File name:

WcInstaller.exe

Full analysis: https://app.any.run/tasks/06647e51-8bac-4fe3-9ee6-bb11339a4c9f
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: January 17, 2024, 13:55:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
adaware
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

1F1218A4F5AB8EC58A217DE06404B86C

SHA1:

C6B70062E36B14E6DB35F94EFB4016C9F621ED74

SHA256:

7DC5FC24BE9A8531F51C47243D0BBE5B8655CFBA6080ADEA23A4E3308F59DDBA

SSDEEP:

24576:G6VnvKemKRkwbPotvtcUB5c2P/TGkJzZ1o0XPqjvudUKmw5e:G6VnvKzKRkaPotlcUB5c2P/TbxZ1o0/I

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WcInstaller.exe (PID: 2408)
    • ADAWARE has been detected (SURICATA)

      • WebCompanionInstaller.exe (PID: 2016)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WcInstaller.exe (PID: 2408)
    • Reads security settings of Internet Explorer

      • WebCompanionInstaller.exe (PID: 2016)
    • Reads settings of System Certificates

      • WebCompanionInstaller.exe (PID: 2016)
    • Checks Windows Trust Settings

      • WebCompanionInstaller.exe (PID: 2016)
    • Adds/modifies Windows certificates

      • WebCompanionInstaller.exe (PID: 2016)
    • Searches for installed software

      • WebCompanionInstaller.exe (PID: 2016)
    • Reads the Internet Settings

      • WebCompanionInstaller.exe (PID: 2016)
    • Process requests binary or script from the Internet

      • WebCompanionInstaller.exe (PID: 2016)
  • INFO

    • Checks supported languages

      • WcInstaller.exe (PID: 2408)
      • WebCompanionInstaller.exe (PID: 2016)
    • Reads the machine GUID from the registry

      • WebCompanionInstaller.exe (PID: 2016)
    • Create files in a temporary directory

      • WcInstaller.exe (PID: 2408)
      • WebCompanionInstaller.exe (PID: 2016)
    • Reads the computer name

      • WebCompanionInstaller.exe (PID: 2016)
    • Reads Environment values

      • WebCompanionInstaller.exe (PID: 2016)
    • Creates files in the program directory

      • WebCompanionInstaller.exe (PID: 2016)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (36.8)
.exe | Win32 Executable MS Visual C++ (generic) (26.6)
.exe | Win64 Executable (generic) (23.6)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2011:04:18 20:54:06+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 104448
InitializedDataSize: 60416
UninitializedDataSize: -
EntryPoint: 0x148d4
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 9.1.0.993
ProductVersionNumber: 9.1.0.993
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileVersion: 9.1.0.993
ProductVersion: 9.1.0.993
CompanyName: Lavasoft
FileDescription: Web Companion Installer
InternalName: Installer.exe
LegalCopyright: c Lavasoft Limited. All Rights Reserved.
OriginalFileName: Installer.exe
ProductName: Web Companion Installer
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start wcinstaller.exe #ADAWARE webcompanioninstaller.exe wcinstaller.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
128"C:\Users\admin\AppData\Local\Temp\WcInstaller.exe" C:\Users\admin\AppData\Local\Temp\WcInstaller.exeexplorer.exe
User:
admin
Company:
Lavasoft
Integrity Level:
MEDIUM
Description:
Web Companion Installer
Exit code:
3221226540
Version:
9.1.0.993
Modules
Images
c:\users\admin\appdata\local\temp\wcinstaller.exe
c:\windows\system32\ntdll.dll
2016.\WebCompanionInstaller.exe --prodC:\Users\admin\AppData\Local\Temp\7zS86972DDD\WebCompanionInstaller.exe
WcInstaller.exe
User:
admin
Company:
Lavasoft
Integrity Level:
HIGH
Description:
Web Companion
Exit code:
0
Version:
9.1.0.993
Modules
Images
c:\users\admin\appdata\local\temp\7zs86972ddd\webcompanioninstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2408"C:\Users\admin\AppData\Local\Temp\WcInstaller.exe" C:\Users\admin\AppData\Local\Temp\WcInstaller.exe
explorer.exe
User:
admin
Company:
Lavasoft
Integrity Level:
HIGH
Description:
Web Companion Installer
Exit code:
0
Version:
9.1.0.993
Modules
Images
c:\users\admin\appdata\local\temp\wcinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
5 698
Read events
5 682
Write events
16
Delete events
0

Modification events

(PID) Process:(2016) WebCompanionInstaller.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2016) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4
Operation:writeName:Blob
Value:
7E000000010000000800000000C001B39667D601530000000100000041000000303F3020060A6086480186FA6C0A010230123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C0190000000100000010000000FA46CE7CBB85CFB4310075313A09EE0562000000010000002000000043DF5774B03E7FEF5FE40D931A7BEDF1BB2E6B42738C4E6D3841103D3AA7F3390B000000010000001800000045006E00740072007500730074002E006E006500740000001400000001000000140000006A72267AD01EEF7DE73B6951D46C8D9F901266AB1D0000000100000010000000521B5F4582C1DCAAE381B05E37CA2D340300000001000000140000008CF427FD790C3AD166068DE81E57EFBB932272D40F0000000100000020000000FDE5F2D9CE2026E1E10064C0A468C9F355B90ACF85BAF5CE6F52D4016837FD94090000000100000054000000305206082B0601050507030206082B06010505070303060A2B0601040182370A030406082B0601050507030406082B0601050507030606082B0601050507030706082B0601050507030106082B060105050703087F000000010000002C000000302A060A2B0601040182370A030406082B0601050507030506082B0601050507030606082B060105050703072000000001000000420400003082043E30820326A00302010202044A538C28300D06092A864886F70D01010B05003081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D204732301E170D3039303730373137323535345A170D3330313230373137353535345A3081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D20473230820122300D06092A864886F70D01010105000382010F003082010A0282010100BA84B672DB9E0C6BE299E93001A776EA32B895411AC9DA614E5872CFFEF68279BF7361060AA527D8B35FD3454E1C72D64E32F2728A0FF78319D06A808000451EB0C7E79ABF1257271CA3682F0A87BD6A6B0E5E65F31C77D5D4858D7021B4B332E78BA2D5863902B1B8D247CEE4C949C43BA7DEFB547D57BEF0E86EC279B23A0B55E250981632135C2F7856C1C294B3F25AE4279A9F24D7C6ECD09B2582E3CCC2C445C58C977A066B2A119FA90A6E483B6FDBD4111942F78F07BFF5535F9C3EF4172CE669AC4E324C6277EAB7E8E5BB34BC198BAE9C51E7B77EB553B13322E56DCF703C1AFAE29B67B683F48DA5AF624C4DE058AC64341203F8B68D946324A4710203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E041604146A72267AD01EEF7DE73B6951D46C8D9F901266AB300D06092A864886F70D01010B05000382010100799F1D96C6B6793F228D87D3870304606A6B9A2E59897311AC43D1F513FF8D392BC0F2BD4F708CA92FEA17C40B549ED41B9698333CA8AD62A20076AB59696E061D7EC4B9448D98AF12D461DB0A194647F3EBF763C1400540A5D2B7F4B59A36BFA98876880455042B9C877F1A373C7E2DA51AD8D4895ECABDAC3D6CD86DAFD5F3760FCD3B8838229D6C939AC43DBF821B653FA60F5DAAFCE5B215CAB5ADC6BC3DD084E8EA0672B04D393278BF3E119C0BA49D9A21F3F09B0B3078DBC1DC8743FEBC639ACAC5C21CC9C78DFF3B125808E6B63DEC7A2C4EFB8396CE0C3C69875473A473C293FF5110AC155401D8FC05B189A17F74839A49D7DC4E7B8A486F8B45F6
(PID) Process:(2016) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4
Operation:writeName:Blob
Value:
0400000001000000100000004BE2C99196650CF40E5A9392A00AFEB27F000000010000002C000000302A060A2B0601040182370A030406082B0601050507030506082B0601050507030606082B06010505070307090000000100000054000000305206082B0601050507030206082B06010505070303060A2B0601040182370A030406082B0601050507030406082B0601050507030606082B0601050507030706082B0601050507030106082B060105050703080F0000000100000020000000FDE5F2D9CE2026E1E10064C0A468C9F355B90ACF85BAF5CE6F52D4016837FD940300000001000000140000008CF427FD790C3AD166068DE81E57EFBB932272D41D0000000100000010000000521B5F4582C1DCAAE381B05E37CA2D341400000001000000140000006A72267AD01EEF7DE73B6951D46C8D9F901266AB0B000000010000001800000045006E00740072007500730074002E006E0065007400000062000000010000002000000043DF5774B03E7FEF5FE40D931A7BEDF1BB2E6B42738C4E6D3841103D3AA7F339190000000100000010000000FA46CE7CBB85CFB4310075313A09EE05530000000100000041000000303F3020060A6086480186FA6C0A010230123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C07E000000010000000800000000C001B39667D6012000000001000000420400003082043E30820326A00302010202044A538C28300D06092A864886F70D01010B05003081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D204732301E170D3039303730373137323535345A170D3330313230373137353535345A3081BE310B300906035504061302555331163014060355040A130D456E74727573742C20496E632E31283026060355040B131F536565207777772E656E74727573742E6E65742F6C6567616C2D7465726D7331393037060355040B1330286329203230303920456E74727573742C20496E632E202D20666F7220617574686F72697A656420757365206F6E6C793132303006035504031329456E747275737420526F6F742043657274696669636174696F6E20417574686F72697479202D20473230820122300D06092A864886F70D01010105000382010F003082010A0282010100BA84B672DB9E0C6BE299E93001A776EA32B895411AC9DA614E5872CFFEF68279BF7361060AA527D8B35FD3454E1C72D64E32F2728A0FF78319D06A808000451EB0C7E79ABF1257271CA3682F0A87BD6A6B0E5E65F31C77D5D4858D7021B4B332E78BA2D5863902B1B8D247CEE4C949C43BA7DEFB547D57BEF0E86EC279B23A0B55E250981632135C2F7856C1C294B3F25AE4279A9F24D7C6ECD09B2582E3CCC2C445C58C977A066B2A119FA90A6E483B6FDBD4111942F78F07BFF5535F9C3EF4172CE669AC4E324C6277EAB7E8E5BB34BC198BAE9C51E7B77EB553B13322E56DCF703C1AFAE29B67B683F48DA5AF624C4DE058AC64341203F8B68D946324A4710203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E041604146A72267AD01EEF7DE73B6951D46C8D9F901266AB300D06092A864886F70D01010B05000382010100799F1D96C6B6793F228D87D3870304606A6B9A2E59897311AC43D1F513FF8D392BC0F2BD4F708CA92FEA17C40B549ED41B9698333CA8AD62A20076AB59696E061D7EC4B9448D98AF12D461DB0A194647F3EBF763C1400540A5D2B7F4B59A36BFA98876880455042B9C877F1A373C7E2DA51AD8D4895ECABDAC3D6CD86DAFD5F3760FCD3B8838229D6C939AC43DBF821B653FA60F5DAAFCE5B215CAB5ADC6BC3DD084E8EA0672B04D393278BF3E119C0BA49D9A21F3F09B0B3078DBC1DC8743FEBC639ACAC5C21CC9C78DFF3B125808E6B63DEC7A2C4EFB8396CE0C3C69875473A473C293FF5110AC155401D8FC05B189A17F74839A49D7DC4E7B8A486F8B45F6
Executable files
13
Suspicious files
1
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
2408WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS86972DDD\en-US\WebCompanionInstaller.resources.dllexecutable
MD5:A38A454C58268F7D7E515E05B630FD15
SHA256:7927D35DB9171A88EA7DF1C2F604B4E139F5E34A661ABF5366BB3EA67E3C9035
2408WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS86972DDD\ICSharpCode.SharpZipLib.dllexecutable
MD5:E6BB367B7C30C2A892CD2B9A21727547
SHA256:C451F459F3971F2151578E4BA3080B9F25BA8FC2C0BBAEE2C1BF867A27703741
2408WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS86972DDD\tr-TR\WebCompanionInstaller.resources.dllexecutable
MD5:6E4A42861DBE2BF7933CA69287D0C4B1
SHA256:0D0BB607D963EC6EE3DACAC6947589FD2A2066EDB96F89F0709C32F7120F3AAF
2408WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS86972DDD\ru-RU\WebCompanionInstaller.resources.dllexecutable
MD5:0B427E896A2D725C74AA971E95F59ADA
SHA256:DCD1A941DA556923D91035EB792128EA6A2C14F3E3D52C7390FDA80BBCC81396
2408WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS86972DDD\WebCompanionInstaller.exe.configxml
MD5:1103E1618F5BB75851E0F0C753EC8EC5
SHA256:133F4FCE3A299387263F849250CCEE387B137EE3FF36C6B44B4C02328EDFAAF3
2408WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS86972DDD\zh-CHS\WebCompanionInstaller.resources.dllexecutable
MD5:1B6691D38C481CF8261405693434990E
SHA256:34DDFE9488C90EEE14AE4D22585FEACB496A16F268F1ECE876749422311BD93E
2408WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS86972DDD\Newtonsoft.Json.dllexecutable
MD5:2E22312B40CA5093AC2D4C7823BD7F1B
SHA256:6E5CACEBF3911CDD1B41962C6AA150FFCED3B1D44AE6B64ED18F34005B517ACC
2408WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS86972DDD\it-IT\WebCompanionInstaller.resources.dllexecutable
MD5:97A2470A5463243ECA160C28BF617607
SHA256:A03466AF77CD6245AB011128043DED7204E9B4E717DC5BC1A29E7B89A244DE19
2408WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS86972DDD\WebCompanionInstaller.exeexecutable
MD5:80619C0E2165AB0C217D4355461DA07D
SHA256:73184A675024891B66356A2A93FF31BD4D4CDB129274B77B1BA536A35A62D83C
2016WebCompanionInstaller.exeC:\ProgramData\Lavasoft\Web Companion\Options\Statistics.txtbinary
MD5:C380FE5FF7CD92AD1043A86B67DB4DE0
SHA256:D164736356F0E2FF1462BBC7A4C8EDB9D52CE85C86B567CB676066357544C74A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
7
DNS requests
3
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2016
WebCompanionInstaller.exe
POST
200
104.17.9.52:80
http://flow.lavasoft.com/v1/event-stat-wc?Type=ProgressInstall&ProductID=wc&EventVersion=1
unknown
binary
29 b
unknown
2016
WebCompanionInstaller.exe
GET
104.17.9.52:80
http://wcdownloadercdn.lavasoft.com/7.0.2417.4248/WcInstaller.exe
unknown
unknown
2016
WebCompanionInstaller.exe
POST
200
64.18.87.81:80
http://wc-update-service.lavasoft.com/update.asmx
unknown
xml
1.45 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2016
WebCompanionInstaller.exe
104.17.9.52:80
flow.lavasoft.com
CLOUDFLARENET
shared
1080
svchost.exe
224.0.0.252:5355
unknown
2016
WebCompanionInstaller.exe
64.18.87.81:80
wc-update-service.lavasoft.com
MTO
CA
unknown

DNS requests

Domain
IP
Reputation
flow.lavasoft.com
  • 104.17.9.52
  • 104.17.8.52
whitelisted
wc-update-service.lavasoft.com
  • 64.18.87.81
  • 64.18.87.82
whitelisted
wcdownloadercdn.lavasoft.com
  • 104.17.9.52
  • 104.17.8.52
whitelisted

Threats

PID
Process
Class
Message
2016
WebCompanionInstaller.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
2016
WebCompanionInstaller.exe
Potential Corporate Privacy Violation
AV POLICY HTTP request for .exe file with no User-Agent
2016
WebCompanionInstaller.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
2016
WebCompanionInstaller.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
Process
Message
WebCompanionInstaller.exe
Detecting windows culture
WebCompanionInstaller.exe
1/17/2024 1:55:44 PM :-> Starting installer 9.1.0.993 with: .\WebCompanionInstaller.exe --prod, Run as admin: True