File name:

utorrent-for-windows-ru.exe

Full analysis: https://app.any.run/tasks/83d58102-eb17-42c3-9a03-4ee2db051a03
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: April 16, 2025, 16:19:50
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
evasion
upx
bittorrent
loader
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, 3 sections
MD5:

699EEE9C5D4F3C79DF7080F63FD9D579

SHA1:

D9B8B6C06FF20B979C68EE14AA88EF3A6ABF5F4D

SHA256:

618FDCC08C81ACC946ED078F651F40070566B7866E34F5A2847D863BD2043B80

SSDEEP:

98304:sorb/9i4Oz0XJ3IOUZMK02TX2958hTrZaday0dCcCZnalyvc2n1aZln+t12dZ0P/:yhpg

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • utorrent-for-windows-ru.exe (PID: 2624)
      • utorrent-for-windows-ru.exe (PID: 672)
      • uTorrent.exe (PID: 3816)
    • Sends HTTP request (SCRIPT)

      • cscript.exe (PID: 3300)
    • Opens an HTTP connection (SCRIPT)

      • cscript.exe (PID: 3300)
    • Creates internet connection object (SCRIPT)

      • cscript.exe (PID: 3300)
    • Changes the autorun value in the registry

      • uTorrent.exe (PID: 3816)
    • BITTORRENT has been detected (SURICATA)

      • uTorrent.exe (PID: 3816)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • utorrent-for-windows-ru.exe (PID: 2624)
      • utorrent-for-windows-ru.exe (PID: 672)
      • uTorrent.exe (PID: 3816)
      • utorrentie.exe (PID: 2772)
      • utorrentie.exe (PID: 3248)
      • utorrentie.exe (PID: 3056)
      • utorrentie.exe (PID: 3128)
      • utorrentie.exe (PID: 2876)
      • utorrentie.exe (PID: 1088)
      • utorrentie.exe (PID: 3084)
      • utorrentie.exe (PID: 2064)
    • Mutex name with non-standard characters

      • utorrent-for-windows-ru.exe (PID: 2624)
    • Application launched itself

      • utorrent-for-windows-ru.exe (PID: 2624)
    • Reads the Internet Settings

      • utorrent-for-windows-ru.exe (PID: 2624)
      • mshta.exe (PID: 3016)
      • utorrent-for-windows-ru.exe (PID: 672)
      • uTorrent.exe (PID: 3816)
      • utorrentie.exe (PID: 2772)
      • utorrentie.exe (PID: 3248)
      • utorrentie.exe (PID: 3056)
      • utorrentie.exe (PID: 3128)
      • utorrentie.exe (PID: 2876)
      • utorrentie.exe (PID: 1088)
      • utorrentie.exe (PID: 3084)
      • utorrentie.exe (PID: 2064)
    • Accesses command line arguments (SCRIPT)

      • cscript.exe (PID: 3300)
    • The process executes JS scripts

      • mshta.exe (PID: 3016)
    • Runs PING.EXE to delay simulation

      • mshta.exe (PID: 3016)
    • Checks for external IP

      • svchost.exe (PID: 1080)
      • mshta.exe (PID: 3016)
    • There is functionality for taking screenshot (YARA)

      • utorrent-for-windows-ru.exe (PID: 672)
    • Executable content was dropped or overwritten

      • mshta.exe (PID: 3016)
      • uTorrent.exe (PID: 3816)
    • Potential Corporate Privacy Violation

      • utorrent-for-windows-ru.exe (PID: 672)
      • uTorrent.exe (PID: 3816)
    • Searches for installed software

      • uTorrent.exe (PID: 3816)
    • Changes Internet Explorer settings (feature browser emulation)

      • uTorrent.exe (PID: 3816)
    • Creates a software uninstall entry

      • mshta.exe (PID: 3016)
    • Reads Microsoft Outlook installation path

      • utorrentie.exe (PID: 2772)
      • utorrentie.exe (PID: 3248)
      • utorrentie.exe (PID: 3056)
      • utorrentie.exe (PID: 3128)
      • utorrentie.exe (PID: 2876)
      • utorrentie.exe (PID: 1088)
      • utorrentie.exe (PID: 3084)
      • utorrentie.exe (PID: 2064)
    • Process requests binary or script from the Internet

      • uTorrent.exe (PID: 3816)
      • utorrentie.exe (PID: 3084)
    • Reads settings of System Certificates

      • utorrentie.exe (PID: 3084)
    • Reads Internet Explorer settings

      • utorrentie.exe (PID: 3084)
      • utorrentie.exe (PID: 2064)
  • INFO

    • Reads the machine GUID from the registry

      • utorrent-for-windows-ru.exe (PID: 2624)
      • utorrent-for-windows-ru.exe (PID: 672)
      • uTorrent.exe (PID: 3816)
      • utorrentie.exe (PID: 2772)
      • utorrentie.exe (PID: 3248)
      • utorrentie.exe (PID: 3056)
      • utorrentie.exe (PID: 3128)
      • utorrentie.exe (PID: 2876)
      • utorrentie.exe (PID: 1088)
      • utorrentie.exe (PID: 3084)
      • utorrentie.exe (PID: 2064)
    • The sample compiled with english language support

      • utorrent-for-windows-ru.exe (PID: 2624)
      • uTorrent.exe (PID: 3816)
      • mshta.exe (PID: 3016)
    • Reads the computer name

      • utorrent-for-windows-ru.exe (PID: 2624)
      • utorrent-for-windows-ru.exe (PID: 672)
      • uTorrent.exe (PID: 3816)
      • utorrentie.exe (PID: 3248)
      • utorrentie.exe (PID: 3056)
      • utorrentie.exe (PID: 2772)
      • utorrentie.exe (PID: 3128)
      • utorrentie.exe (PID: 2876)
      • utorrentie.exe (PID: 1088)
      • utorrentie.exe (PID: 3084)
      • utorrentie.exe (PID: 2064)
    • Checks supported languages

      • utorrent-for-windows-ru.exe (PID: 2624)
      • utorrent-for-windows-ru.exe (PID: 672)
      • uTorrent.exe (PID: 3816)
      • utorrentie.exe (PID: 2772)
      • utorrentie.exe (PID: 3248)
      • utorrentie.exe (PID: 3128)
      • utorrentie.exe (PID: 2876)
      • utorrentie.exe (PID: 3056)
      • utorrentie.exe (PID: 1088)
      • utorrentie.exe (PID: 3084)
      • utorrentie.exe (PID: 2064)
    • Create files in a temporary directory

      • utorrent-for-windows-ru.exe (PID: 2624)
      • utorrent-for-windows-ru.exe (PID: 672)
      • uTorrent.exe (PID: 3816)
    • Checks proxy server information

      • utorrent-for-windows-ru.exe (PID: 2624)
      • utorrent-for-windows-ru.exe (PID: 672)
      • mshta.exe (PID: 3016)
      • uTorrent.exe (PID: 3816)
      • utorrentie.exe (PID: 2772)
      • utorrentie.exe (PID: 3248)
      • utorrentie.exe (PID: 3056)
      • utorrentie.exe (PID: 3128)
      • utorrentie.exe (PID: 2876)
      • utorrentie.exe (PID: 1088)
      • utorrentie.exe (PID: 3084)
      • utorrentie.exe (PID: 2064)
    • Creates files or folders in the user directory

      • utorrent-for-windows-ru.exe (PID: 2624)
      • utorrent-for-windows-ru.exe (PID: 672)
      • uTorrent.exe (PID: 3816)
      • utorrentie.exe (PID: 2772)
      • utorrentie.exe (PID: 3248)
      • utorrentie.exe (PID: 3056)
      • utorrentie.exe (PID: 3128)
      • utorrentie.exe (PID: 2876)
      • utorrentie.exe (PID: 1088)
      • utorrentie.exe (PID: 3084)
      • utorrentie.exe (PID: 2064)
    • Reads security settings of Internet Explorer

      • cscript.exe (PID: 2416)
      • cscript.exe (PID: 3300)
    • UPX packer has been detected

      • utorrent-for-windows-ru.exe (PID: 672)
    • Reads Internet Explorer settings

      • mshta.exe (PID: 3016)
    • Self-termination (SCRIPT)

      • cscript.exe (PID: 2416)
    • Manual execution by a user

      • uTorrent.exe (PID: 3816)
    • Reads the software policy settings

      • utorrentie.exe (PID: 3084)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (39.3)
.exe | Win32 EXE Yoda's Crypter (38.6)
.dll | Win32 Dynamic Link Library (generic) (9.5)
.exe | Win32 Executable (generic) (6.5)
.exe | Generic Win/DOS Executable (2.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:11:18 21:31:28+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 2265088
InitializedDataSize: 126976
UninitializedDataSize: 3735552
EntryPoint: 0x5b8820
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 3.4.9.42973
ProductVersionNumber: 3.4.9.42973
FileFlagsMask: 0x002b
FileFlags: Special build
FileOS: Unknown (0)
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: BitTorrent Inc.
FileDescription: µTorrent
FileVersion: 3.4.9.42973
InternalName: uTorrent.exe
OriginalFileName: uTorrent.exe
LegalCopyright: ©2016 BitTorrent, Inc. All Rights Reserved.
ProductName: µTorrent
ProductVersion: 3.4.9.42973
SpecialBuild: stable34 stable
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
56
Monitored processes
16
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start utorrent-for-windows-ru.exe utorrent-for-windows-ru.exe mshta.exe cscript.exe no specs ping.exe no specs svchost.exe cscript.exe #BITTORRENT utorrent.exe utorrentie.exe no specs utorrentie.exe no specs utorrentie.exe no specs utorrentie.exe no specs utorrentie.exe no specs utorrentie.exe no specs utorrentie.exe utorrentie.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
672"C:\Users\admin\AppData\Local\Temp\utorrent-for-windows-ru.exe" /HYDRA_PERMISSIONS_RESTART /HYDRA_LOG "C:\Users\admin\AppData\Local\Temp\HYD1AA8.tmp.1744820395\index.hta.log" /HYDRA_HTADIR "C:\Users\admin\AppData\Local\Temp\HYD1AA8.tmp.1744820395\HTA"C:\Users\admin\AppData\Local\Temp\utorrent-for-windows-ru.exe
utorrent-for-windows-ru.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
HIGH
Description:
µTorrent
Exit code:
0
Version:
3.4.9.42973
Modules
Images
c:\users\admin\appdata\local\temp\utorrent-for-windows-ru.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
1080C:\Windows\system32\svchost.exe -k NetworkServiceC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1088"C:\Users\admin\AppData\Roaming\uTorrent\updates\3.4.9_42973\utorrentie.exe" uTorrent_3816_0020DAD0_1394121642 µTorrent4823DF041B09 uTorrentC:\Users\admin\AppData\Roaming\uTorrent\updates\3.4.9_42973\utorrentie.exeuTorrent.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
LOW
Description:
WebHelper
Exit code:
0
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\roaming\utorrent\updates\3.4.9_42973\utorrentie.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2064"C:\Users\admin\AppData\Roaming\uTorrent\updates\3.4.9_42973\utorrentie.exe" uTorrent_3816_0020DAD0_707572474 µTorrent4823DF041B09 uTorrentC:\Users\admin\AppData\Roaming\uTorrent\updates\3.4.9_42973\utorrentie.exeuTorrent.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
LOW
Description:
WebHelper
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\roaming\utorrent\updates\3.4.9_42973\utorrentie.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2416"C:\Windows\System32\cscript.exe" "shell_scripts/check_if_cscript_is_working.js"C:\Windows\System32\cscript.exemshta.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Console Based Script Host
Exit code:
99
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\cscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2624"C:\Users\admin\AppData\Local\Temp\utorrent-for-windows-ru.exe" C:\Users\admin\AppData\Local\Temp\utorrent-for-windows-ru.exe
explorer.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
MEDIUM
Description:
µTorrent
Exit code:
0
Version:
3.4.9.42973
Modules
Images
c:\users\admin\appdata\local\temp\utorrent-for-windows-ru.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
2772"C:\Users\admin\AppData\Roaming\uTorrent\updates\3.4.9_42973\utorrentie.exe" uTorrent_3816_0020D908_1082765521 µTorrent4823DF041B09 uTorrentC:\Users\admin\AppData\Roaming\uTorrent\updates\3.4.9_42973\utorrentie.exeuTorrent.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
LOW
Description:
WebHelper
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\roaming\utorrent\updates\3.4.9_42973\utorrentie.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2876"C:\Users\admin\AppData\Roaming\uTorrent\updates\3.4.9_42973\utorrentie.exe" uTorrent_3816_0020DB68_973353966 µTorrent4823DF041B09 uTorrentC:\Users\admin\AppData\Roaming\uTorrent\updates\3.4.9_42973\utorrentie.exeuTorrent.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
LOW
Description:
WebHelper
Exit code:
0
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\roaming\utorrent\updates\3.4.9_42973\utorrentie.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3016"C:\Windows\System32\mshta.exe" "C:\Users\admin\AppData\Local\Temp\HYD1AA8.tmp.1744820395\HTA\index.hta?utorrent" "C:\Users\admin\AppData\Local\Temp\utorrent-for-windows-ru.exe" /LOG "C:\Users\admin\AppData\Local\Temp\HYD1AA8.tmp.1744820395\index.hta.log" /PID "672" /CID "Ys7zMSixcc3AVDP5" /VERSION "110340061" /BUCKET "0" /SSB "2" /COUNTRY "US" /OS "6.1" /BROWSERS "\"C:\Program Files\Mozilla Firefox\firefox.exe\",\"C:\Program Files\Google\Chrome\Application\chrome.exe\",C:\Program Files\Internet Explorer\iexplore.exe,\"C:\Program Files\Microsoft\Edge\Application\msedge.exe\",\"C:\Program Files\Opera\Opera.exe\"" /ARCHITECTURE "32" /LANG "en" /USERNAME "admin" /SID "S-1-5-21-1302019708-1500728564-335382590-1000" /CLIENT "utorrent"C:\Windows\System32\mshta.exe
utorrent-for-windows-ru.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft (R) HTML Application host
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\windows\system32\mshta.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
3056"C:\Users\admin\AppData\Roaming\uTorrent\updates\3.4.9_42973\utorrentie.exe" uTorrent_3816_0020DB68_1406615676 µTorrent4823DF041B09 uTorrentC:\Users\admin\AppData\Roaming\uTorrent\updates\3.4.9_42973\utorrentie.exeuTorrent.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
LOW
Description:
WebHelper
Exit code:
0
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\roaming\utorrent\updates\3.4.9_42973\utorrentie.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
18 028
Read events
17 851
Write events
164
Delete events
13

Modification events

(PID) Process:(2624) utorrent-for-windows-ru.exeKey:HKEY_CURRENT_USER\Software\BitTorrent\uTorrent
Operation:writeName:OfferAccepted
Value:
0
(PID) Process:(2624) utorrent-for-windows-ru.exeKey:HKEY_CURRENT_USER\Software\BitTorrent\uTorrent
Operation:writeName:OfferViaCAU
Value:
0
(PID) Process:(2624) utorrent-for-windows-ru.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2624) utorrent-for-windows-ru.exeKey:HKEY_CURRENT_USER\Software\BitTorrent\uTorrent
Operation:writeName:OfferProvider
Value:
(PID) Process:(2624) utorrent-for-windows-ru.exeKey:HKEY_CURRENT_USER\Software\BitTorrent\uTorrent
Operation:writeName:OfferName
Value:
(PID) Process:(2624) utorrent-for-windows-ru.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2624) utorrent-for-windows-ru.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2624) utorrent-for-windows-ru.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(672) utorrent-for-windows-ru.exeKey:HKEY_CURRENT_USER\Software\BitTorrent\uTorrent
Operation:writeName:OfferProvider
Value:
(PID) Process:(672) utorrent-for-windows-ru.exeKey:HKEY_CURRENT_USER\Software\BitTorrent\uTorrent
Operation:writeName:OfferName
Value:
Executable files
3
Suspicious files
48
Text files
31
Unknown types
1

Dropped files

PID
Process
Filename
Type
2624utorrent-for-windows-ru.exeC:\Users\admin\AppData\Local\Temp\utt19CC.tmp
MD5:
SHA256:
2624utorrent-for-windows-ru.exeC:\Users\admin\AppData\Local\Temp\HYD1AA8.tmp.1744820395\HTA\i18n\br.jsonbinary
MD5:F12764DFC1ADE6DB8FBAC38762A53911
SHA256:968738E0C8C5413C4CD516E04D2FC43F9FB6449C1BF44B2010E84176E462514A
2624utorrent-for-windows-ru.exeC:\Users\admin\AppData\Local\Temp\HYD1AA8.tmp.1744820395\HTA\index.htahtml
MD5:76903930C0ADE2285F1AB1BF54BE660D
SHA256:61ACD6E7405FAD348433F8DE4B12ED97B42CACCBCF28FE0E4BA4B4A5D2EA707E
2624utorrent-for-windows-ru.exeC:\Users\admin\AppData\Roaming\uTorrent\settings.datbinary
MD5:FA3BBD27901D02011C5EA6B9F2687808
SHA256:F3AFFB23370E55A1ABF1D464D0AB356BE9B17507599A8A3E93353CBFC4A40CF8
2624utorrent-for-windows-ru.exeC:\Users\admin\AppData\Local\Temp\HYD1AA8.tmp.1744820395\HTA\install.1744820395.zipcompressed
MD5:4D1B02AAB7F853198FA650363DBB3A62
SHA256:0B6C040F29755A0A952AF7C262165658AD88E36809904698E95DA8E237F9A007
2624utorrent-for-windows-ru.exeC:\Users\admin\AppData\Local\Temp\HYD1AA8.tmp.1744820395\HTA\uninstall.htahtml
MD5:D91D3DAD4FB278BAB416A6CF49FDA09E
SHA256:E5A870DDA2BCA2B632F9AA3EEE7768B5DD1498046D53AF5FB6B5D5920DEBE27A
2624utorrent-for-windows-ru.exeC:\Users\admin\AppData\Local\Temp\HYD1AA8.tmp.1744820395\HTA\i18n\es.jsonbinary
MD5:D208BD6553A40136D75A78D5C0E11F52
SHA256:AAC630FBE06486BACE04D05DA5E12CC96715B263CB3CAE8F246E630B6166DE41
2624utorrent-for-windows-ru.exeC:\Users\admin\AppData\Local\Temp\HYD1AA8.tmp.1744820395\HTA\i18n\de.jsonbinary
MD5:C6ABA232E3CA1843E2CE5C0EA95A597A
SHA256:7E6E3722FE5BA7CF7709055DF67EC0F7710C357C1600E500F3D4EC0F403F3354
2624utorrent-for-windows-ru.exeC:\Users\admin\AppData\Local\Temp\HYD1AA8.tmp.1744820395\HTA\i18n\en.jsonbinary
MD5:FDBF70C76CF4C3077571C0EED1B9848D
SHA256:81639B0A15DEF13CD646EFD2BA40442524A3DFFAE3ACD218B812BE9F12364CF9
2624utorrent-for-windows-ru.exeC:\Users\admin\AppData\Local\Temp\HYD1AA8.tmp.1744820395\HTA\images\bt_icon_48px.pngimage
MD5:6B6BD42C4A13B48F45A9F278B23D6B2B
SHA256:7C5123103DC089C1912B1EAE0BBBE2B7C32E39ECF83649A53A8E9F3AEA960602
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
32
TCP/UDP connections
169
DNS requests
26
Threats
10

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2624
utorrent-for-windows-ru.exe
GET
302
18.244.18.57:80
http://download-lb.utorrent.com/endpoint/hydra-ut/os/win7/track/stable/browser/other/os-region/US/os-lang/en/os-ver/6.1/enc-ver/110340061/
unknown
whitelisted
2624
utorrent-for-windows-ru.exe
POST
200
52.5.183.94:80
http://i-50.b-000.xyz.bench.utorrent.com/e?i=50
unknown
whitelisted
2624
utorrent-for-windows-ru.exe
POST
200
52.5.183.94:80
http://i-50.b-000.xyz.bench.utorrent.com/e?i=50
unknown
whitelisted
2624
utorrent-for-windows-ru.exe
POST
200
52.5.183.94:80
http://i-50.b-000.xyz.bench.utorrent.com/e?i=50
unknown
whitelisted
3016
mshta.exe
GET
200
208.95.112.1:80
http://ip-api.com/json?callback=jQuery19107831450408281542_1744820398722&_=1744820398723
unknown
whitelisted
2624
utorrent-for-windows-ru.exe
POST
200
52.5.183.94:80
http://i-50.b-000.xyz.bench.utorrent.com/e?i=50
unknown
whitelisted
672
utorrent-for-windows-ru.exe
POST
200
52.5.183.94:80
http://i-50.b-000.xyz.bench.utorrent.com/e?i=50
unknown
whitelisted
672
utorrent-for-windows-ru.exe
POST
200
52.5.183.94:80
http://i-50.b-000.xyz.bench.utorrent.com/e?i=50
unknown
whitelisted
672
utorrent-for-windows-ru.exe
POST
200
52.5.183.94:80
http://i-50.b-000.xyz.bench.utorrent.com/e?i=50
unknown
whitelisted
672
utorrent-for-windows-ru.exe
GET
301
34.201.157.226:80
http://utorrent.com/download/langpacks/dl.php?build=42973&ref=client&client=utorrent&sys_l=en&sel_l=-1&tk=stable34
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted
2624
utorrent-for-windows-ru.exe
52.5.183.94:80
i-50.b-000.xyz.bench.utorrent.com
AMAZON-AES
US
whitelisted
2624
utorrent-for-windows-ru.exe
18.244.18.57:80
download-lb.utorrent.com
US
whitelisted
4
System
192.168.100.255:138
whitelisted
672
utorrent-for-windows-ru.exe
52.5.183.94:80
i-50.b-000.xyz.bench.utorrent.com
AMAZON-AES
US
whitelisted
3016
mshta.exe
208.95.112.1:80
ip-api.com
TUT-AS
US
whitelisted
3016
mshta.exe
82.221.103.245:80
update.utorrent.com
Advania Island ehf
IS
whitelisted
3300
cscript.exe
52.5.183.94:80
i-50.b-000.xyz.bench.utorrent.com
AMAZON-AES
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.206.78
whitelisted
router.bittorrent.com
  • 67.215.246.10
whitelisted
router.utorrent.com
  • 82.221.103.244
whitelisted
i-50.b-000.xyz.bench.utorrent.com
  • 52.5.183.94
  • 54.84.120.194
  • 44.213.18.236
  • 44.195.239.248
  • 54.165.132.207
  • 3.214.187.24
whitelisted
download-lb.utorrent.com
  • 18.244.18.57
  • 18.244.18.73
  • 18.244.18.72
  • 18.244.18.50
whitelisted
ip-api.com
  • 208.95.112.1
whitelisted
update.utorrent.com
  • 82.221.103.245
  • 82.221.103.246
whitelisted
utorrent.com
  • 34.201.157.226
whitelisted
legacy.utorrent.com
  • 67.215.246.34
whitelisted
i-21.b-42973.ut.bench.utorrent.com
  • 54.84.120.194
  • 54.165.132.207
  • 52.5.183.94
  • 44.195.239.248
  • 3.214.187.24
  • 44.213.18.236
whitelisted

Threats

PID
Process
Class
Message
1080
svchost.exe
Device Retrieving External IP Address Detected
INFO [ANY.RUN] External IP Check (ip-api .com)
1080
svchost.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (ip-api .com)
3016
mshta.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup ip-api.com
672
utorrent-for-windows-ru.exe
Potential Corporate Privacy Violation
ET P2P BTWebClient UA uTorrent in use
672
utorrent-for-windows-ru.exe
Potential Corporate Privacy Violation
ET P2P BTWebClient UA uTorrent in use
3816
uTorrent.exe
Misc activity
INFO [ANY.RUN] P2P BitTorrent Protocol
3816
uTorrent.exe
Potential Corporate Privacy Violation
ET P2P BTWebClient UA uTorrent in use
3816
uTorrent.exe
Potential Corporate Privacy Violation
ET P2P BTWebClient UA uTorrent in use
3816
uTorrent.exe
Potential Corporate Privacy Violation
ET P2P BTWebClient UA uTorrent in use
1080
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
No debug info