| File name: | setup.exe.zip |
| Full analysis: | https://app.any.run/tasks/341a1dc2-e0f7-4887-8021-83917cea4cdf |
| Verdict: | Malicious activity |
| Analysis date: | May 06, 2024, 13:25:47 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=deflate |
| MD5: | 1143DF1D473D701BAD02F6D9FB8042AA |
| SHA1: | BBAE4E63C2D569EF7C52D53BA9E655553C72E645 |
| SHA256: | A3B8BAEE58C3BC16E6897DAA6D5CC7E4B8BBFADF712866321497EA95CC583D95 |
| SSDEEP: | 24576:q0ilvGvkZx1gdYEMP8A3v+HuuyUTkBas22TATvgSYzLFfh+k:q/lvGvkZx1gdYEMEA3v+HuuyUTkBa/2f |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0001 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2024:05:06 13:24:14 |
| ZipCRC: | 0xbc45fbdd |
| ZipCompressedSize: | 456243 |
| ZipUncompressedSize: | 545000 |
| ZipFileName: | tmpu6lmwu0esetup.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 112 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb3980.30911\tmpu6lmwu0esetup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb3980.30911\tmpu6lmwu0esetup.exe | WinRAR.exe | ||||||||||||
User: admin Company: Lavasoft Integrity Level: MEDIUM Description: Web Companion Installer Version: 12.901.4.1003 Modules
| |||||||||||||||
| 864 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2036 | .\WebCompanion-Installer.exe --savename=Setup.exe --partner=IN240402 --nonadmin --direct --tych --campaign=21184387389 --version=12.901.4.1003 | C:\Users\admin\AppData\Local\Temp\7zS0701F5D0\WebCompanion-Installer.exe | tmpu6lmwu0esetup.exe | ||||||||||||
User: admin Company: Lavasoft Integrity Level: MEDIUM Description: Web Companion Version: 12.901.4.1003 Modules
| |||||||||||||||
| 3980 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\setup.exe.zip | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
| 4072 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb3980.26895\tmpu6lmwu0esetup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb3980.26895\tmpu6lmwu0esetup.exe | WinRAR.exe | ||||||||||||
User: admin Company: Lavasoft Integrity Level: MEDIUM Description: Web Companion Installer Version: 12.901.4.1003 Modules
| |||||||||||||||
| 4084 | .\WebCompanion-Installer.exe --savename=Setup.exe --partner=IN240402 --nonadmin --direct --tych --campaign=21184387389 --version=12.901.4.1003 | C:\Users\admin\AppData\Local\Temp\7zS8EF24A60\WebCompanion-Installer.exe | tmpu6lmwu0esetup.exe | ||||||||||||
User: admin Company: Lavasoft Integrity Level: MEDIUM Description: Web Companion Version: 12.901.4.1003 Modules
| |||||||||||||||
| (PID) Process: | (3980) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3980) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3980) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3980) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3980) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3980) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (3980) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\setup.exe.zip | |||
| (PID) Process: | (3980) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3980) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3980) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4072 | tmpu6lmwu0esetup.exe | C:\Users\admin\AppData\Local\Temp\7zS8EF24A60\WebCompanion-Installer.exe.config | xml | |
MD5:BE34B448B611DC35DD383ED545E8FA96 | SHA256:DEEBA89FAB938088E2E65942E93210E6E368EEF6BC1CA8E8724ED43154701851 | |||
| 4072 | tmpu6lmwu0esetup.exe | C:\Users\admin\AppData\Local\Temp\7zS8EF24A60\pt-BR\WebCompanion-Installer.resources.dll | executable | |
MD5:917BC855C6178351A99AE65DC3C45129 | SHA256:2960AE10EBE3BCE868C0D7FF416FFB462F2B6E3032A5D576C7154FF451ACC713 | |||
| 3980 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb3980.26895\tmpu6lmwu0esetup.exe | executable | |
MD5:43072A4A5F32AF6C33691E407CD306B7 | SHA256:60F7B74188E8578D16F6711D7BE0B50F5907AD98BF3CC5EFD00018628C86F759 | |||
| 4072 | tmpu6lmwu0esetup.exe | C:\Users\admin\AppData\Local\Temp\7zS8EF24A60\ICSharpCode.SharpZipLib.dll | executable | |
MD5:B0040D764201ABD71C26560E798BFA7F | SHA256:13C3E0FEC7FF29EB8AB28B321102C2D27AFCBB410884CD693CFD3D211BBEF1D5 | |||
| 4072 | tmpu6lmwu0esetup.exe | C:\Users\admin\AppData\Local\Temp\7zS8EF24A60\fr-CA\WebCompanion-Installer.resources.dll | executable | |
MD5:E3F8A037101B250E7D355AEBBE6DF9ED | SHA256:C9E73B71A6F04A113E2765E7FFAA6051E09E5F3E86CE2F67D264B3DB05F9E19A | |||
| 4072 | tmpu6lmwu0esetup.exe | C:\Users\admin\AppData\Local\Temp\7zS8EF24A60\it-IT\WebCompanion-Installer.resources.dll | executable | |
MD5:B1E13550602007500AB49888607320E7 | SHA256:5126C176226EF22564CED739E43F65A50EE96034F4D709AB184A3E1C07D53797 | |||
| 4072 | tmpu6lmwu0esetup.exe | C:\Users\admin\AppData\Local\Temp\7zS8EF24A60\Newtonsoft.Json.dll | executable | |
MD5:746C1F0EA5A5C0A67FE96DBA4E32AC76 | SHA256:9EE20B0B7E54E633EFF1A25B6E379201D499552689AD29EEBD5AD90F221B1386 | |||
| 4072 | tmpu6lmwu0esetup.exe | C:\Users\admin\AppData\Local\Temp\7zS8EF24A60\en-US\WebCompanion-Installer.resources.dll | executable | |
MD5:E4266F63970E9BB702FDED23ABB07AD7 | SHA256:83CF07757CA5E7C3DD2A8CABC44BA246B6B6F24C3D7042CEB3FC91DDFA8C4160 | |||
| 4072 | tmpu6lmwu0esetup.exe | C:\Users\admin\AppData\Local\Temp\7zS8EF24A60\es-ES\WebCompanion-Installer.resources.dll | executable | |
MD5:49097A52EE5BB99275F10224FBDF8DEF | SHA256:8922F2BE98BDEF22CA58CB24AD75CAC9CC9A6EEEB5E61C359CC9D639B0CA72B9 | |||
| 4084 | WebCompanion-Installer.exe | C:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Options\Statistics.txt | binary | |
MD5:5D9E3E0732A8E072E1F9FDB4E4A178B1 | SHA256:0AB1B510C8062FCB99F18C0F1C200837FAEFA37A6DD23F66D401E9C83118B7B8 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4084 | WebCompanion-Installer.exe | GET | — | 104.16.148.130:80 | http://geo.lavasoft.com/ | unknown | — | — | unknown |
2036 | WebCompanion-Installer.exe | GET | — | 104.16.148.130:80 | http://geo.lavasoft.com/ | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4084 | WebCompanion-Installer.exe | 104.16.148.130:80 | geo.lavasoft.com | CLOUDFLARENET | — | unknown |
2036 | WebCompanion-Installer.exe | 104.16.148.130:80 | geo.lavasoft.com | CLOUDFLARENET | — | unknown |
Domain | IP | Reputation |
|---|---|---|
geo.lavasoft.com |
| unknown |
Process | Message |
|---|---|
WebCompanion-Installer.exe | Failed to OpenWcfHost: System.ServiceModel.AddressAccessDeniedException: HTTP could not register URL http://+:9008/webcompanion/. Your process does not have access rights to this namespace (see http://go.microsoft.com/fwlink/?LinkId=70353 for details). ---> System.Net.HttpListenerException: Access is denied
at System.Net.HttpListener.AddAllPrefixes()
at System.Net.HttpListener.Start()
at System.ServiceModel.Channels.SharedHttpTransportManager.OnOpen()
--- End of inner exception stack trace ---
at System.ServiceModel.Channels.SharedHttpTransportManager.OnOpen()
at System.ServiceModel.Channels.TransportManager.Open(TransportChannelListener channelListener)
at System.ServiceModel.Channels.TransportManagerContainer.Open(SelectTransportManagersCallback selectTransportManagerCallback)
at System.ServiceModel.Channels.TransportChannelListener.OnOpen(TimeSpan timeout)
at System.ServiceModel.Channels.HttpChannelListener`1.OnOpen(TimeSpan timeout)
at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout)
at System.ServiceModel.Dispatcher.ChannelDispatcher.OnOpen(TimeSpan timeout)
at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout)
at System.ServiceModel.ServiceHostBase.OnOpen(TimeSpan timeout)
at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout)
at WebCompanionInstaller.App.OpenInstallerWcfHost()
|
WebCompanion-Installer.exe | Detecting windows culture
|
WebCompanion-Installer.exe | Failed to OpenWcfHost: System.ServiceModel.AddressAccessDeniedException: HTTP could not register URL http://+:9008/webcompanion/. Your process does not have access rights to this namespace (see http://go.microsoft.com/fwlink/?LinkId=70353 for details). ---> System.Net.HttpListenerException: Access is denied
at System.Net.HttpListener.AddAllPrefixes()
at System.Net.HttpListener.Start()
at System.ServiceModel.Channels.SharedHttpTransportManager.OnOpen()
--- End of inner exception stack trace ---
at System.ServiceModel.Channels.SharedHttpTransportManager.OnOpen()
at System.ServiceModel.Channels.TransportManager.Open(TransportChannelListener channelListener)
at System.ServiceModel.Channels.TransportManagerContainer.Open(SelectTransportManagersCallback selectTransportManagerCallback)
at System.ServiceModel.Channels.TransportChannelListener.OnOpen(TimeSpan timeout)
at System.ServiceModel.Channels.HttpChannelListener`1.OnOpen(TimeSpan timeout)
at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout)
at System.ServiceModel.Dispatcher.ChannelDispatcher.OnOpen(TimeSpan timeout)
at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout)
at System.ServiceModel.ServiceHostBase.OnOpen(TimeSpan timeout)
at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout)
at WebCompanionInstaller.App.OpenInstallerWcfHost()
|
WebCompanion-Installer.exe | Detecting windows culture
|