Gridinsoft Logo
File Icon

The utorrent_installer.exe (uТorrеnt® Classic) File Analysis

Technical Analysis

File Name utorrent_installer.exe
File Type
Win32 EXE
Magic Bytes PE32 executable (GUI) Intel 80386, for MS Windows
SSDEEP Hash
24576:uawwKusHwEwSDMnsQMJU/628S04FSq2FKfUbpW7/tumQ1wBRR:OwREDDMkU/6tS0QpYWVumQ1wvR
Scanner Version 1.0.197.174
Database Version 2024-11-26 08:00:38 UTC

Suspicious File Detected

Detected by 10 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.

OfferCore refers to software bundlers that install adware and potentially unwanted programs. These bundlers are sources of unwanted software installations on user systems.
14%
Detection Rate
1,869,632
File Size (bytes)
10/72
Engines Detected
2024-11-26
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
32710bfba1858421cbf383e6f5c1ad8d
SHA1
313d79259c5936b8705d0fda24ff3cb59758c36b
SHA256
cb0abb633f628eeac47bec9379d698e08b4f281965277703d77fcb548b022496
SHA512
66d9316854f39cafd650d16e6ad02d3eb30e9f9aede455c91d369e94e8db6251e9997f4261dfc7f8f04b0778f6c37e3924b8bdb22e326f42c28808eda71326ef
ImpHash
40ab50289f7ef5fae60801f88d4541fc

Security Engines with Detections (10 of 72)

Cylance
Unsafe Malicious
K7AntiVirus
Adware ( 005a22c31 ) Malicious
K7GW
Adware ( 005a22c31 ) Malicious
ESET-NOD32
a variant of Win32/OfferCore.E potentially unwanted Malicious
Sophos
OfferCore (PUA) Malicious
Ikarus
PUA.OfferCore Malicious
Malwarebytes
PUP.Optional.BundleInstaller Malicious
Fortinet
Riskware/OfferCore Malicious
GData
Win32.Application.Agent.X4N4S5 Malicious
DeepInstinct
MALICIOUS Malicious
62 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: 7ec2b329075d5006effa6bbc04f44475
Fuzzy: d5b4c97d99af0de364dcff143e5b7173
dHash: f8cacecc9c69b8f8
Image Base 0x00400000
Entry Point 0x004a83bc
Compilation Time 2024-07-12 07:26:53
Checksum 0x001cec0d (Actual: 0x001cec0d)
OS Version 6.1
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
Digital Signature OK
Imports 5 libraries
kernel32, comctl32, user32, oleaut32, advapi32
Exports 2 functions
Resources 22 Resources
Sections 11 Sections

Version Information

Comments This installation was built with Inno Setup.
CompanyName
FileDescription uТorrеnt® Classic
FileVersion 3.6
LegalCopyright ©2022 RainBerry Inc. All Rights Reserved
OriginalFileName
ProductName uТorrеnt® Classic
ProductVersion 3.6
Translation 0x0000 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 677,516 bytes 677,888 bytes 6.38 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ B889D302F6FC48A904DE33D8D947AE80
.itext 0x000a7000 7,012 bytes 7,168 bytes 6.11 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 588DD0A8AB499300D3701CBD11B017D9
.data 0x000a9000 14,392 bytes 14,848 bytes 4.96 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 5C0C76E77AEF52EBC6702430837CCB6E
.bss 0x000ad000 29,272 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.idata 0x000b5000 4,076 bytes 4,096 bytes 5.02 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 627340DFF539EF99048969AA4824FB2D
.didata 0x000b6000 420 bytes 512 bytes 2.73 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE FD11C1109737963CC6CB7258063ABFD6
.edata 0x000b7000 113 bytes 512 bytes 1.31 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 7DE8CA0C7A61668A728FD3A88DC0942D
.tls 0x000b8000 24 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.rdata 0x000b9000 93 bytes 512 bytes 1.39 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D84006640084DC9F74A07C2FF9C7D656
.reloc 0x000ba000 69,544 bytes 69,632 bytes 6.71 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ A85FDA2741BD9417695DAA5FC5A9D7A5
.rsrc 0x000cb000 53,376 bytes 53,760 bytes 6.72 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 9AD3DBA767D58CA99BD4EDE2F6EAE181
Entropy Analysis Alert

2 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 22 (52,102 bytes)
Resource Type Count Total Size Percentage
RT_ICON 5 39,474 bytes
75.8%
RT_STRING 11 8,336 bytes
16%
RT_RCDATA 3 844 bytes
1.6%
RT_GROUP_ICON 1 76 bytes
0.1%
RT_VERSION 1 1,412 bytes
2.7%
RT_MANIFEST 1 1,960 bytes
3.8%

Certificate Chain Analysis

Certificate Information
Product uТorrеnt® Classic
Description uТorrеnt® Classic
File Version 3.6
Signing Date 02:20 PM 10/11/2024 (605 days ago)
Verification Status Signed
Signers Rainberry Inc; DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1; DigiCert Trusted Root G4; DigiCert
Counter Signers DigiCert Timestamp 2024; DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA; DigiCert Trusted Root G4; DigiCert
Copyright ©2022 RainBerry Inc. All Rights Reserved
Certificate Chain Summary
DigiCert Trusted Root G4 #1 Primary
Validity Period: 2022-08-01 00:00:00 → 2031-11-09 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 0E 9B 18 8E F9 D0 2D E7 EF DB 50 E2 08 40 18 5A
DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA #2 Chain
Validity Period: 2022-03-23 00:00:00 → 2037-03-22 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 07 36 37 B7 24 54 7C D8 47 AC FD 28 66 2A 5E 5B
DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 #3 Chain
Validity Period: 2021-04-29 00:00:00 → 2036-04-28 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 08 AD 40 B2 60 D2 9C 4C 9F 5E CD A9 BD 93 AE D9
DigiCert Timestamp 2024 #4 Chain
Validity Period: 2024-09-26 00:00:00 → 2035-11-25 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 0B AE 66 BC 5A BA 7F 95 87 C6 F9 E9 04 E3 33 04
Rainberry Inc #5 Chain
Validity Period: 2022-04-13 00:00:00 → 2025-04-12 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 01 86 E4 B7 44 4F 5E EB 2B 4B 7E C9 13 41 E4 B2

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. 1
    Weekly Quick Scans: Set a reminder to run a scan every Sunday. Most infections are caught within the first week, so regular checks give you peace of mind.
  2. 2
    Update Everything: Those annoying update popups exist for a reason — they patch security holes. Windows, browsers, Adobe, Java — keep them all current.
  3. 3
    Download Smart: Stick to official websites and app stores. If a "free" version of paid software sounds too good to be true, it probably comes with unwanted extras.
  4. 4
    Think Before You Click: Malware loves email attachments and "urgent" links. Even if an email looks like it's from your bank or a friend, verify suspicious requests through a different channel.
Proactive Protection
10 security engines flagged this file. Could be a real threat, or could be a false alarm — common with keygens, game trainers, and legitimate system utilities. Check if the file has a valid digital signature and whether it came from the official source.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Gridinsoft Portal
Signed in via Gridinsoft Portal · View profile
Your Score for

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware