download:

WcInstaller.exe

Full analysis: https://app.any.run/tasks/0355a3ee-a928-4a51-8849-b4abd013df26
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: November 18, 2021, 21:21:22
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
installer
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

EEEBFBDCA0B69687668117BC2C8F725D

SHA1:

DD36613A2D5453FBB4F50F7B16F00540EE26F7EF

SHA256:

2C3AF025BA5EBBD5B5138CD86D8A635521DFA3A83C30BCA6F478A80BA4B5F1CC

SSDEEP:

12288:zG5knZfFKessImXPiASR2ru2sjNkEpb1A17toXPwvgs:zG50ZfFKd6XRSR2h6duufi

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • WcInstaller.exe (PID: 2832)
      • WcInstaller.exe (PID: 1396)
    • Changes settings of System certificates

      • WebCompanionInstaller.exe (PID: 3200)
    • Application was dropped or rewritten from another process

      • WebCompanionInstaller.exe (PID: 3200)
      • WcInstaller.exe (PID: 1396)
      • WebCompanionInstaller.exe (PID: 1340)
    • Loads dropped or rewritten executable

      • WebCompanionInstaller.exe (PID: 3200)
      • WebCompanionInstaller.exe (PID: 1340)
  • SUSPICIOUS

    • Checks supported languages

      • WcInstaller.exe (PID: 2832)
      • WebCompanionInstaller.exe (PID: 3200)
      • WcInstaller.exe (PID: 1396)
      • WebCompanionInstaller.exe (PID: 1340)
      • PresentationFontCache.exe (PID: 3172)
    • Executable content was dropped or overwritten

      • WcInstaller.exe (PID: 2832)
      • WebCompanionInstaller.exe (PID: 3200)
      • WcInstaller.exe (PID: 1396)
    • Drops a file that was compiled in debug mode

      • WcInstaller.exe (PID: 2832)
      • WcInstaller.exe (PID: 1396)
    • Drops a file with a compile date too recent

      • WcInstaller.exe (PID: 2832)
      • WebCompanionInstaller.exe (PID: 3200)
      • WcInstaller.exe (PID: 1396)
    • Reads the computer name

      • WebCompanionInstaller.exe (PID: 3200)
      • WebCompanionInstaller.exe (PID: 1340)
      • PresentationFontCache.exe (PID: 3172)
    • Adds / modifies Windows certificates

      • WebCompanionInstaller.exe (PID: 3200)
    • Reads Environment values

      • WebCompanionInstaller.exe (PID: 3200)
      • WebCompanionInstaller.exe (PID: 1340)
    • Creates files in the program directory

      • WebCompanionInstaller.exe (PID: 3200)
    • Creates files in the Windows directory

      • WebCompanionInstaller.exe (PID: 3200)
    • Executed as Windows Service

      • PresentationFontCache.exe (PID: 3172)
    • Searches for installed software

      • WebCompanionInstaller.exe (PID: 3200)
  • INFO

    • Checks Windows Trust Settings

      • WebCompanionInstaller.exe (PID: 3200)
      • WebCompanionInstaller.exe (PID: 1340)
    • Reads settings of System Certificates

      • WebCompanionInstaller.exe (PID: 3200)
      • WebCompanionInstaller.exe (PID: 1340)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (36.8)
.exe | Win32 Executable MS Visual C++ (generic) (26.6)
.exe | Win64 Executable (generic) (23.6)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2011:04:18 20:54:06+02:00
PEType: PE32
LinkerVersion: 6
CodeSize: 104448
InitializedDataSize: 60416
UninitializedDataSize: -
EntryPoint: 0x148d4
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 8.9.0.371
ProductVersionNumber: 8.9.0.371
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileVersion: 8.9.0.371
ProductVersion: 8.9.0.371
CompanyName: Lavasoft
FileDescription: Web Companion Installer
InternalName: Installer.exe
LegalCopyright: c Lavasoft Limited. All Rights Reserved.
OriginalFileName: Installer.exe
ProductName: Web Companion Installer
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
6
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
1340.\WebCompanionInstaller.exe --prod --nanouniqueid=1637270496510 --prodC:\Users\admin\AppData\Local\Temp\7zS475F57F0\WebCompanionInstaller.exe
WcInstaller.exe
User:
admin
Company:
Lavasoft
Integrity Level:
HIGH
Description:
Web Companion
Exit code:
0
Version:
7.0.2417.4248
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\mscoree.dll
c:\users\admin\appdata\local\temp\7zs475f57f0\webcompanioninstaller.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1396"C:\Users\admin\AppData\Local\Temp\wctmp_139114680\WcInstaller.exe" --nanouniqueid=1637270496510 --prodC:\Users\admin\AppData\Local\Temp\wctmp_139114680\WcInstaller.exe
WebCompanionInstaller.exe
User:
admin
Company:
Lavasoft
Integrity Level:
HIGH
Description:
Web Companion Installer
Exit code:
0
Version:
7.0.2417.4248
Modules
Images
c:\users\admin\appdata\local\temp\wctmp_139114680\wcinstaller.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1636"C:\Users\admin\AppData\Local\Temp\WcInstaller.exe" C:\Users\admin\AppData\Local\Temp\WcInstaller.exeExplorer.EXE
User:
admin
Company:
Lavasoft
Integrity Level:
MEDIUM
Description:
Web Companion Installer
Exit code:
3221226540
Version:
8.9.0.371
Modules
Images
c:\users\admin\appdata\local\temp\wcinstaller.exe
c:\windows\system32\ntdll.dll
2832"C:\Users\admin\AppData\Local\Temp\WcInstaller.exe" C:\Users\admin\AppData\Local\Temp\WcInstaller.exe
Explorer.EXE
User:
admin
Company:
Lavasoft
Integrity Level:
HIGH
Description:
Web Companion Installer
Exit code:
0
Version:
8.9.0.371
Modules
Images
c:\users\admin\appdata\local\temp\wcinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3172C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exeC:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exeservices.exe
User:
LOCAL SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
PresentationFontCache.exe
Exit code:
0
Version:
3.0.6920.4902 built by: NetFXw7
Modules
Images
c:\windows\microsoft.net\framework\v3.0\wpf\presentationfontcache.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3200.\WebCompanionInstaller.exe --prodC:\Users\admin\AppData\Local\Temp\7zS01BB0990\WebCompanionInstaller.exe
WcInstaller.exe
User:
admin
Company:
Lavasoft
Integrity Level:
HIGH
Description:
Web Companion
Exit code:
0
Version:
8.9.0.371
Modules
Images
c:\users\admin\appdata\local\temp\7zs01bb0990\webcompanioninstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
12 491
Read events
12 443
Write events
48
Delete events
0

Modification events

(PID) Process:(3200) WebCompanionInstaller.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3200) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4
Operation:writeName:Blob
Value:
0400000001000000100000004BE2C99196650CF40E5A9392A00AFEB27F000000010000002C000000302A060A2B0601040182370A030406082B0601050507030506082B0601050507030606082B06010505070307090000000100000054000000305206082B0601050507030206082B06010505070303060A2B0601040182370A030406082B0601050507030406082B0601050507030606082B0601050507030706082B0601050507030106082B060105050703080F0000000100000020000000FDE5F2D9CE2026E1E10064C0A468C9F355B90ACF85BAF5CE6F52D4016837FD940300000001000000140000008CF427FD790C3AD166068DE81E57EFBB932272D41D0000000100000010000000521B5F4582C1DCAAE381B05E37CA2D341400000001000000140000006A72267AD01EEF7DE73B6951D46C8D9F901266AB0B000000010000001800000045006E00740072007500730074002E006E0065007400000062000000010000002000000043DF5774B03E7FEF5FE40D931A7BEDF1BB2E6B42738C4E6D3841103D3AA7F339190000000100000010000000FA46CE7CBB85CFB4310075313A09EE05530000000100000041000000303F3020060A6086480186FA6C0A010230123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C07E000000010000000800000000C001B39667D6012000000001000000420400003082043E30820326A00302010202044A538C28300D06092A864886F70D01010B05003081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D204732301E170D3039303730373137323535345A170D3330313230373137353535345A3081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D20473230820122300D06092A864886F70D01010105000382010F003082010A0282010100BA84B672DB9E0C6BE299E93001A776EA32B895411AC9DA614E5872CFFEF68279BF7361060AA527D8B35FD3454E1C72D64E32F2728A0FF78319D06A808000451EB0C7E79ABF1257271CA3682F0A87BD6A6B0E5E65F31C77D5D4858D7021B4B332E78BA2D5863902B1B8D247CEE4C949C43BA7DEFB547D57BEF0E86EC279B23A0B55E250981632135C2F7856C1C294B3F25AE4279A9F24D7C6ECD09B2582E3CCC2C445C58C977A066B2A119FA90A6E483B6FDBD4111942F78F07BFF5535F9C3EF4172CE669AC4E324C6277EAB7E8E5BB34BC198BAE9C51E7B77EB553B13322E56DCF703C1AFAE29B67B683F48DA5AF624C4DE058AC64341203F8B68D946324A4710203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E041604146A72267AD01EEF7DE73B6951D46C8D9F901266AB300D06092A864886F70D01010B05000382010100799F1D96C6B6793F228D87D3870304606A6B9A2E59897311AC43D1F513FF8D392BC0F2BD4F708CA92FEA17C40B549ED41B9698333CA8AD62A20076AB59696E061D7EC4B9448D98AF12D461DB0A194647F3EBF763C1400540A5D2B7F4B59A36BFA98876880455042B9C877F1A373C7E2DA51AD8D4895ECABDAC3D6CD86DAFD5F3760FCD3B8838229D6C939AC43DBF821B653FA60F5DAAFCE5B215CAB5ADC6BC3DD084E8EA0672B04D393278BF3E119C0BA49D9A21F3F09B0B3078DBC1DC8743FEBC639ACAC5C21CC9C78DFF3B125808E6B63DEC7A2C4EFB8396CE0C3C69875473A473C293FF5110AC155401D8FC05B189A17F74839A49D7DC4E7B8A486F8B45F6
(PID) Process:(3200) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4
Operation:writeName:Blob
Value:
5C0000000100000004000000000800007E000000010000000800000000C001B39667D601530000000100000041000000303F3020060A6086480186FA6C0A010230123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C0190000000100000010000000FA46CE7CBB85CFB4310075313A09EE0562000000010000002000000043DF5774B03E7FEF5FE40D931A7BEDF1BB2E6B42738C4E6D3841103D3AA7F3390B000000010000001800000045006E00740072007500730074002E006E006500740000001400000001000000140000006A72267AD01EEF7DE73B6951D46C8D9F901266AB1D0000000100000010000000521B5F4582C1DCAAE381B05E37CA2D340300000001000000140000008CF427FD790C3AD166068DE81E57EFBB932272D40F0000000100000020000000FDE5F2D9CE2026E1E10064C0A468C9F355B90ACF85BAF5CE6F52D4016837FD94090000000100000054000000305206082B0601050507030206082B06010505070303060A2B0601040182370A030406082B0601050507030406082B0601050507030606082B0601050507030706082B0601050507030106082B060105050703087F000000010000002C000000302A060A2B0601040182370A030406082B0601050507030506082B0601050507030606082B060105050703070400000001000000100000004BE2C99196650CF40E5A9392A00AFEB22000000001000000420400003082043E30820326A00302010202044A538C28300D06092A864886F70D01010B05003081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D204732301E170D3039303730373137323535345A170D3330313230373137353535345A3081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D20473230820122300D06092A864886F70D01010105000382010F003082010A0282010100BA84B672DB9E0C6BE299E93001A776EA32B895411AC9DA614E5872CFFEF68279BF7361060AA527D8B35FD3454E1C72D64E32F2728A0FF78319D06A808000451EB0C7E79ABF1257271CA3682F0A87BD6A6B0E5E65F31C77D5D4858D7021B4B332E78BA2D5863902B1B8D247CEE4C949C43BA7DEFB547D57BEF0E86EC279B23A0B55E250981632135C2F7856C1C294B3F25AE4279A9F24D7C6ECD09B2582E3CCC2C445C58C977A066B2A119FA90A6E483B6FDBD4111942F78F07BFF5535F9C3EF4172CE669AC4E324C6277EAB7E8E5BB34BC198BAE9C51E7B77EB553B13322E56DCF703C1AFAE29B67B683F48DA5AF624C4DE058AC64341203F8B68D946324A4710203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E041604146A72267AD01EEF7DE73B6951D46C8D9F901266AB300D06092A864886F70D01010B05000382010100799F1D96C6B6793F228D87D3870304606A6B9A2E59897311AC43D1F513FF8D392BC0F2BD4F708CA92FEA17C40B549ED41B9698333CA8AD62A20076AB59696E061D7EC4B9448D98AF12D461DB0A194647F3EBF763C1400540A5D2B7F4B59A36BFA98876880455042B9C877F1A373C7E2DA51AD8D4895ECABDAC3D6CD86DAFD5F3760FCD3B8838229D6C939AC43DBF821B653FA60F5DAAFCE5B215CAB5ADC6BC3DD084E8EA0672B04D393278BF3E119C0BA49D9A21F3F09B0B3078DBC1DC8743FEBC639ACAC5C21CC9C78DFF3B125808E6B63DEC7A2C4EFB8396CE0C3C69875473A473C293FF5110AC155401D8FC05B189A17F74839A49D7DC4E7B8A486F8B45F6
(PID) Process:(3200) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Lavasoft\Web Companion
Operation:writeName:MachineId
Value:
8569aaff-63aa-a71d-8040-0e2571e89667
(PID) Process:(3200) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanionInstaller_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(3200) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanionInstaller_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(3200) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanionInstaller_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(3200) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanionInstaller_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(3200) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanionInstaller_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(3200) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanionInstaller_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
Executable files
27
Suspicious files
5
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
3200WebCompanionInstaller.exeC:\ProgramData\Lavasoft\Web Companion\Options\Statistics.txtbinary
MD5:E9EB82138B0B000AF2576C1CA1988788
SHA256:9DDB95279B69FB74A5EE08AD4B1A04492006BD18925DE06ACEAFAE8940AE351E
2832WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS01BB0990\tr-TR\WebCompanionInstaller.resources.dllexecutable
MD5:ABDDAC3D531C7B93BD373F63E8F8FEBF
SHA256:59F16CA7B40030EE22C901143C5DEC66751CD02F7FF08095E04C70D6D278394C
2832WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS01BB0990\ja-JP\WebCompanionInstaller.resources.dllexecutable
MD5:E227E5AECA87C9298DFF139FAD88DD79
SHA256:23EC6D9BA15B78571F6A080FC09238AB6639AF2DE492FE77168655066303CF61
2832WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS01BB0990\ru-RU\WebCompanionInstaller.resources.dllexecutable
MD5:B2A163B835CA97F7D9E5B7FFB27A7ECB
SHA256:7E57788B463C3AE9EE99F688D381BDAB8B536EC6D09D4DB70F64F047B0A4A88C
2832WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS01BB0990\es-ES\WebCompanionInstaller.resources.dllexecutable
MD5:4A5565C368DD7749691EF7014DC98E68
SHA256:237FC3A8BE884DD0278522975232AF5BEF3412A7F817B6A9214D8C8C39EEF56E
2832WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS01BB0990\Newtonsoft.Json.dllexecutable
MD5:32D2B354D49A144AD9CC73FDA584C11C
SHA256:ED30E38E44C49B859B801D05621D8E902D04D502EBF5DE676DE04C23825B0290
2832WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS01BB0990\pt-BR\WebCompanionInstaller.resources.dllexecutable
MD5:EC6EE089D4501F6FEB7687C58860360B
SHA256:5B7C0792A129C9D023B20D19334E78B7C34058BB8421E84FB849851CCDE648CC
2832WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS01BB0990\WebCompanionInstaller.exeexecutable
MD5:FB2CE6E0D7D5944E86697425C10CD11F
SHA256:DED4D86BF32884B7AD4639E26B4C79C0140060B8BCA23660D31EBBCD66FA25B8
2832WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS01BB0990\zh-CHS\WebCompanionInstaller.resources.dllexecutable
MD5:5F8B87ACDEE0564F8386757240AEF70C
SHA256:A95C14E01A02EF4601564C9E7E9A581C57AA39C251A566093498255FF54592BD
2832WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS01BB0990\en-US\WebCompanionInstaller.resources.dllexecutable
MD5:5E93B9DB49037894DDDEE3416D42AF34
SHA256:4BB16BDA62652E4645444D316B57AAA5066665385D05FF04A99FD45C88D2A29A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
6
DNS requests
3
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3200
WebCompanionInstaller.exe
POST
200
64.18.87.81:80
http://wc-update-service.lavasoft.com/update.asmx
CA
xml
1.45 Kb
whitelisted
1340
WebCompanionInstaller.exe
POST
200
64.18.87.81:80
http://wc-update-service.lavasoft.com/update.asmx
CA
xml
1.45 Kb
whitelisted
3200
WebCompanionInstaller.exe
GET
200
104.18.88.101:80
http://wcdownloadercdn.lavasoft.com/7.0.2417.4248/WcInstaller.exe
US
executable
494 Kb
whitelisted
1340
WebCompanionInstaller.exe
POST
200
104.18.87.101:80
http://flow.lavasoft.com/v1/event-stat-wc?Type=ProgressInstall&ProductID=wc&EventVersion=1
US
binary
29 b
whitelisted
3200
WebCompanionInstaller.exe
POST
200
104.18.87.101:80
http://flow.lavasoft.com/v1/event-stat-wc?Type=ProgressInstall&ProductID=wc&EventVersion=1
US
binary
29 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3200
WebCompanionInstaller.exe
104.18.87.101:80
flow.lavasoft.com
Cloudflare Inc
US
shared
3200
WebCompanionInstaller.exe
64.18.87.81:80
wc-update-service.lavasoft.com
COGECODATA
CA
unknown
3200
WebCompanionInstaller.exe
104.18.88.101:80
flow.lavasoft.com
Cloudflare Inc
US
shared
1340
WebCompanionInstaller.exe
64.18.87.81:80
wc-update-service.lavasoft.com
COGECODATA
CA
unknown
1340
WebCompanionInstaller.exe
104.18.87.101:80
flow.lavasoft.com
Cloudflare Inc
US
shared

DNS requests

Domain
IP
Reputation
flow.lavasoft.com
  • 104.18.87.101
  • 104.18.88.101
whitelisted
wc-update-service.lavasoft.com
  • 64.18.87.81
  • 64.18.87.82
whitelisted
wcdownloadercdn.lavasoft.com
  • 104.18.88.101
  • 104.18.87.101
whitelisted

Threats

PID
Process
Class
Message
3200
WebCompanionInstaller.exe
Potential Corporate Privacy Violation
AV POLICY HTTP request for .exe file with no User-Agent
3200
WebCompanionInstaller.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
3200
WebCompanionInstaller.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
Process
Message
WebCompanionInstaller.exe
Detecting windows culture
WebCompanionInstaller.exe
11/18/2021 9:21:36 PM :-> Starting installer 8.9.0.371 with: .\WebCompanionInstaller.exe --prod, Run as admin: True
WebCompanionInstaller.exe
Detecting windows culture
WebCompanionInstaller.exe
11/18/2021 9:21:41 PM :-> Starting installer 7.0.2417.4248 with: .\WebCompanionInstaller.exe --prod --nanouniqueid=1637270496510 --prod, Run as admin: True