URL:

http://wcdownloadercdn.lavasoft.com/8.9.0.992/WcInstaller.exe

Full analysis: https://app.any.run/tasks/fc10390a-e8b3-4676-b1d8-465b360f99ce
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: February 06, 2024, 15:00:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
adaware
loader
Indicators:
MD5:

856358547E774A4F1C80F9ACA540F61F

SHA1:

7BE44B71B22F16E70A854D7D88E10DF960425430

SHA256:

919C1483DFE8E93BF1026AD3F77AF6B252325D6E0595D66BE7BCEAC56D6C811E

SSDEEP:

3:N1KJGDodXGpJEraRdWhccXpbJOXLNn:CIAQmccXptOXLN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WcInstaller.exe (PID: 2672)
      • WebCompanionInstaller.exe (PID: 3180)
      • WcInstaller.exe (PID: 1560)
      • WebCompanionInstaller.exe (PID: 2596)
    • ADAWARE has been detected (SURICATA)

      • WebCompanionInstaller.exe (PID: 3180)
      • WebCompanionInstaller.exe (PID: 2596)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WcInstaller.exe (PID: 2672)
      • WebCompanionInstaller.exe (PID: 3180)
      • WcInstaller.exe (PID: 1560)
      • WebCompanionInstaller.exe (PID: 2596)
    • Checks Windows Trust Settings

      • WebCompanionInstaller.exe (PID: 3180)
      • WebCompanionInstaller.exe (PID: 2596)
    • Reads security settings of Internet Explorer

      • WebCompanionInstaller.exe (PID: 3180)
      • WebCompanionInstaller.exe (PID: 2596)
    • Reads settings of System Certificates

      • WebCompanionInstaller.exe (PID: 3180)
      • WebCompanionInstaller.exe (PID: 2596)
    • Searches for installed software

      • WebCompanionInstaller.exe (PID: 3180)
    • Adds/modifies Windows certificates

      • WebCompanionInstaller.exe (PID: 3180)
    • Process requests binary or script from the Internet

      • WebCompanionInstaller.exe (PID: 3180)
      • WebCompanionInstaller.exe (PID: 2596)
    • Reads the Internet Settings

      • WebCompanionInstaller.exe (PID: 3180)
      • WebCompanionInstaller.exe (PID: 2596)
    • Executes as Windows Service

      • PresentationFontCache.exe (PID: 2484)
    • Reads Microsoft Outlook installation path

      • WebCompanionInstaller.exe (PID: 2596)
    • Reads Internet Explorer settings

      • WebCompanionInstaller.exe (PID: 2596)
    • Process drops legitimate windows executable

      • WebCompanionInstaller.exe (PID: 2596)
    • Starts SC.EXE for service management

      • WebCompanionInstaller.exe (PID: 2596)
    • The process drops C-runtime libraries

      • WebCompanionInstaller.exe (PID: 2596)
    • Drops 7-zip archiver for unpacking

      • WebCompanionInstaller.exe (PID: 2596)
    • The process verifies whether the antivirus software is installed

      • WebCompanionInstaller.exe (PID: 2596)
  • INFO

    • Executable content was dropped or overwritten

      • msedge.exe (PID: 3264)
      • msedge.exe (PID: 1380)
    • Application launched itself

      • msedge.exe (PID: 1380)
    • The process uses the downloaded file

      • msedge.exe (PID: 2036)
      • msedge.exe (PID: 1380)
    • Checks supported languages

      • WcInstaller.exe (PID: 2672)
      • WebCompanionInstaller.exe (PID: 3180)
      • WcInstaller.exe (PID: 1560)
      • WebCompanionInstaller.exe (PID: 2596)
      • PresentationFontCache.exe (PID: 2484)
    • Drops the executable file immediately after the start

      • msedge.exe (PID: 3264)
      • msedge.exe (PID: 1380)
    • Create files in a temporary directory

      • WcInstaller.exe (PID: 2672)
      • WebCompanionInstaller.exe (PID: 3180)
      • WcInstaller.exe (PID: 1560)
      • WebCompanionInstaller.exe (PID: 2596)
    • Reads the machine GUID from the registry

      • WebCompanionInstaller.exe (PID: 3180)
      • WebCompanionInstaller.exe (PID: 2596)
      • PresentationFontCache.exe (PID: 2484)
    • Reads the computer name

      • WebCompanionInstaller.exe (PID: 3180)
      • WebCompanionInstaller.exe (PID: 2596)
      • PresentationFontCache.exe (PID: 2484)
    • Reads Environment values

      • WebCompanionInstaller.exe (PID: 3180)
      • WebCompanionInstaller.exe (PID: 2596)
    • Creates files in the program directory

      • WebCompanionInstaller.exe (PID: 3180)
      • WebCompanionInstaller.exe (PID: 2596)
    • Checks proxy server information

      • WebCompanionInstaller.exe (PID: 2596)
    • Creates files or folders in the user directory

      • WebCompanionInstaller.exe (PID: 2596)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
73
Monitored processes
29
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs wcinstaller.exe no specs wcinstaller.exe #ADAWARE webcompanioninstaller.exe wcinstaller.exe #ADAWARE webcompanioninstaller.exe presentationfontcache.exe no specs msedge.exe no specs msedge.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1380"C:\Program Files\Microsoft\Edge\Application\msedge.exe" "http://wcdownloadercdn.lavasoft.com/8.9.0.992/WcInstaller.exe"C:\Program Files\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1432"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4016 --field-trial-handle=1172,i,17327395588281958551,3422126822179231382,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1504"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6bc6f598,0x6bc6f5a8,0x6bc6f5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1560"C:\Users\admin\AppData\Local\Temp\wctmp_457688062\WcInstaller.exe" --nanouniqueid=1707231651693 --prodC:\Users\admin\AppData\Local\Temp\wctmp_457688062\WcInstaller.exe
WebCompanionInstaller.exe
User:
admin
Company:
Lavasoft
Integrity Level:
HIGH
Description:
Web Companion Installer
Exit code:
0
Version:
7.0.2417.4248
Modules
Images
c:\users\admin\appdata\local\temp\wctmp_457688062\wcinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1696"C:\Users\admin\Downloads\WcInstaller.exe" C:\Users\admin\Downloads\WcInstaller.exemsedge.exe
User:
admin
Company:
Lavasoft
Integrity Level:
MEDIUM
Description:
Web Companion Installer
Exit code:
3221226540
Version:
8.9.0.992
Modules
Images
c:\users\admin\downloads\wcinstaller.exe
c:\windows\system32\ntdll.dll
1792"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2324 --field-trial-handle=1172,i,17327395588281958551,3422126822179231382,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2036"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2184 --field-trial-handle=1172,i,17327395588281958551,3422126822179231382,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2172"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2384 --field-trial-handle=1172,i,17327395588281958551,3422126822179231382,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2484C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exeC:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exeservices.exe
User:
LOCAL SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
PresentationFontCache.exe
Exit code:
0
Version:
3.0.6920.4902 built by: NetFXw7
Modules
Images
c:\windows\microsoft.net\framework\v3.0\wpf\presentationfontcache.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2556"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1628 --field-trial-handle=1172,i,17327395588281958551,3422126822179231382,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
19 016
Read events
18 892
Write events
123
Delete events
1

Modification events

(PID) Process:(1380) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(1380) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(1380) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(1380) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(1380) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\EdgeUpdate\ClientState\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
Operation:writeName:dr
Value:
1
(PID) Process:(1380) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
1
(PID) Process:(1380) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1302019708-1500728564-335382590-1000
Value:
6F4801F01D6B2F00
(PID) Process:(1380) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge
Operation:writeName:UsageStatsInSample
Value:
1
(PID) Process:(1380) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
Operation:writeName:usagestats
Value:
1
(PID) Process:(1380) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
Operation:writeName:urlstats
Value:
1
Executable files
101
Suspicious files
71
Text files
45
Unknown types
0

Dropped files

PID
Process
Filename
Type
1380msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF163722.TMP
MD5:
SHA256:
1380msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
1380msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF163741.TMP
MD5:
SHA256:
1380msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old
MD5:
SHA256:
1380msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF163751.TMP
MD5:
SHA256:
1380msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF16378f.TMP
MD5:
SHA256:
1380msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old
MD5:
SHA256:
1504msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\CrashpadMetrics.pmabinary
MD5:886E82F2CA62ECCCE64601B30592078A
SHA256:E5E13D53601100FF3D6BB71514CBCCC4C73FE9B7EF5E930100E644187B42948E
1380msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Session Storage\LOG.old~RF163889.TMPtext
MD5:AA87E3E91C255D17ED464CAB6C93C80C
SHA256:5E1C0D9217284C819583F549F063E5EF89B3D4C2A660396E3B5B4ADE8B13997C
1380msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.datbinary
MD5:DF0BCCD68449F07F531D76F53C718178
SHA256:12025F4DA9E53A8B91892D4F6E6A9B89513F3488BFE9F1EEEC3C05F7EF96BDD8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
21
TCP/UDP connections
35
DNS requests
24
Threats
17

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2596
WebCompanionInstaller.exe
GET
200
104.18.211.25:80
http://webcompanion.com/installer/css/styles.css?1707231658
unknown
text
928 b
unknown
3180
WebCompanionInstaller.exe
POST
200
104.17.9.52:80
http://flow.lavasoft.com/v1/event-stat-wc?Type=ProgressInstall&ProductID=wc&EventVersion=1
unknown
binary
29 b
unknown
3180
WebCompanionInstaller.exe
GET
200
104.17.8.52:80
http://wcdownloadercdn.lavasoft.com/7.0.2417.4248/WcInstaller.exe
unknown
executable
494 Kb
unknown
2596
WebCompanionInstaller.exe
POST
200
64.18.87.82:80
http://wc-update-service.lavasoft.com/update.asmx
unknown
xml
1.45 Kb
unknown
3180
WebCompanionInstaller.exe
POST
200
64.18.87.82:80
http://wc-update-service.lavasoft.com/update.asmx
unknown
xml
1.45 Kb
unknown
2596
WebCompanionInstaller.exe
GET
200
104.18.212.25:80
http://www.webcompanion.com/installerview/consent_2?culture=en&hp=1&se=1
unknown
html
1.35 Kb
unknown
2596
WebCompanionInstaller.exe
POST
200
104.17.9.52:80
http://flow.lavasoft.com/v1/event-stat-wc?Type=ProgressInstall&ProductID=wc&EventVersion=1
unknown
binary
29 b
unknown
2596
WebCompanionInstaller.exe
POST
200
104.17.9.52:80
http://flow.lavasoft.com/v1/event-stat-wc?Type=ProgressInstall&ProductID=wc&EventVersion=1
unknown
binary
29 b
unknown
2596
WebCompanionInstaller.exe
POST
200
104.17.9.52:80
http://flow.lavasoft.com/v1/event-stat-wc?Type=ProgressInstall&ProductID=wc&EventVersion=1
unknown
binary
29 b
unknown
2596
WebCompanionInstaller.exe
POST
200
64.18.87.82:80
http://wc-update-service.lavasoft.com/update.asmx
unknown
xml
1.45 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1380
msedge.exe
239.255.255.250:1900
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
3264
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
3264
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3264
msedge.exe
104.17.9.52:443
wcdownloadercdn.lavasoft.com
CLOUDFLARENET
shared
3264
msedge.exe
152.199.21.175:443
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com
EDGECAST
DE
whitelisted
1380
msedge.exe
224.0.0.251:5353
unknown
3264
msedge.exe
2.19.96.90:443
www.bing.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
wcdownloadercdn.lavasoft.com
  • 104.17.8.52
  • 104.17.9.52
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com
  • 152.199.21.175
whitelisted
www.bing.com
  • 2.19.96.90
  • 2.19.96.83
  • 2.19.96.104
  • 2.19.96.107
  • 2.19.96.106
  • 2.19.96.91
  • 2.19.96.88
  • 2.19.96.99
  • 2.19.96.89
whitelisted
flow.lavasoft.com
  • 104.17.9.52
  • 104.17.8.52
whitelisted
wc-update-service.lavasoft.com
  • 64.18.87.82
  • 64.18.87.81
whitelisted
www.webcompanion.com
  • 104.18.212.25
  • 104.18.211.25
unknown
webcompanion.com
  • 104.18.211.25
  • 104.18.212.25
unknown
code.jquery.com
  • 151.101.194.137
  • 151.101.66.137
  • 151.101.2.137
  • 151.101.130.137
whitelisted

Threats

PID
Process
Class
Message
3180
WebCompanionInstaller.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
3180
WebCompanionInstaller.exe
Potential Corporate Privacy Violation
AV POLICY HTTP request for .exe file with no User-Agent
3180
WebCompanionInstaller.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
3180
WebCompanionInstaller.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
2596
WebCompanionInstaller.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
2596
WebCompanionInstaller.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
2596
WebCompanionInstaller.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
2596
WebCompanionInstaller.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
2596
WebCompanionInstaller.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
2596
WebCompanionInstaller.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
Process
Message
WebCompanionInstaller.exe
Detecting windows culture
WebCompanionInstaller.exe
2/6/2024 3:00:51 PM :-> Starting installer 8.9.0.992 with: .\WebCompanionInstaller.exe --prod, Run as admin: True
WebCompanionInstaller.exe
Detecting windows culture
WebCompanionInstaller.exe
2/6/2024 3:00:53 PM :-> Starting installer 7.0.2417.4248 with: .\WebCompanionInstaller.exe --prod --nanouniqueid=1707231651693 --prod, Run as admin: True
WebCompanionInstaller.exe
Preparing for installing Web Companion
WebCompanionInstaller.exe
2/6/2024 3:01:18 PM :-> Machine Id and Install Id has been generated
WebCompanionInstaller.exe
2/6/2024 3:01:18 PM :-> Generating Machine and Install Id ...
WebCompanionInstaller.exe
2/6/2024 3:02:13 PM :-> Checking prerequisites ...
WebCompanionInstaller.exe
2/6/2024 3:02:13 PM :-> Antivirus not detected
WebCompanionInstaller.exe
2/6/2024 3:02:13 PM :-> vm_check False