File name:

Redline stealer 2022 Crack.zip

Full analysis: https://app.any.run/tasks/ff52c2f8-e76f-4961-9478-2a0ea839ea0d
Verdict: Malicious activity
Threats:

AsyncRAT is a RAT that can monitor and remotely control infected systems. This malware was introduced on Github as a legitimate open-source remote administration software, but hackers use it for its many powerful malicious functions.

Analysis date: November 23, 2023, 13:07:05
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
redline
rat
asyncrat
remote
xworm
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

9F2B4AFA22391D606B3577CB8DFAC6FE

SHA1:

51F3E0D2CF684B8246F500534929706D61B6B842

SHA256:

91FDDF7CDF9462984D929296EB1F0ADD771532117E921EF85272FC12BC796C9E

SSDEEP:

98304:w+T6a7NCbD+Zr3of0LNhXvJIXrAFqHnpsezuW33p4dfx+MkuVV84mzmP76Yf2nZz:QqHRRvkP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • REDLINE has been detected (YARA)

      • RedLine.MainPanel-cracked.exe (PID: 3504)
    • Drops the executable file immediately after the start

      • builder.exe (PID: 3952)
      • Build.exe (PID: 3788)
    • Bypass execution policy to execute commands

      • powershell.exe (PID: 756)
      • powershell.exe (PID: 608)
      • powershell.exe (PID: 1344)
    • Adds path to the Windows Defender exclusion list

      • Build.exe (PID: 3788)
    • Changes powershell execution policy (Bypass)

      • Build.exe (PID: 3788)
    • ASYNCRAT has been detected (SURICATA)

      • svchost.exe (PID: 1356)
    • Create files in the Startup directory

      • cfmon.exe (PID: 2028)
    • Connects to the CnC server

      • cfmon.exe (PID: 2028)
    • XWORM has been detected (SURICATA)

      • cfmon.exe (PID: 2028)
  • SUSPICIOUS

    • Reads the Internet Settings

      • RedLine.MainPanel-cracked.exe (PID: 3504)
      • builder.exe (PID: 3952)
      • Build.exe (PID: 3788)
      • svchost.exe (PID: 1356)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • cmd.exe (PID: 3500)
    • Executing commands from a ".bat" file

      • WinRAR.exe (PID: 3440)
    • Starts CMD.EXE for commands execution

      • WinRAR.exe (PID: 3440)
    • Process uses IPCONFIG to get network configuration information

      • cmd.exe (PID: 3832)
    • Powershell version downgrade attack

      • powershell.exe (PID: 756)
      • powershell.exe (PID: 1344)
      • powershell.exe (PID: 608)
    • Script adds exclusion path to Windows Defender

      • Build.exe (PID: 3788)
    • Starts POWERSHELL.EXE for commands execution

      • Build.exe (PID: 3788)
    • Reads settings of System Certificates

      • svchost.exe (PID: 1356)
    • The process creates files with name similar to system file names

      • Build.exe (PID: 3788)
    • Connects to unusual port

      • cfmon.exe (PID: 2028)
      • svchost.exe (PID: 1356)
  • INFO

    • Checks supported languages

      • RedLine.MainPanel-cracked.exe (PID: 3504)
      • builder.exe (PID: 3952)
      • Build.exe (PID: 3788)
      • utorrent.exe (PID: 1852)
      • Loader.exe (PID: 3236)
      • cfmon.exe (PID: 2028)
      • svchost.exe (PID: 1356)
      • wmpnscfg.exe (PID: 368)
      • wmpnscfg.exe (PID: 3200)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3440)
    • Reads the machine GUID from the registry

      • RedLine.MainPanel-cracked.exe (PID: 3504)
      • builder.exe (PID: 3952)
      • Build.exe (PID: 3788)
      • utorrent.exe (PID: 1852)
      • cfmon.exe (PID: 2028)
      • svchost.exe (PID: 1356)
      • wmpnscfg.exe (PID: 368)
      • wmpnscfg.exe (PID: 3200)
    • Reads the computer name

      • RedLine.MainPanel-cracked.exe (PID: 3504)
      • builder.exe (PID: 3952)
      • Build.exe (PID: 3788)
      • utorrent.exe (PID: 1852)
      • svchost.exe (PID: 1356)
      • cfmon.exe (PID: 2028)
      • wmpnscfg.exe (PID: 368)
      • wmpnscfg.exe (PID: 3200)
    • Reads Environment values

      • RedLine.MainPanel-cracked.exe (PID: 3504)
      • utorrent.exe (PID: 1852)
      • svchost.exe (PID: 1356)
    • Manual execution by a user

      • cmd.exe (PID: 3832)
      • Build.exe (PID: 3788)
      • wmpnscfg.exe (PID: 368)
      • wmpnscfg.exe (PID: 3200)
      • msconfig.exe (PID: 3468)
      • msconfig.exe (PID: 304)
    • Create files in a temporary directory

      • builder.exe (PID: 3952)
      • Build.exe (PID: 3788)
      • svchost.exe (PID: 1356)
      • cfmon.exe (PID: 2028)
    • Creates files or folders in the user directory

      • utorrent.exe (PID: 1852)
      • cfmon.exe (PID: 2028)
    • Checks proxy server information

      • RedLine.MainPanel-cracked.exe (PID: 3504)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2023:09:12 20:59:58
ZipCRC: 0x4e87ef64
ZipCompressedSize: 90
ZipUncompressedSize: 107
ZipFileName: Redline stealer 2022 Crack/gbpast - Login.url
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
75
Monitored processes
19
Malicious processes
8
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe no specs #REDLINE redline.mainpanel-cracked.exe no specs cmd.exe no specs netsh.exe no specs cmd.exe no specs ipconfig.exe no specs builder.exe no specs build.exe no specs loader.exe no specs powershell.exe no specs powershell.exe no specs utorrent.exe #ASYNCRAT svchost.exe powershell.exe no specs #XWORM cfmon.exe wmpnscfg.exe no specs wmpnscfg.exe no specs msconfig.exe no specs msconfig.exe

Process information

PID
CMD
Path
Indicators
Parent process
304"C:\Windows\system32\msconfig.exe" C:\Windows\System32\msconfig.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
System Configuration Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
368"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
608"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass Add-MpPreference -ExclusionPath 'C:\Users\admin\AppData\Local\Temp\svchost.exe'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeBuild.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
756"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass Add-MpPreference -ExclusionPath 'C:\Users\admin\AppData\Local\Temp\utorrent.exe'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeBuild.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
1344"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass Add-MpPreference -ExclusionPath 'C:\Users\admin\AppData\Local\Temp\cfmon.exe'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeBuild.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
1356"C:\Users\admin\AppData\Local\Temp\svchost.exe" C:\Users\admin\AppData\Local\Temp\svchost.exe
Build.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
3.6.0.0
Modules
Images
c:\users\admin\appdata\local\temp\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1852"C:\Users\admin\AppData\Local\Temp\utorrent.exe" C:\Users\admin\AppData\Local\Temp\utorrent.exe
Build.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
2148734499
Version:
6.0.1
Modules
Images
c:\users\admin\appdata\local\temp\utorrent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2028"C:\Users\admin\AppData\Local\Temp\cfmon.exe" C:\Users\admin\AppData\Local\Temp\cfmon.exe
Build.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\cfmon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3200"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
3236"C:\Users\admin\Desktop\Loader.exe" C:\Users\admin\Desktop\Loader.exeBuild.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\loader.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
Total events
18 293
Read events
17 943
Write events
340
Delete events
10

Modification events

(PID) Process:(3440) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
21
Suspicious files
25
Text files
9
Unknown types
0

Dropped files

PID
Process
Filename
Type
3440WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3440.32452\Redline stealer 2022 Crack\Libraries\builder.exeexecutable
MD5:DE6F68CDF350FCE9BE13803D84BE98C4
SHA256:51BBC69942823B84C2A1F0EFDB9D63FB04612B223E86AF8A83B4B307DD15CD24
3440WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3440.32452\Redline stealer 2022 Crack\Home - cybergoons.urlbinary
MD5:EF51820E228C5BBCF9AABE92E747782E
SHA256:59AC2D12EA4559253FA25F2D367F75B7689BB7B772965101903063F646AE9B4D
3440WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3440.32452\Redline stealer 2022 Crack\Home - blankhack.urlbinary
MD5:4A4418C24D2F2A9DEEE8046363BDD28F
SHA256:55DFE247F8FD6A8B0B66B3CB61FEEAE96D0B357338CD95771E89897AAC1A6839
3440WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3440.32452\Redline stealer 2022 Crack\learn all kind of hacking.urlbinary
MD5:7ADE4A739CBD8F44D0EF52A2F1BC6E7B
SHA256:CC7649ED53C65E4851ACE414529564FE16801BB2BED4CB15588BFD6B4AC13616
3440WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3440.32452\Redline stealer 2022 Crack\gbpast - Login.urlbinary
MD5:4A4F5BE9370E206241BB73BFC2367F3C
SHA256:210F2EE620FE51ACDBE59BBA7BB4ACBDE397034818B09156F6F0874B016A5B18
3440WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3440.32452\Redline stealer 2022 Crack\Libraries\builder.pdbbinary
MD5:418DC008EF956465E179EC29D3C3C245
SHA256:8C7E21B37540211D56C5FDBB7E731655A96945AA83F2988E33D5ADB8AA7C8DF1
3440WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3440.32452\Redline stealer 2022 Crack\Libraries\Bunifu_UI_v1.52.dllexecutable
MD5:5ECA94D909F1BA4C5F3E35AC65A49076
SHA256:DE0E530D46C803D85B8AEB6D18816F1B09CB3DAFEFB5E19FDFA15C9F41E0F474
3440WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3440.32452\Redline stealer 2022 Crack\Libraries\GuiLib.dllexecutable
MD5:EAF9C55793CD26F133708714ED3A5397
SHA256:87CFC70BEC2D2A37BCD5D46F9E6F0051F82E015FF96E8F2BC2D81B85F2632F15
3440WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3440.32452\Redline stealer 2022 Crack\Libraries\Loader.exeexecutable
MD5:CFF63E16C0F61DA3CF1329EBCF462773
SHA256:E3BD0202BA4C688CA4C5917BC6892808089246968FACF6FF8AF52028FB0FFF6E
3440WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3440.32452\Redline stealer 2022 Crack\Libraries\MetroSet UI.dllbinary
MD5:F13DC3CFFEF729D26C4DA102674561CF
SHA256:D490C04E6E89462FD46099D3454985F319F57032176C67403B3B92C86CA58BCB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
18
DNS requests
4
Threats
55

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
828
svchost.exe
OPTIONS
185.235.129.102:80
http://blankhack.com/
NL
unknown
828
svchost.exe
PROPFIND
200
185.235.129.102:80
http://blankhack.com/
NL
html
35.5 Kb
unknown
828
svchost.exe
PROPFIND
200
185.235.129.102:80
http://blankhack.com/
NL
html
35.5 Kb
unknown
828
svchost.exe
PROPFIND
185.235.129.102:80
http://blankhack.com/
NL
unknown
828
svchost.exe
PROPFIND
200
185.235.129.102:80
http://blankhack.com/
NL
html
35.5 Kb
unknown
828
svchost.exe
PROPFIND
185.235.129.102:80
http://blankhack.com/
NL
unknown
1356
svchost.exe
GET
200
23.53.40.73:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?d0ed9152b953db0d
DE
compressed
61.6 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1356
svchost.exe
206.123.140.95:3232
M247 Ltd
DE
malicious
1356
svchost.exe
23.53.40.73:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2028
cfmon.exe
206.123.140.95:7000
M247 Ltd
DE
malicious
828
svchost.exe
185.235.129.102:80
blankhack.com
Zomro B.V.
NL
unknown

DNS requests

Domain
IP
Reputation
ctldl.windowsupdate.com
  • 23.53.40.73
  • 23.53.40.72
  • 23.53.40.48
  • 23.53.40.59
  • 23.53.40.25
  • 23.53.40.65
  • 23.53.40.18
  • 23.53.40.19
  • 23.53.40.35
whitelisted
blankhack.com
  • 185.235.129.102
unknown
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

PID
Process
Class
Message
1356
svchost.exe
Domain Observed Used for C2 Detected
REMOTE [ANY.RUN] AsyncRAT SSL certificate
1356
svchost.exe
Malware Command and Control Activity Detected
REMOTE [ANY.RUN] AsyncRAT Successful Connection
2028
cfmon.exe
Malware Command and Control Activity Detected
SUSPICIOUS [ANY.RUN] Possible Xworm Network Packet
2028
cfmon.exe
Malware Command and Control Activity Detected
SUSPICIOUS [ANY.RUN] Possible Xworm Network Packet
51 ETPRO signatures available at the full report
Process
Message
utorrent.exe
CLR: Managed code called FailFast without specifying a reason.