File name:

BitTorrent.zip

Full analysis: https://app.any.run/tasks/3a297b09-75a2-4b5c-ad16-b5ac3d98c20e
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: October 14, 2024, 11:23:38
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
arch-scr
arch-html
arch-doc
loader
upx
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

3FFE27C3878005FA0CE7365FE8FE83A8

SHA1:

CABFBFC9547B861DDDD2322DA380C70FC85681DD

SHA256:

6B85413E803B96D99EA70575D165A53DD362418E1A060BAF30E9356F28BE6401

SSDEEP:

98304:vg2KtED5Vepi8DYkLwewg9wRDKxyMIjNUJ9xpuWdFSt8Ot11eInRySiVMj9BV1Pp:Mw

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 6024)
  • SUSPICIOUS

    • Process requests binary or script from the Internet

      • BitTorrent.exe (PID: 6892)
    • Potential Corporate Privacy Violation

      • BitTorrent.exe (PID: 6892)
    • Executable content was dropped or overwritten

      • BitTorrent.exe (PID: 6892)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6024)
    • UPX packer has been detected

      • BitTorrent.exe (PID: 6892)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (36.3)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2024:10:14 11:21:26
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: BitTorrent/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
143
Monitored processes
9
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe THREAT bittorrent.exe bittorrentie.exe no specs bittorrentie.exe no specs bittorrentie.exe no specs bittorrentie.exe no specs sppextcomobj.exe no specs slui.exe slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2420C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
2652"C:\Users\admin\AppData\Local\Temp\Rar$EXa6024.34664\BitTorrent\updates\7.10.4_44847\bittorrentie.exe" BitTorrent_6892_03D68FF8_236954489 BT4823DF041B09 BitTorrentC:\Users\admin\AppData\Local\Temp\Rar$EXa6024.34664\BitTorrent\updates\7.10.4_44847\bittorrentie.exeBitTorrent.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
LOW
Description:
WebHelper
Exit code:
0
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6024.34664\bittorrent\updates\7.10.4_44847\bittorrentie.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
3732C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
3764"C:\Users\admin\AppData\Local\Temp\Rar$EXa6024.34664\BitTorrent\updates\7.10.4_44847\bittorrentie.exe" BitTorrent_6892_03D68A08_1860229164 BT4823DF041B09 BitTorrentC:\Users\admin\AppData\Local\Temp\Rar$EXa6024.34664\BitTorrent\updates\7.10.4_44847\bittorrentie.exeBitTorrent.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
LOW
Description:
WebHelper
Exit code:
0
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6024.34664\bittorrent\updates\7.10.4_44847\bittorrentie.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
5588"C:\Users\admin\AppData\Local\Temp\Rar$EXa6024.34664\BitTorrent\updates\7.10.4_44847\bittorrentie.exe" BitTorrent_6892_03D68840_849538115 BT4823DF041B09 BitTorrentC:\Users\admin\AppData\Local\Temp\Rar$EXa6024.34664\BitTorrent\updates\7.10.4_44847\bittorrentie.exeBitTorrent.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
LOW
Description:
WebHelper
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6024.34664\bittorrent\updates\7.10.4_44847\bittorrentie.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
6024"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\BitTorrent.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6416"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6772"C:\Users\admin\AppData\Local\Temp\Rar$EXa6024.34664\BitTorrent\updates\7.10.4_44847\bittorrentie.exe" BitTorrent_6892_03D69090_1983701369 BT4823DF041B09 BitTorrentC:\Users\admin\AppData\Local\Temp\Rar$EXa6024.34664\BitTorrent\updates\7.10.4_44847\bittorrentie.exeBitTorrent.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
LOW
Description:
WebHelper
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6024.34664\bittorrent\updates\7.10.4_44847\bittorrentie.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
6892"C:\Users\admin\AppData\Local\Temp\Rar$EXa6024.34664\BitTorrent\BitTorrent.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa6024.34664\BitTorrent\BitTorrent.exe
WinRAR.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
MEDIUM
Description:
BitTorrent
Version:
7.10.4.44847
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6024.34664\bittorrent\bittorrent.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
Total events
10 196
Read events
10 143
Write events
53
Delete events
0

Modification events

(PID) Process:(6024) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(6024) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\BitTorrent.zip
(PID) Process:(6024) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6024) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6024) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6024) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6892) BitTorrent.exeKey:HKEY_CLASSES_ROOT\FalconBetaAccount
Operation:writeName:remote_access_client_id
Value:
3387214235
(PID) Process:(6892) BitTorrent.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:BitTorrent
Value:
"C:\Users\admin\AppData\Local\Temp\Rar$EXa6024.34664\BitTorrent\BitTorrent.exe" /MINIMIZED
(PID) Process:(6892) BitTorrent.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SCRIPTURL_MITIGATION
Operation:writeName:bittorrentie.exe
Value:
1
(PID) Process:(6892) BitTorrent.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_CROSS_DOMAIN_REDIRECT_MITIGATION
Operation:writeName:bittorrentie.exe
Value:
0
Executable files
6
Suspicious files
25
Text files
12
Unknown types
0

Dropped files

PID
Process
Filename
Type
6024WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6024.34664\BitTorrent\apps\72F0D3E2141065DACF6134D07A06A2DF20590748\index.jstext
MD5:E88F72FA422391F3B6AF1E39F0573AEB
SHA256:95849DF126C8E7528611B7A6112E1649D7AEB5EC0F0DFF0EE805C93778BC9B9D
6024WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6024.34664\BitTorrent\apps\72F0D3E2141065DACF6134D07A06A2DF20590748\main.csstext
MD5:5576D6B99675F1B041C5A8D3E94D9B7C
SHA256:08936A0B3D1E9C9C9C560C1962642C966B5844CBF089A1AF08D9CD357FCB867F
6024WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6024.34664\BitTorrent\apps\72F0D3E2141065DACF6134D07A06A2DF20590748\index.htmlhtml
MD5:E3FB701BBBC2D73011F0A1D811A73F27
SHA256:5BA6A42877193044F7F501B15A240DDF90025A892E5F0380EDC7629DDDEE0C0A
6024WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6024.34664\BitTorrent\apps\72F0D3E2141065DACF6134D07A06A2DF20590748\btapptext
MD5:0AC39D67E3569074A86EDF6938219759
SHA256:259687AC76A6E5BDD09D671657BE55885DFD4B90D2B0926B329E9E984BECE80E
6024WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6024.34664\BitTorrent\$I30binary
MD5:C38F406D4266F718F69B4B6E52D5DA82
SHA256:9D4FD4F131E98269F3AB9F7FDFE9A365A4B5EAF100C7B43371C80E1A059FD903
6024WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6024.34664\BitTorrent\apps\player.btappcompressed
MD5:AD7F4A848B1A9463468543F8F667832A
SHA256:0EBA42AF0FEDCE7AAF9DD95E2748449764A825CA871C5CE422AD3091BD29CE9B
6024WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6024.34664\BitTorrent\apps\72F0D3E2141065DACF6134D07A06A2DF20590748\$I30binary
MD5:B98E897B331FC90EBA49F794617C92A8
SHA256:453AB5BDD09048AAD3D97AEEEE89F821B4E904284C1F5CDE4F3796B00E9B8D48
6024WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6024.34664\BitTorrent\dht.datbinary
MD5:D48C42DD9BE3D866AE5D06C1B082D5E1
SHA256:7B14D502F50781C4EEB595D6E6210F41692DDEE60C589D2A42E63C3CB5240C5B
6024WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6024.34664\BitTorrent\BitTorrent.exeexecutable
MD5:72EA6DAAF08109331F53DAC82B8C980F
SHA256:CCC4A5825C6DF992EC6676857316E46C7A74C514EABEE341D1471DA3EBA49BE9
6024WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6024.34664\BitTorrent\apps\72F0D3E2141065DACF6134D07A06A2DF20590748\icon.bmpimage
MD5:7399A0F1DCC4CA5BA628F0CE211ED809
SHA256:9969899F7B8B189362EDD8985D7465E7D290A5EECF995E382983368D0B46D66C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
41
TCP/UDP connections
99
DNS requests
55
Threats
10

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6944
svchost.exe
GET
200
23.32.238.107:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6944
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6892
BitTorrent.exe
GET
41.63.96.2:80
http://apps.bittorrent.com/utorrent-onboarding/player.btapp?h=hisZQuVrj1k5nIxX&v=256487215&ol=en&ul=&tk=stable34&c=BitTorrent
unknown
whitelisted
GET
200
41.63.96.130:80
http://cdn.ap.bittorrent.com/control/tags/bt.json
unknown
shared
6892
BitTorrent.exe
GET
200
41.63.96.130:80
http://cdn.ap.bittorrent.com/control/feature/tags/bt.json
unknown
shared
6892
BitTorrent.exe
POST
200
34.233.38.200:80
http://i-27.b-44847.bt.bench.utorrent.com/e?i=27
unknown
whitelisted
6892
BitTorrent.exe
POST
200
34.233.38.200:80
http://i-27.b-44847.bt.bench.utorrent.com/e?i=27
unknown
whitelisted
6892
BitTorrent.exe
POST
200
3.218.105.250:80
http://i-21.b-44847.bt.bench.utorrent.com/e?i=21
unknown
whitelisted
6892
BitTorrent.exe
POST
200
44.195.252.69:80
http://i-29.b-44847.bt.bench.utorrent.com/e?i=29
unknown
whitelisted
6892
BitTorrent.exe
POST
200
52.7.198.75:80
http://i-32.b-44847.bt.bench.utorrent.com/e?i=32
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6944
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5488
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1588
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
6944
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6944
svchost.exe
23.32.238.107:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
6944
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
6892
BitTorrent.exe
67.215.246.10:6881
router.bittorrent.com
whitelisted
6892
BitTorrent.exe
3.218.105.250:80
i-21.b-44847.bt.bench.utorrent.com
AMAZON-AES
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
whitelisted
google.com
  • 216.58.206.46
whitelisted
crl.microsoft.com
  • 23.32.238.107
  • 23.32.238.112
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
router.bittorrent.com
  • 67.215.246.10
whitelisted
router.utorrent.com
  • 82.221.103.244
whitelisted
i-21.b-44847.bt.bench.utorrent.com
  • 3.218.105.250
  • 52.71.189.0
  • 52.73.44.126
  • 34.192.204.133
  • 3.212.242.171
  • 52.4.124.242
  • 18.235.236.81
  • 34.233.38.200
whitelisted
apps.bittorrent.com
  • 41.63.96.2
whitelisted
cdn.ap.bittorrent.com
  • 41.63.96.2
  • 41.63.96.130
shared
update.bittorrent.com
  • 173.254.195.58
whitelisted

Threats

PID
Process
Class
Message
6892
BitTorrent.exe
Potential Corporate Privacy Violation
ET P2P BTWebClient UA uTorrent in use
6892
BitTorrent.exe
Potential Corporate Privacy Violation
ET P2P BTWebClient UA uTorrent in use
6892
BitTorrent.exe
Potential Corporate Privacy Violation
ET P2P BitTorrent DHT ping request
6892
BitTorrent.exe
Potential Corporate Privacy Violation
ET P2P BTWebClient UA uTorrent in use
6892
BitTorrent.exe
Potential Corporate Privacy Violation
ET P2P BTWebClient UA uTorrent in use
6892
BitTorrent.exe
Potential Corporate Privacy Violation
ET P2P BTWebClient UA uTorrent in use
6892
BitTorrent.exe
Potential Corporate Privacy Violation
ET P2P BTWebClient UA uTorrent in use
6892
BitTorrent.exe
Potential Corporate Privacy Violation
ET P2P BTWebClient UA uTorrent in use
6892
BitTorrent.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
6892
BitTorrent.exe
Potential Corporate Privacy Violation
ET P2P BTWebClient UA uTorrent in use
No debug info