File name:

utorrent182.exe

Full analysis: https://app.any.run/tasks/db2c9d22-89b6-4903-bfbe-03563535f20f
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: May 16, 2025, 20:28:00
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
upx
loader
bittorrent
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, 3 sections
MD5:

3AF137144D244E89ABE9FBF14829D1FA

SHA1:

4B8269442EA27090287DC7D520BF28E586773E21

SHA256:

639E5D2BF7B06CDE7CE729882F8EE41EA592B089067CAC5029E9140FC2427ED8

SSDEEP:

6144:yA2cfIGJVTdhdV8BYepIwdOgw5bY6rqX7L:yBY9rwBfWI6E6rqX7L

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • utorrent182.exe (PID: 7312)
      • utorrent182.exe (PID: 7948)
      • uTorrent.exe (PID: 8048)
    • BITTORRENT has been detected (SURICATA)

      • uTorrent.exe (PID: 8048)
  • SUSPICIOUS

    • Mutex name with non-standard characters

      • utorrent182.exe (PID: 7312)
      • uTorrent.exe (PID: 8048)
    • There is functionality for taking screenshot (YARA)

      • utorrent182.exe (PID: 7312)
      • uTorrent.exe (PID: 8048)
    • Reads security settings of Internet Explorer

      • utorrent182.exe (PID: 7312)
    • Application launched itself

      • utorrent182.exe (PID: 7312)
    • Potential Corporate Privacy Violation

      • utorrent182.exe (PID: 7312)
      • uTorrent.exe (PID: 8048)
    • Executable content was dropped or overwritten

      • utorrent182.exe (PID: 7948)
    • Starts itself from another location

      • utorrent182.exe (PID: 7312)
    • Searches for installed software

      • utorrent182.exe (PID: 7948)
    • Process requests binary or script from the Internet

      • utorrent182.exe (PID: 7312)
    • Creates a software uninstall entry

      • utorrent182.exe (PID: 7948)
  • INFO

    • Checks supported languages

      • utorrent182.exe (PID: 7312)
      • utorrent182.exe (PID: 7948)
      • uTorrent.exe (PID: 8048)
    • The sample compiled with english language support

      • utorrent182.exe (PID: 7312)
      • utorrent182.exe (PID: 7948)
    • Reads the computer name

      • utorrent182.exe (PID: 7312)
      • utorrent182.exe (PID: 7948)
      • uTorrent.exe (PID: 8048)
    • Checks proxy server information

      • utorrent182.exe (PID: 7312)
    • Reads the machine GUID from the registry

      • utorrent182.exe (PID: 7312)
      • utorrent182.exe (PID: 7948)
      • uTorrent.exe (PID: 8048)
    • UPX packer has been detected

      • utorrent182.exe (PID: 7312)
      • uTorrent.exe (PID: 8048)
    • Process checks computer location settings

      • utorrent182.exe (PID: 7312)
    • Creates files in the program directory

      • utorrent182.exe (PID: 7948)
    • Creates files or folders in the user directory

      • utorrent182.exe (PID: 7948)
      • utorrent182.exe (PID: 7312)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (39.3)
.exe | Win32 EXE Yoda's Crypter (38.6)
.dll | Win32 Dynamic Link Library (generic) (9.5)
.exe | Win32 Executable (generic) (6.5)
.exe | Generic Win/DOS Executable (2.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2009:05:05 20:07:52+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 258048
InitializedDataSize: 16384
UninitializedDataSize: 417792
EntryPoint: 0xa4440
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.8.2.15357
ProductVersionNumber: 1.8.2.15357
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Unknown (0)
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: BitTorrent, Inc.
FileDescription: µTorrent
FileVersion: 1.8.2.15357
LegalCopyright: ©2009 BitTorrent, Inc. All Rights Reserved.
ProductName: µTorrent
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
137
Monitored processes
6
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start utorrent182.exe sppextcomobj.exe no specs slui.exe no specs utorrent182.exe HNetCfg.FwPolicy2 no specs #BITTORRENT utorrent.exe

Process information

PID
CMD
Path
Indicators
Parent process
7312"C:\Users\admin\AppData\Local\Temp\utorrent182.exe" C:\Users\admin\AppData\Local\Temp\utorrent182.exe
explorer.exe
User:
admin
Company:
BitTorrent, Inc.
Integrity Level:
MEDIUM
Description:
µTorrent
Exit code:
0
Version:
1.8.2.15357
Modules
Images
c:\users\admin\appdata\local\temp\utorrent182.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
7396C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
7428"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
7948"C:\Users\admin\AppData\Local\Temp\utorrent182.exe" /PERFORMINSTALL 12751 "C:\Program Files (x86)\uTorrent"C:\Users\admin\AppData\Local\Temp\utorrent182.exe
utorrent182.exe
User:
admin
Company:
BitTorrent, Inc.
Integrity Level:
HIGH
Description:
µTorrent
Exit code:
1
Version:
1.8.2.15357
Modules
Images
c:\users\admin\appdata\local\temp\utorrent182.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
8004C:\WINDOWS\SysWOW64\DllHost.exe /Processid:{E2B3C97F-6AE1-41AC-817A-F6F92166D7DD}C:\Windows\SysWOW64\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\ucrtbase.dll
c:\windows\syswow64\combase.dll
8048uTorrent.exe /NOINSTALL /BRINGTOFRONTC:\Program Files (x86)\uTorrent\uTorrent.exe
utorrent182.exe
User:
admin
Company:
BitTorrent, Inc.
Integrity Level:
MEDIUM
Description:
µTorrent
Version:
1.8.2.15357
Modules
Images
c:\program files (x86)\utorrent\utorrent.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
1 602
Read events
1 590
Write events
11
Delete events
1

Modification events

(PID) Process:(7948) utorrent182.exeKey:HKEY_CURRENT_USER\SOFTWARE\BitTorrent\uTorrent
Operation:writeName:Revision
Value:
15357
(PID) Process:(7948) utorrent182.exeKey:HKEY_CLASSES_ROOT\.torrent\OpenWithProgids
Operation:writeName:uTorrent
Value:
(PID) Process:(7948) utorrent182.exeKey:HKEY_CLASSES_ROOT\.btsearch\OpenWithProgids
Operation:writeName:uTorrent
Value:
(PID) Process:(7948) utorrent182.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent
Operation:writeName:DisplayIcon
Value:
C:\Program Files (x86)\uTorrent\uTorrent.exe,0
(PID) Process:(7948) utorrent182.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent
Operation:writeName:DisplayName
Value:
µTorrent
(PID) Process:(7948) utorrent182.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent
Operation:writeName:DisplayVersion
Value:
1.8.2
(PID) Process:(7948) utorrent182.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent
Operation:writeName:UninstallString
Value:
"C:\Program Files (x86)\uTorrent\uTorrent.exe" /UNINSTALL
(PID) Process:(7948) utorrent182.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent
Operation:writeName:InstallLocation
Value:
C:\Program Files (x86)\uTorrent
(PID) Process:(7948) utorrent182.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent
Operation:writeName:NoModify
Value:
1
(PID) Process:(7948) utorrent182.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent
Operation:writeName:NoRepair
Value:
1
Executable files
1
Suspicious files
8
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
7948utorrent182.exeC:\Program Files (x86)\uTorrent\uTorrent.exeexecutable
MD5:3AF137144D244E89ABE9FBF14829D1FA
SHA256:639E5D2BF7B06CDE7CE729882F8EE41EA592B089067CAC5029E9140FC2427ED8
7948utorrent182.exeC:\Users\admin\AppData\Roaming\uTorrent\settings.datbinary
MD5:5D15184C6CC3F67CD0B3479CC0E9E7F2
SHA256:4F835076AAA24F3DF958C49E03E04913CAA8E88F1DB1F63805F8C3A9029A55CF
7312utorrent182.exeC:\Users\admin\AppData\Roaming\uTorrent\settings.dat.oldbinary
MD5:5D15184C6CC3F67CD0B3479CC0E9E7F2
SHA256:4F835076AAA24F3DF958C49E03E04913CAA8E88F1DB1F63805F8C3A9029A55CF
7948utorrent182.exeC:\Users\admin\Desktop\µTorrent.lnkbinary
MD5:974863D15090CD10E8CCA2ED72435320
SHA256:8B9E5FA766A0DA48416C4BE9D95EBFE940C114DCE33097DB1D858096872B9EC2
7948utorrent182.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnkbinary
MD5:49EDA0F6728DB785431B40327200B0BE
SHA256:AF68A336199AF038ED39F06BC5DCB213B33E9C58709A0F5A3B43C24412D38213
7948utorrent182.exeC:\Users\admin\AppData\Roaming\uTorrent\settings.dat.newbinary
MD5:5D15184C6CC3F67CD0B3479CC0E9E7F2
SHA256:4F835076AAA24F3DF958C49E03E04913CAA8E88F1DB1F63805F8C3A9029A55CF
7312utorrent182.exeC:\Users\admin\AppData\Roaming\uTorrent\settings.dat.newbinary
MD5:21F056EAE869D41DBF173FC3664C3B3B
SHA256:FCB7765EC5FC631A7B7EABFBED7EF427C244A0F7D0D18D3011AE98573072D0AA
7948utorrent182.exeC:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnkbinary
MD5:92EBD13C916491FD58D3E7D7BFA5F4DC
SHA256:628B704514BFFFD208136D99C2A6FF83089B3317194CB94B107E65C0F5692AC1
7312utorrent182.exeC:\Users\admin\AppData\Roaming\uTorrent\settings.datbinary
MD5:21F056EAE869D41DBF173FC3664C3B3B
SHA256:FCB7765EC5FC631A7B7EABFBED7EF427C244A0F7D0D18D3011AE98573072D0AA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
17
TCP/UDP connections
84
DNS requests
18
Threats
13

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.168.124:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7312
utorrent182.exe
GET
200
82.221.103.245:80
http://update.utorrent.com/installstats.php?v=50674685&h=mJCCmxBNzAZ8M3m8&w=23F00206&showwarning
unknown
whitelisted
7312
utorrent182.exe
GET
200
82.221.103.245:80
http://update.utorrent.com/installstats.php?v=50674685&h=mJCCmxBNzAZ8M3m8&w=23F00206&warningresult=1&exit=1
unknown
whitelisted
7312
utorrent182.exe
GET
200
82.221.103.245:80
http://update.utorrent.com/installstats.php?v=50674685&h=mJCCmxBNzAZ8M3m8&w=23F00206&showinstall
unknown
whitelisted
7312
utorrent182.exe
GET
200
82.221.103.245:80
http://update.utorrent.com/installstats.php?v=50674685&h=mJCCmxBNzAZ8M3m8&w=23F00206&installresult=12623&exit=6
unknown
whitelisted
7312
utorrent182.exe
GET
522
43.175.236.102:80
http://ll.download3.utorrent.com/offers/tb_ask-4.1.0.5.bmp
unknown
whitelisted
7312
utorrent182.exe
GET
200
82.221.103.245:80
http://update.utorrent.com/installstats.php?v=50674685&h=mJCCmxBNzAZ8M3m8&w=23F00206&tboffer&tb=1
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.16.168.124:80
crl.microsoft.com
Akamai International B.V.
RU
whitelisted
5496
MoUsoCoreWorker.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
7312
utorrent182.exe
82.221.103.245:80
update.utorrent.com
Advania Island ehf
IS
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.159.129:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 172.217.16.142
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 2.16.168.124
  • 2.16.168.114
whitelisted
www.microsoft.com
  • 2.23.246.101
  • 184.30.21.171
whitelisted
update.utorrent.com
  • 82.221.103.245
  • 82.221.103.246
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.159.129
  • 20.190.159.71
  • 40.126.31.2
  • 40.126.31.69
  • 40.126.31.1
  • 40.126.31.131
  • 40.126.31.0
  • 40.126.31.67
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
ll.download3.utorrent.com
  • 43.175.236.102
whitelisted
router.bittorrent.com
  • 67.215.246.10
whitelisted

Threats

PID
Process
Class
Message
7312
utorrent182.exe
Potential Corporate Privacy Violation
ET P2P Bittorrent P2P Client User-Agent (uTorrent)
7312
utorrent182.exe
Potential Corporate Privacy Violation
ET P2P Bittorrent P2P Client User-Agent (uTorrent)
7312
utorrent182.exe
Potential Corporate Privacy Violation
ET P2P Bittorrent P2P Client User-Agent (uTorrent)
7312
utorrent182.exe
Potential Corporate Privacy Violation
ET P2P Bittorrent P2P Client User-Agent (uTorrent)
7312
utorrent182.exe
Potential Corporate Privacy Violation
ET P2P Bittorrent P2P Client User-Agent (uTorrent)
7312
utorrent182.exe
Potential Corporate Privacy Violation
ET P2P Bittorrent P2P Client User-Agent (uTorrent)
8048
uTorrent.exe
Potential Corporate Privacy Violation
ET P2P BTWebClient UA uTorrent in use
8048
uTorrent.exe
Misc activity
INFO [ANY.RUN] P2P BitTorrent Protocol
7312
utorrent182.exe
Potential Corporate Privacy Violation
ET P2P Bittorrent P2P Client User-Agent (uTorrent)
7312
utorrent182.exe
Potential Corporate Privacy Violation
ET P2P Bittorrent P2P Client User-Agent (uTorrent)
No debug info