URL:

https://webcompanion.com/nano_download.php?savename=Setup.exe&partner=IN220101&nonadmin&direct&tych&campaign=20290905988

Full analysis: https://app.any.run/tasks/26c6006a-b222-4293-aac2-e2aec036aa53
Verdict: Malicious activity
Analysis date: December 26, 2023, 15:17:59
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

01DFD6EFA7FBEF0BA3AC0ED89B7000E9

SHA1:

5F7A0EAB448CB9B2774EB3DAD9F7FBFA8EA7ED6C

SHA256:

269B6383DA6DBDD3B17366F29F1193E6DBA14F5946D70DB22A0E7E7C7CB8E92D

SSDEEP:

3:N8RmgDKQiKqJLJleLIUA2VkmVEXynMTEzxo3NPoEMIB2VTd:2Qg+tXJDapVknXynMTyo3NPtB2td

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Steals credentials from Web Browsers

      • WebCompanion.exe (PID: 2760)
      • WebCompanion.exe (PID: 2800)
      • WebCompanion.exe (PID: 3640)
    • Changes the autorun value in the registry

      • WebCompanion.exe (PID: 2800)
    • Actions looks like stealing of personal data

      • WebCompanion.exe (PID: 3640)
      • WebCompanion.exe (PID: 2800)
      • WebCompanion.exe (PID: 2760)
  • SUSPICIOUS

    • Searches for installed software

      • WebCompanion-Installer.exe (PID: 1316)
      • WebCompanion.exe (PID: 2760)
      • WebCompanion.exe (PID: 2800)
      • WebCompanion.exe (PID: 3640)
    • Reads settings of System Certificates

      • WebCompanion-Installer.exe (PID: 1316)
      • WebCompanion.exe (PID: 2760)
      • WebCompanion.exe (PID: 2800)
      • WebCompanion.exe (PID: 3640)
    • Reads the Internet Settings

      • WebCompanion-Installer.exe (PID: 1316)
      • WebCompanion.exe (PID: 2760)
      • WebCompanion.exe (PID: 2800)
      • WebCompanion.exe (PID: 3640)
    • The process creates files with name similar to system file names

      • WebCompanion-Installer.exe (PID: 1316)
    • Starts CMD.EXE for commands execution

      • WebCompanion-Installer.exe (PID: 1316)
    • Changes internet zones settings

      • WebCompanion-Installer.exe (PID: 1316)
    • Suspicious use of NETSH.EXE

      • cmd.exe (PID: 2464)
    • Checks Windows Trust Settings

      • WebCompanion.exe (PID: 2760)
      • WebCompanion.exe (PID: 2800)
      • WebCompanion.exe (PID: 3640)
    • Reads security settings of Internet Explorer

      • WebCompanion.exe (PID: 2760)
      • WebCompanion.exe (PID: 2800)
      • WebCompanion.exe (PID: 3640)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 2184)
      • chrome.exe (PID: 2672)
    • Checks supported languages

      • Setup.exe (PID: 1584)
      • WebCompanion-Installer.exe (PID: 1316)
      • WebCompanion.exe (PID: 2760)
      • WebCompanion.exe (PID: 2800)
      • WebCompanion.exe (PID: 3640)
    • The process uses the downloaded file

      • iexplore.exe (PID: 2184)
      • chrome.exe (PID: 268)
      • chrome.exe (PID: 3852)
      • chrome.exe (PID: 2344)
    • Drops the executable file immediately after the start

      • iexplore.exe (PID: 1056)
      • Setup.exe (PID: 1584)
      • iexplore.exe (PID: 2184)
      • WebCompanion-Installer.exe (PID: 1316)
    • Reads the computer name

      • WebCompanion-Installer.exe (PID: 1316)
      • WebCompanion.exe (PID: 2760)
      • WebCompanion.exe (PID: 2800)
      • WebCompanion.exe (PID: 3640)
    • Create files in a temporary directory

      • Setup.exe (PID: 1584)
      • WebCompanion-Installer.exe (PID: 1316)
    • Reads the machine GUID from the registry

      • WebCompanion-Installer.exe (PID: 1316)
      • WebCompanion.exe (PID: 2760)
      • WebCompanion.exe (PID: 2800)
      • WebCompanion.exe (PID: 3640)
    • Reads Environment values

      • WebCompanion-Installer.exe (PID: 1316)
      • WebCompanion.exe (PID: 2760)
      • WebCompanion.exe (PID: 2800)
      • WebCompanion.exe (PID: 3640)
    • The process drops C-runtime libraries

      • WebCompanion-Installer.exe (PID: 1316)
    • Creates files or folders in the user directory

      • WebCompanion-Installer.exe (PID: 1316)
      • WebCompanion.exe (PID: 2760)
      • WebCompanion.exe (PID: 2800)
      • WebCompanion.exe (PID: 3640)
    • Drops 7-zip archiver for unpacking

      • WebCompanion-Installer.exe (PID: 1316)
    • Process drops legitimate windows executable

      • WebCompanion-Installer.exe (PID: 1316)
    • Creates files in the program directory

      • WebCompanion.exe (PID: 2760)
    • Reads product name

      • WebCompanion.exe (PID: 2760)
      • WebCompanion.exe (PID: 2800)
      • WebCompanion.exe (PID: 3640)
    • Manual execution by a user

      • WebCompanion.exe (PID: 3640)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
62
Monitored processes
25
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe no specs iexplore.exe setup.exe no specs webcompanion-installer.exe cmd.exe no specs netsh.exe no specs webcompanion.exe webcompanion.exe chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs webcompanion.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
268"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --mojo-platform-channel-handle=804 --field-trial-handle=1304,i,9214444064638014091,17144052900330605315,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1020"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --mojo-platform-channel-handle=3656 --field-trial-handle=1304,i,9214444064638014091,17144052900330605315,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1056"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2184 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
1288"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=700 --field-trial-handle=1304,i,9214444064638014091,17144052900330605315,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1316.\WebCompanion-Installer.exe --savename=Setup.exe --partner=IN220101 --nonadmin --direct --tych --campaign=20290905988 --version=11.908.5.907C:\Users\admin\AppData\Local\Temp\7zS036B873E\WebCompanion-Installer.exe
Setup.exe
User:
admin
Company:
Lavasoft
Integrity Level:
MEDIUM
Description:
Web Companion
Exit code:
0
Version:
11.908.5.907
Modules
Images
c:\users\admin\appdata\local\temp\7zs036b873e\webcompanion-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1584"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\Setup.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\Setup.exeiexplore.exe
User:
admin
Company:
Lavasoft
Integrity Level:
MEDIUM
Description:
Web Companion Installer
Exit code:
0
Version:
11.908.5.907
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\po2hn1x2\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1852netsh http add urlacl url=http://+:9007/ user=EveryoneC:\Windows\System32\netsh.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Network Command Shell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
2184"C:\Program Files\Internet Explorer\iexplore.exe" "https://webcompanion.com/nano_download.php?savename=Setup.exe&partner=IN220101&nonadmin&direct&tych&campaign=20290905988"C:\Program Files\Internet Explorer\iexplore.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2344"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --mojo-platform-channel-handle=3388 --field-trial-handle=1304,i,9214444064638014091,17144052900330605315,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2364"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=1548 --field-trial-handle=1304,i,9214444064638014091,17144052900330605315,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
38 674
Read events
38 397
Write events
274
Delete events
3

Modification events

(PID) Process:(2184) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(2184) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(2184) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(2184) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2184) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2184) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2184) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2184) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2184) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2184) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
95
Suspicious files
145
Text files
98
Unknown types
0

Dropped files

PID
Process
Filename
Type
1056iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_28DEA62A0AE77228DD387E155AD0BA27der
MD5:D0294F638C35E03DFA2B41D59E700A86
SHA256:838690A2F6CB1EF7B337D73588F8747AB07CA04015AE5961BB17BAB09CC98997
1056iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\Setup[1].exeexecutable
MD5:69BCC9472CBAD242AD4A5D665A414637
SHA256:8D778E00D466A7554C3D84CDC9F019D2772398421613863C96A84F2D2FE67924
2184iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\Setup.exe.5fuvru2.partial:Zone.Identifiertext
MD5:FBCCF14D504B7B2DBCB5A5BDA75BD93B
SHA256:EACD09517CE90D34BA562171D15AC40D302F0E691B439F91BE1B6406E25F5913
2184iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF975B464391691780.TMPbinary
MD5:2DA88DDA28CA482A9FDBBBE981067B87
SHA256:5800A74FFD016BB3C111CE821F5B4B66BD353D6B6E4D9B710751EBBB2D8AD632
1056iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:E5F774A78EDDD0AE1D3792B5626A0C47
SHA256:0E67CA25F4945D47093B45E14CC1E7C25B6216A157B4DE1D1382DDA3E3190AE1
1056iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
1056iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_28DEA62A0AE77228DD387E155AD0BA27binary
MD5:15AE9564D95964C220AE86275F42B3B9
SHA256:7D466030AE5522F2A1C4B2AA3BFF92534E1676DB144478B7F829950B9529CC2C
1584Setup.exeC:\Users\admin\AppData\Local\Temp\7zS036B873E\es-ES\WebCompanion-Installer.resources.dllexecutable
MD5:EA8579573DEBD7089FBFC379084EC6DE
SHA256:D769B5A9F451BAD20CE9D640B07D659C13E9622DE7A5E943F1EA39012D986CB8
1584Setup.exeC:\Users\admin\AppData\Local\Temp\7zS036B873E\it-IT\WebCompanion-Installer.resources.dllexecutable
MD5:8EBA4FD645732D43A197FCFC2A3EFDAE
SHA256:AE539AE8FF586147AA4831E3235BAE7803903FF328631D2242C57EE0B192DFF5
1584Setup.exeC:\Users\admin\AppData\Local\Temp\7zS036B873E\WebCompanion-Installer.exe.configxml
MD5:795C7FE69D7D105B5FE997366A4EA7CE
SHA256:16C8C66E265F4120F8507E2DF0FE0545A5284A905BBBDB1029A5AF8F27017417
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
13
TCP/UDP connections
61
DNS requests
73
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1056
iexplore.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?6243fee378382ed7
unknown
compressed
4.66 Kb
unknown
1056
iexplore.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f6bf34dbb61e71d7
unknown
compressed
4.66 Kb
unknown
1056
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D
unknown
binary
1.47 Kb
unknown
1080
svchost.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?34275567a5b520f7
unknown
unknown
1316
WebCompanion-Installer.exe
GET
200
104.17.9.52:80
http://geo.lavasoft.com/
unknown
binary
50 b
unknown
1316
WebCompanion-Installer.exe
GET
200
104.17.9.52:80
http://geo.lavasoft.com/
unknown
binary
50 b
unknown
2760
WebCompanion.exe
GET
200
104.17.9.52:80
http://geo.lavasoft.com/
unknown
binary
50 b
unknown
2760
WebCompanion.exe
GET
200
64.18.87.82:80
http://wc-partners.lavasoft.com/Partner.svc/GetPartnerInfo?partner=IN220101
unknown
binary
197 b
unknown
2760
WebCompanion.exe
GET
200
64.18.87.82:80
http://wc-partners.lavasoft.com/Partner.svc/GetPartnerInfo?partner=IN220101_ac
unknown
binary
205 b
unknown
2760
WebCompanion.exe
GET
200
64.18.87.82:80
http://wc-partners.lavasoft.com/Partner.svc/GetPartnerInfo?partner=IN220101_wb
unknown
binary
205 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1056
iexplore.exe
104.18.212.25:443
webcompanion.com
CLOUDFLARENET
unknown
4
System
192.168.100.255:138
whitelisted
1056
iexplore.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
1056
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1316
WebCompanion-Installer.exe
104.17.9.52:80
geo.lavasoft.com
CLOUDFLARENET
shared
1316
WebCompanion-Installer.exe
104.17.9.52:443
geo.lavasoft.com
CLOUDFLARENET
shared
1316
WebCompanion-Installer.exe
104.18.27.149:443
flwadw.com
CLOUDFLARENET
shared
1080
svchost.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted

DNS requests

Domain
IP
Reputation
webcompanion.com
  • 104.18.212.25
  • 104.18.211.25
unknown
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
geo.lavasoft.com
  • 104.17.9.52
  • 104.17.8.52
unknown
featureflags.lavasoft.com
  • 104.17.9.52
  • 104.17.8.52
unknown
flwadw.com
  • 104.18.27.149
  • 104.18.26.149
unknown
wcdownloadercdn.lavasoft.com
  • 104.17.8.52
  • 104.17.9.52
whitelisted
wc-partners.lavasoft.com
  • 64.18.87.82
  • 64.18.87.81
whitelisted
clientservices.googleapis.com
  • 216.58.212.163
whitelisted
accounts.google.com
  • 108.177.15.84
shared

Threats

No threats detected
Process
Message
WebCompanion-Installer.exe
Failed to OpenWcfHost: System.ServiceModel.AddressAccessDeniedException: HTTP could not register URL http://+:9008/webcompanion/. Your process does not have access rights to this namespace (see http://go.microsoft.com/fwlink/?LinkId=70353 for details). ---> System.Net.HttpListenerException: Access is denied at System.Net.HttpListener.AddAllPrefixes() at System.Net.HttpListener.Start() at System.ServiceModel.Channels.SharedHttpTransportManager.OnOpen() --- End of inner exception stack trace --- at System.ServiceModel.Channels.SharedHttpTransportManager.OnOpen() at System.ServiceModel.Channels.TransportManager.Open(TransportChannelListener channelListener) at System.ServiceModel.Channels.TransportManagerContainer.Open(SelectTransportManagersCallback selectTransportManagerCallback) at System.ServiceModel.Channels.TransportChannelListener.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.HttpChannelListener`1.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at System.ServiceModel.Dispatcher.ChannelDispatcher.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at System.ServiceModel.ServiceHostBase.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at WebCompanionInstaller.App.OpenInstallerWcfHost()
WebCompanion-Installer.exe
Detecting windows culture
WebCompanion-Installer.exe
Preparing request for featureflag: {"Geo":"DE","Partner":"IN220101","Campaign":"20290905988","InstallDate":"20231226","TriggerType":"install","TriggerEvent":"installer","Version":"11.908.5.907","featurewp":true,"featureal":true}
WebCompanion-Installer.exe
Getting response from featureflag: [{"sectionCode":"WAC","code":"WAC","configuration":"{\"Icon\": \"https://webcompanion.com/images/favicon.ico\", \"AppName\": \"Web Companion\", \"Settings\": [\"WCAutoUpdate\", \"EnableGranularity\", \"PostRunV2Action\", \"PostRunTimerAction\", \"EnableTelemetryScan\", \"EnableWebProtection\", \"EnableDynamicNotification\"], \"CompanyName\": \"Lavasoft\", \"ConfigVersion\": \"v1\", \"CurrentVersion\": \"9.3.0\"}","targetId":301},{"sectionCode":"WFAI","code":"WCP","configuration":"{\"Version\": \"3.0.2.12\", \"FilePath\": \"https://rt.webcompanion.com/notifications/download/rt/dci/latest/Webprotection.zip\", \"BlackList\": \"https://acs.lavasoft.com/api/v2/url/blacklist\", \"WhiteList\": \"https://acs.lavasoft.com/api/v2/url/permanentwhitelist\", \"DisplayName\": \"Web Protection\", \"FeatureName\": \"WebProtection\"}","targetId":241}]
WebCompanion-Installer.exe
12/26/2023 3:18:25 PM :-> Start
WebCompanion-Installer.exe
Failed to report progress in SendPostRequest: System.Net.WebException: The remote server returned an error: (400) Bad Request. at System.Net.HttpWebRequest.GetResponse() at WebCompanionInstaller.Utils.RestUtils.SendPostRequest(String url, String body)
WebCompanion-Installer.exe
12/26/2023 3:18:29 PM :-> Starting installer 11.908.5.907 with: .\WebCompanion-Installer.exe --savename=Setup.exe --partner=IN220101 --nonadmin --direct --tych --campaign=20290905988 --version=11.908.5.907, Run as admin: False
WebCompanion-Installer.exe
Preparing for installing Web Companion
WebCompanion-Installer.exe
12/26/2023 3:18:30 PM :-> Generating Machine and Install Id ...
WebCompanion-Installer.exe
12/26/2023 3:18:30 PM :-> Machine Id and Install Id has been generated