File name: | uTorrent.exe |
Full analysis: | https://app.any.run/tasks/8f7c09e3-5a0f-45c5-97bc-e0a5bd00e4cb |
Verdict: | Malicious activity |
Analysis date: | May 03, 2021, 14:32:10 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | C7D8BE7EEF6EF338B9D43013A8C103F1 |
SHA1: | CE166B2EA7CB53AD2B8902B25F176B5D7D88B6B6 |
SHA256: | 639D692C2F72E28A4991C5C2BB5E69BC3420B2DF63EA2112A6CD73EF83415BB1 |
SSDEEP: | 98304:tG5Qg4ugWU9CtWWDbJUCMSPMyPUlB8Pxuxc1zhajsdsOnKyBDZeU:tG5K9CtWWDbJUTSdPUlBraaxOnNcU |
.exe | | | Win32 Executable MS Visual C++ (generic) (30.9) |
---|---|---|
.exe | | | Win64 Executable (generic) (27.3) |
.exe | | | UPX compressed Win32 Executable (26.8) |
.dll | | | Win32 Dynamic Link Library (generic) (6.5) |
.exe | | | Win32 Executable (generic) (4.4) |
ProductName: | µTorrent |
---|---|
OriginalFileName: | GenericSetup.exe |
LegalCopyright: | ©2020 BitTorrent, Inc. All Rights Reserved. |
InternalName: | 7zS.sfx |
FileDescription: | Software Installation |
CompanyName: | BitTorrent Inc. |
ProductVersion: | 3.5.5.45988 |
FileVersion: | 3.5.5.45988 |
CharacterSet: | Unicode |
LanguageCode: | English (U.S.) |
FileSubtype: | - |
ObjectFileType: | Executable application |
FileOS: | Windows NT 32-bit |
FileFlags: | (none) |
FileFlagsMask: | 0x003f |
ProductVersionNumber: | 3.5.5.45988 |
FileVersionNumber: | 3.5.5.45988 |
Subsystem: | Windows GUI |
SubsystemVersion: | 4 |
ImageVersion: | - |
OSVersion: | 4 |
EntryPoint: | 0x148d4 |
UninitializedDataSize: | - |
InitializedDataSize: | 82432 |
CodeSize: | 104448 |
LinkerVersion: | 6 |
PEType: | PE32 |
TimeStamp: | 2011:04:18 20:54:06+02:00 |
MachineType: | Intel 386 or later, and compatibles |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
552 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2472 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
872 | "C:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\GenericSetup.exe" C:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\GenericSetup.exe hik=7f351d2a-ce44-42c5-bc6d-5c0d9688af46 hmk=ebf96d2e-2375-7356-d53a-0972f39d3cc2 hut=Admin hpp="QzpcVXNlcnNcYWRtaW5cQXBwRGF0YVxMb2NhbFxUZW1wXHVUb3JyZW50LmV4ZQ==" hts=1620052365972 | C:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\GenericSetup.exe | installer.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Software Installation Exit code: 3221225547 Version: 1.0.11.4537 Modules
| |||||||||||||||
1080 | "C:\Windows\system32\cmd.exe" /C ""C:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\Carrier.exe" /S /FORCEINSTALL 1110010101111110 /CAMPAIGN 180" | C:\Windows\system32\cmd.exe | — | GenericSetup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
1328 | "C:\Users\admin\AppData\Roaming\uTorrent\helper\helper.exe" 63561 --hval BTi3b8NC9Y0wHDg- -- -pid 3044 -version 45988 | C:\Users\admin\AppData\Roaming\uTorrent\helper\helper.exe | uTorrent.exe | ||||||||||||
User: admin Company: BitTorrent Inc. Integrity Level: MEDIUM Description: �Torrent Helper Exit code: 0 Version: 2.0.18.1499 Modules
| |||||||||||||||
1644 | "C:\Users\admin\AppData\Local\Temp\uTorrent.exe" | C:\Users\admin\AppData\Local\Temp\uTorrent.exe | — | Explorer.EXE | |||||||||||
User: admin Company: BitTorrent Inc. Integrity Level: MEDIUM Description: Software Installation Exit code: 3221226540 Version: 3.5.5.45988 Modules
| |||||||||||||||
2076 | "C:\Users\admin\AppData\Roaming\uTorrent\updates\3.5.5_45988\utorrentie.exe" uTorrent_3044_01F7C298_1349132746 �Torrent4823DF041B09 uTorrent | C:\Users\admin\AppData\Roaming\uTorrent\updates\3.5.5_45988\utorrentie.exe | uTorrent.exe | ||||||||||||
User: admin Company: BitTorrent Inc. Integrity Level: LOW Description: WebHelper Exit code: 0 Version: 1.0.0 Modules
| |||||||||||||||
2304 | .\installer.exe | C:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\installer.exe | uTorrent.exe | ||||||||||||
User: admin Company: adaware Integrity Level: HIGH Description: Software Installation Exit code: 0 Version: 6.2.0.4537 Modules
| |||||||||||||||
2472 | "C:\Program Files\Internet Explorer\iexplore.exe" http://utorrent.com/prodnews?v=3%2e5%2e5%2e1%2e45988 | C:\Program Files\Internet Explorer\iexplore.exe | uTorrent.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 1 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
2556 | "C:\Users\admin\AppData\Roaming\uTorrent\updates\3.5.5_45988\utorrentie.exe" uTorrent_3044_01F7BF08_417866879 �Torrent4823DF041B09 uTorrent | C:\Users\admin\AppData\Roaming\uTorrent\updates\3.5.5_45988\utorrentie.exe | uTorrent.exe | ||||||||||||
User: admin Company: BitTorrent Inc. Integrity Level: LOW Description: WebHelper Exit code: 0 Version: 1.0.0 Modules
| |||||||||||||||
2560 | "C:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\Carrier.exe" /S /FORCEINSTALL 1110010101111110 /CAMPAIGN 180 | C:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\Carrier.exe | cmd.exe | ||||||||||||
User: admin Company: BitTorrent Inc. Integrity Level: HIGH Description: �Torrent Exit code: 1 Version: 3.5.5.45988 Modules
|
(PID) Process: | (2304) installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
(PID) Process: | (2304) installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | IntranetName |
Value: 1 | |||
(PID) Process: | (2304) installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
(PID) Process: | (2304) installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 0 | |||
(PID) Process: | (872) GenericSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
(PID) Process: | (872) GenericSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | IntranetName |
Value: 1 | |||
(PID) Process: | (872) GenericSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
(PID) Process: | (872) GenericSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 0 | |||
(PID) Process: | (872) GenericSetup.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16B\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (872) GenericSetup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4 |
Operation: | write | Name: | Blob |
Value: 0400000001000000100000004BE2C99196650CF40E5A9392A00AFEB27F000000010000002C000000302A060A2B0601040182370A030406082B0601050507030506082B0601050507030606082B06010505070307090000000100000054000000305206082B0601050507030206082B06010505070303060A2B0601040182370A030406082B0601050507030406082B0601050507030606082B0601050507030706082B0601050507030106082B060105050703080F0000000100000020000000FDE5F2D9CE2026E1E10064C0A468C9F355B90ACF85BAF5CE6F52D4016837FD940300000001000000140000008CF427FD790C3AD166068DE81E57EFBB932272D41D0000000100000010000000521B5F4582C1DCAAE381B05E37CA2D341400000001000000140000006A72267AD01EEF7DE73B6951D46C8D9F901266AB0B000000010000001800000045006E00740072007500730074002E006E0065007400000062000000010000002000000043DF5774B03E7FEF5FE40D931A7BEDF1BB2E6B42738C4E6D3841103D3AA7F339190000000100000010000000FA46CE7CBB85CFB4310075313A09EE05530000000100000041000000303F3020060A6086480186FA6C0A010230123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C07E000000010000000800000000C001B39667D6012000000001000000420400003082043E30820326A00302010202044A538C28300D06092A864886F70D01010B05003081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D204732301E170D3039303730373137323535345A170D3330313230373137353535345A3081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D20473230820122300D06092A864886F70D01010105000382010F003082010A0282010100BA84B672DB9E0C6BE299E93001A776EA32B895411AC9DA614E5872CFFEF68279BF7361060AA527D8B35FD3454E1C72D64E32F2728A0FF78319D06A808000451EB0C7E79ABF1257271CA3682F0A87BD6A6B0E5E65F31C77D5D4858D7021B4B332E78BA2D5863902B1B8D247CEE4C949C43BA7DEFB547D57BEF0E86EC279B23A0B55E250981632135C2F7856C1C294B3F25AE4279A9F24D7C6ECD09B2582E3CCC2C445C58C977A066B2A119FA90A6E483B6FDBD4111942F78F07BFF5535F9C3EF4172CE669AC4E324C6277EAB7E8E5BB34BC198BAE9C51E7B77EB553B13322E56DCF703C1AFAE29B67B683F48DA5AF624C4DE058AC64341203F8B68D946324A4710203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E041604146A72267AD01EEF7DE73B6951D46C8D9F901266AB300D06092A864886F70D01010B05000382010100799F1D96C6B6793F228D87D3870304606A6B9A2E59897311AC43D1F513FF8D392BC0F2BD4F708CA92FEA17C40B549ED41B9698333CA8AD62A20076AB59696E061D7EC4B9448D98AF12D461DB0A194647F3EBF763C1400540A5D2B7F4B59A36BFA98876880455042B9C877F1A373C7E2DA51AD8D4895ECABDAC3D6CD86DAFD5F3760FCD3B8838229D6C939AC43DBF821B653FA60F5DAAFCE5B215CAB5ADC6BC3DD084E8EA0672B04D393278BF3E119C0BA49D9A21F3F09B0B3078DBC1DC8743FEBC639ACAC5C21CC9C78DFF3B125808E6B63DEC7A2C4EFB8396CE0C3C69875473A473C293FF5110AC155401D8FC05B189A17F74839A49D7DC4E7B8A486F8B45F6 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3676 | uTorrent.exe | C:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\BundleConfig.json | text | |
MD5:— | SHA256:— | |||
3676 | uTorrent.exe | C:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\de\DevLib.resources.dll | executable | |
MD5:— | SHA256:— | |||
3676 | uTorrent.exe | C:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\GenericSetup.exe.config | xml | |
MD5:377B63CF5F7E747B3B7727DDC4D4F288 | SHA256:54FC68E5B9AA2740F740D5BE1E7ED22F39379EAAD9FEE3358B298E39C69E85B1 | |||
3676 | uTorrent.exe | C:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\app.ico | image | |
MD5:21D40E1B37AD7CFDEAC5BE2BC5C2B58D | SHA256:D29353F6C8BA117BDED73A2A12C9F3E5C5E286C168AB4F91DE33CCBAD942AC18 | |||
3676 | uTorrent.exe | C:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\Resources\images\warning48x48.png | image | |
MD5:D3361CF0D689A1B34D84F483D60BA9C9 | SHA256:56739925AADA73F9489F9A6B72BFAAA92892B27D20F4D221380BA3EAE17F1442 | |||
3676 | uTorrent.exe | C:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\Resources\OfferPage.html | html | |
MD5:CD971B3AC121709D874E11D6F5BBA960 | SHA256:96304C4EF7192F521ADD5D9D630ED8AB75A3D45663D8641A7C3186519F88DC42 | |||
3676 | uTorrent.exe | C:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\Resources\LicensePage.html | html | |
MD5:2F4414A76546AE6BA2CC1B3C5102BD83 | SHA256:8C8531CDF663FB92EE8E13FBFF63AF8A22017D424B8F58062B3E6F06050DD941 | |||
3676 | uTorrent.exe | C:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\Resources\tis\Config.tis | text | |
MD5:FB1C09FC31CE983ED99D8913BB9F1474 | SHA256:293959C3F8EBB87BFFE885CE2331F0B40AB5666F9D237BE4791ED4903CE17BF4 | |||
3676 | uTorrent.exe | C:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\Resources\WelcomePage.html | html | |
MD5:26D4E8AC8004F8CD9D622A6C46F15E6B | SHA256:168B5C9528FFDF1E188712DB475390301DA90575C50EF99C35B43DBF317FE8BA | |||
3676 | uTorrent.exe | C:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\Resources\tis\EventHandler.tis | text | |
MD5:21EE55B0B6498245399CB5C9EEE014BA | SHA256:6A760DB61003BE01FA0513EFFD11AB734437CF2C94693BA34C29A6DE86AAD8C7 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
2560 | Carrier.exe | GET | 200 | 82.221.103.246:80 | http://update.utorrent.li/installstats.php?cl=uTorrent&v=111915940&h=BTi3b8NC9Y0wHDg-&w=1DB10106&bu=0&pr=0&cmp=180&ocmp=180&showinstall&pid=2560&cau=0&au=0&view=win32 | IS | — | — | whitelisted |
3044 | uTorrent.exe | GET | — | 178.79.242.16:80 | http://apps.bittorrent.com/utorrent-onboarding/player.btapp | DE | — | — | whitelisted |
2560 | Carrier.exe | GET | 200 | 82.221.103.246:80 | http://update.utorrent.li/installstats.php?cl=uTorrent&v=111915940&h=BTi3b8NC9Y0wHDg-&w=1DB10106&bu=0&pr=0&cmp=180&ocmp=180&installresult&pid=2560&cau=0&installresult=0&exit=1&au=0&ic=1&view=win32 | IS | — | — | whitelisted |
3044 | uTorrent.exe | GET | — | 173.254.195.58:80 | http://update.bittorrent.com/time.php | US | — | — | whitelisted |
3044 | uTorrent.exe | GET | — | 178.79.242.16:80 | http://cdn.ap.bittorrent.com/control/tags/ut.json | DE | — | — | shared |
— | — | GET | 200 | 93.184.220.29:80 | http://crl3.digicert.com/Omniroot2025.crl | US | der | 7.49 Kb | whitelisted |
3044 | uTorrent.exe | POST | — | 107.20.217.71:80 | http://i-29.b-45988.ut.bench.utorrent.com/e?i=29 | US | — | — | suspicious |
3044 | uTorrent.exe | GET | 200 | 178.79.242.16:80 | http://cdn.ap.bittorrent.com/control/feature/tags/ut.json | DE | text | 2.94 Kb | shared |
3044 | uTorrent.exe | POST | — | 107.22.221.32:80 | http://i-32.b-45988.ut.bench.utorrent.com/e?i=32 | US | — | — | suspicious |
2560 | Carrier.exe | GET | 200 | 67.27.234.126:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?d5890ea27afbf096 | US | compressed | 57.2 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
2556 | utorrentie.exe | 178.79.242.181:80 | apps.bittorrent.com | Limelight Networks, Inc. | DE | suspicious |
— | — | 178.79.242.16:80 | apps.bittorrent.com | Limelight Networks, Inc. | DE | suspicious |
— | — | 67.215.246.10:6881 | router.bittorrent.com | QuadraNet, Inc | US | suspicious |
3044 | uTorrent.exe | 82.221.103.244:6881 | router.utorrent.com | Thor Data Center ehf | IS | suspicious |
— | — | 124.210.80.152:18548 | — | KDDI CORPORATION | JP | unknown |
— | — | 203.115.85.93:39593 | — | Broadband Pacenet Pvt. Ltd | IN | unknown |
— | — | 187.254.111.89:36710 | — | Cablevision Red, S.A de C.V. | MX | unknown |
2304 | installer.exe | 104.18.88.101:443 | flow.lavasoft.com | Cloudflare Inc | US | shared |
— | — | 67.27.234.126:80 | ctldl.windowsupdate.com | Level 3 Communications, Inc. | US | suspicious |
— | — | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
Domain | IP | Reputation |
---|---|---|
flow.lavasoft.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
www.google.com |
| malicious |
sos.adaware.com |
| whitelisted |
crl3.digicert.com |
| whitelisted |
router.bittorrent.com |
| shared |
router.utorrent.com |
| whitelisted |
update.utorrent.li |
| whitelisted |
i-21.b-45988.ut.bench.utorrent.com |
| suspicious |
PID | Process | Class | Message |
---|---|---|---|
— | — | Potential Corporate Privacy Violation | ET P2P Bittorrent P2P Client User-Agent (uTorrent) |
— | — | Potential Corporate Privacy Violation | ET P2P Bittorrent P2P Client User-Agent (uTorrent) |
— | — | Potential Corporate Privacy Violation | ET P2P BTWebClient UA uTorrent in use |
— | — | Potential Corporate Privacy Violation | ET P2P BTWebClient UA uTorrent in use |
— | — | Potential Corporate Privacy Violation | ET P2P BTWebClient UA uTorrent in use |
— | — | Potential Corporate Privacy Violation | ET P2P BitTorrent DHT ping request |
— | — | Potential Corporate Privacy Violation | ET P2P BTWebClient UA uTorrent in use |
— | — | Potential Corporate Privacy Violation | ET P2P BTWebClient UA uTorrent in use |
— | — | Potential Corporate Privacy Violation | ET P2P BTWebClient UA uTorrent in use |
— | — | Potentially Bad Traffic | ET POLICY Executable served from Amazon S3 |
Process | Message |
---|---|
installer.exe | [debug][2021-05-03 15:32:43.394187][installer][wWinMain][266]: bundle config file path=C:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\BundleConfig.json
|
installer.exe | [debug][2021-05-03 15:32:43.394187][installer][CreateBundleConfig][96]: DisableStubEvents=0
|
installer.exe | [debug][2021-05-03 15:32:43.394187][installer][wWinMain][273]: install id=7f351d2a-ce44-42c5-bc6d-5c0d9688af46
|
installer.exe | [debug][2021-05-03 15:32:45.956687][installer][wWinMain][277]: machine Id id=ebf96d2e-2375-7356-d53a-0972f39d3cc2
|
installer.exe | [debug][2021-05-03 15:32:45.972312][installer][wWinMain][429]: generic setup path=C:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\GenericSetup.exe
|
installer.exe | [debug][2021-05-03 15:32:45.972312][installer][EventService::SendEvent][62]: send event. event name=StubStart. disable stub events=0
|
installer.exe | [debug][2021-05-03 15:32:45.972312][installer][EventService::SendEvent][110]: StubStart data = {"Data":{"EventCategory":"Success","BundleId":"UT008","DeltaMs":64,"MachineId":"ebf96d2e-2375-7356-d53a-0972f39d3cc2","InstallId":"7f351d2a-ce44-42c5-bc6d-5c0d9688af46","PartnerVersion":"1.0.11.4537","BundleVersion":"6.2.3.0","OsVersion":"Microsoft Windows 7 Professional Service Pack 1 (build 7601), 32-bit","DotNetFramework":"3.5, 4.0 Client, 4.0 Full, 4.5, 4.5.1, 4.5.2"}}
|
installer.exe | [debug][2021-05-03 15:32:45.972312][installer][EventService::SendEvent][120]: url=https://flow.lavasoft.com/v1/event-stat?ProductID=IS&Type=StubStart
|
installer.exe | [debug][2021-05-03 15:32:45.972312][installer][ProcessService::GetProcessName][46]: Module filename is: C:\Users\admin\AppData\Local\Temp\uTorrent.exe
|
installer.exe | [debug][2021-05-03 15:32:45.972312][installer][wWinMain][436]: cmd=C:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\GenericSetup.exe hik=7f351d2a-ce44-42c5-bc6d-5c0d9688af46 hmk=ebf96d2e-2375-7356-d53a-0972f39d3cc2 hut=Admin hpp="QzpcVXNlcnNcYWRtaW5cQXBwRGF0YVxMb2NhbFxUZW1wXHVUb3JyZW50LmV4ZQ==" hts=1620052365972
|