File name:

MDE_File_Sample_cb3af2f95862289fc38a301c4052d38ffe8de74a.zip

Full analysis: https://app.any.run/tasks/0412711f-5caf-4d27-a16f-6156cf9fc855
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: May 16, 2025, 00:12:42
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
adware
adaware
arch-scr
webcompanion
tool
stealer
arch-exec
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

5B60E411F0D8BF18BD8EDB8481ABE106

SHA1:

BFD6F9375B65D58B8BFF9E357A7835EB2718B81B

SHA256:

8044ADD86C79CAAD19BFC20157FB29BA64DF6BD9B9364914F52CC5C6E5768B42

SSDEEP:

24576:6mTwWjWLxni3bi7q7cb1NX42FFx4QnjB14RLbnZg6M:6mTwWj6xni3+7q7cb1NX4KFx4QnjB14i

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • WebCompanion.exe (PID: 7204)
      • WebCompanion.exe (PID: 5892)
    • ADAWARE has been detected (SURICATA)

      • WebCompanion.exe (PID: 7204)
    • Actions looks like stealing of personal data

      • WebCompanion.exe (PID: 5892)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 976)
      • Setup (3).exe (PID: 7692)
      • WebCompanion.exe (PID: 7204)
      • WebCompanion.exe (PID: 5892)
    • Drops 7-zip archiver for unpacking

      • Setup (3).exe (PID: 7692)
    • Executable content was dropped or overwritten

      • Setup (3).exe (PID: 7692)
    • The process creates files with name similar to system file names

      • Setup (3).exe (PID: 7692)
    • The process drops C-runtime libraries

      • Setup (3).exe (PID: 7692)
    • Process drops legitimate windows executable

      • Setup (3).exe (PID: 7692)
    • Creates a software uninstall entry

      • Setup (3).exe (PID: 7692)
    • Searches for installed software

      • Setup (3).exe (PID: 7692)
      • WebCompanion.exe (PID: 7204)
      • WebCompanion.exe (PID: 5892)
    • Starts CMD.EXE for commands execution

      • Setup (3).exe (PID: 7692)
    • Access to an unwanted program domain was detected

      • WebCompanion.exe (PID: 7204)
    • Suspicious use of NETSH.EXE

      • cmd.exe (PID: 8088)
    • The process checks if it is being run in the virtual environment

      • WebCompanion.exe (PID: 5892)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 976)
    • Checks supported languages

      • Setup (3).exe (PID: 7692)
      • WebCompanion.exe (PID: 7204)
      • WebCompanion.exe (PID: 5892)
    • Reads the machine GUID from the registry

      • Setup (3).exe (PID: 7692)
      • WebCompanion.exe (PID: 7204)
      • WebCompanion.exe (PID: 5892)
    • Create files in a temporary directory

      • Setup (3).exe (PID: 7692)
    • Reads the computer name

      • Setup (3).exe (PID: 7692)
      • WebCompanion.exe (PID: 7204)
      • WebCompanion.exe (PID: 5892)
    • Creates files or folders in the user directory

      • Setup (3).exe (PID: 7692)
      • WebCompanion.exe (PID: 7204)
      • WebCompanion.exe (PID: 5892)
    • Disables trace logs

      • Setup (3).exe (PID: 7692)
      • WebCompanion.exe (PID: 7204)
      • WebCompanion.exe (PID: 5892)
    • Checks proxy server information

      • Setup (3).exe (PID: 7692)
      • WebCompanion.exe (PID: 7204)
      • WebCompanion.exe (PID: 5892)
    • Reads the software policy settings

      • Setup (3).exe (PID: 7692)
      • WebCompanion.exe (PID: 7204)
      • WebCompanion.exe (PID: 5892)
    • The sample compiled with english language support

      • Setup (3).exe (PID: 7692)
    • Process checks computer location settings

      • Setup (3).exe (PID: 7692)
    • SQLite executable

      • Setup (3).exe (PID: 7692)
    • Creates files in the program directory

      • WebCompanion.exe (PID: 7204)
    • ADAWAREWEBCOMPANION mutex has been found

      • WebCompanion.exe (PID: 5892)
    • Application launched itself

      • firefox.exe (PID: 3760)
      • firefox.exe (PID: 7152)
      • chrome.exe (PID: 5392)
    • Manual execution by a user

      • firefox.exe (PID: 3760)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0001
ZipCompression: Deflated
ZipModifyDate: 2025:05:16 00:12:00
ZipCRC: 0x192ea16b
ZipCompressedSize: 473671
ZipUncompressedSize: 744712
ZipFileName: Setup (3).exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
182
Monitored processes
45
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe sppextcomobj.exe no specs slui.exe setup (3).exe cmd.exe no specs conhost.exe no specs netsh.exe no specs #ADAWARE webcompanion.exe webcompanion.exe chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs slui.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs rundll32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
132"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4964 -parentBuildID 20240213221259 -sandboxingKind 0 -prefsHandle 5004 -prefMapHandle 4920 -prefsLen 38192 -prefMapSize 244975 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {584e40a3-e11d-4cc5-be99-fbc1e11a283b} 7152 "\\.\pipe\gecko-crash-server-pipe.7152" 22123876f10 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
1
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\vcruntime140_1.dll
300"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=6012 --field-trial-handle=1964,i,652033650562675634,8979838265349369336,262144 --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
616"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4940 -childID 5 -isForBrowser -prefsHandle 5084 -prefMapHandle 4196 -prefsLen 31247 -prefMapSize 244975 -jsInitHandle 1524 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {08717e76-2871-4186-96ab-238c422fa193} 7152 "\\.\pipe\gecko-crash-server-pipe.7152" 22125c89f50 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
976"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\MDE_File_Sample_cb3af2f95862289fc38a301c4052d38ffe8de74a.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1628"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.ProcessorMetrics --lang=en-US --service-sandbox-type=none --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=5584 --field-trial-handle=1964,i,652033650562675634,8979838265349369336,262144 --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1912"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4976 -childID 3 -isForBrowser -prefsHandle 4984 -prefMapHandle 4332 -prefsLen 31247 -prefMapSize 244975 -jsInitHandle 1524 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {0fe9adc1-dd0c-4c9b-8e63-2e74bfeb8f27} 7152 "\\.\pipe\gecko-crash-server-pipe.7152" 221252c2f50 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\msvcp140.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\crypt32.dll
2268"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=4872 --field-trial-handle=1964,i,652033650562675634,8979838265349369336,262144 --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2288"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=6060 --field-trial-handle=1964,i,652033650562675634,8979838265349369336,262144 --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2504"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=1952 --field-trial-handle=1964,i,652033650562675634,8979838265349369336,262144 --variations-seed-version /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2800"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=5884 --field-trial-handle=1964,i,652033650562675634,8979838265349369336,262144 --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
42 383
Read events
42 307
Write events
74
Delete events
2

Modification events

(PID) Process:(976) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(976) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(976) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(976) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\MDE_File_Sample_cb3af2f95862289fc38a301c4052d38ffe8de74a.zip
(PID) Process:(976) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(976) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(976) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(976) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(976) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(7692) Setup (3).exeKey:HKEY_CURRENT_USER\SOFTWARE\Lavasoft\Web Companion
Operation:writeName:MachineId
Value:
ad1f12af-3f36-3c28-b351-2ce4355f42c2
Executable files
70
Suspicious files
305
Text files
109
Unknown types
1

Dropped files

PID
Process
Filename
Type
7692Setup (3).exeC:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Options\Statistics.txtbinary
MD5:97B0DF43F589721404517904603ACAB6
SHA256:5C0BBC0A8BDFFFF0335A3AEB7DF7F1B6828C0BF8C364FE746C7AC29CA86F43D6
7692Setup (3).exeC:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Application\BCUEngineS.dllexecutable
MD5:AFCCE3F23C9C31DE19A91FC7D436A516
SHA256:4055E2A085F44DBCD464983F9316E5A33B5056AF8ABED05FD4DFEBFDE162DD77
7692Setup (3).exeC:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Application\FeatureInstaller.exeexecutable
MD5:70F3C5BB9046EDB9EE0BA0CDF63698DF
SHA256:8EB6D08CCDF88ACC4F7DE252779565A93BB57379591275EF3FA0C33303C60C0E
976WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb976.18675\Setup (3).exeexecutable
MD5:26550D533B6D68DEBCA235495FE9461C
SHA256:1293BB8E0C70D890EE9C841DF7DAD43DA6A7192641F73A55B0DC4D14108FF279
7692Setup (3).exeC:\Users\admin\AppData\Local\Temp\Rar$EXb976.18675\App.configxml
MD5:9965A5BB6C522F5E1F52EBAB89A9EF69
SHA256:937962C98E0CDBF26416C0A4EA4F5F4F6C26FCD7ADA158883D51602CDF0462E1
7692Setup (3).exeC:\Users\admin\AppData\Local\Temp\WebCompanion.zipcompressed
MD5:C0A2AAF917E6BC1D951EC481213D4138
SHA256:2F87DCD36A114502A3C80ECF8A8C5F5EF60475951F9C142A1A68BDEC6CAA3E23
7692Setup (3).exeC:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Application\acs17.dllexecutable
MD5:56732B85F3168BA6852CD1EAC84164B0
SHA256:AAAF2F91C0F5172AFBCF15D9F06A706BB23FBBEA40361F64E8552A7D7C96F62D
7692Setup (3).exeC:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Application\FeatureComponent.dllexecutable
MD5:76F9FF88BFAB074CF3657E8CD007C858
SHA256:42087B3045C86316D2B85FA23466A0BB84935B52D0537D9B2A6C857DEC4EDA38
7692Setup (3).exeC:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Application\7za.exeexecutable
MD5:7BE563AC01DDE847D6837D38575CEA85
SHA256:6ACE813AAAE0D754B92C31178564623045B12A4F239BBC075270DB3D97F0FF2D
7692Setup (3).exeC:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Application\FeatureMainComponent.exe.configxml
MD5:568B93BE462E5660BDB8E9CFAE715B4D
SHA256:CF8F505544E172B3A91138D2FA71A8B3CAA2B5296B500275AC50406D2B116593
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
33
TCP/UDP connections
120
DNS requests
174
Threats
14

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7204
WebCompanion.exe
GET
200
64.18.87.81:80
http://wc-partners.lavasoft.com/Partner.svc/GetPartnerInfo?partner=IN250101_ac
unknown
whitelisted
7204
WebCompanion.exe
GET
200
64.18.87.81:80
http://wc-partners.lavasoft.com/Partner.svc/GetPartnerInfo?partner=IN250101_ab
unknown
whitelisted
7204
WebCompanion.exe
GET
200
64.18.87.81:80
http://wc-partners.lavasoft.com/Partner.svc/GetPartnerInfo?partner=IN250101
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
7204
WebCompanion.exe
GET
200
104.16.148.130:80
http://geo.lavasoft.com/
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
7204
WebCompanion.exe
GET
200
104.19.208.152:80
http://webcompanion.com/version_logs?json=true&version=13.900.0.1080
unknown
unknown
2924
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
GET
200
23.216.77.42:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
23.216.77.42:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:137
whitelisted
6544
svchost.exe
20.190.159.64:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7692
Setup (3).exe
104.16.148.130:80
geo.lavasoft.com
CLOUDFLARENET
whitelisted
7692
Setup (3).exe
104.16.149.130:443
geo.lavasoft.com
CLOUDFLARENET
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 23.216.77.42
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
google.com
  • 216.58.206.78
whitelisted
login.live.com
  • 20.190.159.64
  • 40.126.31.130
  • 40.126.31.128
  • 40.126.31.71
  • 40.126.31.73
  • 20.190.159.71
  • 20.190.159.68
  • 20.190.159.4
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
geo.lavasoft.com
  • 104.16.148.130
  • 104.16.149.130
whitelisted
featureflags.lavasoft.com
  • 104.16.149.130
  • 104.16.148.130
whitelisted
flwadw.com
  • 104.18.26.149
  • 104.18.27.149
unknown
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted

Threats

PID
Process
Class
Message
7204
WebCompanion.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
7204
WebCompanion.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
7204
WebCompanion.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
7392
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
7392
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
7392
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
7392
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
7392
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
7392
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
7392
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
No debug info