks, Inc.
DE
suspicious
1968
BitTorrent.exe
107.20.217.71:80
i-21.b-45785.bt.bench.utorrent.com
Amazon.com, Inc.
US
suspicious

DNS requests

Domain
IP
Reputation
flow.lavasoft.com
  • 104.18.87.101
  • 104.18.88.101
whitelisted
sos.adaware.com
  • 104.16.235.79
  • 104.16.236.79
whitelisted
www.download.windowsupdate.com
  • 67.27.159.126
  • 67.27.158.126
  • 67.26.83.254
  • 8.248.135.254
  • 67.26.139.254
whitelisted
router.bittorrent.com
  • 67.215.246.10
shared
router.utorrent.com
  • 82.221.103.244
whitelisted
update.utorrent.li
  • 82.221.103.246
  • 82.221.103.245
whitelisted
i-21.b-45785.bt.bench.utorrent.com
  • 23.21.43.186
  • 54.243.113.215
  • 54.235.208.27
  • 50.17.220.153
  • 54.225.194.96
  • 54.197.251.114
  • 23.21.139.158
  • 107.20.217.71
suspicious
apps.bittorrent.com
  • 178.79.242.147
  • 178.79.242.19
whitelisted
i-67.b-45785.bt.bench.utorrent.com
  • 107.20.217.71
  • 23.21.139.158
  • 23.21.92.252
  • 54.235.208.27
  • 54.225.194.96
  • 54.197.251.114
  • 54.243.113.215
  • 23.23.85.1
suspicious
update.bittorrent.com
  • 173.254.195.58
whitelisted

Threats

PID
Process
Class
Message
2520
installer.exe
A Network Trojan was detected
ET MALWARE Lavasoft PUA/Adware Client Install
2520
installer.exe
Misc activity
ADWARE [PTsecurity] lavasoft StubBundleStart PUP Install
2520
installer.exe
Misc activity
ADWARE [PTsecurity] lavasoft StubBundleStart PUP Install
1968
BitTorrent.exe
Potential Corporate Privacy Violation
ET P2P BTWebClient UA uTorrent in use
1968
BitTorrent.exe
Potential Corporate Privacy Violation
ET P2P BitTorrent DHT ping request
1968
BitTorrent.exe
Potential Corporate Privacy Violation
ET P2P BTWebClient UA uTorrent in use
1968
BitTorrent.exe
Potential Corporate Privacy Violation
ET P2P BTWebClient UA uTorrent in use
1968
BitTorrent.exe
Potential Corporate Privacy Violation
ET P2P BTWebClient UA uTorrent in use
1968
BitTorrent.exe
Potentially Bad Traffic
ET POLICY Executable served from Amazon S3
1968
BitTorrent.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Process
Message
GenericSetup.exe
at sciter:init-script.tis
GenericSetup.exe
GenericSetup.exe
file:resources/tis/TranslateOfferTemplate.tis(82) : warning :'async' does not contain any 'await'
GenericSetup.exe
Error: File not found - h2osciter:console.tis
GenericSetup.exe
GenericSetup.exe
at sciter:init-script.tis
GenericSetup.exe
file:resources/tis/TranslateOfferTemplate.tis(82) : warning :'async' does not contain any 'await'
GenericSetup.exe
GenericSetup.exe
at sciter:init-script.tis
GenericSetup.exe