File name:

uTorrent.exe

Full analysis: https://app.any.run/tasks/9d791352-e3b4-4c1b-95d4-e7ed7151f0bf
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: November 03, 2020, 12:56:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
installer
adware
pua
lavasoft
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

021DB6AE2083C0DD60B343BBB78B2EA8

SHA1:

693E99408C8371174AD3C47D4F5BFC199FE92DB9

SHA256:

CDCA0C3E8950AC521395D73CFE10078AE5977827CAE5457CF18999793ED800B6

SSDEEP:

98304:UG5QgSlEuoButa4v6UdJ/lQnTGv37sJyrrZ4RgSimqQ:UG5iqb4ta4CUdRqnTE37wy25gQ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • installer.exe (PID: 2600)
      • Carrier.exe (PID: 2268)
      • GenericSetup.exe (PID: 2772)
      • Carrier.exe (PID: 3116)
      • WebCompanionInstaller.exe (PID: 2156)
      • uTorrent.exe (PID: 2560)
      • 20enimvx.s4m.exe (PID: 3000)
      • utorrentie.exe (PID: 2380)
      • helper.exe (PID: 1764)
      • utorrentie.exe (PID: 1916)
      • utorrentie.exe (PID: 1012)
    • Loads dropped or rewritten executable

      • GenericSetup.exe (PID: 2772)
    • LAVASOFT was detected

      • installer.exe (PID: 2600)
    • Changes settings of System certificates

      • GenericSetup.exe (PID: 2772)
      • Carrier.exe (PID: 2268)
      • WebCompanionInstaller.exe (PID: 2156)
    • Changes the autorun value in the registry

      • Carrier.exe (PID: 2268)
      • uTorrent.exe (PID: 2560)
    • Loads the Task Scheduler COM API

      • GenericSetup.exe (PID: 2772)
  • SUSPICIOUS

    • Reads Internet Cache Settings

      • Carrier.exe (PID: 2268)
      • uTorrent.exe (PID: 2560)
      • utorrentie.exe (PID: 1916)
      • utorrentie.exe (PID: 2380)
      • utorrentie.exe (PID: 1012)
    • Modifies the open verb of a shell class

      • Carrier.exe (PID: 2268)
    • Executable content was dropped or overwritten

      • uTorrent.exe (PID: 3760)
      • 20enimvx.s4m.exe (PID: 3000)
      • GenericSetup.exe (PID: 2772)
      • uTorrent.exe (PID: 2560)
      • Carrier.exe (PID: 2268)
    • Reads the Windows organization settings

      • GenericSetup.exe (PID: 2772)
    • Reads Windows owner or organization settings

      • GenericSetup.exe (PID: 2772)
    • Reads Environment values

      • GenericSetup.exe (PID: 2772)
    • Creates a software uninstall entry

      • Carrier.exe (PID: 2268)
    • Adds / modifies Windows certificates

      • WebCompanionInstaller.exe (PID: 2156)
      • GenericSetup.exe (PID: 2772)
    • Creates files in the program directory

      • WebCompanionInstaller.exe (PID: 2156)
    • Executed via Task Scheduler

      • cmd.exe (PID: 2384)
    • Starts CMD.EXE for commands execution

      • GenericSetup.exe (PID: 2772)
    • Creates files in the user directory

      • uTorrent.exe (PID: 2560)
      • Carrier.exe (PID: 2268)
      • utorrentie.exe (PID: 1916)
    • Changes IE settings (feature browser emulation)

      • uTorrent.exe (PID: 2560)
    • Reads internet explorer settings

      • utorrentie.exe (PID: 1916)
      • utorrentie.exe (PID: 1012)
      • utorrentie.exe (PID: 2380)
    • Searches for installed software

      • GenericSetup.exe (PID: 2772)
  • INFO

    • Reads settings of System Certificates

      • GenericSetup.exe (PID: 2772)
      • utorrentie.exe (PID: 1916)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (23.1)
.exe | Win32 EXE PECompact compressed (generic) (22.3)
.exe | Win32 Executable MS Visual C++ (generic) (16.8)
.exe | Win64 Executable (generic) (14.8)
.exe | UPX compressed Win32 Executable (14.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2011:04:18 20:54:06+02:00
PEType: PE32
LinkerVersion: 6
CodeSize: 104448
InitializedDataSize: 83968
UninitializedDataSize: -
EntryPoint: 0x148d4
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 3.5.5.45798
ProductVersionNumber: 3.5.5.45798
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileVersion: 3.5.5.45798
ProductVersion: 3.5.5.45798
CompanyName: BitTorrent Inc.
FileDescription: µTorrent
InternalName: uTorrent.exe
LegalCopyright: ©2020 BitTorrent, Inc. All Rights Reserved.
OriginalFileName: uTorrent.exe
ProductName: µTorrent
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
61
Monitored processes
16
Malicious processes
7
Suspicious processes
4

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start drop and start drop and start utorrent.exe #LAVASOFT installer.exe genericsetup.exe carrier.exe no specs cmd.exe no specs carrier.exe cmd.exe no specs 20enimvx.s4m.exe webcompanioninstaller.exe cmd.exe no specs utorrent.exe utorrentie.exe utorrentie.exe helper.exe utorrentie.exe utorrent.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1012"C:\Users\admin\AppData\Roaming\uTorrent\updates\3.5.5_45798\utorrentie.exe" uTorrent_2560_01F56B80_2080818321 µTorrent4823DF041B09 uTorrentC:\Users\admin\AppData\Roaming\uTorrent\updates\3.5.5_45798\utorrentie.exe
uTorrent.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
LOW
Description:
WebHelper
Exit code:
0
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\roaming\utorrent\updates\3.5.5_45798\utorrentie.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
1764"C:\Users\admin\AppData\Roaming\uTorrent\helper\helper.exe" 52948 --hval e7YidRuJjyjsFmQl -- -pid 2560 -version 45798C:\Users\admin\AppData\Roaming\uTorrent\helper\helper.exe
uTorrent.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
MEDIUM
Description:
µTorrent Helper
Exit code:
0
Version:
2.0.15.1198
Modules
Images
c:\users\admin\appdata\roaming\utorrent\helper\helper.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
1916"C:\Users\admin\AppData\Roaming\uTorrent\updates\3.5.5_45798\utorrentie.exe" uTorrent_2560_01F567F0_936605557 µTorrent4823DF041B09 uTorrentC:\Users\admin\AppData\Roaming\uTorrent\updates\3.5.5_45798\utorrentie.exe
uTorrent.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
LOW
Description:
WebHelper
Exit code:
0
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\roaming\utorrent\updates\3.5.5_45798\utorrentie.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2156.\WebCompanionInstaller.exe --partner=BT170602 --version=6.0.2270.4122 --prod --silent --homepage=1 --search=1 --partner=BT170602C:\Users\admin\AppData\Local\Temp\7zS2A5B.tmp\WebCompanionInstaller.exe
20enimvx.s4m.exe
User:
admin
Company:
Lavasoft
Integrity Level:
HIGH
Description:
Web Companion
Exit code:
0
Version:
6.0.2270.4122
Modules
Images
c:\users\admin\appdata\local\temp\7zs2a5b.tmp\webcompanioninstaller.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
2268"C:\Users\admin\AppData\Local\Temp\7zS0BE1AB25\Carrier.exe" /S /FORCEINSTALL 1100010101111110 /CAMPAIGN 180C:\Users\admin\AppData\Local\Temp\7zS0BE1AB25\Carrier.exe
cmd.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
HIGH
Description:
µTorrent
Exit code:
1
Version:
3.5.5.45798
Modules
Images
c:\users\admin\appdata\local\temp\7zs0be1ab25\carrier.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
2332"C:\Windows\system32\cmd.exe" /C ""C:\Users\admin\AppData\Local\Temp\7zS0BE1AB25\Carrier.exe" /S /FORCEINSTALL 1100010101111110 /CAMPAIGN 180"C:\Windows\system32\cmd.exeGenericSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2380"C:\Users\admin\AppData\Roaming\uTorrent\updates\3.5.5_45798\utorrentie.exe" uTorrent_2560_01F56758_1916169996 µTorrent4823DF041B09 uTorrentC:\Users\admin\AppData\Roaming\uTorrent\updates\3.5.5_45798\utorrentie.exe
uTorrent.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
LOW
Description:
WebHelper
Exit code:
0
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\roaming\utorrent\updates\3.5.5_45798\utorrentie.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2384C:\Windows\system32\cmd.exe /c start "" "C:\Users\admin\AppData\Roaming\uTorrent\uTorrent.exe"C:\Windows\system32\cmd.exetaskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2556"C:\Users\admin\AppData\Local\Temp\uTorrent.exe" C:\Users\admin\AppData\Local\Temp\uTorrent.exeexplorer.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
MEDIUM
Description:
µTorrent
Exit code:
3221226540
Version:
3.5.5.45798
Modules
Images
c:\users\admin\appdata\local\temp\utorrent.exe
c:\systemroot\system32\ntdll.dll
2560"C:\Users\admin\AppData\Roaming\uTorrent\uTorrent.exe" C:\Users\admin\AppData\Roaming\uTorrent\uTorrent.exe
cmd.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
MEDIUM
Description:
µTorrent
Exit code:
0
Version:
3.5.5.45798
Modules
Images
c:\users\admin\appdata\roaming\utorrent\utorrent.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
Total events
11 456
Read events
11 175
Write events
279
Delete events
2

Modification events

(PID) Process:(2600) installer.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager
Operation:writeName:PendingFileRenameOperations
Value:
\??\C:\Users\admin\AppData\Local\Temp\7zS0BE1AB25\de\DevLib.resources.dll
(PID) Process:(2600) installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2600) installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2772) GenericSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2772) GenericSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2772) GenericSetup.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2772) GenericSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474
Operation:writeName:Blob
Value:
040000000100000010000000ACB694A59C17E0D791529BB19706A6E40F0000000100000014000000CE0E658AA3E847E467A147B3049191093D055E6F030000000100000014000000D4DE20D05E66FC53FE1A50882C78DB2852CAE4741D0000000100000010000000918AD43A9475F78BB5243DE886D8103C140000000100000014000000E59D5930824758CCACFA085436867B3AB5044DF062000000010000002000000016AF57A9F676B0AB126095AA5EBADEF22AB31119D644AC95CD4B93DBF3F26AEB0B0000000100000030000000440069006700690043006500720074002000420061006C00740069006D006F0072006500200052006F006F007400000009000000010000003E000000303C06082B0601050507030106082B0601050507030406082B0601050507030206082B0601050507030306082B0601050507030906082B0601050507030853000000010000006200000030603020060A2B06010401B13E01640130123010060A2B0601040182373C0101030200C0301F06096086480186FD6C020130123010060A2B0601040182373C0101030200C0301B060567810C010130123010060A2B0601040182373C0101030200C019000000010000001000000068CB42B035EA773E52EF50ECF50EC52920000000010000007B030000308203773082025FA0030201020204020000B9300D06092A864886F70D0101050500305A310B300906035504061302494531123010060355040A130942616C74696D6F726531133011060355040B130A43796265725472757374312230200603550403131942616C74696D6F7265204379626572547275737420526F6F74301E170D3030303531323138343630305A170D3235303531323233353930305A305A310B300906035504061302494531123010060355040A130942616C74696D6F726531133011060355040B130A43796265725472757374312230200603550403131942616C74696D6F7265204379626572547275737420526F6F7430820122300D06092A864886F70D01010105000382010F003082010A0282010100A304BB22AB983D57E826729AB579D429E2E1E89580B1B0E35B8E2B299A64DFA15DEDB009056DDB282ECE62A262FEB488DA12EB38EB219DC0412B01527B8877D31C8FC7BAB988B56A09E773E81140A7D1CCCA628D2DE58F0BA650D2A850C328EAF5AB25878A9A961CA967B83F0CD5F7F952132FC21BD57070F08FC012CA06CB9AE1D9CA337A77D6F8ECB9F16844424813D2C0C2A4AE5E60FEB6A605FCB4DD075902D459189863F5A563E0900C7D5DB2067AF385EAEBD403AE5E843E5FFF15ED69BCF939367275CF77524DF3C9902CB93DE5C923533F1F2498215C079929BDC63AECE76E863A6B97746333BD681831F0788D76BFFC9E8E5D2A86A74D90DC271A390203010001A3453043301D0603551D0E04160414E59D5930824758CCACFA085436867B3AB5044DF030120603551D130101FF040830060101FF020103300E0603551D0F0101FF040403020106300D06092A864886F70D01010505000382010100850C5D8EE46F51684205A0DDBB4F27258403BDF764FD2DD730E3A41017EBDA2929B6793F76F6191323B8100AF958A4D46170BD04616A128A17D50ABDC5BC307CD6E90C258D86404FECCCA37E38C637114FEDDD68318E4CD2B30174EEBE755E07481A7F70FF165C84C07985B805FD7FBE6511A30FC002B4F852373904D5A9317A18BFA02AF41299F7A34582E33C5EF59D9EB5C89E7C2EC8A49E4E08144B6DFD706D6B1A63BD64E61FB7CEF0F29F2EBB1BB7F250887392C2E2E3168D9A3202AB8E18DDE91011EE7E35AB90AF3E30947AD0333DA7650FF5FC8E9E62CF47442C015DBB1DB532D247D2382ED0FE81DC326A1EB5EE3CD5FCE7811D19C32442EA6339A9
(PID) Process:(2772) GenericSetup.exeKey:HKEY_CURRENT_USER\Software\Opera Stable Offer
Operation:writeName:LastTimeOfferShown
Value:
1604408344
(PID) Process:(2772) GenericSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4
Operation:writeName:Blob
Value:
0400000001000000100000004BE2C99196650CF40E5A9392A00AFEB20F0000000100000020000000FDE5F2D9CE2026E1E10064C0A468C9F355B90ACF85BAF5CE6F52D4016837FD940300000001000000140000008CF427FD790C3AD166068DE81E57EFBB932272D41D0000000100000010000000521B5F4582C1DCAAE381B05E37CA2D341400000001000000140000006A72267AD01EEF7DE73B6951D46C8D9F901266AB0B000000010000001800000045006E00740072007500730074002E006E0065007400000062000000010000002000000043DF5774B03E7FEF5FE40D931A7BEDF1BB2E6B42738C4E6D3841103D3AA7F33953000000010000002400000030223020060A6086480186FA6C0A010230123010060A2B0601040182373C0101030200C0090000000100000054000000305206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B06010505070308060A2B0601040182370A030406082B0601050507030606082B06010505070307190000000100000010000000FA46CE7CBB85CFB4310075313A09EE052000000001000000420400003082043E30820326A00302010202044A538C28300D06092A864886F70D01010B05003081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D204732301E170D3039303730373137323535345A170D3330313230373137353535345A3081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D20473230820122300D06092A864886F70D01010105000382010F003082010A0282010100BA84B672DB9E0C6BE299E93001A776EA32B895411AC9DA614E5872CFFEF68279BF7361060AA527D8B35FD3454E1C72D64E32F2728A0FF78319D06A808000451EB0C7E79ABF1257271CA3682F0A87BD6A6B0E5E65F31C77D5D4858D7021B4B332E78BA2D5863902B1B8D247CEE4C949C43BA7DEFB547D57BEF0E86EC279B23A0B55E250981632135C2F7856C1C294B3F25AE4279A9F24D7C6ECD09B2582E3CCC2C445C58C977A066B2A119FA90A6E483B6FDBD4111942F78F07BFF5535F9C3EF4172CE669AC4E324C6277EAB7E8E5BB34BC198BAE9C51E7B77EB553B13322E56DCF703C1AFAE29B67B683F48DA5AF624C4DE058AC64341203F8B68D946324A4710203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E041604146A72267AD01EEF7DE73B6951D46C8D9F901266AB300D06092A864886F70D01010B05000382010100799F1D96C6B6793F228D87D3870304606A6B9A2E59897311AC43D1F513FF8D392BC0F2BD4F708CA92FEA17C40B549ED41B9698333CA8AD62A20076AB59696E061D7EC4B9448D98AF12D461DB0A194647F3EBF763C1400540A5D2B7F4B59A36BFA98876880455042B9C877F1A373C7E2DA51AD8D4895ECABDAC3D6CD86DAFD5F3760FCD3B8838229D6C939AC43DBF821B653FA60F5DAAFCE5B215CAB5ADC6BC3DD084E8EA0672B04D393278BF3E119C0BA49D9A21F3F09B0B3078DBC1DC8743FEBC639ACAC5C21CC9C78DFF3B125808E6B63DEC7A2C4EFB8396CE0C3C69875473A473C293FF5110AC155401D8FC05B189A17F74839A49D7DC4E7B8A486F8B45F6
(PID) Process:(2268) Carrier.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
46
Suspicious files
52
Text files
76
Unknown types
20

Dropped files

PID
Process
Filename
Type
3760uTorrent.exeC:\Users\admin\AppData\Local\Temp\7zS0BE1AB25\Resources\images\warning48x48.pngimage
MD5:D3361CF0D689A1B34D84F483D60BA9C9
SHA256:56739925AADA73F9489F9A6B72BFAAA92892B27D20F4D221380BA3EAE17F1442
3760uTorrent.exeC:\Users\admin\AppData\Local\Temp\7zS0BE1AB25\app.icoimage
MD5:21D40E1B37AD7CFDEAC5BE2BC5C2B58D
SHA256:D29353F6C8BA117BDED73A2A12C9F3E5C5E286C168AB4F91DE33CCBAD942AC18
3760uTorrent.exeC:\Users\admin\AppData\Local\Temp\7zS0BE1AB25\Resources\images\loader.gifimage
MD5:2B26F73D382AB69F3914A7D9FDA97B0F
SHA256:A6A0B05B1D5C52303DD3E9E2F9CDA1E688A490FBE84EA0D6E22A051AB6EFD643
3760uTorrent.exeC:\Users\admin\AppData\Local\Temp\7zS0BE1AB25\Resources\FinishPage.htmlhtml
MD5:C80FA35AD16A8E6F6D02A003D408200C
SHA256:0C1C1704D0858BBF271EDEEF7C1A9C76126B90AF71A39D121D1159A3EE69599B
3760uTorrent.exeC:\Users\admin\AppData\Local\Temp\7zS0BE1AB25\Resources\OfferPage.htmlhtml
MD5:CD971B3AC121709D874E11D6F5BBA960
SHA256:96304C4EF7192F521ADD5D9D630ED8AB75A3D45663D8641A7C3186519F88DC42
3760uTorrent.exeC:\Users\admin\AppData\Local\Temp\7zS0BE1AB25\Resources\style.csstext
MD5:3C91D96C2471620F4EB0A4A6EC2D378A
SHA256:6D97CFB805FC5702BB40D437B6FC4D0768ECFBB573B5D4FDADBE5DC7AC14999C
3760uTorrent.exeC:\Users\admin\AppData\Local\Temp\7zS0BE1AB25\Resources\tis\ViewStateLoader.tistext
MD5:EF47B355F8A2E6AB49E31E93C587A987
SHA256:E77239DBDCC6762F298CD5C216A4003CF2AA7B0EF45D364DD558A4BD7F3CDB25
3760uTorrent.exeC:\Users\admin\AppData\Local\Temp\7zS0BE1AB25\BundleConfig.jsontext
MD5:CB7719C6897D856163FAA2BC864934B7
SHA256:5C8BBB8AA2C0DF92D0E2A46467D188795F802166225310792601E188CC1A7E12
3760uTorrent.exeC:\Users\admin\AppData\Local\Temp\7zS0BE1AB25\Resources\SettingPage1.htmlhtml
MD5:55A4C91743FD057A8C430767A32AC9A5
SHA256:361F60D1C7DE5B16C3C0FCA967A8B729D85AC19CA4BD847DBA8AAFB2CB5C8BBF
3760uTorrent.exeC:\Users\admin\AppData\Local\Temp\7zS0BE1AB25\Resources\InstallingPage.htmlhtml
MD5:9A8AF9C65D92EBFC67A96BEA03C6C3FC
SHA256:5F558D572E6BA9E5E82BDAEACA5C0FDAE9519F32B854D534EDBA256F20C6F0D5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
70
TCP/UDP connections
164
DNS requests
49
Threats
13

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2772
GenericSetup.exe
GET
104.17.178.102:80
http://webcompanion.com/nano_download.php?partner=BT170602
US
malicious
2268
Carrier.exe
GET
200
82.221.103.245:80
http://update.utorrent.li/installstats.php?cl=uTorrent&v=111915750&h=e7YidRuJjyjsFmQl&w=1DB10106&bu=0&pr=0&cmp=180&ocmp=180&showinstall&pid=2268&cau=0&au=0&view=win32
IS
whitelisted
2268
Carrier.exe
GET
200
82.221.103.245:80
http://update.utorrent.li/installstats.php?cl=uTorrent&v=111915750&h=e7YidRuJjyjsFmQl&w=1DB10106&bu=0&pr=0&cmp=180&ocmp=180&installresult&pid=2268&cau=0&installresult=0&exit=1&au=0&ic=1&view=win32
IS
whitelisted
2560
uTorrent.exe
GET
304
2.16.106.186:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
unknown
whitelisted
2560
uTorrent.exe
GET
178.79.242.147:80
http://apps.bittorrent.com/utorrent-onboarding/player.btapp
DE
whitelisted
2772
GenericSetup.exe
GET
206
104.17.178.102:80
http://webcompanion.com/nano_download.php?partner=BT170602
US
binary
250 Kb
malicious
2156
WebCompanionInstaller.exe
POST
200
64.18.87.81:80
http://wc-update-service.lavasoft.com/update.asmx
CA
xml
1.43 Kb
whitelisted
2600
installer.exe
POST
200
104.18.88.101:80
http://flow.lavasoft.com/v1/event-stat?ProductID=IS&Type=StubStart
US
text
29 b
whitelisted
2156
WebCompanionInstaller.exe
POST
200
104.18.87.101:80
http://flow.lavasoft.com/v1/event-stat-wc?Type=ProgressInstall&ProductID=wc&EventVersion=1
US
text
29 b
whitelisted
2268
Carrier.exe
GET
200
2.16.106.186:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
unknown
compressed
57.5 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2772
GenericSetup.exe
104.18.87.101:443
flow.lavasoft.com
Cloudflare Inc
US
shared
2600
installer.exe
104.18.88.101:80
flow.lavasoft.com
Cloudflare Inc
US
shared
2772
GenericSetup.exe
104.17.178.102:80
webcompanion.com
Cloudflare Inc
US
shared
2268
Carrier.exe
82.221.103.245:80
update.utorrent.li
Thor Data Center ehf
IS
suspicious
2268
Carrier.exe
2.16.106.186:80
www.download.windowsupdate.com
Akamai International B.V.
whitelisted
2156
WebCompanionInstaller.exe
64.18.87.81:80
wc-update-service.lavasoft.com
COGECODATA
CA
unknown
2156
WebCompanionInstaller.exe
104.18.87.101:80
flow.lavasoft.com
Cloudflare Inc
US
shared
2.16.106.186:80
www.download.windowsupdate.com
Akamai International B.V.
whitelisted
2560
uTorrent.exe
23.21.92.252:80
i-21.b-45798.ut.bench.utorrent.com
Amazon.com, Inc.
US
whitelisted
2560
uTorrent.exe
173.254.195.58:80
update.bittorrent.com
QuadraNet, Inc
US
suspicious

DNS requests

Domain
IP
Reputation
flow.lavasoft.com
  • 104.18.87.101
  • 104.18.88.101
whitelisted
www.google.com
  • 172.217.22.100
malicious
sos.adaware.com
  • 104.16.236.79
  • 104.16.235.79
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared
webcompanion.com
  • 104.17.178.102
  • 104.17.177.102
malicious
www.download.windowsupdate.com
  • 2.16.106.186
  • 2.16.106.171
whitelisted
router.bittorrent.com
  • 67.215.246.10
shared
router.utorrent.com
  • 82.221.103.244
whitelisted
update.utorrent.li
  • 82.221.103.245
  • 82.221.103.246
whitelisted
wc-update-service.lavasoft.com
  • 64.18.87.81
  • 64.18.87.82
whitelisted

Threats

PID
Process
Class
Message
2600
installer.exe
A Network Trojan was detected
ET MALWARE Lavasoft PUA/Adware Client Install
2268
Carrier.exe
Potential Corporate Privacy Violation
ET P2P Bittorrent P2P Client User-Agent (uTorrent)
2268
Carrier.exe
Potential Corporate Privacy Violation
ET P2P Bittorrent P2P Client User-Agent (uTorrent)
2772
GenericSetup.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
2772
GenericSetup.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
2772
GenericSetup.exe
Misc activity
ET INFO EXE - Served Attached HTTP
2560
uTorrent.exe
Potential Corporate Privacy Violation
ET P2P BTWebClient UA uTorrent in use
2560
uTorrent.exe
Potential Corporate Privacy Violation
ET P2P BitTorrent DHT ping request
2560
uTorrent.exe
Potential Corporate Privacy Violation
ET P2P BTWebClient UA uTorrent in use
2560
uTorrent.exe
Potential Corporate Privacy Violation
ET P2P BTWebClient UA uTorrent in use
Process
Message
GenericSetup.exe
fiÚ
GenericSetup.exe
file:resources/tis/TranslateOfferTemplate.tis(82) : warning :'async' does not contain any 'await'
GenericSetup.exe
at sciter:init-script.tis
GenericSetup.exe
GenericSetup.exe
at sciter:init-script.tis
GenericSetup.exe
GenericSetup.exe
file:resources/tis/TranslateOfferTemplate.tis(82) : warning :'async' does not contain any 'await'
GenericSetup.exe
at sciter:init-script.tis
GenericSetup.exe
file:resources/tis/TranslateOfferTemplate.tis(82) : warning :'async' does not contain any 'await'
GenericSetup.exe
Error: File not found - h2osciter:console.tis