download:

WcInstaller.exe

Full analysis: https://app.any.run/tasks/0355a3ee-a928-4a51-8849-b4abd013df26
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: November 18, 2021, 21:21:22
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
installer
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

EEEBFBDCA0B69687668117BC2C8F725D

SHA1:

DD36613A2D5453FBB4F50F7B16F00540EE26F7EF

SHA256:

2C3AF025BA5EBBD5B5138CD86D8A635521DFA3A83C30BCA6F478A80BA4B5F1CC

SSDEEP:

12288:zG5knZfFKessImXPiASR2ru2sjNkEpb1A17toXPwvgs:zG50ZfFKd6XRSR2h6duufi

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes settings of System certificates

      • WebCompanionInstaller.exe (PID: 3200)
    • Application was dropped or rewritten from another process

      • WebCompanionInstaller.exe (PID: 3200)
      • WcInstaller.exe (PID: 1396)
      • WebCompanionInstaller.exe (PID: 1340)
    • Loads dropped or rewritten executable

      • WebCompanionInstaller.exe (PID: 3200)
      • WebCompanionInstaller.exe (PID: 1340)
    • Drops executable file immediately after starts

      • WcInstaller.exe (PID: 2832)
      • WcInstaller.exe (PID: 1396)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WcInstaller.exe (PID: 2832)
      • WebCompanionInstaller.exe (PID: 3200)
      • WcInstaller.exe (PID: 1396)
    • Reads Environment values

      • WebCompanionInstaller.exe (PID: 3200)
      • WebCompanionInstaller.exe (PID: 1340)
    • Creates files in the program directory

      • WebCompanionInstaller.exe (PID: 3200)
    • Drops a file with a compile date too recent

      • WebCompanionInstaller.exe (PID: 3200)
      • WcInstaller.exe (PID: 2832)
      • WcInstaller.exe (PID: 1396)
    • Creates files in the Windows directory

      • WebCompanionInstaller.exe (PID: 3200)
    • Checks supported languages

      • WcInstaller.exe (PID: 1396)
      • WcInstaller.exe (PID: 2832)
      • WebCompanionInstaller.exe (PID: 1340)
      • PresentationFontCache.exe (PID: 3172)
      • WebCompanionInstaller.exe (PID: 3200)
    • Drops a file that was compiled in debug mode

      • WcInstaller.exe (PID: 1396)
      • WcInstaller.exe (PID: 2832)
    • Reads the computer name

      • WebCompanionInstaller.exe (PID: 1340)
      • PresentationFontCache.exe (PID: 3172)
      • WebCompanionInstaller.exe (PID: 3200)
    • Executed as Windows Service

      • PresentationFontCache.exe (PID: 3172)
    • Searches for installed software

      • WebCompanionInstaller.exe (PID: 3200)
    • Adds / modifies Windows certificates

      • WebCompanionInstaller.exe (PID: 3200)
  • INFO

    • Reads settings of System Certificates

      • WebCompanionInstaller.exe (PID: 1340)
      • WebCompanionInstaller.exe (PID: 3200)
    • Checks Windows Trust Settings

      • WebCompanionInstaller.exe (PID: 1340)
      • WebCompanionInstaller.exe (PID: 3200)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (36.8)
.exe | Win32 Executable MS Visual C++ (generic) (26.6)
.exe | Win64 Executable (generic) (23.6)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2011:04:18 20:54:06+02:00
PEType: PE32
LinkerVersion: 6
CodeSize: 104448
InitializedDataSize: 60416
UninitializedDataSize: -
EntryPoint: 0x148d4
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 8.9.0.371
ProductVersionNumber: 8.9.0.371
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileVersion: 8.9.0.371
ProductVersion: 8.9.0.371
CompanyName: Lavasoft
FileDescription: Web Companion Installer
InternalName: Installer.exe
LegalCopyright: c Lavasoft Limited. All Rights Reserved.
OriginalFileName: Installer.exe
ProductName: Web Companion Installer
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
6
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start wcinstaller.exe webcompanioninstaller.exe wcinstaller.exe webcompanioninstaller.exe presentationfontcache.exe no specs wcinstaller.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1340.\WebCompanionInstaller.exe --prod --nanouniqueid=1637270496510 --prodC:\Users\admin\AppData\Local\Temp\7zS475F57F0\WebCompanionInstaller.exe
WcInstaller.exe
User:
admin
Company:
Lavasoft
Integrity Level:
HIGH
Description:
Web Companion
Exit code:
0
Version:
7.0.2417.4248
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\mscoree.dll
c:\users\admin\appdata\local\temp\7zs475f57f0\webcompanioninstaller.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1396"C:\Users\admin\AppData\Local\Temp\wctmp_139114680\WcInstaller.exe" --nanouniqueid=1637270496510 --prodC:\Users\admin\AppData\Local\Temp\wctmp_139114680\WcInstaller.exe
WebCompanionInstaller.exe
User:
admin
Company:
Lavasoft
Integrity Level:
HIGH
Description:
Web Companion Installer
Exit code:
0
Version:
7.0.2417.4248
Modules
Images
c:\users\admin\appdata\local\temp\wctmp_139114680\wcinstaller.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1636"C:\Users\admin\AppData\Local\Temp\WcInstaller.exe" C:\Users\admin\AppData\Local\Temp\WcInstaller.exeExplorer.EXE
User:
admin
Company:
Lavasoft
Integrity Level:
MEDIUM
Description:
Web Companion Installer
Exit code:
3221226540
Version:
8.9.0.371
Modules
Images
c:\users\admin\appdata\local\temp\wcinstaller.exe
c:\windows\system32\ntdll.dll
2832"C:\Users\admin\AppData\Local\Temp\WcInstaller.exe" C:\Users\admin\AppData\Local\Temp\WcInstaller.exe
Explorer.EXE
User:
admin
Company:
Lavasoft
Integrity Level:
HIGH
Description:
Web Companion Installer
Exit code:
0
Version:
8.9.0.371
Modules
Images
c:\users\admin\appdata\local\temp\wcinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3172C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exeC:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exeservices.exe
User:
LOCAL SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
PresentationFontCache.exe
Exit code:
0
Version:
3.0.6920.4902 built by: NetFXw7
Modules
Images
c:\windows\microsoft.net\framework\v3.0\wpf\presentationfontcache.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3200.\WebCompanionInstaller.exe --prodC:\Users\admin\AppData\Local\Temp\7zS01BB0990\WebCompanionInstaller.exe
WcInstaller.exe
User:
admin
Company:
Lavasoft
Integrity Level:
HIGH
Description:
Web Companion
Exit code:
0
Version:
8.9.0.371
Modules
Images
c:\users\admin\appdata\local\temp\7zs01bb0990\webcompanioninstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
12 491
Read events
12 443
Write events
48
Delete events
0

Modification events

(PID) Process:(3200) WebCompanionInstaller.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3200) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4
Operation:writeName:Blob
Value:
0400000001000000100000004BE2C99196650CF40E5A9392A00AFEB27F000000010000002C000000302A060A2B0601040182370A030406082B0601050507030506082B0601050507030606082B06010505070307090000000100000054000000305206082B0601050507030206082B06010505070303060A2B0601040182370A030406082B0601050507030406082B0601050507030606082B0601050507030706082B0601050507030106082B060105050703080F0000000100000020000000FDE5F2D9CE2026E1E10064C0A468C9F355B90ACF85BAF5CE6F52D4016837FD940300000001000000140000008CF427FD790C3AD166068DE81E57EFBB932272D41D0000000100000010000000521B5F4582C1DCAAE381B05E37CA2D341400000001000000140000006A72267AD01EEF7DE73B6951D46C8D9F901266AB0B000000010000001800000045006E00740072007500730074002E006E0065007400000062000000010000002000000043DF5774B03E7FEF5FE40D931A7BEDF1BB2E6B42738C4E6D3841103D3AA7F339190000000100000010000000FA46CE7CBB85CFB4310075313A09EE05530000000100000041000000303F3020060A6086480186FA6C0A010230123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C07E000000010000000800000000C001B39667D6012000000001000000420400003082043E30820326A00302010202044A538C28300D06092A864886F70D01010B05003081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D204732301E170D3039303730373137323535345A170D3330313230373137353535345A3081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D20473230820122300D06092A864886F70D01010105000382010F003082010A0282010100BA84B672DB9E0C6BE299E93001A776EA32B895411AC9DA614E5872CFFEF68279BF7361060AA527D8B35FD3454E1C72D64E32F2728A0FF78319D06A808000451EB0C7E79ABF1257271CA3682F0A87BD6A6B0E5E65F31C77D5D4858D7021B4B332E78BA2D5863902B1B8D247CEE4C949C43BA7DEFB547D57BEF0E86EC279B23A0B55E250981632135C2F7856C1C294B3F25AE4279A9F24D7C6ECD09B2582E3CCC2C445C58C977A066B2A119FA90A6E483B6FDBD4111942F78F07BFF5535F9C3EF4172CE669AC4E324C6277EAB7E8E5BB34BC198BAE9C51E7B77EB553B13322E56DCF703C1AFAE29B67B683F48DA5AF624C4DE058AC64341203F8B68D946324A4710203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E041604146A72267AD01EEF7DE73B6951D46C8D9F901266AB300D06092A864886F70D01010B05000382010100799F1D96C6B6793F228D87D3870304606A6B9A2E59897311AC43D1F513FF8D392BC0F2BD4F708CA92FEA17C40B549ED41B9698333CA8AD62A20076AB59696E061D7EC4B9448D98AF12D461DB0A194647F3EBF763C1400540A5D2B7F4B59A36BFA98876880455042B9C877F1A373C7E2DA51AD8D4895ECABDAC3D6CD86DAFD5F3760FCD3B8838229D6C939AC43DBF821B653FA60F5DAAFCE5B215CAB5ADC6BC3DD084E8EA0672B04D393278BF3E119C0BA49D9A21F3F09B0B3078DBC1DC8743FEBC639ACAC5C21CC9C78DFF3B125808E6B63DEC7A2C4EFB8396CE0C3C69875473A473C293FF5110AC155401D8FC05B189A17F74839A49D7DC4E7B8A486F8B45F6
(PID) Process:(3200) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4
Operation:writeName:Blob
Value:
5C0000000100000004000000000800007E000000010000000800000000C001B39667D601530000000100000041000000303F3020060A6086480186FA6C0A010230123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C0190000000100000010000000FA46CE7CBB85CFB4310075313A09EE0562000000010000002000000043DF5774B03E7FEF5FE40D931A7BEDF1BB2E6B42738C4E6D3841103D3AA7F3390B000000010000001800000045006E00740072007500730074002E006E006500740000001400000001000000140000006A72267AD01EEF7DE73B6951D46C8D9F901266AB1D0000000100000010000000521B5F4582C1DCAAE381B05E37CA2D340300000001000000140000008CF427FD790C3AD166068DE81E57EFBB932272D40F0000000100000020000000FDE5F2D9CE2026E1E10064C0A468C9F355B90ACF85BAF5CE6F52D4016837FD94090000000100000054000000305206082B0601050507030206082B06010505070303060A2B0601040182370A030406082B0601050507030406082B0601050507030606082B0601050507030706082B0601050507030106082B060105050703087F000000010000002C000000302A060A2B0601040182370A030406082B0601050507030506082B0601050507030606082B060105050703070400000001000000100000004BE2C99196650CF40E5A9392A00AFEB22000000001000000420400003082043E30820326A00302010202044A538C28300D06092A864886F70D01010B05003081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D204732301E170D3039303730373137323535345A170D3330313230373137353535345A3081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D20473230820122300D06092A864886F70D01010105000382010F003082010A0282010100BA84B672DB9E0C6BE299E93001A776EA32B895411AC9DA614E5872CFFEF68279BF7361060AA527D8B35FD3454E1C72D64E32F2728A0FF78319D06A808000451EB0C7E79ABF1257271CA3682F0A87BD6A6B0E5E65F31C77D5D4858D7021B4B332E78BA2D5863902B1B8D247CEE4C949C43BA7DEFB547D57BEF0E86EC279B23A0B55E250981632135C2F7856C1C294B3F25AE4279A9F24D7C6ECD09B2582E3CCC2C445C58C977A066B2A119FA90A6E483B6FDBD4111942F78F07BFF5535F9C3EF4172CE669AC4E324C6277EAB7E8E5BB34BC198BAE9C51E7B77EB553B13322E56DCF703C1AFAE29B67B683F48DA5AF624C4DE058AC64341203F8B68D946324A4710203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E041604146A72267AD01EEF7DE73B6951D46C8D9F901266AB300D06092A864886F70D01010B05000382010100799F1D96C6B6793F228D87D3870304606A6B9A2E59897311AC43D1F513FF8D392BC0F2BD4F708CA92FEA17C40B549ED41B9698333CA8AD62A20076AB59696E061D7EC4B9448D98AF12D461DB0A194647F3EBF763C1400540A5D2B7F4B59A36BFA98876880455042B9C877F1A373C7E2DA51AD8D4895ECABDAC3D6CD86DAFD5F3760FCD3B8838229D6C939AC43DBF821B653FA60F5DAAFCE5B215CAB5ADC6BC3DD084E8EA0672B04D393278BF3E119C0BA49D9A21F3F09B0B3078DBC1DC8743FEBC639ACAC5C21CC9C78DFF3B125808E6B63DEC7A2C4EFB8396CE0C3C69875473A473C293FF5110AC155401D8FC05B189A17F74839A49D7DC4E7B8A486F8B45F6
(PID) Process:(3200) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Lavasoft\Web Companion
Operation:writeName:MachineId
Value:
8569aaff-63aa-a71d-8040-0e2571e89667
(PID) Process:(3200) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanionInstaller_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(3200) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanionInstaller_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(3200) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanionInstaller_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(3200) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanionInstaller_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(3200) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanionInstaller_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(3200) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanionInstaller_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
Executable files
27
Suspicious files
5
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
2832WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS01BB0990\en-US\WebCompanionInstaller.resources.dllexecutable
MD5:5E93B9DB49037894DDDEE3416D42AF34
SHA256:4BB16BDA62652E4645444D316B57AAA5066665385D05FF04A99FD45C88D2A29A
2832WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS01BB0990\ja-JP\WebCompanionInstaller.resources.dllexecutable
MD5:E227E5AECA87C9298DFF139FAD88DD79
SHA256:23EC6D9BA15B78571F6A080FC09238AB6639AF2DE492FE77168655066303CF61
2832WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS01BB0990\de-DE\WebCompanionInstaller.resources.dllexecutable
MD5:02966F1B955724E884AF158E1D12A9D3
SHA256:4650C70F70AC875D9A94D283C766F98195C53884EC435C531EC5122614DF0FAD
2832WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS01BB0990\es-ES\WebCompanionInstaller.resources.dllexecutable
MD5:4A5565C368DD7749691EF7014DC98E68
SHA256:237FC3A8BE884DD0278522975232AF5BEF3412A7F817B6A9214D8C8C39EEF56E
2832WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS01BB0990\ICSharpCode.SharpZipLib.dllexecutable
MD5:A93DAC647EE7CDDB93F549DCD783B323
SHA256:4F6EB0FE1F4CB547CF03FF19F9A1C051BF0CAC1C793B88650F174C360DED3E39
2832WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS01BB0990\Newtonsoft.Json.dllexecutable
MD5:32D2B354D49A144AD9CC73FDA584C11C
SHA256:ED30E38E44C49B859B801D05621D8E902D04D502EBF5DE676DE04C23825B0290
2832WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS01BB0990\WebCompanionInstaller.exe.configxml
MD5:D9385BDC6E1554260CB7D30F6464DD9E
SHA256:80A15AC4F887309D99B0E6566644A6FB95C028E8E90B130CEEC54D808879A81C
2832WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS01BB0990\WebCompanionInstaller.exeexecutable
MD5:FB2CE6E0D7D5944E86697425C10CD11F
SHA256:DED4D86BF32884B7AD4639E26B4C79C0140060B8BCA23660D31EBBCD66FA25B8
2832WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS01BB0990\fr-CA\WebCompanionInstaller.resources.dllexecutable
MD5:77CC1B7550A3069B841D853CFBC09C33
SHA256:9530F4828FA009EA3A1A5ADB3D74664EF8A78DA5024347C85CDCEE68E160F6F2
2832WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS01BB0990\pt-BR\WebCompanionInstaller.resources.dllexecutable
MD5:EC6EE089D4501F6FEB7687C58860360B
SHA256:5B7C0792A129C9D023B20D19334E78B7C34058BB8421E84FB849851CCDE648CC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
6
DNS requests
3
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3200
WebCompanionInstaller.exe
POST
200
64.18.87.81:80
http://wc-update-service.lavasoft.com/update.asmx
CA
xml
1.45 Kb
whitelisted
1340
WebCompanionInstaller.exe
POST
200
104.18.87.101:80
http://flow.lavasoft.com/v1/event-stat-wc?Type=ProgressInstall&ProductID=wc&EventVersion=1
US
binary
29 b
whitelisted
3200
WebCompanionInstaller.exe
GET
200
104.18.88.101:80
http://wcdownloadercdn.lavasoft.com/7.0.2417.4248/WcInstaller.exe
US
executable
494 Kb
whitelisted
3200
WebCompanionInstaller.exe
POST
200
104.18.87.101:80
http://flow.lavasoft.com/v1/event-stat-wc?Type=ProgressInstall&ProductID=wc&EventVersion=1
US
binary
29 b
whitelisted
1340
WebCompanionInstaller.exe
POST
200
64.18.87.81:80
http://wc-update-service.lavasoft.com/update.asmx
CA
xml
1.45 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3200
WebCompanionInstaller.exe
104.18.87.101:80
flow.lavasoft.com
Cloudflare Inc
US
shared
3200
WebCompanionInstaller.exe
64.18.87.81:80
wc-update-service.lavasoft.com
COGECODATA
CA
unknown
1340
WebCompanionInstaller.exe
104.18.87.101:80
flow.lavasoft.com
Cloudflare Inc
US
shared
1340
WebCompanionInstaller.exe
64.18.87.81:80
wc-update-service.lavasoft.com
COGECODATA
CA
unknown
3200
WebCompanionInstaller.exe
104.18.88.101:80
flow.lavasoft.com
Cloudflare Inc
US
shared

DNS requests

Domain
IP
Reputation
flow.lavasoft.com
  • 104.18.87.101
  • 104.18.88.101
whitelisted
wc-update-service.lavasoft.com
  • 64.18.87.81
  • 64.18.87.82
whitelisted
wcdownloadercdn.lavasoft.com
  • 104.18.88.101
  • 104.18.87.101
whitelisted

Threats

PID
Process
Class
Message
3200
WebCompanionInstaller.exe
Potential Corporate Privacy Violation
AV POLICY HTTP request for .exe file with no User-Agent
3200
WebCompanionInstaller.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
3200
WebCompanionInstaller.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
Process
Message
WebCompanionInstaller.exe
Detecting windows culture
WebCompanionInstaller.exe
11/18/2021 9:21:36 PM :-> Starting installer 8.9.0.371 with: .\WebCompanionInstaller.exe --prod, Run as admin: True
WebCompanionInstaller.exe
Detecting windows culture
WebCompanionInstaller.exe
11/18/2021 9:21:41 PM :-> Starting installer 7.0.2417.4248 with: .\WebCompanionInstaller.exe --prod --nanouniqueid=1637270496510 --prod, Run as admin: True