File name:

btweb_installer.exe

Full analysis: https://app.any.run/tasks/1e2e7ca5-69c6-4598-bf89-4432925d9f5d
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: February 21, 2026, 10:29:28
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
adware
innosetup
bittorrent
delphi
inno
installer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 11 sections
MD5:

E29182C96F50058876D314EE84716195

SHA1:

60454D0C285D49F904BCEBA5361740C49681D51C

SHA256:

C4C8938202053C0B73153446CA9F7CB0B58CBE1BCBC303FE293912E3325FE5B7

SSDEEP:

98304:LPTDKuP2bxmi/0bmhgDsUWUn+BG2PXUrSOcQ2LOQpz9w4fAAj+ow4O+KJktHUPRs:Q8dMJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • INNOSETUP has been detected (SURICATA)

      • btweb_installer.tmp (PID: 8352)
    • Changes the autorun value in the registry

      • btweb.exe (PID: 2780)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • btweb_installer.tmp (PID: 8352)
    • Mutex name with non-standard characters

      • btweb_installer.tmp (PID: 8352)
    • Access to an unwanted program domain was detected

      • btweb_installer.tmp (PID: 8352)
    • The process creates files with name similar to system file names

      • btweb_install_rr.exe (PID: 7868)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • btweb_install_rr.exe (PID: 7868)
  • INFO

    • Drops script file

      • msedge.exe (PID: 8684)
    • Checks supported languages

      • btweb_installer.exe (PID: 8064)
      • btweb_installer.exe (PID: 412)
      • btweb_installer.tmp (PID: 8316)
      • btweb_installer.tmp (PID: 8352)
      • btweb_install_rr.exe (PID: 7868)
      • btweb.exe (PID: 2780)
      • identity_helper.exe (PID: 6496)
      • helper.exe (PID: 7376)
    • Create files in a temporary directory

      • btweb_installer.exe (PID: 8064)
      • btweb_installer.exe (PID: 412)
      • btweb_installer.tmp (PID: 8352)
      • btweb_install_rr.exe (PID: 7868)
    • Process checks computer location settings

      • btweb_installer.tmp (PID: 8316)
    • Reads security settings of Internet Explorer

      • btweb_installer.tmp (PID: 8316)
      • btweb_install_rr.exe (PID: 7868)
      • btweb.exe (PID: 2780)
    • Reads the computer name

      • btweb_installer.tmp (PID: 8316)
      • btweb_installer.exe (PID: 412)
      • btweb_installer.tmp (PID: 8352)
      • btweb_install_rr.exe (PID: 7868)
      • btweb.exe (PID: 2780)
      • helper.exe (PID: 7376)
      • identity_helper.exe (PID: 6496)
    • Reads the machine GUID from the registry

      • btweb_installer.tmp (PID: 8352)
      • btweb.exe (PID: 2780)
    • Checks proxy server information

      • btweb_installer.tmp (PID: 8352)
      • btweb_install_rr.exe (PID: 7868)
      • btweb.exe (PID: 2780)
    • Compiled with Borland Delphi (YARA)

      • btweb_installer.exe (PID: 8064)
      • btweb_installer.tmp (PID: 8316)
      • btweb_installer.exe (PID: 412)
    • Detects InnoSetup installer (YARA)

      • btweb_installer.exe (PID: 8064)
      • btweb_installer.tmp (PID: 8316)
      • btweb_installer.exe (PID: 412)
    • Creates a software uninstall entry

      • btweb_install_rr.exe (PID: 7868)
    • Creates files or folders in the user directory

      • btweb_install_rr.exe (PID: 7868)
      • btweb.exe (PID: 2780)
      • helper.exe (PID: 7376)
    • Launching a file from a Registry key

      • btweb.exe (PID: 2780)
    • Application launched itself

      • msedge.exe (PID: 7936)
      • msedge.exe (PID: 8684)
    • Reads Environment values

      • identity_helper.exe (PID: 6496)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:08:12 16:07:07+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 2.25
CodeSize: 716800
InitializedDataSize: 176128
UninitializedDataSize: -
EntryPoint: 0xb0028
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 1.4.0.0
ProductVersionNumber: 1.4.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Вi??????Tοrᴦent Web®
FileVersion: 1.4.0
LegalCopyright: ©2022 RainBerry Inc. All Rights Reserved
OriginalFileName:
ProductName: Вi??????Tοrᴦent Web®
ProductVersion: 1.4.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
175
Monitored processes
24
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
412"C:\Users\admin\AppData\Local\Temp\btweb_installer.exe" /SPAWNWND=$14038C /NOTIFYWND=$D0232 C:\Users\admin\AppData\Local\Temp\btweb_installer.exe
btweb_installer.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
Вi𝗍Tοrᴦent Web®
Exit code:
0
Version:
1.4.0
Modules
Images
c:\users\admin\appdata\local\temp\btweb_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
1084"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=6012,i,13032704611683752776,6921100140830835393,262144 --variations-seed-version --mojo-platform-channel-handle=6028 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2292C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2780"C:\Users\admin\AppData\Roaming\BitTorrent Web\btweb.exe" /RUNONSTARTUPC:\Users\admin\AppData\Roaming\BitTorrent Web\btweb.exe
btweb_installer.tmp
User:
admin
Company:
BitTorrent Limited
Integrity Level:
MEDIUM
Description:
BitTorrent Web
Exit code:
0
Version:
1.5.0.6335
Modules
Images
c:\users\admin\appdata\roaming\bittorrent web\btweb.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\rpcrt4.dll
3236"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=6688,i,13032704611683752776,6921100140830835393,262144 --variations-seed-version --mojo-platform-channel-handle=6720 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3588"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=133.0.6943.142 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=133.0.3065.92 --initial-client-data=0x1bc,0x1dc,0x298,0x1e0,0x2a0,0x7ffd709ef208,0x7ffd709ef214,0x7ffd709ef220C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4040"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --extension-process --renderer-sub-type=extension --pdf-upsell-enabled --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=7 --always-read-main-dll --field-trial-handle=4268,i,13032704611683752776,6921100140830835393,262144 --variations-seed-version --mojo-platform-channel-handle=4292 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5612"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=5 --always-read-main-dll --field-trial-handle=3656,i,13032704611683752776,6921100140830835393,262144 --variations-seed-version --mojo-platform-channel-handle=3844 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6232"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2784,i,13032704611683752776,6921100140830835393,262144 --variations-seed-version --mojo-platform-channel-handle=2800 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6496"C:\Program Files (x86)\Microsoft\Edge\Application\133.0.3065.92\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=6260,i,13032704611683752776,6921100140830835393,262144 --variations-seed-version --mojo-platform-channel-handle=6420 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\133.0.3065.92\identity_helper.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\identity_helper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\bcrypt.dll
Total events
8 000
Read events
7 976
Write events
22
Delete events
2

Modification events

(PID) Process:(7868) btweb_install_rr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\btweb
Operation:writeName:UninstallString
Value:
"C:\Users\admin\AppData\Roaming\BitTorrent Web\Uninstall.exe"
(PID) Process:(7868) btweb_install_rr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\btweb
Operation:writeName:QuietUninstallString
Value:
"C:\Users\admin\AppData\Roaming\BitTorrent Web\Uninstall.exe" /S
(PID) Process:(7868) btweb_install_rr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\btweb
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Roaming\BitTorrent Web\uninstall.ico
(PID) Process:(7868) btweb_install_rr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\btweb
Operation:writeName:DisplayName
Value:
BitTorrent Web
(PID) Process:(7868) btweb_install_rr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\btweb
Operation:writeName:Publisher
Value:
BitTorrent Limited
(PID) Process:(7868) btweb_install_rr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\btweb
Operation:writeName:DisplayVersion
Value:
1.5.0
(PID) Process:(7868) btweb_install_rr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\btweb
Operation:writeName:NoModify
Value:
1
(PID) Process:(7868) btweb_install_rr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\btweb
Operation:writeName:NoRepair
Value:
1
(PID) Process:(7868) btweb_install_rr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7868) btweb_install_rr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
Executable files
0
Suspicious files
0
Text files
0
Unknown types
506

Dropped files

PID
Process
Filename
Type
412btweb_installer.exeC:\Users\admin\AppData\Local\Temp\is-92OKP.tmp\btweb_installer.tmpbinary
MD5:EF029C2CFC6F3FDEFAD067BB6B9A1ED7
SHA256:742126060D297ACA75A98D8F03B04D79A6B6A5EDA4CEBF40A278406F201765B5
8064btweb_installer.exeC:\Users\admin\AppData\Local\Temp\is-J7LO9.tmp\btweb_installer.tmpbinary
MD5:EF029C2CFC6F3FDEFAD067BB6B9A1ED7
SHA256:742126060D297ACA75A98D8F03B04D79A6B6A5EDA4CEBF40A278406F201765B5
7868btweb_install_rr.exeC:\Users\admin\AppData\Roaming\BitTorrent Web\webui\version.txtbinary
MD5:F254785F0CB49DB8DFB5C5BA19F57551
SHA256:2C5B32B90EAE5212A29C7AA51C423C9F0205CD6CF4D3E92B845F68D33B2BCF70
8352btweb_installer.tmpC:\Users\admin\AppData\Local\Temp\is-GROH8.tmp\_isetup\_setup64.tmpbinary
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
8352btweb_installer.tmpC:\Users\admin\AppData\Local\Temp\is-GROH8.tmp\Logo.pngbinary
MD5:A047D3C01D1E469C5543D2679955149C
SHA256:CF090DEB874784E26829BBE05131CA859C88102F74019FE1B0162A63B412087A
8352btweb_installer.tmpC:\Users\admin\AppData\Local\Temp\is-GROH8.tmp\license.rtfbinary
MD5:8A708BF775DE14E5FBB16F6077B454D5
SHA256:ECA753676C5C71D7BE141451CD6D1426A08ED5C254078BC585D9BA91395A971A
8352btweb_installer.tmpC:\Users\admin\AppData\Local\Temp\is-GROH8.tmp\106.pngbinary
MD5:4CFFF8DC30D353CD3D215FD3A5DBAC24
SHA256:0C430E56D69435D8AB31CBB5916A73A47D11EF65B37D289EE7D11130ADF25856
8352btweb_installer.tmpC:\Users\admin\AppData\Local\Temp\is-GROH8.tmp\is-1BEF8.tmpbinary
MD5:4CFFF8DC30D353CD3D215FD3A5DBAC24
SHA256:0C430E56D69435D8AB31CBB5916A73A47D11EF65B37D289EE7D11130ADF25856
8352btweb_installer.tmpC:\Users\admin\AppData\Local\Temp\is-GROH8.tmp\is-GFEA8.tmpbinary
MD5:0C9FFB87A7D12629B6940F6374507CD6
SHA256:7CFD3A0D702CD39142D3F82D4EF08BD286327BCCA31F01F3BAB3D06613B5DC49
7868btweb_install_rr.exeC:\Users\admin\AppData\Local\Temp\nsh92D8.tmp\UAC.dllbinary
MD5:ADB29E6B186DAA765DC750128649B63D
SHA256:2F7F8FC05DC4FD0D5CDA501B47E4433357E887BBFED7292C028D99C73B52DC08
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
58
TCP/UDP connections
199
DNS requests
120
Threats
18

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
8352
btweb_installer.tmp
HEAD
200
18.244.18.50:443
https://download-lb.utorrent.com/endpoint/btweb/os/riserollout/track/beta
US
unknown
8352
btweb_installer.tmp
POST
200
3.160.213.27:443
https://dkmhk1umcbn9e.cloudfront.net/zbd
US
unknown
8352
btweb_installer.tmp
POST
200
3.160.213.27:443
https://dkmhk1umcbn9e.cloudfront.net/zbd
US
unknown
8352
btweb_installer.tmp
POST
200
3.160.213.27:443
https://dkmhk1umcbn9e.cloudfront.net/o
US
binary
14.6 Kb
malicious
356
svchost.exe
POST
200
20.190.160.128:443
https://login.live.com/RST2.srf
US
binary
11.1 Kb
whitelisted
356
svchost.exe
POST
200
20.190.160.128:443
https://login.live.com/RST2.srf
US
binary
10.3 Kb
whitelisted
356
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
US
binary
471 b
whitelisted
8352
btweb_installer.tmp
GET
200
3.160.213.27:443
https://dkmhk1umcbn9e.cloudfront.net/f/WebAdvisor/images/943/EN.png
US
binary
47.6 Kb
unknown
5512
svchost.exe
GET
200
23.216.77.18:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
5512
svchost.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5780
RUXIMICS.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
6768
MoUsoCoreWorker.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5512
svchost.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
8352
btweb_installer.tmp
3.160.213.27:443
dkmhk1umcbn9e.cloudfront.net
AMAZON-02
US
malicious
356
svchost.exe
20.190.160.128:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
356
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
5512
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
self.events.data.microsoft.com
  • 104.208.16.92
whitelisted
google.com
  • 142.250.186.78
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
dkmhk1umcbn9e.cloudfront.net
  • 3.160.213.27
  • 3.160.213.35
  • 3.160.213.111
  • 3.160.213.71
unknown
login.live.com
  • 20.190.160.128
  • 40.126.32.133
  • 20.190.160.3
  • 20.190.160.67
  • 40.126.32.72
  • 20.190.160.22
  • 20.190.160.66
  • 20.190.160.65
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.124.78.146
whitelisted
download-lb.utorrent.com
  • 18.244.18.50
  • 18.244.18.57
  • 18.244.18.73
  • 18.244.18.72
whitelisted
crl.microsoft.com
  • 23.216.77.18
  • 23.216.77.13
  • 23.216.77.20
  • 23.216.77.19
  • 23.216.77.42
  • 23.216.77.15
  • 23.216.77.35
whitelisted
www.microsoft.com
  • 88.221.169.152
  • 23.52.181.212
whitelisted

Threats

PID
Process
Class
Message
8352
btweb_installer.tmp
Generic Protocol Command Decode
SURICATA HTTP Request unrecognized authorization method
8352
btweb_installer.tmp
Generic Protocol Command Decode
SURICATA HTTP Request unrecognized authorization method
8352
btweb_installer.tmp
A Network Trojan was detected
ET ADWARE_PUP Win32/OfferCore Checkin M1
8352
btweb_installer.tmp
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] InnoSetup Installer
8352
btweb_installer.tmp
Generic Protocol Command Decode
SURICATA HTTP Request unrecognized authorization method
7868
btweb_install_rr.exe
Potentially Bad Traffic
SUSPICIOUS [ANY.RUN] NSIS INetC plugin User-Agent observed in HTTP request
2780
btweb.exe
Potentially Bad Traffic
ET INFO PE EXE or DLL Windows file download HTTP
2780
btweb.exe
Misc activity
INFO [ANY.RUN] P2P BitTorrent Protocol
2780
btweb.exe
Potentially Bad Traffic
ET INFO Executable served from Amazon S3
7740
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
Process
Message
btweb.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.