| File name: | utorrent-for-windows-ru.exe |
| Full analysis: | https://app.any.run/tasks/83d58102-eb17-42c3-9a03-4ee2db051a03 |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | April 16, 2025, 16:19:50 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, 3 sections |
| MD5: | 699EEE9C5D4F3C79DF7080F63FD9D579 |
| SHA1: | D9B8B6C06FF20B979C68EE14AA88EF3A6ABF5F4D |
| SHA256: | 618FDCC08C81ACC946ED078F651F40070566B7866E34F5A2847D863BD2043B80 |
| SSDEEP: | 98304:sorb/9i4Oz0XJ3IOUZMK02TX2958hTrZaday0dCcCZnalyvc2n1aZln+t12dZ0P/:yhpg |
| .exe | | | UPX compressed Win32 Executable (39.3) |
|---|---|---|
| .exe | | | Win32 EXE Yoda's Crypter (38.6) |
| .dll | | | Win32 Dynamic Link Library (generic) (9.5) |
| .exe | | | Win32 Executable (generic) (6.5) |
| .exe | | | Generic Win/DOS Executable (2.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2016:11:18 21:31:28+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 2265088 |
| InitializedDataSize: | 126976 |
| UninitializedDataSize: | 3735552 |
| EntryPoint: | 0x5b8820 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 3.4.9.42973 |
| ProductVersionNumber: | 3.4.9.42973 |
| FileFlagsMask: | 0x002b |
| FileFlags: | Special build |
| FileOS: | Unknown (0) |
| ObjectFileType: | Unknown |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | BitTorrent Inc. |
| FileDescription: | µTorrent |
| FileVersion: | 3.4.9.42973 |
| InternalName: | uTorrent.exe |
| OriginalFileName: | uTorrent.exe |
| LegalCopyright: | ©2016 BitTorrent, Inc. All Rights Reserved. |
| ProductName: | µTorrent |
| ProductVersion: | 3.4.9.42973 |
| SpecialBuild: | stable34 stable |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 672 | "C:\Users\admin\AppData\Local\Temp\utorrent-for-windows-ru.exe" /HYDRA_PERMISSIONS_RESTART /HYDRA_LOG "C:\Users\admin\AppData\Local\Temp\HYD1AA8.tmp.1744820395\index.hta.log" /HYDRA_HTADIR "C:\Users\admin\AppData\Local\Temp\HYD1AA8.tmp.1744820395\HTA" | C:\Users\admin\AppData\Local\Temp\utorrent-for-windows-ru.exe | utorrent-for-windows-ru.exe | ||||||||||||
User: admin Company: BitTorrent Inc. Integrity Level: HIGH Description: µTorrent Exit code: 0 Version: 3.4.9.42973 Modules
| |||||||||||||||
| 1080 | C:\Windows\system32\svchost.exe -k NetworkService | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1088 | "C:\Users\admin\AppData\Roaming\uTorrent\updates\3.4.9_42973\utorrentie.exe" uTorrent_3816_0020DAD0_1394121642 µTorrent4823DF041B09 uTorrent | C:\Users\admin\AppData\Roaming\uTorrent\updates\3.4.9_42973\utorrentie.exe | — | uTorrent.exe | |||||||||||
User: admin Company: BitTorrent Inc. Integrity Level: LOW Description: WebHelper Exit code: 0 Version: 1.0.0 Modules
| |||||||||||||||
| 2064 | "C:\Users\admin\AppData\Roaming\uTorrent\updates\3.4.9_42973\utorrentie.exe" uTorrent_3816_0020DAD0_707572474 µTorrent4823DF041B09 uTorrent | C:\Users\admin\AppData\Roaming\uTorrent\updates\3.4.9_42973\utorrentie.exe | — | uTorrent.exe | |||||||||||
User: admin Company: BitTorrent Inc. Integrity Level: LOW Description: WebHelper Version: 1.0.0 Modules
| |||||||||||||||
| 2416 | "C:\Windows\System32\cscript.exe" "shell_scripts/check_if_cscript_is_working.js" | C:\Windows\System32\cscript.exe | — | mshta.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft ® Console Based Script Host Exit code: 99 Version: 5.8.7600.16385 Modules
| |||||||||||||||
| 2624 | "C:\Users\admin\AppData\Local\Temp\utorrent-for-windows-ru.exe" | C:\Users\admin\AppData\Local\Temp\utorrent-for-windows-ru.exe | explorer.exe | ||||||||||||
User: admin Company: BitTorrent Inc. Integrity Level: MEDIUM Description: µTorrent Exit code: 0 Version: 3.4.9.42973 Modules
| |||||||||||||||
| 2772 | "C:\Users\admin\AppData\Roaming\uTorrent\updates\3.4.9_42973\utorrentie.exe" uTorrent_3816_0020D908_1082765521 µTorrent4823DF041B09 uTorrent | C:\Users\admin\AppData\Roaming\uTorrent\updates\3.4.9_42973\utorrentie.exe | — | uTorrent.exe | |||||||||||
User: admin Company: BitTorrent Inc. Integrity Level: LOW Description: WebHelper Version: 1.0.0 Modules
| |||||||||||||||
| 2876 | "C:\Users\admin\AppData\Roaming\uTorrent\updates\3.4.9_42973\utorrentie.exe" uTorrent_3816_0020DB68_973353966 µTorrent4823DF041B09 uTorrent | C:\Users\admin\AppData\Roaming\uTorrent\updates\3.4.9_42973\utorrentie.exe | — | uTorrent.exe | |||||||||||
User: admin Company: BitTorrent Inc. Integrity Level: LOW Description: WebHelper Exit code: 0 Version: 1.0.0 Modules
| |||||||||||||||
| 3016 | "C:\Windows\System32\mshta.exe" "C:\Users\admin\AppData\Local\Temp\HYD1AA8.tmp.1744820395\HTA\index.hta?utorrent" "C:\Users\admin\AppData\Local\Temp\utorrent-for-windows-ru.exe" /LOG "C:\Users\admin\AppData\Local\Temp\HYD1AA8.tmp.1744820395\index.hta.log" /PID "672" /CID "Ys7zMSixcc3AVDP5" /VERSION "110340061" /BUCKET "0" /SSB "2" /COUNTRY "US" /OS "6.1" /BROWSERS "\"C:\Program Files\Mozilla Firefox\firefox.exe\",\"C:\Program Files\Google\Chrome\Application\chrome.exe\",C:\Program Files\Internet Explorer\iexplore.exe,\"C:\Program Files\Microsoft\Edge\Application\msedge.exe\",\"C:\Program Files\Opera\Opera.exe\"" /ARCHITECTURE "32" /LANG "en" /USERNAME "admin" /SID "S-1-5-21-1302019708-1500728564-335382590-1000" /CLIENT "utorrent" | C:\Windows\System32\mshta.exe | utorrent-for-windows-ru.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft (R) HTML Application host Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 3056 | "C:\Users\admin\AppData\Roaming\uTorrent\updates\3.4.9_42973\utorrentie.exe" uTorrent_3816_0020DB68_1406615676 µTorrent4823DF041B09 uTorrent | C:\Users\admin\AppData\Roaming\uTorrent\updates\3.4.9_42973\utorrentie.exe | — | uTorrent.exe | |||||||||||
User: admin Company: BitTorrent Inc. Integrity Level: LOW Description: WebHelper Exit code: 0 Version: 1.0.0 Modules
| |||||||||||||||
| (PID) Process: | (2624) utorrent-for-windows-ru.exe | Key: | HKEY_CURRENT_USER\Software\BitTorrent\uTorrent |
| Operation: | write | Name: | OfferAccepted |
Value: 0 | |||
| (PID) Process: | (2624) utorrent-for-windows-ru.exe | Key: | HKEY_CURRENT_USER\Software\BitTorrent\uTorrent |
| Operation: | write | Name: | OfferViaCAU |
Value: 0 | |||
| (PID) Process: | (2624) utorrent-for-windows-ru.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2624) utorrent-for-windows-ru.exe | Key: | HKEY_CURRENT_USER\Software\BitTorrent\uTorrent |
| Operation: | write | Name: | OfferProvider |
Value: | |||
| (PID) Process: | (2624) utorrent-for-windows-ru.exe | Key: | HKEY_CURRENT_USER\Software\BitTorrent\uTorrent |
| Operation: | write | Name: | OfferName |
Value: | |||
| (PID) Process: | (2624) utorrent-for-windows-ru.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (2624) utorrent-for-windows-ru.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (2624) utorrent-for-windows-ru.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (672) utorrent-for-windows-ru.exe | Key: | HKEY_CURRENT_USER\Software\BitTorrent\uTorrent |
| Operation: | write | Name: | OfferProvider |
Value: | |||
| (PID) Process: | (672) utorrent-for-windows-ru.exe | Key: | HKEY_CURRENT_USER\Software\BitTorrent\uTorrent |
| Operation: | write | Name: | OfferName |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2624 | utorrent-for-windows-ru.exe | C:\Users\admin\AppData\Local\Temp\utt19CC.tmp | — | |
MD5:— | SHA256:— | |||
| 2624 | utorrent-for-windows-ru.exe | C:\Users\admin\AppData\Local\Temp\HYD1AA8.tmp.1744820395\HTA\uninstall.hta | html | |
MD5:D91D3DAD4FB278BAB416A6CF49FDA09E | SHA256:E5A870DDA2BCA2B632F9AA3EEE7768B5DD1498046D53AF5FB6B5D5920DEBE27A | |||
| 2624 | utorrent-for-windows-ru.exe | C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\1f91d2d17ea675d4c2c3192e241743f9_90059c37-1320-41a4-b58d-2b75a9850d2f | binary | |
MD5:0B2D950C028FAD6CF62189548C5EAEA6 | SHA256:E0CC0EC1E8C436602430A6A0F22BD2156DD7B1FD2C7D09C80EBF4F7A31527F87 | |||
| 2624 | utorrent-for-windows-ru.exe | C:\Users\admin\AppData\Local\Temp\HYD1AA8.tmp.1744820395\HTA\index.hta | html | |
MD5:76903930C0ADE2285F1AB1BF54BE660D | SHA256:61ACD6E7405FAD348433F8DE4B12ED97B42CACCBCF28FE0E4BA4B4A5D2EA707E | |||
| 2624 | utorrent-for-windows-ru.exe | C:\Users\admin\AppData\Roaming\uTorrent\settings.dat | binary | |
MD5:FA3BBD27901D02011C5EA6B9F2687808 | SHA256:F3AFFB23370E55A1ABF1D464D0AB356BE9B17507599A8A3E93353CBFC4A40CF8 | |||
| 2624 | utorrent-for-windows-ru.exe | C:\Users\admin\AppData\Local\Temp\HYD1AA8.tmp.1744820395\HTA\install.1744820395.zip | compressed | |
MD5:4D1B02AAB7F853198FA650363DBB3A62 | SHA256:0B6C040F29755A0A952AF7C262165658AD88E36809904698E95DA8E237F9A007 | |||
| 2624 | utorrent-for-windows-ru.exe | C:\Users\admin\AppData\Local\Temp\HYD1AA8.tmp.1744820395\HTA\i18n\en.json | binary | |
MD5:FDBF70C76CF4C3077571C0EED1B9848D | SHA256:81639B0A15DEF13CD646EFD2BA40442524A3DFFAE3ACD218B812BE9F12364CF9 | |||
| 2624 | utorrent-for-windows-ru.exe | C:\Users\admin\AppData\Local\Temp\HYD1AA8.tmp.1744820395\HTA\i18n\fr.json | binary | |
MD5:D126F1776772BE7164691F18B9FCB041 | SHA256:0416441F460D82C68525EB15CB72E6B260433E509AEDCD4ABDB1326C6D242A7D | |||
| 2624 | utorrent-for-windows-ru.exe | C:\Users\admin\AppData\Local\Temp\HYD1AA8.tmp.1744820395\HTA\i18n\de.json | binary | |
MD5:C6ABA232E3CA1843E2CE5C0EA95A597A | SHA256:7E6E3722FE5BA7CF7709055DF67EC0F7710C357C1600E500F3D4EC0F403F3354 | |||
| 2624 | utorrent-for-windows-ru.exe | C:\Users\admin\AppData\Roaming\uTorrent\settings.dat.new | binary | |
MD5:FA3BBD27901D02011C5EA6B9F2687808 | SHA256:F3AFFB23370E55A1ABF1D464D0AB356BE9B17507599A8A3E93353CBFC4A40CF8 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2624 | utorrent-for-windows-ru.exe | GET | 302 | 18.244.18.57:80 | http://download-lb.utorrent.com/endpoint/hydra-ut/os/win7/track/stable/browser/other/os-region/US/os-lang/en/os-ver/6.1/enc-ver/110340061/ | unknown | — | — | whitelisted |
3016 | mshta.exe | GET | 200 | 82.221.103.245:80 | http://update.utorrent.com/featuredcontent.php?w=6.1 | unknown | — | — | whitelisted |
672 | utorrent-for-windows-ru.exe | POST | 200 | 52.5.183.94:80 | http://i-50.b-000.xyz.bench.utorrent.com/e?i=50 | unknown | — | — | whitelisted |
672 | utorrent-for-windows-ru.exe | GET | 301 | 34.201.157.226:80 | http://utorrent.com/download/langpacks/dl.php?build=42973&ref=client&client=utorrent&sys_l=en&sel_l=-1&tk=stable34 | unknown | — | — | whitelisted |
672 | utorrent-for-windows-ru.exe | POST | 200 | 52.5.183.94:80 | http://i-50.b-000.xyz.bench.utorrent.com/e?i=50 | unknown | — | — | whitelisted |
672 | utorrent-for-windows-ru.exe | GET | 200 | 67.215.246.34:80 | http://legacy.utorrent.com/scripts/dl.php?build=42973&ref=client&client=utorrent&sys_l=en&sel_l=-1&tk=stable34 | unknown | — | — | whitelisted |
3816 | uTorrent.exe | POST | 200 | 54.165.132.207:80 | http://i-29.b-42973.ut.bench.utorrent.com/e?i=29 | unknown | — | — | whitelisted |
3816 | uTorrent.exe | POST | 200 | 54.165.132.207:80 | http://i-29.b-42973.ut.bench.utorrent.com/e?i=29 | unknown | — | — | whitelisted |
2624 | utorrent-for-windows-ru.exe | POST | 200 | 52.5.183.94:80 | http://i-50.b-000.xyz.bench.utorrent.com/e?i=50 | unknown | — | — | whitelisted |
2624 | utorrent-for-windows-ru.exe | POST | 200 | 52.5.183.94:80 | http://i-50.b-000.xyz.bench.utorrent.com/e?i=50 | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 224.0.0.252:5355 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
2624 | utorrent-for-windows-ru.exe | 52.5.183.94:80 | i-50.b-000.xyz.bench.utorrent.com | AMAZON-AES | US | whitelisted |
2624 | utorrent-for-windows-ru.exe | 18.244.18.57:80 | download-lb.utorrent.com | — | US | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
672 | utorrent-for-windows-ru.exe | 52.5.183.94:80 | i-50.b-000.xyz.bench.utorrent.com | AMAZON-AES | US | whitelisted |
3016 | mshta.exe | 208.95.112.1:80 | ip-api.com | TUT-AS | US | whitelisted |
3016 | mshta.exe | 82.221.103.245:80 | update.utorrent.com | Advania Island ehf | IS | whitelisted |
3300 | cscript.exe | 52.5.183.94:80 | i-50.b-000.xyz.bench.utorrent.com | AMAZON-AES | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
router.bittorrent.com |
| whitelisted |
router.utorrent.com |
| whitelisted |
i-50.b-000.xyz.bench.utorrent.com |
| whitelisted |
download-lb.utorrent.com |
| whitelisted |
ip-api.com |
| whitelisted |
update.utorrent.com |
| whitelisted |
utorrent.com |
| whitelisted |
legacy.utorrent.com |
| whitelisted |
i-21.b-42973.ut.bench.utorrent.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1080 | svchost.exe | Device Retrieving External IP Address Detected | INFO [ANY.RUN] External IP Check (ip-api .com) |
1080 | svchost.exe | Device Retrieving External IP Address Detected | ET INFO External IP Lookup Domain in DNS Lookup (ip-api .com) |
3016 | mshta.exe | Device Retrieving External IP Address Detected | ET INFO External IP Lookup ip-api.com |
672 | utorrent-for-windows-ru.exe | Potential Corporate Privacy Violation | ET P2P BTWebClient UA uTorrent in use |
672 | utorrent-for-windows-ru.exe | Potential Corporate Privacy Violation | ET P2P BTWebClient UA uTorrent in use |
3816 | uTorrent.exe | Misc activity | INFO [ANY.RUN] P2P BitTorrent Protocol |
3816 | uTorrent.exe | Potential Corporate Privacy Violation | ET P2P BTWebClient UA uTorrent in use |
3816 | uTorrent.exe | Potential Corporate Privacy Violation | ET P2P BTWebClient UA uTorrent in use |
3816 | uTorrent.exe | Potential Corporate Privacy Violation | ET P2P BTWebClient UA uTorrent in use |
1080 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com) |