| File name: | ADWARE.exe |
| Full analysis: | https://app.any.run/tasks/201bb605-e685-45d4-9529-d5e7ddcb1f80 |
| Verdict: | Malicious activity |
| Threats: | Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security. |
| Analysis date: | October 11, 2020, 04:14:27 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
| MD5: | 9364607DFE2CBFEF763C146EE7E27DFA |
| SHA1: | 53A7D87EEF714750CC1751182443ACFEBC41B832 |
| SHA256: | 3A75D6962893903BDFC8558485DF3E3166989BB5DD5D524D2C5C796F60221F3D |
| SSDEEP: | 24576:eq5TfcdHj4fmbqOY2q570smVkVMyO7BlWEWEzKJ9TtLs2l0llFJ+o0zQJ9TtDi8I:eUTsamVYxkle5YlF55q |
| .exe | | | Win64 Executable (generic) (30.7) |
|---|---|---|
| .exe | | | UPX compressed Win32 Executable (30.1) |
| .exe | | | Win32 EXE Yoda's Crypter (29.5) |
| .exe | | | Win32 Executable (generic) (5) |
| .exe | | | Generic Win/DOS Executable (2.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2015:10:30 10:29:35+01:00 |
| PEType: | PE32 |
| LinkerVersion: | 11 |
| CodeSize: | 344064 |
| InitializedDataSize: | 1122304 |
| UninitializedDataSize: | 1646592 |
| EntryPoint: | 0x1e6900 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.1.5.5 |
| ProductVersionNumber: | 1.1.5.5 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Unknown |
| FileSubtype: | - |
| LanguageCode: | German |
| CharacterSet: | Unicode |
| FileVersion: | 1.1.5.5 |
| Comments: | CHIP Secured Installer |
| FileDescription: | CHIP Secured Installer |
| ProductVersion: | 1.1.5.5 |
| LegalCopyright: | Copyright © 2015 Chip Digital GmbH |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 30-Oct-2015 09:29:35 |
| Detected languages: |
|
| FileVersion: | 1.1.5.5 |
| Comments: | CHIP Secured Installer |
| FileDescription: | CHIP Secured Installer |
| ProductVersion: | 1.1.5.5 |
| LegalCopyright: | Copyright © 2015 Chip Digital GmbH |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x00000108 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 3 |
| Time date stamp: | 30-Oct-2015 09:29:35 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
UPX0 | 0x00001000 | 0x00192000 | 0x00000000 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
UPX1 | 0x00193000 | 0x00054000 | 0x00053C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.9361 |
.rsrc | 0x001E7000 | 0x00112000 | 0x00111400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.79687 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.32366 | 1444 | Latin 1 / Western European | German - Germany | RT_MANIFEST |
4 | 3.75291 | 9640 | Latin 1 / Western European | English - United Kingdom | RT_ICON |
7 | 3.34702 | 1428 | Latin 1 / Western European | English - United Kingdom | RT_STRING |
8 | 3.2817 | 1674 | Latin 1 / Western European | English - United Kingdom | RT_STRING |
9 | 3.28849 | 1168 | Latin 1 / Western European | English - United Kingdom | RT_STRING |
10 | 3.28373 | 1532 | Latin 1 / Western European | English - United Kingdom | RT_STRING |
11 | 3.26322 | 1628 | Latin 1 / Western European | English - United Kingdom | RT_STRING |
12 | 3.25812 | 1126 | Latin 1 / Western European | English - United Kingdom | RT_STRING |
99 | 2.0815 | 20 | Latin 1 / Western European | English - United Kingdom | RT_GROUP_ICON |
166 | 2.68292 | 80 | Latin 1 / Western European | English - United Kingdom | RT_MENU |
ADVAPI32.dll |
COMCTL32.dll |
COMDLG32.dll |
GDI32.dll |
IPHLPAPI.DLL |
KERNEL32.DLL |
MPR.dll |
OLEAUT32.dll |
PSAPI.DLL |
SHELL32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 184 | "C:\Program Files\Opera\71.0.3770.228\opera.exe" --type=renderer --field-trial-handle=1112,13139653042553484088,13785452427808141463,131072 --lang=en-US --extension-process --enable-auto-reload --with-feature:installer-experiment-test=off --with-feature:installer-use-minimal-package=off --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=12 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2520 /prefetch:1 | C:\Program Files\Opera\71.0.3770.228\opera.exe | opera.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: LOW Description: Opera Internet Browser Exit code: 0 Version: 71.0.3770.228 Modules
| |||||||||||||||
| 316 | "C:\Users\admin\AppData\Local\Temp\DMR\Downloads\152e221a8bef8d2d13c58f995563a1a1\107f83e299c4ea15fe7b1a3fc055b7ec\OperaSetup.exe" --silent --allusers=0 --otd="utm.medium:pb,utm.source:chipde,utm.campaign:chipde-installer-ie" --launchopera=0 --launchopera-on-os-start=1 | C:\Users\admin\AppData\Local\Temp\DMR\Downloads\152e221a8bef8d2d13c58f995563a1a1\107f83e299c4ea15fe7b1a3fc055b7ec\OperaSetup.exe | dmr_72.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: HIGH Description: Opera Installer Exit code: 0 Version: 71.0.3770.228 Modules
| |||||||||||||||
| 372 | "C:\Program Files\Lavasoft\Web Companion\Application\Ad-Aware Web Companion.exe" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} | C:\Program Files\Lavasoft\Web Companion\Application\Ad-Aware Web Companion.exe | — | WebCompanion.exe | |||||||||||
User: admin Company: Integrity Level: HIGH Description: Ad-Aware Web Companion.exe Exit code: 0 Version: 6.0.2270.4122 Modules
| |||||||||||||||
| 532 | "C:\Program Files\Opera\71.0.3770.228\opera.exe" --type=renderer --field-trial-handle=1112,13139653042553484088,13785452427808141463,131072 --lang=en-US --enable-auto-reload --with-feature:installer-experiment-test=off --with-feature:installer-use-minimal-package=off --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=17 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2788 /prefetch:1 | C:\Program Files\Opera\71.0.3770.228\opera.exe | — | opera.exe | |||||||||||
User: admin Company: Opera Software Integrity Level: LOW Description: Opera Internet Browser Exit code: 0 Version: 71.0.3770.228 Modules
| |||||||||||||||
| 540 | "C:\Program Files\Opera\71.0.3770.228\opera.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --field-trial-handle=1112,13139653042553484088,13785452427808141463,131072 --lang=en-US --service-sandbox-type=audio --enable-quic --with-feature:installer-experiment-test=off --with-feature:installer-use-minimal-package=off --mojo-platform-channel-handle=3036 /prefetch:8 | C:\Program Files\Opera\71.0.3770.228\opera.exe | opera.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera Internet Browser Exit code: 0 Version: 71.0.3770.228 Modules
| |||||||||||||||
| 580 | "C:\Program Files\Opera\71.0.3770.228\opera_crashreporter.exe" --type=crashpad-handler /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector.opera.com/collector/submit --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktop --annotation=ver=71.0.3770.228 --initial-client-data=0x1e8,0x1ec,0x1f0,0x1bc,0x1f4,0x5bef44d0,0x5bef44e0,0x5bef44ec | C:\Program Files\Opera\71.0.3770.228\opera_crashreporter.exe | opera.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera crash-reporter Exit code: 0 Version: 71.0.3770.228 Modules
| |||||||||||||||
| 608 | "C:\Program Files\Opera\71.0.3770.228\opera.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --field-trial-handle=1112,13139653042553484088,13785452427808141463,131072 --lang=en-US --service-sandbox-type=utility --enable-quic --with-feature:installer-experiment-test=off --with-feature:installer-use-minimal-package=off --mojo-platform-channel-handle=4024 /prefetch:8 | C:\Program Files\Opera\71.0.3770.228\opera.exe | opera.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: LOW Description: Opera Internet Browser Exit code: 0 Version: 71.0.3770.228 Modules
| |||||||||||||||
| 636 | .\WebCompanionInstaller.exe --partner=CH180901IE --campaign=LavasoftIEPRO0 --version=6.0.2270.4122 --prod --silent --partner=CH180901IE --search=1 --homepage=1 | C:\Users\admin\AppData\Local\Temp\7zS1E13.tmp\WebCompanionInstaller.exe | WcInstaller.exe | ||||||||||||
User: admin Company: Lavasoft Integrity Level: HIGH Description: Web Companion Exit code: 0 Version: 6.0.2270.4122 Modules
| |||||||||||||||
| 672 | "C:\Program Files\Opera\71.0.3770.228\opera.exe" --type=gpu-process --field-trial-handle=1112,13139653042553484088,13785452427808141463,131072 --with-feature:installer-experiment-test=off --with-feature:installer-use-minimal-package=off --gpu-preferences=MAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAQAAAAAAAAAAAAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAA= --mojo-platform-channel-handle=1120 /prefetch:2 | C:\Program Files\Opera\71.0.3770.228\opera.exe | opera.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: LOW Description: Opera Internet Browser Exit code: 0 Version: 71.0.3770.228 Modules
| |||||||||||||||
| 712 | "C:\Program Files\Opera\71.0.3770.228\installer.exe" --backend --initial-pid=316 --install --import-browser-data=0 --enable-stats=1 --enable-installer-stats=1 --launchopera=0 --installfolder="C:\Program Files\Opera" --profile-folder --language=en --singleprofile=0 --copyonly=0 --allusers=0 --setdefaultbrowser=1 --pintotaskbar=1 --pin-additional-shortcuts=1 --server-tracking-data=server_tracking_data --package-dir="C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202010110515131" --session-guid=b059cb65-5a4c-4828-a9a1-f4a3861ec674 --server-tracking-blob=YjJiMmQzM2RlNGM1ZDcwNGQ0YWQ3ZTQ2YjhmNDA4MmYwZDlhMDUyOGI2Y2MyNTlhYmE2ZmNiZmVjOWYxMmIwNjp7ImNvdW50cnkiOiJMViIsImluc3RhbGxlcl9uYW1lIjoiT3BlcmFTZXR1cC5leGUiLCJwcm9kdWN0Ijoib3BlcmEiLCJxdWVyeSI6Ii9vcGVyYS9zdGFibGUvd2luZG93cz91dG1fc291cmNlPWNoaXBkZSZ1dG1fbWVkaXVtPXBiJnV0bV9jYW1wYWlnbj1jaGlwZGUtaW5zdGFsbGVyIiwidGltZXN0YW1wIjoiMTYwMjM4OTcxMC4yMDE2IiwidXRtIjp7ImNhbXBhaWduIjoiY2hpcGRlLWluc3RhbGxlci1pZSIsIm1lZGl1bSI6InBiIiwic291cmNlIjoiY2hpcGRlIn0sInV1aWQiOiJjM2E2MzUzYy04ZGJhLTQwZjktYTgyZS1hYjcwYmU4NTM0NTkifQ== --silent --launchopera-on-os-start --desktopshortcut=1 --install-subfolder=71.0.3770.228 | C:\Program Files\Opera\71.0.3770.228\installer.exe | OperaSetup.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: HIGH Description: Opera Installer Exit code: 0 Version: 71.0.3770.228 Modules
| |||||||||||||||
| (PID) Process: | (2612) ADWARE.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2612) ADWARE.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (1748) dmr_72.exe | Key: | HKEY_CURRENT_USER\Software\OCS |
| Operation: | write | Name: | CID |
Value: a549e7b0-f8fb-4e9e-a74d-c7f7fe121563 | |||
| (PID) Process: | (1748) dmr_72.exe | Key: | HKEY_CURRENT_USER\Software\OCS |
| Operation: | write | Name: | PID |
Value: chipderedesign | |||
| (PID) Process: | (1748) dmr_72.exe | Key: | HKEY_CURRENT_USER\Software\OCS |
| Operation: | write | Name: | lastPID |
Value: chipderedesign | |||
| (PID) Process: | (1748) dmr_72.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dmr_72_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (1748) dmr_72.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dmr_72_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (1748) dmr_72.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dmr_72_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: 4294901760 | |||
| (PID) Process: | (1748) dmr_72.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dmr_72_RASAPI32 |
| Operation: | write | Name: | ConsoleTracingMask |
Value: 4294901760 | |||
| (PID) Process: | (1748) dmr_72.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dmr_72_RASAPI32 |
| Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1748 | dmr_72.exe | C:\Users\admin\AppData\Local\Temp\CabFD3D.tmp | — | |
MD5:— | SHA256:— | |||
| 1748 | dmr_72.exe | C:\Users\admin\AppData\Local\Temp\TarFD3E.tmp | — | |
MD5:— | SHA256:— | |||
| 1748 | dmr_72.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\main[1].css | text | |
MD5:— | SHA256:— | |||
| 1748 | dmr_72.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\pic[1].gif | — | |
MD5:— | SHA256:— | |||
| 1748 | dmr_72.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\progress[1].htm | htm | |
MD5:— | SHA256:— | |||
| 1748 | dmr_72.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\jquery.corner[1].js | text | |
MD5:— | SHA256:— | |||
| 1748 | dmr_72.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\kasper-progresspg-ongrey-en[1].gif | image | |
MD5:— | SHA256:— | |||
| 1748 | dmr_72.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\bg-icon-speedometer[1].png | image | |
MD5:— | SHA256:— | |||
| 1748 | dmr_72.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B398B80134F72209547439DB21AB308D_592839A8569F831D0F2306AE4BB5C24B | binary | |
MD5:— | SHA256:— | |||
| 1748 | dmr_72.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\background%20progressad[1].gif | image | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1748 | dmr_72.exe | GET | 200 | 148.251.213.132:80 | http://api.chip-secured-download.de/dotnet/com | DE | text | 24 b | malicious |
1748 | dmr_72.exe | GET | 200 | 148.251.213.132:80 | http://api.chip-secured-download.de/geoip/geoip.php?ip=3137362e3139392e3135312e313935&givezip=true | DE | text | 7 b | malicious |
1748 | dmr_72.exe | GET | 200 | 148.251.213.132:80 | http://api.chip-secured-download.de/track/uac.php?clientid=a549e7b0-f8fb-4e9e-a74d-c7f7fe121563&cid=56269414&pid=chipderedesign&source=mwchk&setupid=fcb4fd7f2fd843e782da1aaa665f1fc2&langcountry=en-US&state=WithoutUAC | DE | text | 24 b | malicious |
1748 | dmr_72.exe | GET | 200 | 148.251.213.132:80 | http://api2.chip-secured-download.de/newbrandmachine/chipderedesign?cid=56269414&scid=&headline1=4F706572612031322E3138202836342042697429&headline2=434849502D444F574E4C4F4144&euid=316261396430656535346664373564343638346634636536&icon=68747470733A2F2F7777772E636869702E64652F69692F312F352F362F382F302F382F372F372F6F706572612D373333353263643439653338616138332E6A7067&screenshot=68747470733A2F2F7777772E636869702E64652F69692F312F352F362F382F302F382F372F372F6F706572612D653433356363643964326462373063642E6A7067&MetaRating=33 | DE | binary | 138 Kb | malicious |
1748 | dmr_72.exe | GET | 200 | 148.251.213.132:80 | http://api.chip-secured-download.de/downloaderContent/progress.php?pid=chipderedesign&cid=56269414&sid=fcb4fd7f2fd843e782da1aaa665f1fc2&appname=4F706572612031322E3138202836342042697429&uid=a549e7b0-f8fb-4e9e-a74d-c7f7fe121563&scid=&source=mwchk&language=en-lv&piddata=&uaexe=696578706C6F72652E657865&Camplist=30396463326630336463346232393737316637656462316562613566643564333B3837363665663961313363373539613266373735396338613362386433356564 | DE | htm | 1.92 Kb | malicious |
1748 | dmr_72.exe | GET | 200 | 148.251.213.132:80 | http://api2.chip-secured-download.de/downloaderContent/img/kasper-progresspg-ongrey-en.gif | DE | image | 2.30 Kb | malicious |
1748 | dmr_72.exe | GET | 200 | 148.251.213.132:80 | http://api.chip-secured-download.de/downloaderContent/main.css?v=1461939270 | DE | text | 6.02 Kb | malicious |
1748 | dmr_72.exe | GET | 200 | 148.251.213.132:80 | http://api.chip-secured-download.de/downloaderContent/jquery.corner.js | DE | text | 94 b | malicious |
1748 | dmr_72.exe | GET | 200 | 148.251.213.132:80 | http://api.chip-secured-download.de/downloaderContent/jquery.js | DE | text | 102 Kb | malicious |
1748 | dmr_72.exe | GET | 200 | 148.251.213.132:80 | http://api.chip-secured-download.de/downloaderContent/img/bg-progressbar.jpg | DE | image | 17.3 Kb | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1748 | dmr_72.exe | 148.251.213.132:80 | api.chip-secured-download.de | Hetzner Online GmbH | DE | malicious |
1748 | dmr_72.exe | 5.9.176.3:8080 | ocs3.chdi-server.de | Hetzner Online GmbH | DE | malicious |
1748 | dmr_72.exe | 5.9.198.84:80 | static.chip-secured-download.de | Hetzner Online GmbH | DE | suspicious |
1748 | dmr_72.exe | 185.33.220.145:443 | secure.adnxs.com | AppNexus, Inc | — | unknown |
1748 | dmr_72.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
1748 | dmr_72.exe | 2.16.186.130:443 | downloaderapi.chip.de | Akamai International B.V. | — | whitelisted |
1748 | dmr_72.exe | 2.16.186.168:443 | downloaderapi.chip.de | Akamai International B.V. | — | whitelisted |
1748 | dmr_72.exe | 2.16.186.130:80 | downloaderapi.chip.de | Akamai International B.V. | — | whitelisted |
1748 | dmr_72.exe | 185.26.182.111:443 | net.geo.opera.com | Opera Software AS | — | whitelisted |
1748 | dmr_72.exe | 104.17.177.102:80 | webcompanion.com | Cloudflare Inc | US | shared |
Domain | IP | Reputation |
|---|---|---|
api.chip-secured-download.de |
| unknown |
ocs3.chdi-server.de |
| unknown |
api2.chip-secured-download.de |
| unknown |
static.chip-secured-download.de |
| suspicious |
secure.adnxs.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
downloaderapi.chip.de |
| whitelisted |
r.chip.de |
| whitelisted |
net.geo.opera.com |
| whitelisted |
webcompanion.com |
| malicious |
PID | Process | Class | Message |
|---|---|---|---|
1748 | dmr_72.exe | Misc activity | ADWARE [PTsecurity] DownloadSponsor outbound artifact m1 |
1748 | dmr_72.exe | Misc activity | ADWARE [PTsecurity] DownloadSponsor inbound artifact m1 |
1748 | dmr_72.exe | Misc activity | ADWARE [PTsecurity] DownloadSponsor inbound artifact m1 |
1748 | dmr_72.exe | A Network Trojan was detected | MALWARE [PTsecurity] DownloadSponsor img_welcome PNG artifact |
1748 | dmr_72.exe | Misc activity | ADWARE [PTsecurity] DownloadSponsor inbound artifact m1 |
1748 | dmr_72.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
1748 | dmr_72.exe | Potentially Bad Traffic | ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download |
1748 | dmr_72.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
1748 | dmr_72.exe | Potentially Bad Traffic | ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download |
1748 | dmr_72.exe | Misc activity | ET INFO EXE - Served Attached HTTP |
Process | Message |
|---|---|
WebCompanionInstaller.exe | Detecting windows culture
|
WebCompanionInstaller.exe | 10/11/2020 5:15:17 AM :-> Starting installer 6.0.2270.4122 with: .\WebCompanionInstaller.exe --partner=CH180901IE --campaign=LavasoftIEPRO0 --version=6.0.2270.4122 --prod --silent --partner=CH180901IE --search=1 --homepage=1, Run as admin: True
|
WebCompanionInstaller.exe | Preparing for installing Web Companion
|
WebCompanionInstaller.exe | 10/11/2020 5:15:18 AM :-> Machine Id and Install Id has been generated
|
WebCompanionInstaller.exe | 10/11/2020 5:15:18 AM :-> Generating Machine and Install Id ...
|
WebCompanionInstaller.exe | 10/11/2020 5:15:18 AM :-> Antivirus not detected
|
WebCompanionInstaller.exe | 10/11/2020 5:15:18 AM :-> Checking prerequisites ...
|
WebCompanionInstaller.exe | 10/11/2020 5:15:19 AM :-> vm_check False
|
WebCompanionInstaller.exe | 10/11/2020 5:15:19 AM :-> reg_check :False
|
WebCompanionInstaller.exe | 10/11/2020 5:15:19 AM :-> Installed .Net framework is V40
|