Page 1 of 1

Weird connection

Posted: Fri Feb 05, 2021 7:09 pm
by Baarsik
Why is qBitTorrent making a strange connection on startup? My antivirus detected and blocked this action. Here is the log:

-Website Information-
Category: Trojan horse
Domain:
IP address: 202.164.139.181
Port: 61013
Type: Outgoing traffic
File: C: \ Program Files \ qBittorrent \ qbittorrent.exe

Re: Weird connection

Posted: Sat Feb 13, 2021 10:39 pm
by busthead
My qBittorrent has also been exhibiting strange behavior.

v4.3.2 and v4.3.3 (at least) may be vulnerable to malicious injection or compromised from the source (unlikely?).

The IP address you provided appears to redirect to 181.139.164.202 which is a dynamically assigned address is Columbia, likely a compromised user system that is part of a bot/command and control net.

May I ask what AV solution detected the trojan horse?

If possible can you please run 'fciv -md5 qbittorrent.exe' at a command line without the quotes and post the output here?

Re: Weird connection

Posted: Mon Feb 22, 2021 9:01 pm
by Nemo
In my years of torrenting (since the beginning..) I've probably connected to millions of people worldwide.. Your antivirus is acting weird thats the issue. Or prove it otherwise.

Re: Weird connection

Posted: Tue Feb 23, 2021 7:24 pm
by busthead
The absence of evidence is not evidence of absence.

It's likely @Baarsik anti-malware software functioning as it should and that a particular torrent, within qBittorrent, is the source of the malicious activity, not qBittorrent itself.

Re: Weird connection

Posted: Wed Feb 24, 2021 9:56 am
by Peter
What kind of AV software y'all are running?
I've been using Defender / ESET NOD / Avast but have never seen such messages... oO

Re: Weird connection

Posted: Fri Feb 26, 2021 3:40 am
by busthead
Host antimalware is Malwarebytes and network IPS is Sophos. Both detected malicious connections from qBt.