File name:

uTorrent.exe

Full analysis: https://app.any.run/tasks/8f7c09e3-5a0f-45c5-97bc-e0a5bd00e4cb
Verdict: Malicious activity
Analysis date: May 03, 2021, 14:32:10
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

C7D8BE7EEF6EF338B9D43013A8C103F1

SHA1:

CE166B2EA7CB53AD2B8902B25F176B5D7D88B6B6

SHA256:

639D692C2F72E28A4991C5C2BB5E69BC3420B2DF63EA2112A6CD73EF83415BB1

SSDEEP:

98304:tG5Qg4ugWU9CtWWDbJUCMSPMyPUlB8Pxuxc1zhajsdsOnKyBDZeU:tG5K9CtWWDbJUTSdPUlBraaxOnNcU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • uTorrent.exe (PID: 3676)
      • Carrier.exe (PID: 2560)
      • uTorrent.exe (PID: 3044)
    • Application was dropped or rewritten from another process

      • installer.exe (PID: 2304)
      • GenericSetup.exe (PID: 872)
      • Carrier.exe (PID: 2560)
      • Carrier.exe (PID: 3128)
      • uTorrent.exe (PID: 3044)
      • utorrentie.exe (PID: 2556)
      • utorrentie.exe (PID: 3464)
      • utorrentie.exe (PID: 2076)
      • helper.exe (PID: 1328)
    • Loads dropped or rewritten executable

      • installer.exe (PID: 2304)
      • GenericSetup.exe (PID: 872)
    • Actions looks like stealing of personal data

      • GenericSetup.exe (PID: 872)
    • Changes settings of System certificates

      • GenericSetup.exe (PID: 872)
    • Changes the autorun value in the registry

      • Carrier.exe (PID: 2560)
      • uTorrent.exe (PID: 3044)
  • SUSPICIOUS

    • Checks supported languages

      • uTorrent.exe (PID: 3676)
      • installer.exe (PID: 2304)
      • GenericSetup.exe (PID: 872)
      • cmd.exe (PID: 1080)
      • Carrier.exe (PID: 2560)
      • uTorrent.exe (PID: 3044)
      • utorrentie.exe (PID: 3464)
      • utorrentie.exe (PID: 2556)
      • utorrentie.exe (PID: 2076)
      • helper.exe (PID: 1328)
    • Executable content was dropped or overwritten

      • uTorrent.exe (PID: 3676)
      • Carrier.exe (PID: 2560)
      • uTorrent.exe (PID: 3044)
    • Drops a file with too old compile date

      • uTorrent.exe (PID: 3676)
      • Carrier.exe (PID: 2560)
      • uTorrent.exe (PID: 3044)
    • Drops a file with a compile date too recent

      • uTorrent.exe (PID: 3676)
      • Carrier.exe (PID: 2560)
      • uTorrent.exe (PID: 3044)
    • Drops a file that was compiled in debug mode

      • uTorrent.exe (PID: 3676)
      • uTorrent.exe (PID: 3044)
    • Reads the computer name

      • installer.exe (PID: 2304)
      • GenericSetup.exe (PID: 872)
      • Carrier.exe (PID: 2560)
      • uTorrent.exe (PID: 3044)
      • utorrentie.exe (PID: 3464)
      • utorrentie.exe (PID: 2556)
      • utorrentie.exe (PID: 2076)
      • helper.exe (PID: 1328)
    • Starts CMD.EXE for commands execution

      • GenericSetup.exe (PID: 872)
    • Adds / modifies Windows certificates

      • GenericSetup.exe (PID: 872)
    • Creates files in the user directory

      • Carrier.exe (PID: 2560)
      • uTorrent.exe (PID: 3044)
      • utorrentie.exe (PID: 3464)
      • utorrentie.exe (PID: 2556)
    • Changes default file association

      • Carrier.exe (PID: 2560)
    • Reads Environment values

      • GenericSetup.exe (PID: 872)
    • Reads Windows owner or organization settings

      • GenericSetup.exe (PID: 872)
    • Reads the Windows organization settings

      • GenericSetup.exe (PID: 872)
    • Creates a software uninstall entry

      • Carrier.exe (PID: 2560)
    • Searches for installed software

      • uTorrent.exe (PID: 3044)
      • GenericSetup.exe (PID: 872)
    • Changes IE settings (feature browser emulation)

      • uTorrent.exe (PID: 3044)
    • Reads Microsoft Outlook installation path

      • utorrentie.exe (PID: 2556)
      • utorrentie.exe (PID: 3464)
      • iexplore.exe (PID: 552)
      • utorrentie.exe (PID: 2076)
    • Reads internet explorer settings

      • utorrentie.exe (PID: 2556)
      • utorrentie.exe (PID: 3464)
      • utorrentie.exe (PID: 2076)
    • Starts Internet Explorer

      • uTorrent.exe (PID: 3044)
    • Reads CPU info

      • utorrentie.exe (PID: 2556)
      • utorrentie.exe (PID: 3464)
  • INFO

    • Reads settings of System Certificates

      • GenericSetup.exe (PID: 872)
      • Carrier.exe (PID: 2560)
      • uTorrent.exe (PID: 3044)
      • utorrentie.exe (PID: 3464)
      • utorrentie.exe (PID: 2556)
      • iexplore.exe (PID: 552)
      • iexplore.exe (PID: 2472)
      • utorrentie.exe (PID: 2076)
      • helper.exe (PID: 1328)
    • Checks Windows Trust Settings

      • GenericSetup.exe (PID: 872)
      • Carrier.exe (PID: 2560)
      • uTorrent.exe (PID: 3044)
      • utorrentie.exe (PID: 2556)
      • iexplore.exe (PID: 552)
      • iexplore.exe (PID: 2472)
      • utorrentie.exe (PID: 3464)
      • utorrentie.exe (PID: 2076)
    • Manual execution by user

      • uTorrent.exe (PID: 3044)
    • Changes internet zones settings

      • iexplore.exe (PID: 2472)
    • Checks supported languages

      • iexplore.exe (PID: 2472)
      • iexplore.exe (PID: 552)
    • Reads the computer name

      • iexplore.exe (PID: 2472)
      • iexplore.exe (PID: 552)
    • Application launched itself

      • iexplore.exe (PID: 2472)
    • Reads internet explorer settings

      • iexplore.exe (PID: 552)
    • Creates files in the user directory

      • iexplore.exe (PID: 552)
    • Reads the date of Windows installation

      • iexplore.exe (PID: 2472)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (30.9)
.exe | Win64 Executable (generic) (27.3)
.exe | UPX compressed Win32 Executable (26.8)
.dll | Win32 Dynamic Link Library (generic) (6.5)
.exe | Win32 Executable (generic) (4.4)

EXIF

EXE

ProductName: µTorrent
OriginalFileName: GenericSetup.exe
LegalCopyright: ©2020 BitTorrent, Inc. All Rights Reserved.
InternalName: 7zS.sfx
FileDescription: Software Installation
CompanyName: BitTorrent Inc.
ProductVersion: 3.5.5.45988
FileVersion: 3.5.5.45988
CharacterSet: Unicode
LanguageCode: English (U.S.)
FileSubtype: -
ObjectFileType: Executable application
FileOS: Windows NT 32-bit
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 3.5.5.45988
FileVersionNumber: 3.5.5.45988
Subsystem: Windows GUI
SubsystemVersion: 4
ImageVersion: -
OSVersion: 4
EntryPoint: 0x148d4
UninitializedDataSize: -
InitializedDataSize: 82432
CodeSize: 104448
LinkerVersion: 6
PEType: PE32
TimeStamp: 2011:04:18 20:54:06+02:00
MachineType: Intel 386 or later, and compatibles
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
14
Malicious processes
10
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start drop and start utorrent.exe installer.exe genericsetup.exe carrier.exe no specs cmd.exe no specs carrier.exe utorrent.exe utorrentie.exe utorrentie.exe iexplore.exe iexplore.exe utorrentie.exe helper.exe utorrent.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
552"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2472 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
872"C:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\GenericSetup.exe" C:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\GenericSetup.exe hik=7f351d2a-ce44-42c5-bc6d-5c0d9688af46 hmk=ebf96d2e-2375-7356-d53a-0972f39d3cc2 hut=Admin hpp="QzpcVXNlcnNcYWRtaW5cQXBwRGF0YVxMb2NhbFxUZW1wXHVUb3JyZW50LmV4ZQ==" hts=1620052365972C:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\GenericSetup.exe
installer.exe
User:
admin
Integrity Level:
HIGH
Description:
Software Installation
Exit code:
3221225547
Version:
1.0.11.4537
Modules
Images
c:\users\admin\appdata\local\temp\7zsc5e9e2c1\genericsetup.exe
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\rpcrt4.dll
1080"C:\Windows\system32\cmd.exe" /C ""C:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\Carrier.exe" /S /FORCEINSTALL 1110010101111110 /CAMPAIGN 180"C:\Windows\system32\cmd.exeGenericSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1328"C:\Users\admin\AppData\Roaming\uTorrent\helper\helper.exe" 63561 --hval BTi3b8NC9Y0wHDg- -- -pid 3044 -version 45988C:\Users\admin\AppData\Roaming\uTorrent\helper\helper.exe
uTorrent.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
MEDIUM
Description:
�Torrent Helper
Exit code:
0
Version:
2.0.18.1499
Modules
Images
c:\users\admin\appdata\roaming\utorrent\helper\helper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wininet.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\usp10.dll
1644"C:\Users\admin\AppData\Local\Temp\uTorrent.exe" C:\Users\admin\AppData\Local\Temp\uTorrent.exeExplorer.EXE
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
MEDIUM
Description:
Software Installation
Exit code:
3221226540
Version:
3.5.5.45988
Modules
Images
c:\users\admin\appdata\local\temp\utorrent.exe
c:\windows\system32\ntdll.dll
2076"C:\Users\admin\AppData\Roaming\uTorrent\updates\3.5.5_45988\utorrentie.exe" uTorrent_3044_01F7C298_1349132746 �Torrent4823DF041B09 uTorrentC:\Users\admin\AppData\Roaming\uTorrent\updates\3.5.5_45988\utorrentie.exe
uTorrent.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
LOW
Description:
WebHelper
Exit code:
0
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\roaming\utorrent\updates\3.5.5_45988\utorrentie.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\user32.dll
2304.\installer.exeC:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\installer.exe
uTorrent.exe
User:
admin
Company:
adaware
Integrity Level:
HIGH
Description:
Software Installation
Exit code:
0
Version:
6.2.0.4537
Modules
Images
c:\users\admin\appdata\local\temp\7zsc5e9e2c1\installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\normaliz.dll
2472"C:\Program Files\Internet Explorer\iexplore.exe" http://utorrent.com/prodnews?v=3%2e5%2e5%2e1%2e45988C:\Program Files\Internet Explorer\iexplore.exe
uTorrent.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2556"C:\Users\admin\AppData\Roaming\uTorrent\updates\3.5.5_45988\utorrentie.exe" uTorrent_3044_01F7BF08_417866879 �Torrent4823DF041B09 uTorrentC:\Users\admin\AppData\Roaming\uTorrent\updates\3.5.5_45988\utorrentie.exe
uTorrent.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
LOW
Description:
WebHelper
Exit code:
0
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\roaming\utorrent\updates\3.5.5_45988\utorrentie.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\user32.dll
2560"C:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\Carrier.exe" /S /FORCEINSTALL 1110010101111110 /CAMPAIGN 180C:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\Carrier.exe
cmd.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
HIGH
Description:
�Torrent
Exit code:
1
Version:
3.5.5.45988
Modules
Images
c:\users\admin\appdata\local\temp\7zsc5e9e2c1\carrier.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
Total events
61 182
Read events
60 709
Write events
466
Delete events
7

Modification events

(PID) Process:(2304) installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2304) installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2304) installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2304) installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(872) GenericSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(872) GenericSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(872) GenericSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(872) GenericSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(872) GenericSetup.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(872) GenericSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4
Operation:writeName:Blob
Value:
0400000001000000100000004BE2C99196650CF40E5A9392A00AFEB27F000000010000002C000000302A060A2B0601040182370A030406082B0601050507030506082B0601050507030606082B06010505070307090000000100000054000000305206082B0601050507030206082B06010505070303060A2B0601040182370A030406082B0601050507030406082B0601050507030606082B0601050507030706082B0601050507030106082B060105050703080F0000000100000020000000FDE5F2D9CE2026E1E10064C0A468C9F355B90ACF85BAF5CE6F52D4016837FD940300000001000000140000008CF427FD790C3AD166068DE81E57EFBB932272D41D0000000100000010000000521B5F4582C1DCAAE381B05E37CA2D341400000001000000140000006A72267AD01EEF7DE73B6951D46C8D9F901266AB0B000000010000001800000045006E00740072007500730074002E006E0065007400000062000000010000002000000043DF5774B03E7FEF5FE40D931A7BEDF1BB2E6B42738C4E6D3841103D3AA7F339190000000100000010000000FA46CE7CBB85CFB4310075313A09EE05530000000100000041000000303F3020060A6086480186FA6C0A010230123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C07E000000010000000800000000C001B39667D6012000000001000000420400003082043E30820326A00302010202044A538C28300D06092A864886F70D01010B05003081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D204732301E170D3039303730373137323535345A170D3330313230373137353535345A3081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D20473230820122300D06092A864886F70D01010105000382010F003082010A0282010100BA84B672DB9E0C6BE299E93001A776EA32B895411AC9DA614E5872CFFEF68279BF7361060AA527D8B35FD3454E1C72D64E32F2728A0FF78319D06A808000451EB0C7E79ABF1257271CA3682F0A87BD6A6B0E5E65F31C77D5D4858D7021B4B332E78BA2D5863902B1B8D247CEE4C949C43BA7DEFB547D57BEF0E86EC279B23A0B55E250981632135C2F7856C1C294B3F25AE4279A9F24D7C6ECD09B2582E3CCC2C445C58C977A066B2A119FA90A6E483B6FDBD4111942F78F07BFF5535F9C3EF4172CE669AC4E324C6277EAB7E8E5BB34BC198BAE9C51E7B77EB553B13322E56DCF703C1AFAE29B67B683F48DA5AF624C4DE058AC64341203F8B68D946324A4710203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E041604146A72267AD01EEF7DE73B6951D46C8D9F901266AB300D06092A864886F70D01010B05000382010100799F1D96C6B6793F228D87D3870304606A6B9A2E59897311AC43D1F513FF8D392BC0F2BD4F708CA92FEA17C40B549ED41B9698333CA8AD62A20076AB59696E061D7EC4B9448D98AF12D461DB0A194647F3EBF763C1400540A5D2B7F4B59A36BFA98876880455042B9C877F1A373C7E2DA51AD8D4895ECABDAC3D6CD86DAFD5F3760FCD3B8838229D6C939AC43DBF821B653FA60F5DAAFCE5B215CAB5ADC6BC3DD084E8EA0672B04D393278BF3E119C0BA49D9A21F3F09B0B3078DBC1DC8743FEBC639ACAC5C21CC9C78DFF3B125808E6B63DEC7A2C4EFB8396CE0C3C69875473A473C293FF5110AC155401D8FC05B189A17F74839A49D7DC4E7B8A486F8B45F6
Executable files
32
Suspicious files
115
Text files
168
Unknown types
58

Dropped files

PID
Process
Filename
Type
3676uTorrent.exeC:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\BundleConfig.jsontext
MD5:
SHA256:
3676uTorrent.exeC:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\app.icoimage
MD5:21D40E1B37AD7CFDEAC5BE2BC5C2B58D
SHA256:D29353F6C8BA117BDED73A2A12C9F3E5C5E286C168AB4F91DE33CCBAD942AC18
3676uTorrent.exeC:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\de\DevLib.resources.dllexecutable
MD5:
SHA256:
3676uTorrent.exeC:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\GenericSetup.exe.configxml
MD5:377B63CF5F7E747B3B7727DDC4D4F288
SHA256:54FC68E5B9AA2740F740D5BE1E7ED22F39379EAAD9FEE3358B298E39C69E85B1
3676uTorrent.exeC:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\Resources\InstallingPage.htmlhtml
MD5:9A8AF9C65D92EBFC67A96BEA03C6C3FC
SHA256:5F558D572E6BA9E5E82BDAEACA5C0FDAE9519F32B854D534EDBA256F20C6F0D5
3676uTorrent.exeC:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\Resources\images\warning48x48.pngimage
MD5:D3361CF0D689A1B34D84F483D60BA9C9
SHA256:56739925AADA73F9489F9A6B72BFAAA92892B27D20F4D221380BA3EAE17F1442
3676uTorrent.exeC:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\Resources\SettingPage1.htmlhtml
MD5:55A4C91743FD057A8C430767A32AC9A5
SHA256:361F60D1C7DE5B16C3C0FCA967A8B729D85AC19CA4BD847DBA8AAFB2CB5C8BBF
3676uTorrent.exeC:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\Resources\FinishPage.htmlhtml
MD5:C80FA35AD16A8E6F6D02A003D408200C
SHA256:0C1C1704D0858BBF271EDEEF7C1A9C76126B90AF71A39D121D1159A3EE69599B
3676uTorrent.exeC:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\Resources\tis\TranslateOfferTemplate.tistext
MD5:551029A3E046C5ED6390CC85F632A689
SHA256:7B8C76A85261C5F9E40E49F97E01A14320E9B224FF3D6AF8286632CA94CF96F8
3676uTorrent.exeC:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\Resources\images\loader.gifimage
MD5:2B26F73D382AB69F3914A7D9FDA97B0F
SHA256:A6A0B05B1D5C52303DD3E9E2F9CDA1E688A490FBE84EA0D6E22A051AB6EFD643
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
116
TCP/UDP connections
339
DNS requests
109
Threats
17

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2560
Carrier.exe
GET
200
82.221.103.246:80
http://update.utorrent.li/installstats.php?cl=uTorrent&v=111915940&h=BTi3b8NC9Y0wHDg-&w=1DB10106&bu=0&pr=0&cmp=180&ocmp=180&showinstall&pid=2560&cau=0&au=0&view=win32
IS
whitelisted
2560
Carrier.exe
GET
200
82.221.103.246:80
http://update.utorrent.li/installstats.php?cl=uTorrent&v=111915940&h=BTi3b8NC9Y0wHDg-&w=1DB10106&bu=0&pr=0&cmp=180&ocmp=180&installresult&pid=2560&cau=0&installresult=0&exit=1&au=0&ic=1&view=win32
IS
whitelisted
3044
uTorrent.exe
GET
178.79.242.16:80
http://cdn.ap.bittorrent.com/control/tags/ut.json
DE
shared
3044
uTorrent.exe
GET
178.79.242.16:80
http://apps.bittorrent.com/utorrent-onboarding/player.btapp
DE
whitelisted
3044
uTorrent.exe
GET
173.254.195.58:80
http://update.bittorrent.com/time.php
US
whitelisted
GET
200
93.184.220.29:80
http://crl3.digicert.com/Omniroot2025.crl
US
der
7.49 Kb
whitelisted
2560
Carrier.exe
GET
200
67.27.234.126:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?d5890ea27afbf096
US
compressed
57.2 Kb
whitelisted
3044
uTorrent.exe
POST
107.22.221.32:80
http://i-32.b-45988.ut.bench.utorrent.com/e?i=32
US
suspicious
3044
uTorrent.exe
POST
107.20.217.71:80
http://i-29.b-45988.ut.bench.utorrent.com/e?i=29
US
suspicious
3044
uTorrent.exe
GET
200
178.79.242.16:80
http://cdn.ap.bittorrent.com/control/feature/tags/ut.json
DE
text
2.94 Kb
shared
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2304
installer.exe
104.18.88.101:443
flow.lavasoft.com
Cloudflare Inc
US
shared
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
67.27.234.126:80
ctldl.windowsupdate.com
Level 3 Communications, Inc.
US
suspicious
872
GenericSetup.exe
104.18.88.101:443
flow.lavasoft.com
Cloudflare Inc
US
shared
872
GenericSetup.exe
104.16.236.79:443
sos.adaware.com
Cloudflare Inc
US
shared
872
GenericSetup.exe
104.16.235.79:443
sos.adaware.com
Cloudflare Inc
US
shared
2560
Carrier.exe
67.27.234.126:80
ctldl.windowsupdate.com
Level 3 Communications, Inc.
US
suspicious
3044
uTorrent.exe
107.22.221.32:80
i-21.b-45988.ut.bench.utorrent.com
Amazon.com, Inc.
US
suspicious
2560
Carrier.exe
82.221.103.246:80
update.utorrent.li
Thor Data Center ehf
IS
suspicious
3044
uTorrent.exe
23.21.74.8:80
i-21.b-45988.ut.bench.utorrent.com
Amazon.com, Inc.
US
suspicious

DNS requests

Domain
IP
Reputation
flow.lavasoft.com
  • 104.18.88.101
  • 104.18.87.101
whitelisted
ctldl.windowsupdate.com
  • 67.27.234.126
  • 67.26.139.254
  • 8.253.207.121
  • 67.27.233.126
  • 8.248.139.254
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
www.google.com
  • 142.250.185.132
malicious
sos.adaware.com
  • 104.16.235.79
  • 104.16.236.79
whitelisted
crl3.digicert.com
  • 93.184.220.29
whitelisted
router.bittorrent.com
  • 67.215.246.10
shared
router.utorrent.com
  • 82.221.103.244
whitelisted
update.utorrent.li
  • 82.221.103.246
  • 82.221.103.245
whitelisted
i-21.b-45988.ut.bench.utorrent.com
  • 107.22.221.32
  • 23.21.74.8
  • 23.23.85.1
  • 107.20.217.71
  • 50.17.181.247
  • 54.243.58.192
  • 107.22.246.37
  • 23.23.132.92
suspicious

Threats

PID
Process
Class
Message
Potential Corporate Privacy Violation
ET P2P Bittorrent P2P Client User-Agent (uTorrent)
Potential Corporate Privacy Violation
ET P2P Bittorrent P2P Client User-Agent (uTorrent)
Potential Corporate Privacy Violation
ET P2P BTWebClient UA uTorrent in use
Potential Corporate Privacy Violation
ET P2P BTWebClient UA uTorrent in use
Potential Corporate Privacy Violation
ET P2P BTWebClient UA uTorrent in use
Potential Corporate Privacy Violation
ET P2P BitTorrent DHT ping request
Potential Corporate Privacy Violation
ET P2P BTWebClient UA uTorrent in use
Potential Corporate Privacy Violation
ET P2P BTWebClient UA uTorrent in use
Potential Corporate Privacy Violation
ET P2P BTWebClient UA uTorrent in use
Potentially Bad Traffic
ET POLICY Executable served from Amazon S3
Process
Message
installer.exe
[debug][2021-05-03 15:32:43.394187][installer][wWinMain][266]: bundle config file path=C:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\BundleConfig.json
installer.exe
[debug][2021-05-03 15:32:43.394187][installer][CreateBundleConfig][96]: DisableStubEvents=0
installer.exe
[debug][2021-05-03 15:32:43.394187][installer][wWinMain][273]: install id=7f351d2a-ce44-42c5-bc6d-5c0d9688af46
installer.exe
[debug][2021-05-03 15:32:45.956687][installer][wWinMain][277]: machine Id id=ebf96d2e-2375-7356-d53a-0972f39d3cc2
installer.exe
[debug][2021-05-03 15:32:45.972312][installer][wWinMain][429]: generic setup path=C:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\GenericSetup.exe
installer.exe
[debug][2021-05-03 15:32:45.972312][installer][EventService::SendEvent][62]: send event. event name=StubStart. disable stub events=0
installer.exe
[debug][2021-05-03 15:32:45.972312][installer][EventService::SendEvent][110]: StubStart data = {"Data":{"EventCategory":"Success","BundleId":"UT008","DeltaMs":64,"MachineId":"ebf96d2e-2375-7356-d53a-0972f39d3cc2","InstallId":"7f351d2a-ce44-42c5-bc6d-5c0d9688af46","PartnerVersion":"1.0.11.4537","BundleVersion":"6.2.3.0","OsVersion":"Microsoft Windows 7 Professional Service Pack 1 (build 7601), 32-bit","DotNetFramework":"3.5, 4.0 Client, 4.0 Full, 4.5, 4.5.1, 4.5.2"}}
installer.exe
[debug][2021-05-03 15:32:45.972312][installer][EventService::SendEvent][120]: url=https://flow.lavasoft.com/v1/event-stat?ProductID=IS&Type=StubStart
installer.exe
[debug][2021-05-03 15:32:45.972312][installer][ProcessService::GetProcessName][46]: Module filename is: C:\Users\admin\AppData\Local\Temp\uTorrent.exe
installer.exe
[debug][2021-05-03 15:32:45.972312][installer][wWinMain][436]: cmd=C:\Users\admin\AppData\Local\Temp\7zSC5E9E2C1\GenericSetup.exe hik=7f351d2a-ce44-42c5-bc6d-5c0d9688af46 hmk=ebf96d2e-2375-7356-d53a-0972f39d3cc2 hut=Admin hpp="QzpcVXNlcnNcYWRtaW5cQXBwRGF0YVxMb2NhbFxUZW1wXHVUb3JyZW50LmV4ZQ==" hts=1620052365972