URL:

http://wcdownloadercdn.lavasoft.com/8.9.0.992/WcInstaller.exe

Full analysis: https://app.any.run/tasks/a1e2a410-1fc0-4928-9cf8-90d552ade76d
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: January 31, 2024, 20:08:39
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
adware
adaware
Indicators:
MD5:

856358547E774A4F1C80F9ACA540F61F

SHA1:

7BE44B71B22F16E70A854D7D88E10DF960425430

SHA256:

919C1483DFE8E93BF1026AD3F77AF6B252325D6E0595D66BE7BCEAC56D6C811E

SSDEEP:

3:N1KJGDodXGpJEraRdWhccXpbJOXLNn:CIAQmccXptOXLN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WcInstaller.exe (PID: 3420)
      • WebCompanionInstaller.exe (PID: 3624)
      • WcInstaller.exe (PID: 4040)
    • ADAWARE has been detected (SURICATA)

      • WebCompanionInstaller.exe (PID: 3624)
      • WebCompanionInstaller.exe (PID: 2540)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WcInstaller.exe (PID: 3420)
      • WebCompanionInstaller.exe (PID: 3624)
      • WcInstaller.exe (PID: 4040)
    • Reads security settings of Internet Explorer

      • WebCompanionInstaller.exe (PID: 3624)
      • WebCompanionInstaller.exe (PID: 2540)
    • Searches for installed software

      • WebCompanionInstaller.exe (PID: 3624)
    • Checks Windows Trust Settings

      • WebCompanionInstaller.exe (PID: 3624)
      • WebCompanionInstaller.exe (PID: 2540)
    • Adds/modifies Windows certificates

      • WebCompanionInstaller.exe (PID: 3624)
    • Reads settings of System Certificates

      • WebCompanionInstaller.exe (PID: 3624)
      • WebCompanionInstaller.exe (PID: 2540)
    • Reads the Internet Settings

      • WebCompanionInstaller.exe (PID: 3624)
      • WebCompanionInstaller.exe (PID: 2540)
    • Process requests binary or script from the Internet

      • WebCompanionInstaller.exe (PID: 3624)
      • WebCompanionInstaller.exe (PID: 2540)
    • Reads Microsoft Outlook installation path

      • WebCompanionInstaller.exe (PID: 2540)
    • Reads Internet Explorer settings

      • WebCompanionInstaller.exe (PID: 2540)
    • Executes as Windows Service

      • PresentationFontCache.exe (PID: 2812)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 1392)
    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 2416)
      • iexplore.exe (PID: 1392)
    • Drops the executable file immediately after the start

      • iexplore.exe (PID: 2416)
      • iexplore.exe (PID: 1392)
    • Checks supported languages

      • WcInstaller.exe (PID: 3420)
      • WebCompanionInstaller.exe (PID: 3624)
      • WcInstaller.exe (PID: 4040)
      • WebCompanionInstaller.exe (PID: 2540)
      • PresentationFontCache.exe (PID: 2812)
    • The process uses the downloaded file

      • iexplore.exe (PID: 1392)
    • Create files in a temporary directory

      • WcInstaller.exe (PID: 3420)
      • WebCompanionInstaller.exe (PID: 3624)
      • WcInstaller.exe (PID: 4040)
    • Reads the computer name

      • WebCompanionInstaller.exe (PID: 3624)
      • PresentationFontCache.exe (PID: 2812)
      • WebCompanionInstaller.exe (PID: 2540)
    • Reads Environment values

      • WebCompanionInstaller.exe (PID: 3624)
      • WebCompanionInstaller.exe (PID: 2540)
    • Reads the machine GUID from the registry

      • WebCompanionInstaller.exe (PID: 3624)
      • PresentationFontCache.exe (PID: 2812)
      • WebCompanionInstaller.exe (PID: 2540)
    • Creates files in the program directory

      • WebCompanionInstaller.exe (PID: 3624)
    • Creates files or folders in the user directory

      • WebCompanionInstaller.exe (PID: 2540)
    • Checks proxy server information

      • WebCompanionInstaller.exe (PID: 2540)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
8
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe wcinstaller.exe no specs wcinstaller.exe #ADAWARE webcompanioninstaller.exe wcinstaller.exe #ADAWARE webcompanioninstaller.exe presentationfontcache.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1392"C:\Program Files\Internet Explorer\iexplore.exe" "http://wcdownloadercdn.lavasoft.com/8.9.0.992/WcInstaller.exe"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2416"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1392 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2540.\WebCompanionInstaller.exe --prod --nanouniqueid=1706731783401 --prodC:\Users\admin\AppData\Local\Temp\7zS8CF42907\WebCompanionInstaller.exe
WcInstaller.exe
User:
admin
Company:
Lavasoft
Integrity Level:
HIGH
Description:
Web Companion
Exit code:
0
Version:
7.0.2417.4248
Modules
Images
c:\users\admin\appdata\local\temp\7zs8cf42907\webcompanioninstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2812C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exeC:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exeservices.exe
User:
LOCAL SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
PresentationFontCache.exe
Exit code:
0
Version:
3.0.6920.4902 built by: NetFXw7
Modules
Images
c:\windows\microsoft.net\framework\v3.0\wpf\presentationfontcache.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3380"C:\Users\admin\Downloads\WcInstaller.exe" C:\Users\admin\Downloads\WcInstaller.exeiexplore.exe
User:
admin
Company:
Lavasoft
Integrity Level:
MEDIUM
Description:
Web Companion Installer
Exit code:
3221226540
Version:
8.9.0.992
Modules
Images
c:\users\admin\downloads\wcinstaller.exe
c:\windows\system32\ntdll.dll
3420"C:\Users\admin\Downloads\WcInstaller.exe" C:\Users\admin\Downloads\WcInstaller.exe
iexplore.exe
User:
admin
Company:
Lavasoft
Integrity Level:
HIGH
Description:
Web Companion Installer
Exit code:
0
Version:
8.9.0.992
Modules
Images
c:\users\admin\downloads\wcinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3624.\WebCompanionInstaller.exe --prodC:\Users\admin\AppData\Local\Temp\7zSC5D10437\WebCompanionInstaller.exe
WcInstaller.exe
User:
admin
Company:
Lavasoft
Integrity Level:
HIGH
Description:
Web Companion
Exit code:
0
Version:
8.9.0.992
Modules
Images
c:\users\admin\appdata\local\temp\7zsc5d10437\webcompanioninstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
4040"C:\Users\admin\AppData\Local\Temp\wctmp_1689517070\WcInstaller.exe" --nanouniqueid=1706731783401 --prodC:\Users\admin\AppData\Local\Temp\wctmp_1689517070\WcInstaller.exe
WebCompanionInstaller.exe
User:
admin
Company:
Lavasoft
Integrity Level:
HIGH
Description:
Web Companion Installer
Exit code:
0
Version:
7.0.2417.4248
Modules
Images
c:\users\admin\appdata\local\temp\wctmp_1689517070\wcinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
20 051
Read events
19 880
Write events
166
Delete events
5

Modification events

(PID) Process:(1392) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(1392) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(1392) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(1392) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1392) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1392) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(1392) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1392) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1392) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1392) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
30
Suspicious files
18
Text files
19
Unknown types
1

Dropped files

PID
Process
Filename
Type
1392iexplore.exeC:\Users\admin\AppData\Local\Temp\~DFCCDEF5DC246923B1.TMPbinary
MD5:EFF2E56C494F062B5805B420B37022E8
SHA256:FAC83EFF6094C6B1952C1E5FECBB4209F2CB940946AF55870A2B6C7304DE4ADD
3420WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zSC5D10437\ICSharpCode.SharpZipLib.dllexecutable
MD5:B4ECB8001F71894C1A17860476981441
SHA256:E6133BAA62122E214AB9C114E9FFF73BF25956518907A88577A85C8FB88C561F
3420WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zSC5D10437\de-DE\WebCompanionInstaller.resources.dllexecutable
MD5:6D31FF257169C7216C8EF0A89D1D2C1C
SHA256:076DE7430A997476FFB506AA31B8CA59A5F06FE82CBD1B752563CC037A3B602D
1392iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\VersionManager\verAC52.tmpxml
MD5:CBD0581678FA40F0EDCBC7C59E0CAD10
SHA256:159BD4343F344A08F6AF3B716B6FA679859C1BD1D7030D26FF5EF0255B86E1D9
3420WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zSC5D10437\fr-CA\WebCompanionInstaller.resources.dllexecutable
MD5:B61FCD433F37FCF2B5B2ABCF775888E1
SHA256:25B308729B23565F4B4A6A21931CBA07A6910F645DBCF90D04927C47A759A482
3420WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zSC5D10437\ja-JP\WebCompanionInstaller.resources.dllexecutable
MD5:1E2ABC220B1A13150501462E0E031D53
SHA256:6FE287EE1BD5D2B387A400913E3AFC5526BC5504294F30C6E0AE1A5968A6C052
1392iexplore.exeC:\Users\admin\Downloads\WcInstaller.exe.t2vq8gz.partial:Zone.Identifiertext
MD5:FBCCF14D504B7B2DBCB5A5BDA75BD93B
SHA256:EACD09517CE90D34BA562171D15AC40D302F0E691B439F91BE1B6406E25F5913
3420WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zSC5D10437\en-US\WebCompanionInstaller.resources.dllexecutable
MD5:A21DABEEE8DB587546D2707B900392E6
SHA256:3F150074F1D3FFB9FDB622F088D50494C10061AFFF7C7850D9FDF4EC356FD1C5
3420WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zSC5D10437\it-IT\WebCompanionInstaller.resources.dllexecutable
MD5:B78EBE3329120DEAD1827ECDC661A5FD
SHA256:D3878890C2825A2DF38B99B3002CCC79EA67150F7BD0DDE3885AD2F69B1CF4B8
2416iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\WcInstaller[1].exeexecutable
MD5:2992447D74CB81AE8B2047B913C11C7D
SHA256:7A738EDF305F6BF95B1046D41FBDD8CAD18F2D32CB48C89375606429F7B8FC4D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
18
TCP/UDP connections
28
DNS requests
16
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
304
2.16.100.178:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c7ba49abb4fd7e2c
unknown
unknown
GET
304
2.16.100.178:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?1ae98d7f76faa131
unknown
unknown
2416
iexplore.exe
GET
200
104.17.8.52:80
http://wcdownloadercdn.lavasoft.com/8.9.0.992/WcInstaller.exe
unknown
executable
552 Kb
unknown
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
binary
471 b
unknown
3624
WebCompanionInstaller.exe
POST
200
104.17.8.52:80
http://flow.lavasoft.com/v1/event-stat-wc?Type=ProgressInstall&ProductID=wc&EventVersion=1
unknown
binary
29 b
unknown
3624
WebCompanionInstaller.exe
POST
200
64.18.87.82:80
http://wc-update-service.lavasoft.com/update.asmx
unknown
xml
1.45 Kb
unknown
1080
svchost.exe
GET
200
2.16.100.155:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?0754c686571bd23f
unknown
compressed
65.2 Kb
unknown
GET
304
2.16.100.178:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?8fcaa0645b01cfef
unknown
unknown
3624
WebCompanionInstaller.exe
GET
200
104.17.8.52:80
http://wcdownloadercdn.lavasoft.com/7.0.2417.4248/WcInstaller.exe
unknown
executable
494 Kb
unknown
1392
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAxq6XzO1ZmDhpCgCp6lMhQ%3D
unknown
binary
471 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2416
iexplore.exe
104.17.8.52:80
wcdownloadercdn.lavasoft.com
CLOUDFLARENET
shared
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
1392
iexplore.exe
152.199.19.161:443
r20swj13mr.microsoft.com
EDGECAST
US
whitelisted
1392
iexplore.exe
2.16.100.178:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
whitelisted
1392
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3624
WebCompanionInstaller.exe
104.17.8.52:80
wcdownloadercdn.lavasoft.com
CLOUDFLARENET
shared
3624
WebCompanionInstaller.exe
64.18.87.82:80
wc-update-service.lavasoft.com
MTO
CA
malicious
1080
svchost.exe
2.16.100.155:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
wcdownloadercdn.lavasoft.com
  • 104.17.8.52
  • 104.17.9.52
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
ctldl.windowsupdate.com
  • 2.16.100.178
  • 88.221.110.80
  • 88.221.110.59
  • 88.221.110.67
  • 2.16.100.155
  • 2.16.100.152
  • 2.16.100.163
  • 88.221.110.83
  • 2.16.100.177
  • 2.16.100.161
  • 88.221.110.65
  • 88.221.110.66
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
flow.lavasoft.com
  • 104.17.8.52
  • 104.17.9.52
whitelisted
wc-update-service.lavasoft.com
  • 64.18.87.82
  • 64.18.87.81
whitelisted
ieonline.microsoft.com
  • 204.79.197.200
whitelisted
go.microsoft.com
  • 2.19.86.20
whitelisted
www.msn.com
  • 204.79.197.203
whitelisted

Threats

PID
Process
Class
Message
2416
iexplore.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
3624
WebCompanionInstaller.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
3624
WebCompanionInstaller.exe
Potential Corporate Privacy Violation
AV POLICY HTTP request for .exe file with no User-Agent
3624
WebCompanionInstaller.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
3624
WebCompanionInstaller.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
2540
WebCompanionInstaller.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
Process
Message
WebCompanionInstaller.exe
Detecting windows culture
WebCompanionInstaller.exe
1/31/2024 8:09:43 PM :-> Starting installer 8.9.0.992 with: .\WebCompanionInstaller.exe --prod, Run as admin: True
WebCompanionInstaller.exe
Detecting windows culture
WebCompanionInstaller.exe
1/31/2024 8:09:51 PM :-> Starting installer 7.0.2417.4248 with: .\WebCompanionInstaller.exe --prod --nanouniqueid=1706731783401 --prod, Run as admin: True