File name:

utorrent_installer.exe

Full analysis: https://app.any.run/tasks/e9273589-1c88-4336-b20c-a62035e87878
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: January 16, 2024, 18:09:38
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

1E629A27296FCA6F356A9F0F2608465A

SHA1:

49A5FEFE3A925205017E3307FFFB541956C28026

SHA256:

F52131E0AF75B1B81D943E53E85D3E69812B6CB4082AB3FC42B731F5DFCFA956

SSDEEP:

49152:/7HecD4dnbibBlkGjpbQGkhT5hHGZ8NvuzI5B8ONLi+aSRMgtBN/ohB/ZWYnoN3a:T+cD4dngRQGWm+Z5B7u+auMSGhBxJnYq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • utorrent_installer.exe (PID: 2040)
      • utorrent_installer.exe (PID: 1392)
      • uTorrent.exe (PID: 1264)
      • utorrent_installer.tmp (PID: 492)
      • utorrent.exe (PID: 1732)
      • uTorrent.exe (PID: 1600)
    • Changes the autorun value in the registry

      • uTorrent.exe (PID: 1600)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • utorrent_installer.exe (PID: 2040)
      • utorrent_installer.exe (PID: 1392)
      • uTorrent.exe (PID: 1264)
      • utorrent_installer.tmp (PID: 492)
      • utorrent.exe (PID: 1732)
      • uTorrent.exe (PID: 1600)
    • Reads the Windows owner or organization settings

      • utorrent_installer.tmp (PID: 492)
    • Reads settings of System Certificates

      • utorrent_installer.tmp (PID: 492)
    • Reads the Internet Settings

      • utorrent_installer.tmp (PID: 492)
      • uTorrent.exe (PID: 1264)
      • utorrent.exe (PID: 1732)
      • saBSI.exe (PID: 1388)
      • uTorrent.exe (PID: 1600)
    • The process creates files with name similar to system file names

      • uTorrent.exe (PID: 1264)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • uTorrent.exe (PID: 1264)
    • Checks Windows Trust Settings

      • utorrent.exe (PID: 1732)
      • uTorrent.exe (PID: 1600)
      • saBSI.exe (PID: 1388)
    • Reads security settings of Internet Explorer

      • utorrent.exe (PID: 1732)
      • saBSI.exe (PID: 1388)
      • uTorrent.exe (PID: 1600)
    • Searches for installed software

      • uTorrent.exe (PID: 1600)
    • Changes Internet Explorer settings (feature browser emulation)

      • uTorrent.exe (PID: 1600)
    • Process requests binary or script from the Internet

      • uTorrent.exe (PID: 1600)
  • INFO

    • Checks supported languages

      • utorrent_installer.exe (PID: 2040)
      • utorrent_installer.tmp (PID: 124)
      • utorrent_installer.exe (PID: 1392)
      • wmpnscfg.exe (PID: 1044)
      • utorrent_installer.tmp (PID: 492)
      • utorrent.exe (PID: 1732)
      • uTorrent.exe (PID: 1264)
      • saBSI.exe (PID: 1388)
      • uTorrent.exe (PID: 1600)
    • Reads the computer name

      • utorrent_installer.tmp (PID: 124)
      • utorrent_installer.tmp (PID: 492)
      • wmpnscfg.exe (PID: 1044)
      • uTorrent.exe (PID: 1264)
      • uTorrent.exe (PID: 1600)
      • utorrent.exe (PID: 1732)
      • saBSI.exe (PID: 1388)
    • Create files in a temporary directory

      • utorrent_installer.exe (PID: 2040)
      • utorrent_installer.exe (PID: 1392)
      • utorrent_installer.tmp (PID: 492)
      • uTorrent.exe (PID: 1264)
      • utorrent.exe (PID: 1732)
      • uTorrent.exe (PID: 1600)
    • Reads the machine GUID from the registry

      • utorrent_installer.tmp (PID: 492)
      • uTorrent.exe (PID: 1264)
      • utorrent.exe (PID: 1732)
      • saBSI.exe (PID: 1388)
      • uTorrent.exe (PID: 1600)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 1044)
    • Creates files or folders in the user directory

      • uTorrent.exe (PID: 1264)
      • utorrent.exe (PID: 1732)
      • uTorrent.exe (PID: 1600)
    • Checks proxy server information

      • uTorrent.exe (PID: 1264)
      • utorrent.exe (PID: 1732)
      • uTorrent.exe (PID: 1600)
    • Creates files in the program directory

      • saBSI.exe (PID: 1388)
    • Application launched itself

      • msedge.exe (PID: 2732)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (65.1)
.exe | Win32 EXE PECompact compressed (generic) (24.6)
.dll | Win32 Dynamic Link Library (generic) (3.9)
.exe | Win32 Executable (generic) (2.6)
.exe | Win16/32 Executable Delphi generic (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:04:14 18:10:23+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 73216
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 3.6.0.0
ProductVersionNumber: 3.6.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: uТorrеnt® Classic
FileVersion: 3.6
LegalCopyright: ©2022 RainBerry Inc. All Rights Reserved
OriginalFileName:
ProductName: uТorrеnt® Classic
ProductVersion: 3.6
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
65
Monitored processes
24
Malicious processes
6
Suspicious processes
2

Behavior graph

Click at the process to see the details
start utorrent_installer.exe utorrent_installer.tmp no specs utorrent_installer.exe utorrent_installer.tmp wmpnscfg.exe no specs utorrent.exe utorrent.exe sabsi.exe utorrent.exe utorrentie.exe no specs utorrentie.exe no specs utorrentie.exe no specs utorrentie.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs utorrentie.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
124"C:\Users\admin\AppData\Local\Temp\is-5GQJ2.tmp\utorrent_installer.tmp" /SL5="$301AA,840711,816128,C:\Users\admin\AppData\Local\Temp\utorrent_installer.exe" C:\Users\admin\AppData\Local\Temp\is-5GQJ2.tmp\utorrent_installer.tmputorrent_installer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-5gqj2.tmp\utorrent_installer.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
492"C:\Users\admin\AppData\Local\Temp\is-NEQTC.tmp\utorrent_installer.tmp" /SL5="$501AC,840711,816128,C:\Users\admin\AppData\Local\Temp\utorrent_installer.exe" /SPAWNWND=$401B2 /NOTIFYWND=$301AA C:\Users\admin\AppData\Local\Temp\is-NEQTC.tmp\utorrent_installer.tmp
utorrent_installer.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-neqtc.tmp\utorrent_installer.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
680"C:\Users\admin\AppData\Roaming\uTorrent\updates\3.6.0_46922\utorrentie.exe" uTorrent_1600_02C34830_906232386 µTorrent4823DF041B09 uTorrent ie unpC:\Users\admin\AppData\Roaming\utorrent\updates\3.6.0_46922\utorrentie.exeuTorrent.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
LOW
Description:
WebHelper
Exit code:
3221225785
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\roaming\utorrent\updates\3.6.0_46922\utorrentie.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1044"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1220"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1292 --field-trial-handle=1332,i,17446359339119561188,3939889317234246780,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1264"C:\Users\admin\AppData\Local\Temp\is-188BA.tmp\uTorrent.exe" /S /FORCEINSTALL 1110010101111110C:\Users\admin\AppData\Local\Temp\is-188BA.tmp\uTorrent.exe
utorrent_installer.tmp
User:
admin
Company:
Rainberry, Inc.
Integrity Level:
HIGH
Description:
utorrent
Exit code:
0
Version:
3.6.0.46922
Modules
Images
c:\users\admin\appdata\local\temp\is-188ba.tmp\utorrent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1388"C:\Users\admin\AppData\Local\Temp\is-188BA.tmp\component0_extract\saBSI.exe" /affid 91082 PaidDistribution=true CountryCode=DEC:\Users\admin\AppData\Local\Temp\is-188BA.tmp\component0_extract\saBSI.exe
utorrent_installer.tmp
User:
admin
Company:
McAfee, LLC
Integrity Level:
HIGH
Description:
McAfee WebAdvisor(bootstrap installer)
Exit code:
4294967295
Version:
4,1,1,818
Modules
Images
c:\users\admin\appdata\local\temp\is-188ba.tmp\component0_extract\sabsi.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1392"C:\Users\admin\AppData\Local\Temp\utorrent_installer.exe" /SPAWNWND=$401B2 /NOTIFYWND=$301AA C:\Users\admin\AppData\Local\Temp\utorrent_installer.exe
utorrent_installer.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
uТorrеnt® Classic
Exit code:
0
Version:
3.6
Modules
Images
c:\users\admin\appdata\local\temp\utorrent_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1600"C:\Users\admin\AppData\Roaming\uTorrent\uTorrent.exe"C:\Users\admin\AppData\Roaming\utorrent\uTorrent.exe
utorrent_installer.tmp
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
MEDIUM
Description:
µTorrent
Exit code:
0
Version:
3.6.0.46922
Modules
Images
c:\users\admin\appdata\roaming\utorrent\utorrent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\users\admin\appdata\roaming\utorrent\bt_datachannel.dll
c:\windows\system32\user32.dll
1732"C:\Users\admin\AppData\Local\Temp\nsaD3E7.tmp\utorrent.exe" /S /FORCEINSTALL 1110010101111110C:\Users\admin\AppData\Local\Temp\nsaD3E7.tmp\utorrent.exe
uTorrent.exe
User:
admin
Company:
BitTorrent Inc.
Integrity Level:
HIGH
Description:
µTorrent
Exit code:
1
Version:
3.6.0.46922
Modules
Images
c:\users\admin\appdata\local\temp\nsad3e7.tmp\utorrent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\users\admin\appdata\local\temp\nsad3e7.tmp\bt_datachannel.dll
c:\windows\system32\user32.dll
Total events
9 070
Read events
8 935
Write events
129
Delete events
6

Modification events

(PID) Process:(492) utorrent_installer.tmpKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1264) uTorrent.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1264) uTorrent.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1264) uTorrent.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(1264) uTorrent.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1264) uTorrent.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1264) uTorrent.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1264) uTorrent.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1264) uTorrent.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1732) utorrent.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
18
Suspicious files
96
Text files
49
Unknown types
0

Dropped files

PID
Process
Filename
Type
1732utorrent.exeC:\Users\admin\AppData\Local\Temp\uttD9F0.tmp
MD5:
SHA256:
492utorrent_installer.tmpC:\Users\admin\AppData\Local\Temp\is-188BA.tmp\Logo.pngimage
MD5:B5D74EA9BCD66F6FA463DA4A914223D2
SHA256:4E75D7C057873B4E4A4DBC40E407A29F0DCF5DA43525884EEE6938BF62F51F2A
492utorrent_installer.tmpC:\Users\admin\AppData\Local\Temp\is-188BA.tmp\is-6FUD8.tmpimage
MD5:4CFFF8DC30D353CD3D215FD3A5DBAC24
SHA256:0C430E56D69435D8AB31CBB5916A73A47D11EF65B37D289EE7D11130ADF25856
1264uTorrent.exeC:\Users\admin\AppData\Local\Temp\nsaD3E7.tmp\System.dllexecutable
MD5:CFF85C549D536F651D4FB8387F1976F2
SHA256:8DC562CDA7217A3A52DB898243DE3E2ED68B80E62DDCB8619545ED0B4E7F65A8
492utorrent_installer.tmpC:\Users\admin\AppData\Local\Temp\is-188BA.tmp\WebAdvisor.pngimage
MD5:4CFFF8DC30D353CD3D215FD3A5DBAC24
SHA256:0C430E56D69435D8AB31CBB5916A73A47D11EF65B37D289EE7D11130ADF25856
1264uTorrent.exeC:\Users\admin\AppData\Local\Temp\nsaD3E7.tmp\utorrent.exeexecutable
MD5:C020799E4AB5E3266AD6A6E20127E948
SHA256:A3EB4CCB3265575ECAD27583BA614C5D4C4C7436948EB1CFB0B6D326444F445D
492utorrent_installer.tmpC:\Users\admin\AppData\Local\Temp\is-188BA.tmp\is-65HQR.tmpcompressed
MD5:CD9C77BC5840AF008799985F397FE1C3
SHA256:26D7704B540DF18E2BCCD224DF677061FFB9F03CAB5B3C191055A84BF43A9085
492utorrent_installer.tmpC:\Users\admin\AppData\Local\Temp\is-188BA.tmp\uTorrent.exeexecutable
MD5:3839CF1C5D36C519D906EFB02F1CE926
SHA256:A874053DF1DD29288B9F3518B8E14FE6BE99728FD86AF9FB070A02C997C87731
492utorrent_installer.tmpC:\Users\admin\AppData\Local\Temp\is-188BA.tmp\is-314IV.tmpexecutable
MD5:3839CF1C5D36C519D906EFB02F1CE926
SHA256:A874053DF1DD29288B9F3518B8E14FE6BE99728FD86AF9FB070A02C997C87731
492utorrent_installer.tmpC:\Users\admin\AppData\Local\Temp\is-188BA.tmp\component0compressed
MD5:CD9C77BC5840AF008799985F397FE1C3
SHA256:26D7704B540DF18E2BCCD224DF677061FFB9F03CAB5B3C191055A84BF43A9085
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
30
TCP/UDP connections
253
DNS requests
62
Threats
20

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
492
utorrent_installer.tmp
HEAD
200
67.215.238.66:80
http://download-new.utorrent.com/endpoint/utorrent/os/riserollout/track/stable
unknown
unknown
1600
uTorrent.exe
POST
200
44.219.106.198:80
http://i-29.b-46922.ut.bench.utorrent.com/e?i=29
unknown
binary
21 b
unknown
1600
uTorrent.exe
POST
200
44.219.106.198:80
http://i-29.b-46922.ut.bench.utorrent.com/e?i=29
unknown
binary
21 b
unknown
492
utorrent_installer.tmp
GET
200
67.215.238.66:80
http://download-new.utorrent.com/endpoint/utorrent/os/riserollout/track/stable
unknown
executable
3.71 Mb
unknown
1264
uTorrent.exe
POST
200
52.202.186.203:80
http://i-6000.b-46922.ut.bench.utorrent.com/e?i=6000
unknown
binary
21 b
unknown
1732
utorrent.exe
GET
200
67.215.246.203:80
http://update.utorrent.com/installstats.php?cl=uTorrent&v=113358666&h=Cf6tvKqYUGU7aVis&w=1DB10106&bu=0&pr=0&cmp=0&ocmp=0&showinstall&pid=1732&cau=0&lunv=0&au=0&view=win32
unknown
unknown
1732
utorrent.exe
GET
200
67.215.246.203:80
http://update.utorrent.com/installstats.php?cl=uTorrent&v=113358666&h=Cf6tvKqYUGU7aVis&w=1DB10106&bu=0&pr=0&cmp=0&ocmp=0&installresult&pid=1732&cau=0&lunv=0&installresult=0&exit=1&au=0&ic=1&view=win32
unknown
unknown
1264
uTorrent.exe
POST
52.202.186.203:80
http://i-6000.b-46922.ut.bench.utorrent.com/e?i=6000
unknown
unknown
1600
uTorrent.exe
GET
178.79.242.181:80
http://apps.bittorrent.com/utorrent-onboarding/player.btapp
unknown
unknown
1600
uTorrent.exe
POST
200
44.219.106.198:80
http://i-21.b-46922.ut.bench.utorrent.com/e?i=21
unknown
binary
21 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
492
utorrent_installer.tmp
18.66.121.36:443
d25ed8nduj7yxj.cloudfront.net
AMAZON-02
US
unknown
492
utorrent_installer.tmp
67.215.238.66:80
download-new.utorrent.com
ASN-QUADRANET-GLOBAL
US
unknown
1264
uTorrent.exe
52.202.186.203:80
i-6000.b-46922.ut.bench.utorrent.com
AMAZON-AES
US
unknown
1732
utorrent.exe
67.215.246.203:80
update.utorrent.com
ASN-QUADRANET-GLOBAL
US
unknown
492
utorrent_installer.tmp
18.66.121.96:443
d25ed8nduj7yxj.cloudfront.net
AMAZON-02
US
unknown
1388
saBSI.exe
35.165.29.28:443
analytics.apis.mcafee.com
AMAZON-02
US
unknown
1388
saBSI.exe
23.50.131.210:443
sadownload.mcafee.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
d25ed8nduj7yxj.cloudfront.net
  • 18.66.121.36
  • 18.66.121.96
  • 18.66.121.12
  • 18.66.121.145
unknown
download-new.utorrent.com
  • 67.215.238.66
whitelisted
i-6000.b-46922.ut.bench.utorrent.com
  • 52.202.186.203
  • 52.0.245.199
  • 52.203.139.100
  • 52.44.67.51
  • 52.4.173.144
  • 52.2.217.107
  • 44.219.211.183
  • 52.45.177.180
unknown
router.bittorrent.com
  • 67.215.246.10
shared
router.utorrent.com
  • 82.221.103.244
whitelisted
update.utorrent.com
  • 67.215.246.203
whitelisted
analytics.apis.mcafee.com
  • 35.165.29.28
  • 52.41.182.30
  • 54.213.186.82
  • 35.163.5.137
  • 52.35.189.215
  • 54.191.51.254
  • 35.155.163.235
  • 52.88.235.102
unknown
sadownload.mcafee.com
  • 23.50.131.210
  • 23.50.131.197
whitelisted
i-21.b-46922.ut.bench.utorrent.com
  • 44.219.106.198
  • 44.209.4.93
  • 44.215.174.64
  • 52.0.245.199
  • 52.203.139.100
  • 52.23.25.49
  • 44.219.211.183
  • 52.4.173.144
unknown
go.microsoft.com
  • 23.213.166.81
whitelisted

Threats

PID
Process
Class
Message
492
utorrent_installer.tmp
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] InnoSetup Installer
492
utorrent_installer.tmp
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
492
utorrent_installer.tmp
Misc activity
ET INFO EXE - Served Attached HTTP
1264
uTorrent.exe
Potentially Bad Traffic
ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla))
Potential Corporate Privacy Violation
ET P2P Bittorrent P2P Client User-Agent (uTorrent)
1732
utorrent.exe
Potential Corporate Privacy Violation
ET P2P Bittorrent P2P Client User-Agent (uTorrent)
1264
uTorrent.exe
Potentially Bad Traffic
ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla))
1600
uTorrent.exe
Potential Corporate Privacy Violation
ET P2P BTWebClient UA uTorrent in use
1600
uTorrent.exe
Potential Corporate Privacy Violation
ET P2P BitTorrent DHT ping request
1600
uTorrent.exe
Potential Corporate Privacy Violation
ET P2P BTWebClient UA uTorrent in use
Process
Message
saBSI.exe
NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\is-188BA.tmp\component0_extract\saBSI.exe loading C:\Users\admin\AppData\Local\Temp\is-188BA.tmp\component0_extract\mfeaaca.dll, WinVerifyTrust failed with 80092003
saBSI.exe
NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\is-188BA.tmp\component0_extract\saBSI.exe loading C:\Users\admin\AppData\Local\Temp\is-188BA.tmp\component0_extract\mfeaaca.dll, WinVerifyTrust failed with 80092003
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in current directory
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in current directory
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in EXE directory
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in current directory
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in current directory
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in current directory
saBSI.exe
NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\is-188BA.tmp\component0_extract\saBSI.exe loading C:\Users\admin\AppData\Local\Temp\is-188BA.tmp\component0_extract\mfeaaca.dll, WinVerifyTrust failed with 80092003
saBSI.exe
NCPrivateLoadAndValidateMPTDll: Looking in EXE directory