| File name: | utorrent_2.2.1.exe |
| Full analysis: | https://app.any.run/tasks/29422b16-0195-4636-b8e7-95cbe944405d |
| Verdict: | Malicious activity |
| Analysis date: | February 22, 2024, 16:37:16 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 6DBC20E7530C2EFFBEDB828645A9638F |
| SHA1: | B72377B175BAB8F36D44409585706894DF7030B5 |
| SHA256: | 740F943D3843BB352E52B2D3EFDD3C17CC1D44C9571BDF09136D6A1CB3B7BC3D |
| SSDEEP: | 98304:wrONTVP+Lz4DrUqHciAd+Ot1kDEa5fvXb1/rohj5kjvWbxRX/jdAl7lm5KHLoaFV:9hTg/iI+LcgLJrAtu2Fcx |
| .exe | | | Inno Setup installer (77.7) |
|---|---|---|
| .exe | | | Win32 Executable Delphi generic (10) |
| .dll | | | Win32 Dynamic Link Library (generic) (4.6) |
| .exe | | | Win32 Executable (generic) (3.1) |
| .exe | | | Win16/32 Executable Delphi generic (1.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1992:06:19 22:22:17+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 41472 |
| InitializedDataSize: | 17920 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xaa98 |
| OSVersion: | 1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 0.0.0.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | |
| FileDescription: | Setup Setup |
| FileVersion: | |
| LegalCopyright: | |
| ProductName: | Setup |
| ProductVersion: |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 796 | "C:\Program Files\Common Files\AddTek\uninstall\helper.exe" /SetAsDefaultAppUser | C:\Program Files\Common Files\AddTek\uninstall\helper.exe | update.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: HIGH Description: Firefox Helper Exit code: 2 Version: 3.6.3 Modules
| |||||||||||||||
| 2756 | "C:\Program Files\Common Files\AddTek\update.exe" about:robots | C:\Program Files\Common Files\AddTek\update.exe | update.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: HIGH Description: Firefox Exit code: 0 Version: 1.9.2.3 Modules
| |||||||||||||||
| 2840 | "C:\Users\admin\AppData\Local\Temp\is-D9GO7.tmp\utorrent_2.2.1.tmp" /SL5="$19013E,11959346,57856,C:\Users\admin\AppData\Local\Temp\utorrent_2.2.1.exe" /SPAWNWND=$1A01BC /NOTIFYWND=$E0170 | C:\Users\admin\AppData\Local\Temp\is-D9GO7.tmp\utorrent_2.2.1.tmp | utorrent_2.2.1.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| 2848 | "C:\Users\admin\AppData\Local\Temp\utorrent_2.2.1.exe" /SPAWNWND=$1A01BC /NOTIFYWND=$E0170 | C:\Users\admin\AppData\Local\Temp\utorrent_2.2.1.exe | utorrent_2.2.1.tmp | ||||||||||||
User: admin Company: Integrity Level: HIGH Description: Setup Setup Exit code: 0 Version: Modules
| |||||||||||||||
| 3500 | "C:\Program Files\Common Files\AddTek\update.exe" about:robots | C:\Program Files\Common Files\AddTek\update.exe | — | update.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: HIGH Description: Firefox Exit code: 0 Version: 1.9.2.3 Modules
| |||||||||||||||
| 3672 | "C:\Users\admin\AppData\Local\Temp\utorrent_2.2.1.exe" | C:\Users\admin\AppData\Local\Temp\utorrent_2.2.1.exe | explorer.exe | ||||||||||||
User: admin Company: Integrity Level: MEDIUM Description: Setup Setup Exit code: 0 Version: Modules
| |||||||||||||||
| 3700 | "C:\Users\admin\AppData\Local\Temp\is-4PO61.tmp\utorrent_2.2.1.tmp" /SL5="$E0170,11959346,57856,C:\Users\admin\AppData\Local\Temp\utorrent_2.2.1.exe" | C:\Users\admin\AppData\Local\Temp\is-4PO61.tmp\utorrent_2.2.1.tmp | — | utorrent_2.2.1.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| 3944 | "C:\Program Files\Common Files\AddTek\update.exe" about:robots | C:\Program Files\Common Files\AddTek\update.exe | — | utorrent_2.2.1.tmp | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: HIGH Description: Firefox Exit code: 0 Version: 1.9.2.3 Modules
| |||||||||||||||
| 3948 | "C:\Users\admin\AppData\Roaming\utorrent_2.2.1.exe" | C:\Users\admin\AppData\Roaming\utorrent_2.2.1.exe | utorrent_2.2.1.tmp | ||||||||||||
User: admin Company: BitTorrent, Inc. Integrity Level: HIGH Description: µTorrent Exit code: 0 Version: 2.2.1.25110 Modules
| |||||||||||||||
| (PID) Process: | (2840) utorrent_2.2.1.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: 180B00001E1AD26FAD65DA01 | |||
| (PID) Process: | (2840) utorrent_2.2.1.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: A1D83C9D6B7CD07B2C18DE82D7EEF4B8E3E7E6064E33C5098AB20FC31A8ECBFA | |||
| (PID) Process: | (2840) utorrent_2.2.1.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (2840) utorrent_2.2.1.tmp | Key: | HKEY_CURRENT_USER\Software\DownloadHelper |
| Operation: | write | Name: | Cro5Scn |
Value: WFB7WU3EWJTWNWI5ELBX | |||
| (PID) Process: | (2840) utorrent_2.2.1.tmp | Key: | HKEY_CURRENT_USER\Software\DownloadHelper\ConvertHelper |
| Operation: | write | Name: | EsIdfydtaP0 |
Value: 0a8eed90f3a8e8e0c53a2648e9:0 | |||
| (PID) Process: | (2840) utorrent_2.2.1.tmp | Key: | HKEY_CURRENT_USER\Software\DownloadHelper\ConvertHelper |
| Operation: | write | Name: | SwpmVzPfzW1 |
Value: 1c94fbcaf7aee9eece603055e1970015d14b:0 | |||
| (PID) Process: | (2840) utorrent_2.2.1.tmp | Key: | HKEY_CURRENT_USER\Software\DownloadHelper\ConvertHelper |
| Operation: | write | Name: | yqLBUfhTlb2 |
Value: 1090f6d8e1bee3f7da762009eadc1d:0 | |||
| (PID) Process: | (2840) utorrent_2.2.1.tmp | Key: | HKEY_CURRENT_USER\Software\DownloadHelper\ConvertHelper |
| Operation: | write | Name: | HJoKwxAPcj3 |
Value: 188ff3d2f3b5fce6c33a2648e9:0 | |||
| (PID) Process: | (2840) utorrent_2.2.1.tmp | Key: | HKEY_CURRENT_USER\Software\DownloadHelper\ConvertHelper |
| Operation: | write | Name: | XHEYmastDN4 |
Value: 1690f4d5bcb8f4ee:0 | |||
| (PID) Process: | (2840) utorrent_2.2.1.tmp | Key: | HKEY_CURRENT_USER\Software\DownloadHelper\ConvertHelper |
| Operation: | write | Name: | brdnKRaUEv5 |
Value: 1c9effdaf0b2efe0c7713609e7d604:0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2840 | utorrent_2.2.1.tmp | C:\Users\admin\AppData\Local\Temp\is-RO53R.tmp\freebl3.dll | executable | |
MD5:26B018758226A5DC06DE45496C394D40 | SHA256:F1BC4EF7914E7E24104F987AD4BB0596900BD8F2C685270389D086DC39ADE68A | |||
| 2840 | utorrent_2.2.1.tmp | C:\Program Files\Common Files\AddTek\blocklist.xml | xml | |
MD5:096C36008D2CA63382176D0AEE04C78B | SHA256:EC165C899E97365CD7DECA4B56CC6F188398B4AC5352A30D046664B7B5E94FE1 | |||
| 2840 | utorrent_2.2.1.tmp | C:\Program Files\Common Files\AddTek\AccessibleMarshal.dll | executable | |
MD5:BEB10DE06617501F696E65942894C3D1 | SHA256:D1D7D0E9EE80CB3CEAB554755DB8D1C0EBFDC980F1817E77CF787287A19CC0B1 | |||
| 2840 | utorrent_2.2.1.tmp | C:\Users\admin\AppData\Local\Temp\is-RO53R.tmp\blocklist.xml | xml | |
MD5:096C36008D2CA63382176D0AEE04C78B | SHA256:EC165C899E97365CD7DECA4B56CC6F188398B4AC5352A30D046664B7B5E94FE1 | |||
| 2840 | utorrent_2.2.1.tmp | C:\Program Files\Common Files\AddTek\browserconfig.properties | text | |
MD5:30D93764AEB3C6B09E14886D2D27C9DD | SHA256:912561A9B4E573E00C698E5E6DC2173E5EE99DAA114D44B141C2537303E5876F | |||
| 2840 | utorrent_2.2.1.tmp | C:\Users\admin\AppData\Local\Temp\is-RO53R.tmp\crashreporter.exe | executable | |
MD5:FD4942F6C32C8982177037142253FFBF | SHA256:280EBFEE47BF6533796691F2CED8D51D7DCC866E53FB6A6466FFFC53D0BF7405 | |||
| 2840 | utorrent_2.2.1.tmp | C:\Users\admin\AppData\Local\Temp\is-RO53R.tmp\application.ini | text | |
MD5:9828130EFAA3D6CA46026B17F4C3E816 | SHA256:31A2A25E4546FC6B0FC2015A0F902AA70CE2BAB54521AF652728087CB9224BFD | |||
| 2840 | utorrent_2.2.1.tmp | C:\Users\admin\AppData\Local\Temp\is-RO53R.tmp\browserconfig.properties | text | |
MD5:30D93764AEB3C6B09E14886D2D27C9DD | SHA256:912561A9B4E573E00C698E5E6DC2173E5EE99DAA114D44B141C2537303E5876F | |||
| 2840 | utorrent_2.2.1.tmp | C:\Program Files\Common Files\AddTek\crashreporter-override.ini | text | |
MD5:28EBA36367C7F7FE951C7C8DD23B8F78 | SHA256:92958F88855106C5ABB33A5256E0FAE2F59F9552BE15E12606628036A2FF4C9C | |||
| 2840 | utorrent_2.2.1.tmp | C:\Program Files\Common Files\AddTek\freebl3.chk | binary | |
MD5:7C6E18145B1B6720A9F177C27A04A87C | SHA256:7CA0F26D8BBC350C3EFBABCBBD7C5037B94AE7627FA259EA923D14F4A407EF2A | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2756 | update.exe | POST | 200 | 142.250.184.195:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 472 b | unknown |
2756 | update.exe | POST | 200 | 142.250.184.195:80 | http://ocsp.pki.goog/gtsr1 | unknown | binary | 724 b | unknown |
2756 | update.exe | POST | 200 | 142.250.184.195:80 | http://ocsp.pki.goog/gsr1 | unknown | binary | 1.41 Kb | unknown |
3948 | utorrent_2.2.1.exe | GET | — | 67.215.246.203:80 | http://update.utorrent.com/installoffer.php?h=L2VaFY20jk6XQsmp&v=71524886&w=1DB10106&l=en&c=US&tb=0&bu=0&w64=0&db=msedge.exe%22&cl=uTorrent&au=0 | unknown | — | — | unknown |
2756 | update.exe | GET | — | 104.26.13.149:80 | http://evilangel.com/ | unknown | — | — | unknown |
3948 | utorrent_2.2.1.exe | GET | — | 67.215.246.203:80 | http://update.utorrent.com/installstats.php?v=71524886&h=L2VaFY20jk6XQsmp&hn=1&w=1DB10106&bu=0&pr=0&tbe=0 | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3948 | utorrent_2.2.1.exe | 67.215.246.203:80 | update.utorrent.com | ASN-QUADRANET-GLOBAL | US | unknown |
2756 | update.exe | 142.250.186.174:443 | sb-ssl.google.com | GOOGLE | US | whitelisted |
2756 | update.exe | 142.250.184.195:80 | ocsp.pki.goog | GOOGLE | US | whitelisted |
2756 | update.exe | 172.67.71.41:80 | evilangel.com | CLOUDFLARENET | US | unknown |
2756 | update.exe | 104.26.13.149:80 | evilangel.com | CLOUDFLARENET | US | unknown |
3948 | utorrent_2.2.1.exe | 67.215.233.132:80 | download.utorrent.com | ASN-QUADRANET-GLOBAL | US | unknown |
2756 | update.exe | 3.141.96.53:80 | fallenteenangels.com | AMAZON-02 | US | unknown |
Domain | IP | Reputation |
|---|---|---|
update.utorrent.com |
| whitelisted |
sb-ssl.google.com |
| whitelisted |
ocsp.pki.goog |
| whitelisted |
fxfeeds.mozilla.com |
| unknown |
evilangel.com |
| whitelisted |
download.utorrent.com |
| unknown |
fallenteenangels.com |
| malicious |
PID | Process | Class | Message |
|---|---|---|---|
3948 | utorrent_2.2.1.exe | Potential Corporate Privacy Violation | ET P2P Bittorrent P2P Client User-Agent (uTorrent) |
3948 | utorrent_2.2.1.exe | Potential Corporate Privacy Violation | ET P2P Bittorrent P2P Client User-Agent (uTorrent) |