utorrent.3.4.2.exe

uTorrent installer

LLC IT Integration

The application utorrent.3.4.2.exe by LLC IT Integration has been detected as a potentially unwanted program by 5 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. The file has been seen being downloaded from getfile.utorrent.info.
Publisher:
LLC IT Integration  (signed and verified)

Product:
uTorrent installer

Version:
3.0.0.75

MD5:
e72d07171b922fb8c61ea509961b077d

SHA-1:
04606e2c618acbfcbfdb311b4ba1ef567eebb7f4

SHA-256:
e886ed12255baea8675f9d9218b3292d8876d5ce6eee1b546945970080f998ae

Scanner detections:
5 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 1:53:04 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic
2017.0.2807

Bkav FE
W32.HfsAdware
1.3.0.6979

Dr.Web
Trojan.LoadMoney.660
9.0.1.071

ESET NOD32
Win32/LlcIt.C potentially unwanted (variant)
10.11989

IKARUS anti.virus
PUA.LlcIt
t3scan.1.9.5.0

File size:
4.8 MB (5,081,184 bytes)

Product version:
2.0.0.0

Copyright:
LLC IT Integration

Trademarks:
LLC IT Integration

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\utorrent.3.4.2.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
10/30/2014 3:00:00 AM

Valid to:
10/31/2015 2:59:59 AM

Subject:
CN=LLC IT Integration, O=LLC IT Integration, STREET="Karelskiy, 22", L=Moscow, S=Moscow region, PostalCode=127411, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
008F55DB3F65E2CBDB4562D26EEEACB96A

File PE Metadata
Compilation timestamp:
3/6/2015 3:37:36 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.0

CTPH (ssdeep):
49152:kOzroFZYGN1knG0w1ASFT0CWmImNj3AFG8AWfaFaU7TDNqLCJzNL:bzkFZYGk/mH/j3Ak8AZcUoLw

Entry address:
0x2344

Entry point:
EB, 10, 66, 62, 3A, 43, 2B, 2B, 48, 4F, 4F, 4B, 90, E9, AC, 30, 80, 00, A1, 9F, 30, 80, 00, C1, E0, 02, A3, A3, 30, 80, 00, 52, 6A, 00, E8, C9, F5, 3F, 00, 8B, D0, E8, D6, F2, 3A, 00, 5A, E8, F8, F1, 3A, 00, E8, 27, F4, 3A, 00, 6A, 00, E8, E0, B7, 3B, 00, 59, 68, 48, 30, 80, 00, 6A, 00, E8, A3, F5, 3F, 00, A3, A7, 30, 80, 00, 6A, 00, E9, F3, A5, 3B, 00, E9, 12, B8, 3B, 00, 33, C0, A0, 91, 30, 80, 00, C3, A1, A7, 30, 80, 00, C3, 60, BB, 00, 50, B0, BC, 53, 68, AD, 0B, 00, 00, C3, B9, F5, 00, 00, 00, 0B, C9...
 
[+]

Code size:
4 MB (4,202,496 bytes)

The file utorrent.3.4.2.exe has been seen being distributed by the following URL.

Remove utorrent.3.4.2.exe - Powered by Reason Core Security