File name:

utorrent_2.2.1.exe

Full analysis: https://app.any.run/tasks/29422b16-0195-4636-b8e7-95cbe944405d
Verdict: Malicious activity
Analysis date: February 22, 2024, 16:37:16
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

6DBC20E7530C2EFFBEDB828645A9638F

SHA1:

B72377B175BAB8F36D44409585706894DF7030B5

SHA256:

740F943D3843BB352E52B2D3EFDD3C17CC1D44C9571BDF09136D6A1CB3B7BC3D

SSDEEP:

98304:wrONTVP+Lz4DrUqHciAd+Ot1kDEa5fvXb1/rohj5kjvWbxRX/jdAl7lm5KHLoaFV:9hTg/iI+LcgLJrAtu2Fcx

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • utorrent_2.2.1.exe (PID: 3672)
      • utorrent_2.2.1.exe (PID: 2848)
      • utorrent_2.2.1.tmp (PID: 2840)
      • update.exe (PID: 2756)
      • helper.exe (PID: 796)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • utorrent_2.2.1.exe (PID: 3672)
      • utorrent_2.2.1.exe (PID: 2848)
      • utorrent_2.2.1.tmp (PID: 2840)
      • update.exe (PID: 2756)
      • helper.exe (PID: 796)
    • Reads the Windows owner or organization settings

      • utorrent_2.2.1.tmp (PID: 2840)
      • update.exe (PID: 2756)
    • Reads the Internet Settings

      • update.exe (PID: 3500)
      • utorrent_2.2.1.exe (PID: 3948)
      • update.exe (PID: 2756)
    • Application launched itself

      • update.exe (PID: 3944)
      • update.exe (PID: 3500)
    • Reads security settings of Internet Explorer

      • utorrent_2.2.1.exe (PID: 3948)
    • Checks for Java to be installed

      • update.exe (PID: 2756)
    • Reads the date of Windows installation

      • update.exe (PID: 2756)
    • Process requests binary or script from the Internet

      • utorrent_2.2.1.exe (PID: 3948)
    • The process creates files with name similar to system file names

      • helper.exe (PID: 796)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • helper.exe (PID: 796)
  • INFO

    • Create files in a temporary directory

      • utorrent_2.2.1.exe (PID: 3672)
      • utorrent_2.2.1.exe (PID: 2848)
      • utorrent_2.2.1.tmp (PID: 2840)
      • update.exe (PID: 2756)
      • utorrent_2.2.1.exe (PID: 3948)
      • helper.exe (PID: 796)
    • Checks supported languages

      • utorrent_2.2.1.exe (PID: 3672)
      • utorrent_2.2.1.tmp (PID: 3700)
      • utorrent_2.2.1.exe (PID: 2848)
      • utorrent_2.2.1.tmp (PID: 2840)
      • update.exe (PID: 3944)
      • utorrent_2.2.1.exe (PID: 3948)
      • update.exe (PID: 2756)
      • update.exe (PID: 3500)
      • helper.exe (PID: 796)
    • Reads the computer name

      • utorrent_2.2.1.tmp (PID: 3700)
      • utorrent_2.2.1.tmp (PID: 2840)
      • utorrent_2.2.1.exe (PID: 3948)
      • update.exe (PID: 3944)
      • update.exe (PID: 2756)
      • update.exe (PID: 3500)
      • helper.exe (PID: 796)
    • Reads the machine GUID from the registry

      • utorrent_2.2.1.exe (PID: 3948)
      • update.exe (PID: 3500)
      • update.exe (PID: 2756)
    • Creates files or folders in the user directory

      • update.exe (PID: 3944)
      • utorrent_2.2.1.tmp (PID: 2840)
      • update.exe (PID: 2756)
      • utorrent_2.2.1.exe (PID: 3948)
      • update.exe (PID: 3500)
    • Creates files in the program directory

      • utorrent_2.2.1.tmp (PID: 2840)
      • update.exe (PID: 3944)
    • Creates a software uninstall entry

      • utorrent_2.2.1.tmp (PID: 2840)
    • Checks proxy server information

      • utorrent_2.2.1.exe (PID: 3948)
    • Reads Environment values

      • update.exe (PID: 2756)
    • Reads Windows Product ID

      • update.exe (PID: 2756)
    • Reads product name

      • update.exe (PID: 2756)
    • Process checks whether UAC notifications are on

      • update.exe (PID: 2756)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (77.7)
.exe | Win32 Executable Delphi generic (10)
.dll | Win32 Dynamic Link Library (generic) (4.6)
.exe | Win32 Executable (generic) (3.1)
.exe | Win16/32 Executable Delphi generic (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 41472
InitializedDataSize: 17920
UninitializedDataSize: -
EntryPoint: 0xaa98
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Setup Setup
FileVersion:
LegalCopyright:
ProductName: Setup
ProductVersion:
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
9
Malicious processes
6
Suspicious processes
3

Behavior graph

Click at the process to see the details
start utorrent_2.2.1.exe utorrent_2.2.1.tmp no specs utorrent_2.2.1.exe utorrent_2.2.1.tmp update.exe no specs utorrent_2.2.1.exe update.exe no specs update.exe helper.exe

Process information

PID
CMD
Path
Indicators
Parent process
796"C:\Program Files\Common Files\AddTek\uninstall\helper.exe" /SetAsDefaultAppUserC:\Program Files\Common Files\AddTek\uninstall\helper.exe
update.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
HIGH
Description:
Firefox Helper
Exit code:
2
Version:
3.6.3
Modules
Images
c:\program files\common files\addtek\uninstall\helper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2756"C:\Program Files\Common Files\AddTek\update.exe" about:robotsC:\Program Files\Common Files\AddTek\update.exe
update.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
HIGH
Description:
Firefox
Exit code:
0
Version:
1.9.2.3
Modules
Images
c:\program files\common files\addtek\update.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\common files\addtek\xul.dll
c:\program files\common files\addtek\sqlite3.dll
c:\program files\common files\addtek\mozcrt19.dll
c:\windows\system32\msvcrt.dll
c:\program files\common files\addtek\js3250.dll
c:\program files\common files\addtek\nspr4.dll
2840"C:\Users\admin\AppData\Local\Temp\is-D9GO7.tmp\utorrent_2.2.1.tmp" /SL5="$19013E,11959346,57856,C:\Users\admin\AppData\Local\Temp\utorrent_2.2.1.exe" /SPAWNWND=$1A01BC /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\is-D9GO7.tmp\utorrent_2.2.1.tmp
utorrent_2.2.1.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-d9go7.tmp\utorrent_2.2.1.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2848"C:\Users\admin\AppData\Local\Temp\utorrent_2.2.1.exe" /SPAWNWND=$1A01BC /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\utorrent_2.2.1.exe
utorrent_2.2.1.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
Setup Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\utorrent_2.2.1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3500"C:\Program Files\Common Files\AddTek\update.exe" about:robotsC:\Program Files\Common Files\AddTek\update.exeupdate.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
HIGH
Description:
Firefox
Exit code:
0
Version:
1.9.2.3
Modules
Images
c:\program files\common files\addtek\update.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\common files\addtek\xul.dll
c:\program files\common files\addtek\sqlite3.dll
c:\program files\common files\addtek\mozcrt19.dll
c:\windows\system32\msvcrt.dll
c:\program files\common files\addtek\js3250.dll
c:\program files\common files\addtek\nspr4.dll
3672"C:\Users\admin\AppData\Local\Temp\utorrent_2.2.1.exe" C:\Users\admin\AppData\Local\Temp\utorrent_2.2.1.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\utorrent_2.2.1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3700"C:\Users\admin\AppData\Local\Temp\is-4PO61.tmp\utorrent_2.2.1.tmp" /SL5="$E0170,11959346,57856,C:\Users\admin\AppData\Local\Temp\utorrent_2.2.1.exe" C:\Users\admin\AppData\Local\Temp\is-4PO61.tmp\utorrent_2.2.1.tmputorrent_2.2.1.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-4po61.tmp\utorrent_2.2.1.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3944"C:\Program Files\Common Files\AddTek\update.exe" about:robotsC:\Program Files\Common Files\AddTek\update.exeutorrent_2.2.1.tmp
User:
admin
Company:
Mozilla Corporation
Integrity Level:
HIGH
Description:
Firefox
Exit code:
0
Version:
1.9.2.3
Modules
Images
c:\program files\common files\addtek\update.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\common files\addtek\xul.dll
c:\program files\common files\addtek\sqlite3.dll
c:\program files\common files\addtek\mozcrt19.dll
c:\windows\system32\msvcrt.dll
c:\program files\common files\addtek\js3250.dll
c:\program files\common files\addtek\nspr4.dll
3948"C:\Users\admin\AppData\Roaming\utorrent_2.2.1.exe"C:\Users\admin\AppData\Roaming\utorrent_2.2.1.exe
utorrent_2.2.1.tmp
User:
admin
Company:
BitTorrent, Inc.
Integrity Level:
HIGH
Description:
µTorrent
Exit code:
0
Version:
2.2.1.25110
Modules
Images
c:\users\admin\appdata\roaming\utorrent_2.2.1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
Total events
5 311
Read events
5 220
Write events
66
Delete events
25

Modification events

(PID) Process:(2840) utorrent_2.2.1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
180B00001E1AD26FAD65DA01
(PID) Process:(2840) utorrent_2.2.1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
A1D83C9D6B7CD07B2C18DE82D7EEF4B8E3E7E6064E33C5098AB20FC31A8ECBFA
(PID) Process:(2840) utorrent_2.2.1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(2840) utorrent_2.2.1.tmpKey:HKEY_CURRENT_USER\Software\DownloadHelper
Operation:writeName:Cro5Scn
Value:
WFB7WU3EWJTWNWI5ELBX
(PID) Process:(2840) utorrent_2.2.1.tmpKey:HKEY_CURRENT_USER\Software\DownloadHelper\ConvertHelper
Operation:writeName:EsIdfydtaP0
Value:
0a8eed90f3a8e8e0c53a2648e9:0
(PID) Process:(2840) utorrent_2.2.1.tmpKey:HKEY_CURRENT_USER\Software\DownloadHelper\ConvertHelper
Operation:writeName:SwpmVzPfzW1
Value:
1c94fbcaf7aee9eece603055e1970015d14b:0
(PID) Process:(2840) utorrent_2.2.1.tmpKey:HKEY_CURRENT_USER\Software\DownloadHelper\ConvertHelper
Operation:writeName:yqLBUfhTlb2
Value:
1090f6d8e1bee3f7da762009eadc1d:0
(PID) Process:(2840) utorrent_2.2.1.tmpKey:HKEY_CURRENT_USER\Software\DownloadHelper\ConvertHelper
Operation:writeName:HJoKwxAPcj3
Value:
188ff3d2f3b5fce6c33a2648e9:0
(PID) Process:(2840) utorrent_2.2.1.tmpKey:HKEY_CURRENT_USER\Software\DownloadHelper\ConvertHelper
Operation:writeName:XHEYmastDN4
Value:
1690f4d5bcb8f4ee:0
(PID) Process:(2840) utorrent_2.2.1.tmpKey:HKEY_CURRENT_USER\Software\DownloadHelper\ConvertHelper
Operation:writeName:brdnKRaUEv5
Value:
1c9effdaf0b2efe0c7713609e7d604:0
Executable files
57
Suspicious files
49
Text files
396
Unknown types
10

Dropped files

PID
Process
Filename
Type
2840utorrent_2.2.1.tmpC:\Users\admin\AppData\Local\Temp\is-RO53R.tmp\freebl3.dllexecutable
MD5:26B018758226A5DC06DE45496C394D40
SHA256:F1BC4EF7914E7E24104F987AD4BB0596900BD8F2C685270389D086DC39ADE68A
2840utorrent_2.2.1.tmpC:\Program Files\Common Files\AddTek\blocklist.xmlxml
MD5:096C36008D2CA63382176D0AEE04C78B
SHA256:EC165C899E97365CD7DECA4B56CC6F188398B4AC5352A30D046664B7B5E94FE1
2840utorrent_2.2.1.tmpC:\Program Files\Common Files\AddTek\AccessibleMarshal.dllexecutable
MD5:BEB10DE06617501F696E65942894C3D1
SHA256:D1D7D0E9EE80CB3CEAB554755DB8D1C0EBFDC980F1817E77CF787287A19CC0B1
2840utorrent_2.2.1.tmpC:\Users\admin\AppData\Local\Temp\is-RO53R.tmp\blocklist.xmlxml
MD5:096C36008D2CA63382176D0AEE04C78B
SHA256:EC165C899E97365CD7DECA4B56CC6F188398B4AC5352A30D046664B7B5E94FE1
2840utorrent_2.2.1.tmpC:\Program Files\Common Files\AddTek\browserconfig.propertiestext
MD5:30D93764AEB3C6B09E14886D2D27C9DD
SHA256:912561A9B4E573E00C698E5E6DC2173E5EE99DAA114D44B141C2537303E5876F
2840utorrent_2.2.1.tmpC:\Users\admin\AppData\Local\Temp\is-RO53R.tmp\crashreporter.exeexecutable
MD5:FD4942F6C32C8982177037142253FFBF
SHA256:280EBFEE47BF6533796691F2CED8D51D7DCC866E53FB6A6466FFFC53D0BF7405
2840utorrent_2.2.1.tmpC:\Users\admin\AppData\Local\Temp\is-RO53R.tmp\application.initext
MD5:9828130EFAA3D6CA46026B17F4C3E816
SHA256:31A2A25E4546FC6B0FC2015A0F902AA70CE2BAB54521AF652728087CB9224BFD
2840utorrent_2.2.1.tmpC:\Users\admin\AppData\Local\Temp\is-RO53R.tmp\browserconfig.propertiestext
MD5:30D93764AEB3C6B09E14886D2D27C9DD
SHA256:912561A9B4E573E00C698E5E6DC2173E5EE99DAA114D44B141C2537303E5876F
2840utorrent_2.2.1.tmpC:\Program Files\Common Files\AddTek\crashreporter-override.initext
MD5:28EBA36367C7F7FE951C7C8DD23B8F78
SHA256:92958F88855106C5ABB33A5256E0FAE2F59F9552BE15E12606628036A2FF4C9C
2840utorrent_2.2.1.tmpC:\Program Files\Common Files\AddTek\freebl3.chkbinary
MD5:7C6E18145B1B6720A9F177C27A04A87C
SHA256:7CA0F26D8BBC350C3EFBABCBBD7C5037B94AE7627FA259EA923D14F4A407EF2A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
14
DNS requests
11
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2756
update.exe
POST
200
142.250.184.195:80
http://ocsp.pki.goog/gts1c3
unknown
binary
472 b
unknown
2756
update.exe
POST
200
142.250.184.195:80
http://ocsp.pki.goog/gtsr1
unknown
binary
724 b
unknown
2756
update.exe
POST
200
142.250.184.195:80
http://ocsp.pki.goog/gsr1
unknown
binary
1.41 Kb
unknown
3948
utorrent_2.2.1.exe
GET
67.215.246.203:80
http://update.utorrent.com/installoffer.php?h=L2VaFY20jk6XQsmp&v=71524886&w=1DB10106&l=en&c=US&tb=0&bu=0&w64=0&db=msedge.exe%22&cl=uTorrent&au=0
unknown
unknown
2756
update.exe
GET
104.26.13.149:80
http://evilangel.com/
unknown
unknown
3948
utorrent_2.2.1.exe
GET
67.215.246.203:80
http://update.utorrent.com/installstats.php?v=71524886&h=L2VaFY20jk6XQsmp&hn=1&w=1DB10106&bu=0&pr=0&tbe=0
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3948
utorrent_2.2.1.exe
67.215.246.203:80
update.utorrent.com
ASN-QUADRANET-GLOBAL
US
unknown
2756
update.exe
142.250.186.174:443
sb-ssl.google.com
GOOGLE
US
whitelisted
2756
update.exe
142.250.184.195:80
ocsp.pki.goog
GOOGLE
US
whitelisted
2756
update.exe
172.67.71.41:80
evilangel.com
CLOUDFLARENET
US
unknown
2756
update.exe
104.26.13.149:80
evilangel.com
CLOUDFLARENET
US
unknown
3948
utorrent_2.2.1.exe
67.215.233.132:80
download.utorrent.com
ASN-QUADRANET-GLOBAL
US
unknown
2756
update.exe
3.141.96.53:80
fallenteenangels.com
AMAZON-02
US
unknown

DNS requests

Domain
IP
Reputation
update.utorrent.com
  • 67.215.246.203
whitelisted
sb-ssl.google.com
  • 142.250.186.174
whitelisted
ocsp.pki.goog
  • 142.250.184.195
whitelisted
fxfeeds.mozilla.com
unknown
evilangel.com
  • 172.67.71.41
  • 104.26.13.149
  • 104.26.12.149
whitelisted
download.utorrent.com
  • 67.215.233.132
unknown
fallenteenangels.com
  • 3.141.96.53
  • 3.20.137.44
malicious

Threats

PID
Process
Class
Message
3948
utorrent_2.2.1.exe
Potential Corporate Privacy Violation
ET P2P Bittorrent P2P Client User-Agent (uTorrent)
3948
utorrent_2.2.1.exe
Potential Corporate Privacy Violation
ET P2P Bittorrent P2P Client User-Agent (uTorrent)
No debug info