File name:

WcInstaller.exe

Full analysis: https://app.any.run/tasks/06647e51-8bac-4fe3-9ee6-bb11339a4c9f
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: January 17, 2024, 13:55:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
adaware
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

1F1218A4F5AB8EC58A217DE06404B86C

SHA1:

C6B70062E36B14E6DB35F94EFB4016C9F621ED74

SHA256:

7DC5FC24BE9A8531F51C47243D0BBE5B8655CFBA6080ADEA23A4E3308F59DDBA

SSDEEP:

24576:G6VnvKemKRkwbPotvtcUB5c2P/TGkJzZ1o0XPqjvudUKmw5e:G6VnvKzKRkaPotlcUB5c2P/TbxZ1o0/I

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WcInstaller.exe (PID: 2408)
    • ADAWARE has been detected (SURICATA)

      • WebCompanionInstaller.exe (PID: 2016)
  • SUSPICIOUS

    • Reads settings of System Certificates

      • WebCompanionInstaller.exe (PID: 2016)
    • Adds/modifies Windows certificates

      • WebCompanionInstaller.exe (PID: 2016)
    • Executable content was dropped or overwritten

      • WcInstaller.exe (PID: 2408)
    • Searches for installed software

      • WebCompanionInstaller.exe (PID: 2016)
    • Reads security settings of Internet Explorer

      • WebCompanionInstaller.exe (PID: 2016)
    • Checks Windows Trust Settings

      • WebCompanionInstaller.exe (PID: 2016)
    • Process requests binary or script from the Internet

      • WebCompanionInstaller.exe (PID: 2016)
    • Reads the Internet Settings

      • WebCompanionInstaller.exe (PID: 2016)
  • INFO

    • Checks supported languages

      • WebCompanionInstaller.exe (PID: 2016)
      • WcInstaller.exe (PID: 2408)
    • Create files in a temporary directory

      • WcInstaller.exe (PID: 2408)
      • WebCompanionInstaller.exe (PID: 2016)
    • Reads the machine GUID from the registry

      • WebCompanionInstaller.exe (PID: 2016)
    • Reads Environment values

      • WebCompanionInstaller.exe (PID: 2016)
    • Reads the computer name

      • WebCompanionInstaller.exe (PID: 2016)
    • Creates files in the program directory

      • WebCompanionInstaller.exe (PID: 2016)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (36.8)
.exe | Win32 Executable MS Visual C++ (generic) (26.6)
.exe | Win64 Executable (generic) (23.6)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2011:04:18 20:54:06+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 104448
InitializedDataSize: 60416
UninitializedDataSize: -
EntryPoint: 0x148d4
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 9.1.0.993
ProductVersionNumber: 9.1.0.993
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileVersion: 9.1.0.993
ProductVersion: 9.1.0.993
CompanyName: Lavasoft
FileDescription: Web Companion Installer
InternalName: Installer.exe
LegalCopyright: c Lavasoft Limited. All Rights Reserved.
OriginalFileName: Installer.exe
ProductName: Web Companion Installer
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start wcinstaller.exe #ADAWARE webcompanioninstaller.exe wcinstaller.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
128"C:\Users\admin\AppData\Local\Temp\WcInstaller.exe" C:\Users\admin\AppData\Local\Temp\WcInstaller.exeexplorer.exe
User:
admin
Company:
Lavasoft
Integrity Level:
MEDIUM
Description:
Web Companion Installer
Exit code:
3221226540
Version:
9.1.0.993
Modules
Images
c:\users\admin\appdata\local\temp\wcinstaller.exe
c:\windows\system32\ntdll.dll
2016.\WebCompanionInstaller.exe --prodC:\Users\admin\AppData\Local\Temp\7zS86972DDD\WebCompanionInstaller.exe
WcInstaller.exe
User:
admin
Company:
Lavasoft
Integrity Level:
HIGH
Description:
Web Companion
Exit code:
0
Version:
9.1.0.993
Modules
Images
c:\users\admin\appdata\local\temp\7zs86972ddd\webcompanioninstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2408"C:\Users\admin\AppData\Local\Temp\WcInstaller.exe" C:\Users\admin\AppData\Local\Temp\WcInstaller.exe
explorer.exe
User:
admin
Company:
Lavasoft
Integrity Level:
HIGH
Description:
Web Companion Installer
Exit code:
0
Version:
9.1.0.993
Modules
Images
c:\users\admin\appdata\local\temp\wcinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
5 698
Read events
5 682
Write events
16
Delete events
0

Modification events

(PID) Process:(2016) WebCompanionInstaller.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2016) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4
Operation:writeName:Blob
Value:
7E000000010000000800000000C001B39667D601530000000100000041000000303F3020060A6086480186FA6C0A010230123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C0190000000100000010000000FA46CE7CBB85CFB4310075313A09EE0562000000010000002000000043DF5774B03E7FEF5FE40D931A7BEDF1BB2E6B42738C4E6D3841103D3AA7F3390B000000010000001800000045006E00740072007500730074002E006E006500740000001400000001000000140000006A72267AD01EEF7DE73B6951D46C8D9F901266AB1D0000000100000010000000521B5F4582C1DCAAE381B05E37CA2D340300000001000000140000008CF427FD790C3AD166068DE81E57EFBB932272D40F0000000100000020000000FDE5F2D9CE2026E1E10064C0A468C9F355B90ACF85BAF5CE6F52D4016837FD94090000000100000054000000305206082B0601050507030206082B06010505070303060A2B0601040182370A030406082B0601050507030406082B0601050507030606082B0601050507030706082B0601050507030106082B060105050703087F000000010000002C000000302A060A2B0601040182370A030406082B0601050507030506082B0601050507030606082B060105050703072000000001000000420400003082043E30820326A00302010202044A538C28300D06092A864886F70D01010B05003081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D204732301E170D3039303730373137323535345A170D3330313230373137353535345A3081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D20473230820122300D06092A864886F70D01010105000382010F003082010A0282010100BA84B672DB9E0C6BE299E93001A776EA32B895411AC9DA614E5872CFFEF68279BF7361060AA527D8B35FD3454E1C72D64E32F2728A0FF78319D06A808000451EB0C7E79ABF1257271CA3682F0A87BD6A6B0E5E65F31C77D5D4858D7021B4B332E78BA2D5863902B1B8D247CEE4C949C43BA7DEFB547D57BEF0E86EC279B23A0B55E250981632135C2F7856C1C294B3F25AE4279A9F24D7C6ECD09B2582E3CCC2C445C58C977A066B2A119FA90A6E483B6FDBD4111942F78F07BFF5535F9C3EF4172CE669AC4E324C6277EAB7E8E5BB34BC198BAE9C51E7B77EB553B13322E56DCF703C1AFAE29B67B683F48DA5AF624C4DE058AC64341203F8B68D946324A4710203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E041604146A72267AD01EEF7DE73B6951D46C8D9F901266AB300D06092A864886F70D01010B05000382010100799F1D96C6B6793F228D87D3870304606A6B9A2E59897311AC43D1F513FF8D392BC0F2BD4F708CA92FEA17C40B549ED41B9698333CA8AD62A20076AB59696E061D7EC4B9448D98AF12D461DB0A194647F3EBF763C1400540A5D2B7F4B59A36BFA98876880455042B9C877F1A373C7E2DA51AD8D4895ECABDAC3D6CD86DAFD5F3760FCD3B8838229D6C939AC43DBF821B653FA60F5DAAFCE5B215CAB5ADC6BC3DD084E8EA0672B04D393278BF3E119C0BA49D9A21F3F09B0B3078DBC1DC8743FEBC639ACAC5C21CC9C78DFF3B125808E6B63DEC7A2C4EFB8396CE0C3C69875473A473C293FF5110AC155401D8FC05B189A17F74839A49D7DC4E7B8A486F8B45F6
(PID) Process:(2016) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4
Operation:writeName:Blob
Value:
0400000001000000100000004BE2C99196650CF40E5A9392A00AFEB27F000000010000002C000000302A060A2B0601040182370A030406082B0601050507030506082B0601050507030606082B06010505070307090000000100000054000000305206082B0601050507030206082B06010505070303060A2B0601040182370A030406082B0601050507030406082B0601050507030606082B0601050507030706082B0601050507030106082B060105050703080F0000000100000020000000FDE5F2D9CE2026E1E10064C0A468C9F355B90ACF85BAF5CE6F52D4016837FD940300000001000000140000008CF427FD790C3AD166068DE81E57EFBB932272D41D0000000100000010000000521B5F4582C1DCAAE381B05E37CA2D341400000001000000140000006A72267AD01EEF7DE73B6951D46C8D9F901266AB0B000000010000001800000045006E00740072007500730074002E006E0065007400000062000000010000002000000043DF5774B03E7FEF5FE40D931A7BEDF1BB2E6B42738C4E6D3841103D3AA7F339190000000100000010000000FA46CE7CBB85CFB4310075313A09EE05530000000100000041000000303F3020060A6086480186FA6C0A010230123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C07E000000010000000800000000C001B39667D6012000000001000000420400003082043E30820326A00302010202044A538C28300D06092A864886F70D01010B05003081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D204732301E170D3039303730373137323535345A170D3330313230373137353535345A3081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D20473230820122300D06092A864886F70D01010105000382010F003082010A0282010100BA84B672DB9E0C6BE299E93001A776EA32B895411AC9DA614E5872CFFEF68279BF7361060AA527D8B35FD3454E1C72D64E32F2728A0FF78319D06A808000451EB0C7E79ABF1257271CA3682F0A87BD6A6B0E5E65F31C77D5D4858D7021B4B332E78BA2D5863902B1B8D247CEE4C949C43BA7DEFB547D57BEF0E86EC279B23A0B55E250981632135C2F7856C1C294B3F25AE4279A9F24D7C6ECD09B2582E3CCC2C445C58C977A066B2A119FA90A6E483B6FDBD4111942F78F07BFF5535F9C3EF4172CE669AC4E324C6277EAB7E8E5BB34BC198BAE9C51E7B77EB553B13322E56DCF703C1AFAE29B67B683F48DA5AF624C4DE058AC64341203F8B68D946324A4710203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E041604146A72267AD01EEF7DE73B6951D46C8D9F901266AB300D06092A864886F70D01010B05000382010100799F1D96C6B6793F228D87D3870304606A6B9A2E59897311AC43D1F513FF8D392BC0F2BD4F708CA92FEA17C40B549ED41B9698333CA8AD62A20076AB59696E061D7EC4B9448D98AF12D461DB0A194647F3EBF763C1400540A5D2B7F4B59A36BFA98876880455042B9C877F1A373C7E2DA51AD8D4895ECABDAC3D6CD86DAFD5F3760FCD3B8838229D6C939AC43DBF821B653FA60F5DAAFCE5B215CAB5ADC6BC3DD084E8EA0672B04D393278BF3E119C0BA49D9A21F3F09B0B3078DBC1DC8743FEBC639ACAC5C21CC9C78DFF3B125808E6B63DEC7A2C4EFB8396CE0C3C69875473A473C293FF5110AC155401D8FC05B189A17F74839A49D7DC4E7B8A486F8B45F6
Executable files
13
Suspicious files
1
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
2408WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS86972DDD\de-DE\WebCompanionInstaller.resources.dllexecutable
MD5:CC635544603937E6C0B95528C6174D36
SHA256:706A3B4FD8343489EEE470A1E3D1C1065CB5D63B40FD10680286EDEE261D186A
2408WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS86972DDD\ru-RU\WebCompanionInstaller.resources.dllexecutable
MD5:0B427E896A2D725C74AA971E95F59ADA
SHA256:DCD1A941DA556923D91035EB792128EA6A2C14F3E3D52C7390FDA80BBCC81396
2408WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS86972DDD\pt-BR\WebCompanionInstaller.resources.dllexecutable
MD5:D75883F958CC8E6F01BA6CA238B9B062
SHA256:A258724DA32D945361CE4FBFD3DFA9D40CC574BB5E19BC8106DBBA9549640BB2
2408WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS86972DDD\en-US\WebCompanionInstaller.resources.dllexecutable
MD5:A38A454C58268F7D7E515E05B630FD15
SHA256:7927D35DB9171A88EA7DF1C2F604B4E139F5E34A661ABF5366BB3EA67E3C9035
2408WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS86972DDD\tr-TR\WebCompanionInstaller.resources.dllexecutable
MD5:6E4A42861DBE2BF7933CA69287D0C4B1
SHA256:0D0BB607D963EC6EE3DACAC6947589FD2A2066EDB96F89F0709C32F7120F3AAF
2408WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS86972DDD\es-ES\WebCompanionInstaller.resources.dllexecutable
MD5:D3DA635F012FB80108EDA2BC7A28A7E6
SHA256:4B11F05CFED5E4DB094FEBAD3DDAF7A4C869F70AAAF3C1868A45378700030894
2408WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS86972DDD\ja-JP\WebCompanionInstaller.resources.dllexecutable
MD5:5B9E5F2E9C9F380FC0E6C36A65AE8980
SHA256:3F2824E50E88B92127A94942F9384E5B843C8E99E621E707A155DC7A5AE9AEB8
2408WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS86972DDD\Newtonsoft.Json.dllexecutable
MD5:2E22312B40CA5093AC2D4C7823BD7F1B
SHA256:6E5CACEBF3911CDD1B41962C6AA150FFCED3B1D44AE6B64ED18F34005B517ACC
2408WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS86972DDD\it-IT\WebCompanionInstaller.resources.dllexecutable
MD5:97A2470A5463243ECA160C28BF617607
SHA256:A03466AF77CD6245AB011128043DED7204E9B4E717DC5BC1A29E7B89A244DE19
2016WebCompanionInstaller.exeC:\ProgramData\Lavasoft\Web Companion\Options\Statistics.txtbinary
MD5:C380FE5FF7CD92AD1043A86B67DB4DE0
SHA256:D164736356F0E2FF1462BBC7A4C8EDB9D52CE85C86B567CB676066357544C74A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
7
DNS requests
3
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2016
WebCompanionInstaller.exe
POST
200
104.17.9.52:80
http://flow.lavasoft.com/v1/event-stat-wc?Type=ProgressInstall&ProductID=wc&EventVersion=1
unknown
binary
29 b
unknown
2016
WebCompanionInstaller.exe
GET
104.17.9.52:80
http://wcdownloadercdn.lavasoft.com/7.0.2417.4248/WcInstaller.exe
unknown
unknown
2016
WebCompanionInstaller.exe
POST
200
64.18.87.81:80
http://wc-update-service.lavasoft.com/update.asmx
unknown
xml
1.45 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2016
WebCompanionInstaller.exe
104.17.9.52:80
flow.lavasoft.com
CLOUDFLARENET
shared
1080
svchost.exe
224.0.0.252:5355
unknown
2016
WebCompanionInstaller.exe
64.18.87.81:80
wc-update-service.lavasoft.com
MTO
CA
unknown

DNS requests

Domain
IP
Reputation
flow.lavasoft.com
  • 104.17.9.52
  • 104.17.8.52
whitelisted
wc-update-service.lavasoft.com
  • 64.18.87.81
  • 64.18.87.82
whitelisted
wcdownloadercdn.lavasoft.com
  • 104.17.9.52
  • 104.17.8.52
whitelisted

Threats

PID
Process
Class
Message
2016
WebCompanionInstaller.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
2016
WebCompanionInstaller.exe
Potential Corporate Privacy Violation
AV POLICY HTTP request for .exe file with no User-Agent
2016
WebCompanionInstaller.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
2016
WebCompanionInstaller.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
Process
Message
WebCompanionInstaller.exe
Detecting windows culture
WebCompanionInstaller.exe
1/17/2024 1:55:44 PM :-> Starting installer 9.1.0.993 with: .\WebCompanionInstaller.exe --prod, Run as admin: True