File name:

utorrent_installer.exe

Full analysis: https://app.any.run/tasks/b20acda4-8f54-4032-8c45-911fa3d8ce4f
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: April 08, 2024, 17:22:44
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
innosetup
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

D204F311D28E362F34A4916BD946DA42

SHA1:

2D385A49472352218787B8F31C1A6E699F20CF61

SHA256:

BDB05A92A4C80A2D3E186B8667C0B2F69DEDD79A65160E5D8279CF50327F8C0E

SSDEEP:

49152:z7HecD4dnbibBlRzGjnj27kCaaQss/J3Kuhk/XgyxncpdTtjX2GOeGRnmd6hxKSr:/+cD4dngzGjnQYsmJ36VBcTtjX2lRGal

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • utorrent_installer.exe (PID: 1696)
      • utorrent_installer.exe (PID: 2792)
      • uTorrent.exe (PID: 1656)
      • utorrent_installer.tmp (PID: 1824)
      • utorrent.exe (PID: 3308)
      • avg_antivirus_free_setup.exe (PID: 2968)
      • avg_antivirus_free_online_setup.exe (PID: 3680)
      • uTorrent.exe (PID: 968)
    • Changes the autorun value in the registry

      • utorrent.exe (PID: 3308)
      • uTorrent.exe (PID: 968)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • utorrent_installer.tmp (PID: 1824)
    • Executable content was dropped or overwritten

      • utorrent_installer.exe (PID: 1696)
      • utorrent_installer.exe (PID: 2792)
      • utorrent_installer.tmp (PID: 1824)
      • uTorrent.exe (PID: 1656)
      • utorrent.exe (PID: 3308)
      • avg_antivirus_free_setup.exe (PID: 2968)
      • uTorrent.exe (PID: 968)
      • avg_antivirus_free_online_setup.exe (PID: 3680)
    • Mutex name with non-standard characters

      • utorrent_installer.tmp (PID: 1824)
      • uTorrent.exe (PID: 968)
    • Reads settings of System Certificates

      • utorrent_installer.tmp (PID: 1824)
      • avg_antivirus_free_setup.exe (PID: 2968)
      • avg_antivirus_free_online_setup.exe (PID: 3680)
    • Reads the Internet Settings

      • utorrent_installer.tmp (PID: 1824)
      • uTorrent.exe (PID: 1656)
      • utorrent.exe (PID: 3308)
      • uTorrent.exe (PID: 968)
    • The process creates files with name similar to system file names

      • uTorrent.exe (PID: 1656)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • uTorrent.exe (PID: 1656)
    • Reads security settings of Internet Explorer

      • uTorrent.exe (PID: 1656)
      • utorrent_installer.tmp (PID: 1824)
      • utorrent.exe (PID: 3308)
      • uTorrent.exe (PID: 968)
    • Searches for installed software

      • utorrent.exe (PID: 3308)
      • uTorrent.exe (PID: 968)
    • Creates a software uninstall entry

      • utorrent.exe (PID: 3308)
    • Checks Windows Trust Settings

      • uTorrent.exe (PID: 968)
      • utorrent.exe (PID: 3308)
    • Changes Internet Explorer settings (feature browser emulation)

      • uTorrent.exe (PID: 968)
    • Non-standard symbols in registry

      • utorrent_installer.tmp (PID: 1824)
    • Process requests binary or script from the Internet

      • uTorrent.exe (PID: 968)
  • INFO

    • Create files in a temporary directory

      • utorrent_installer.exe (PID: 1696)
      • utorrent_installer.exe (PID: 2792)
      • utorrent_installer.tmp (PID: 1824)
      • uTorrent.exe (PID: 1656)
      • utorrent.exe (PID: 3308)
      • avg_antivirus_free_online_setup.exe (PID: 3680)
      • uTorrent.exe (PID: 968)
    • Checks supported languages

      • utorrent_installer.exe (PID: 1696)
      • utorrent_installer.tmp (PID: 2648)
      • utorrent_installer.exe (PID: 2792)
      • utorrent_installer.tmp (PID: 1824)
      • uTorrent.exe (PID: 1656)
      • utorrent.exe (PID: 3308)
      • avg_antivirus_free_setup.exe (PID: 2968)
      • avg_antivirus_free_online_setup.exe (PID: 3680)
      • uTorrent.exe (PID: 968)
    • Reads the computer name

      • utorrent_installer.tmp (PID: 1824)
      • utorrent_installer.tmp (PID: 2648)
      • uTorrent.exe (PID: 1656)
      • utorrent.exe (PID: 3308)
      • avg_antivirus_free_setup.exe (PID: 2968)
      • uTorrent.exe (PID: 968)
      • avg_antivirus_free_online_setup.exe (PID: 3680)
    • Reads the machine GUID from the registry

      • utorrent_installer.tmp (PID: 1824)
      • uTorrent.exe (PID: 1656)
      • utorrent.exe (PID: 3308)
      • avg_antivirus_free_setup.exe (PID: 2968)
      • avg_antivirus_free_online_setup.exe (PID: 3680)
      • uTorrent.exe (PID: 968)
    • Reads the software policy settings

      • utorrent_installer.tmp (PID: 1824)
      • avg_antivirus_free_setup.exe (PID: 2968)
      • avg_antivirus_free_online_setup.exe (PID: 3680)
    • Creates files or folders in the user directory

      • uTorrent.exe (PID: 1656)
      • utorrent.exe (PID: 3308)
      • uTorrent.exe (PID: 968)
    • Checks proxy server information

      • uTorrent.exe (PID: 1656)
      • utorrent.exe (PID: 3308)
      • uTorrent.exe (PID: 968)
    • Creates files in the program directory

      • avg_antivirus_free_online_setup.exe (PID: 3680)
    • Application launched itself

      • msedge.exe (PID: 2660)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (65.1)
.exe | Win32 EXE PECompact compressed (generic) (24.6)
.dll | Win32 Dynamic Link Library (generic) (3.9)
.exe | Win32 Executable (generic) (2.6)
.exe | Win16/32 Executable Delphi generic (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:04:14 16:10:23+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 73216
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 3.6.0.0
ProductVersionNumber: 3.6.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: uТorrеnt® Classic
FileVersion: 3.6
LegalCopyright: ©2022 RainBerry Inc. All Rights Reserved
OriginalFileName:
ProductName: uТorrеnt® Classic
ProductVersion: 3.6
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
64
Monitored processes
23
Malicious processes
9
Suspicious processes
0

Behavior graph

Click at the process to see the details
start utorrent_installer.exe utorrent_installer.tmp no specs utorrent_installer.exe utorrent_installer.tmp utorrent.exe utorrent.exe avg_antivirus_free_setup.exe avg_antivirus_free_online_setup.exe utorrent.exe utorrentie.exe no specs utorrentie.exe no specs utorrentie.exe no specs utorrentie.exe no specs msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
968"C:\Users\admin\AppData\Roaming\uTorrent\uTorrent.exe"C:\Users\admin\AppData\Roaming\utorrent\uTorrent.exe
utorrent_installer.tmp
User:
admin
Company:
BitTorrent Limited
Integrity Level:
MEDIUM
Description:
µTorrent
Version:
3.6.0.47044
Modules
Images
c:\users\admin\appdata\roaming\utorrent\utorrent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\users\admin\appdata\roaming\utorrent\bt_datachannel.dll
c:\windows\system32\user32.dll
1592"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1548 --field-trial-handle=1260,i,16219769738958140635,3265976728848185641,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1596"C:\Users\admin\AppData\Roaming\uTorrent\updates\3.6.0_47044\utorrentie.exe" uTorrent_968_02D03290_968553423 µTorrent4823DF041B09 uTorrent ie unpC:\Users\admin\AppData\Roaming\utorrent\updates\3.6.0_47044\utorrentie.exeuTorrent.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
LOW
Description:
WebHelper
Exit code:
3221225785
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\roaming\utorrent\updates\3.6.0_47044\utorrentie.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1656"C:\Users\admin\AppData\Local\Temp\is-OH2JB.tmp\uTorrent.exe" /S /FORCEINSTALL 1110010101111110C:\Users\admin\AppData\Local\Temp\is-OH2JB.tmp\uTorrent.exe
utorrent_installer.tmp
User:
admin
Company:
BitTorrent Limited
Integrity Level:
HIGH
Description:
utorrent
Exit code:
0
Version:
3.6.0.47044
Modules
Images
c:\users\admin\appdata\local\temp\is-oh2jb.tmp\utorrent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1696"C:\Users\admin\AppData\Local\Temp\utorrent_installer.exe" C:\Users\admin\AppData\Local\Temp\utorrent_installer.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
uТorrеnt® Classic
Version:
3.6
Modules
Images
c:\users\admin\appdata\local\temp\utorrent_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1736"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2160 --field-trial-handle=1260,i,16219769738958140635,3265976728848185641,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1820"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2148 --field-trial-handle=1260,i,16219769738958140635,3265976728848185641,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1824"C:\Users\admin\AppData\Local\Temp\is-PPI0M.tmp\utorrent_installer.tmp" /SL5="$F0130,840718,816128,C:\Users\admin\AppData\Local\Temp\utorrent_installer.exe" /SPAWNWND=$18013E /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\is-PPI0M.tmp\utorrent_installer.tmp
utorrent_installer.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Setup/Uninstall
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-ppi0m.tmp\utorrent_installer.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2020"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6bbdf598,0x6bbdf5a8,0x6bbdf5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2172"C:\Users\admin\AppData\Roaming\uTorrent\updates\3.6.0_47044\utorrentie.exe" uTorrent_968_02D03030_767803207 µTorrent4823DF041B09 uTorrent ie unpC:\Users\admin\AppData\Roaming\utorrent\updates\3.6.0_47044\utorrentie.exeuTorrent.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
LOW
Description:
WebHelper
Exit code:
3221225785
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\roaming\utorrent\updates\3.6.0_47044\utorrentie.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
23 894
Read events
23 632
Write events
231
Delete events
31

Modification events

(PID) Process:(1824) utorrent_installer.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
2007000040A50364D989DA01
(PID) Process:(1824) utorrent_installer.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
5E6010EE5F7C880FCAE8E85C65149D9644AD0D8A715E7D41787B3FD042A9E5CC
(PID) Process:(1824) utorrent_installer.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(1824) utorrent_installer.tmpKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1824) utorrent_installer.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates
Operation:delete valueName:9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Value:
(PID) Process:(1824) utorrent_installer.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Operation:writeName:Blob
Value:
0F00000001000000200000009065F32AFC2CFEA7F452D2D6BE94D20C877EFC1C05433D9935696193FDCC05D80300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB6200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3
(PID) Process:(1824) utorrent_installer.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Operation:writeName:Blob
Value:
1400000001000000140000005D6CA352CEFC713CBBC5E21F663C3639FD19D4D70300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB60F00000001000000200000009065F32AFC2CFEA7F452D2D6BE94D20C877EFC1C05433D9935696193FDCC05D8200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3
(PID) Process:(1824) utorrent_installer.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Operation:writeName:Blob
Value:
190000000100000010000000BCC80DAA2F98A4692805BFF4CBB372EB0F00000001000000200000009065F32AFC2CFEA7F452D2D6BE94D20C877EFC1C05433D9935696193FDCC05D80300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB61400000001000000140000005D6CA352CEFC713CBBC5E21F663C3639FD19D4D7200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3
(PID) Process:(1656) uTorrent.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(1656) uTorrent.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
Executable files
20
Suspicious files
44
Text files
38
Unknown types
15

Dropped files

PID
Process
Filename
Type
1696utorrent_installer.exeC:\Users\admin\AppData\Local\Temp\is-O4986.tmp\utorrent_installer.tmpexecutable
MD5:
SHA256:
2792utorrent_installer.exeC:\Users\admin\AppData\Local\Temp\is-PPI0M.tmp\utorrent_installer.tmpexecutable
MD5:
SHA256:
1824utorrent_installer.tmpC:\Users\admin\AppData\Local\Temp\is-OH2JB.tmp\Logo.pngimage
MD5:
SHA256:
1824utorrent_installer.tmpC:\Users\admin\AppData\Local\Temp\is-OH2JB.tmp\license.rtftext
MD5:
SHA256:
1824utorrent_installer.tmpC:\Users\admin\AppData\Local\Temp\is-OH2JB.tmp\is-1DQRJ.tmpimage
MD5:
SHA256:
1824utorrent_installer.tmpC:\Users\admin\AppData\Local\Temp\is-OH2JB.tmp\AVG_AV.pngimage
MD5:
SHA256:
1824utorrent_installer.tmpC:\Users\admin\AppData\Local\Temp\is-OH2JB.tmp\is-5T8LM.tmp
MD5:
SHA256:
1824utorrent_installer.tmpC:\Users\admin\AppData\Local\Temp\is-OH2JB.tmp\uTorrent.exeexecutable
MD5:
SHA256:
1824utorrent_installer.tmpC:\Users\admin\AppData\Local\Temp\is-OH2JB.tmp\is-2EJFA.tmpcompressed
MD5:
SHA256:
1824utorrent_installer.tmpC:\Users\admin\AppData\Local\Temp\is-OH2JB.tmp\component0compressed
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
26
TCP/UDP connections
149
DNS requests
46
Threats
11

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1824
utorrent_installer.tmp
GET
200
67.215.238.66:80
http://download-new.utorrent.com/endpoint/utorrent/os/riserollout/track/stable
unknown
unknown
1824
utorrent_installer.tmp
HEAD
200
67.215.238.66:80
http://download-new.utorrent.com/endpoint/utorrent/os/riserollout/track/stable
unknown
unknown
3308
utorrent.exe
GET
200
82.221.103.245:80
http://update.utorrent.li/installstats.php?cl=uTorrent&v=113358788&h=IYm1R3fGzNHZBp5f&w=1DB10106&bu=0&pr=0&cmp=0&ocmp=0&showinstall&pid=3308&cau=0&lunv=0&au=0&view=win32
unknown
unknown
3308
utorrent.exe
GET
200
82.221.103.245:80
http://update.utorrent.li/installstats.php?cl=uTorrent&v=113358788&h=IYm1R3fGzNHZBp5f&w=1DB10106&bu=0&pr=0&cmp=0&ocmp=0&installresult&pid=3308&cau=0&lunv=0&installresult=0&exit=1&au=0&ic=1&view=win32
unknown
unknown
2968
avg_antivirus_free_setup.exe
POST
204
34.117.223.223:80
http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
unknown
unknown
1656
uTorrent.exe
POST
200
52.0.69.196:80
http://i-6000.b-47044.ut.bench.utorrent.com/e?i=6000
unknown
unknown
2968
avg_antivirus_free_setup.exe
POST
200
142.250.185.110:80
http://www.google-analytics.com/collect
unknown
unknown
1656
uTorrent.exe
POST
200
52.0.69.196:80
http://i-6000.b-47044.ut.bench.utorrent.com/e?i=6000
unknown
unknown
2968
avg_antivirus_free_setup.exe
POST
204
34.117.223.223:80
http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
unknown
unknown
2968
avg_antivirus_free_setup.exe
POST
200
142.250.185.110:80
http://www.google-analytics.com/collect
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1824
utorrent_installer.tmp
18.65.40.220:443
d1l65h99sv20xf.cloudfront.net
AMAZON-02
US
unknown
1824
utorrent_installer.tmp
18.245.86.26:443
api.playanext.com
US
unknown
1824
utorrent_installer.tmp
18.245.86.79:443
api.playanext.com
US
unknown
1824
utorrent_installer.tmp
67.215.238.66:80
download-new.utorrent.com
ASN-QUADRANET-GLOBAL
US
unknown
1656
uTorrent.exe
52.0.69.196:80
i-6000.b-47044.ut.bench.utorrent.com
AMAZON-AES
US
unknown
3308
utorrent.exe
82.221.103.245:80
update.utorrent.li
Advania Island ehf
IS
unknown
2968
avg_antivirus_free_setup.exe
142.250.185.110:80
www.google-analytics.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
d1l65h99sv20xf.cloudfront.net
  • 18.65.40.220
  • 18.65.40.126
  • 18.65.40.45
  • 18.65.40.212
unknown
api.playanext.com
  • 18.245.86.26
  • 18.245.86.105
  • 18.245.86.84
  • 18.245.86.79
whitelisted
download-new.utorrent.com
  • 67.215.238.66
whitelisted
i-6000.b-47044.ut.bench.utorrent.com
  • 52.0.69.196
  • 52.54.124.114
  • 52.204.74.82
  • 52.21.82.152
  • 50.19.77.244
  • 52.1.134.238
  • 52.6.196.246
  • 52.201.176.53
unknown
router.bittorrent.com
  • 67.215.246.10
shared
router.utorrent.com
  • 82.221.103.244
whitelisted
update.utorrent.li
  • 82.221.103.245
  • 82.221.103.246
whitelisted
v7event.stats.avast.com
  • 34.117.223.223
whitelisted
www.google-analytics.com
  • 142.250.185.110
whitelisted
honzik.avcdn.net
  • 2.18.161.23
unknown

Threats

PID
Process
Class
Message
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] InnoSetup Installer
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Misc activity
ET INFO EXE - Served Attached HTTP
1656
uTorrent.exe
Potentially Bad Traffic
ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla))
3308
utorrent.exe
Potential Corporate Privacy Violation
ET P2P Bittorrent P2P Client User-Agent (uTorrent)
3308
utorrent.exe
Potential Corporate Privacy Violation
ET P2P Bittorrent P2P Client User-Agent (uTorrent)
Potentially Bad Traffic
ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla))
968
uTorrent.exe
Potential Corporate Privacy Violation
ET P2P BTWebClient UA uTorrent in use
968
uTorrent.exe
Potential Corporate Privacy Violation
ET P2P BitTorrent DHT ping request
968
uTorrent.exe
Potential Corporate Privacy Violation
ET P2P BTWebClient UA uTorrent in use
No debug info