File name: | setup.exe.zip |
Full analysis: | https://app.any.run/tasks/341a1dc2-e0f7-4887-8021-83917cea4cdf |
Verdict: | Malicious activity |
Analysis date: | May 06, 2024, 13:25:47 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v2.0 to extract, compression method=deflate |
MD5: | 1143DF1D473D701BAD02F6D9FB8042AA |
SHA1: | BBAE4E63C2D569EF7C52D53BA9E655553C72E645 |
SHA256: | A3B8BAEE58C3BC16E6897DAA6D5CC7E4B8BBFADF712866321497EA95CC583D95 |
SSDEEP: | 24576:q0ilvGvkZx1gdYEMP8A3v+HuuyUTkBas22TATvgSYzLFfh+k:q/lvGvkZx1gdYEMEA3v+HuuyUTkBa/2f |
.zip | | | ZIP compressed archive (100) |
---|
ZipFileName: | tmpu6lmwu0esetup.exe |
---|---|
ZipUncompressedSize: | 545000 |
ZipCompressedSize: | 456243 |
ZipCRC: | 0xbc45fbdd |
ZipModifyDate: | 2024:05:06 13:24:14 |
ZipCompression: | Deflated |
ZipBitFlag: | 0x0001 |
ZipRequiredVersion: | 20 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
3980 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\setup.exe.zip | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
4072 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb3980.26895\tmpu6lmwu0esetup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb3980.26895\tmpu6lmwu0esetup.exe | WinRAR.exe | ||||||||||||
User: admin Company: Lavasoft Integrity Level: MEDIUM Description: Web Companion Installer Version: 12.901.4.1003 Modules
| |||||||||||||||
4084 | .\WebCompanion-Installer.exe --savename=Setup.exe --partner=IN240402 --nonadmin --direct --tych --campaign=21184387389 --version=12.901.4.1003 | C:\Users\admin\AppData\Local\Temp\7zS8EF24A60\WebCompanion-Installer.exe | tmpu6lmwu0esetup.exe | ||||||||||||
User: admin Company: Lavasoft Integrity Level: MEDIUM Description: Web Companion Version: 12.901.4.1003 Modules
| |||||||||||||||
864 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
112 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb3980.30911\tmpu6lmwu0esetup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb3980.30911\tmpu6lmwu0esetup.exe | WinRAR.exe | ||||||||||||
User: admin Company: Lavasoft Integrity Level: MEDIUM Description: Web Companion Installer Version: 12.901.4.1003 Modules
| |||||||||||||||
2036 | .\WebCompanion-Installer.exe --savename=Setup.exe --partner=IN240402 --nonadmin --direct --tych --campaign=21184387389 --version=12.901.4.1003 | C:\Users\admin\AppData\Local\Temp\7zS0701F5D0\WebCompanion-Installer.exe | tmpu6lmwu0esetup.exe | ||||||||||||
User: admin Company: Lavasoft Integrity Level: MEDIUM Description: Web Companion Version: 12.901.4.1003 Modules
|
(PID) Process: | (3980) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (3980) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (3980) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (3980) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
(PID) Process: | (3980) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
(PID) Process: | (3980) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
(PID) Process: | (3980) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\setup.exe.zip | |||
(PID) Process: | (3980) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (3980) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (3980) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 |
PID | Process | Filename | Type | |
---|---|---|---|---|
4072 | tmpu6lmwu0esetup.exe | C:\Users\admin\AppData\Local\Temp\7zS8EF24A60\WebCompanion-Installer.exe | executable | |
MD5:F6271B5D4729C2FD7DD9950F41D57C8B | SHA256:04E8C3DE51503351B4D52FA9B010AEBB41D3CCA46387046E8E689FBAA7063C16 | |||
4072 | tmpu6lmwu0esetup.exe | C:\Users\admin\AppData\Local\Temp\7zS8EF24A60\WebCompanion-Installer.exe.config | xml | |
MD5:BE34B448B611DC35DD383ED545E8FA96 | SHA256:DEEBA89FAB938088E2E65942E93210E6E368EEF6BC1CA8E8724ED43154701851 | |||
4072 | tmpu6lmwu0esetup.exe | C:\Users\admin\AppData\Local\Temp\7zS8EF24A60\ru-RU\WebCompanion-Installer.resources.dll | executable | |
MD5:F0D226185C695EA2479FDB885A7FB704 | SHA256:53435A7C3E55C7F3E9733F704E60014C2BD12512C902F16134492C2AE1C591BB | |||
4072 | tmpu6lmwu0esetup.exe | C:\Users\admin\AppData\Local\Temp\7zS8EF24A60\pt-BR\WebCompanion-Installer.resources.dll | executable | |
MD5:917BC855C6178351A99AE65DC3C45129 | SHA256:2960AE10EBE3BCE868C0D7FF416FFB462F2B6E3032A5D576C7154FF451ACC713 | |||
112 | tmpu6lmwu0esetup.exe | C:\Users\admin\AppData\Local\Temp\7zS0701F5D0\de-DE\WebCompanion-Installer.resources.dll | executable | |
MD5:882D661D8E16DBBB09AC9B31454130F2 | SHA256:91B10F5BB33CE0A3C1D10BA53AC71DBD95A5702CB7B183A65210C54FFB9CD585 | |||
112 | tmpu6lmwu0esetup.exe | C:\Users\admin\AppData\Local\Temp\7zS0701F5D0\WebCompanion-Installer.exe.config | xml | |
MD5:BE34B448B611DC35DD383ED545E8FA96 | SHA256:DEEBA89FAB938088E2E65942E93210E6E368EEF6BC1CA8E8724ED43154701851 | |||
4072 | tmpu6lmwu0esetup.exe | C:\Users\admin\AppData\Local\Temp\7zS8EF24A60\Newtonsoft.Json.dll | executable | |
MD5:746C1F0EA5A5C0A67FE96DBA4E32AC76 | SHA256:9EE20B0B7E54E633EFF1A25B6E379201D499552689AD29EEBD5AD90F221B1386 | |||
112 | tmpu6lmwu0esetup.exe | C:\Users\admin\AppData\Local\Temp\7zS0701F5D0\en-US\WebCompanion-Installer.resources.dll | executable | |
MD5:E4266F63970E9BB702FDED23ABB07AD7 | SHA256:83CF07757CA5E7C3DD2A8CABC44BA246B6B6F24C3D7042CEB3FC91DDFA8C4160 | |||
4072 | tmpu6lmwu0esetup.exe | C:\Users\admin\AppData\Local\Temp\7zS8EF24A60\fr-CA\WebCompanion-Installer.resources.dll | executable | |
MD5:E3F8A037101B250E7D355AEBBE6DF9ED | SHA256:C9E73B71A6F04A113E2765E7FFAA6051E09E5F3E86CE2F67D264B3DB05F9E19A | |||
4072 | tmpu6lmwu0esetup.exe | C:\Users\admin\AppData\Local\Temp\7zS8EF24A60\tr-TR\WebCompanion-Installer.resources.dll | executable | |
MD5:DD93ABF6BC320748F8981C9815C533B1 | SHA256:486D1257C3B23A868C3DFF1B08D6D03A0333DF9EE1024BD0CCA961165CDAED85 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
2036 | WebCompanion-Installer.exe | GET | — | 104.16.148.130:80 | http://geo.lavasoft.com/ | unknown | — | — | unknown |
4084 | WebCompanion-Installer.exe | GET | — | 104.16.148.130:80 | http://geo.lavasoft.com/ | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4084 | WebCompanion-Installer.exe | 104.16.148.130:80 | geo.lavasoft.com | CLOUDFLARENET | — | unknown |
2036 | WebCompanion-Installer.exe | 104.16.148.130:80 | geo.lavasoft.com | CLOUDFLARENET | — | unknown |
Domain | IP | Reputation |
---|---|---|
geo.lavasoft.com |
| unknown |
Process | Message |
---|---|
WebCompanion-Installer.exe | Failed to OpenWcfHost: System.ServiceModel.AddressAccessDeniedException: HTTP could not register URL http://+:9008/webcompanion/. Your process does not have access rights to this namespace (see http://go.microsoft.com/fwlink/?LinkId=70353 for details). ---> System.Net.HttpListenerException: Access is denied
at System.Net.HttpListener.AddAllPrefixes()
at System.Net.HttpListener.Start()
at System.ServiceModel.Channels.SharedHttpTransportManager.OnOpen()
--- End of inner exception stack trace ---
at System.ServiceModel.Channels.SharedHttpTransportManager.OnOpen()
at System.ServiceModel.Channels.TransportManager.Open(TransportChannelListener channelListener)
at System.ServiceModel.Channels.TransportManagerContainer.Open(SelectTransportManagersCallback selectTransportManagerCallback)
at System.ServiceModel.Channels.TransportChannelListener.OnOpen(TimeSpan timeout)
at System.ServiceModel.Channels.HttpChannelListener`1.OnOpen(TimeSpan timeout)
at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout)
at System.ServiceModel.Dispatcher.ChannelDispatcher.OnOpen(TimeSpan timeout)
at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout)
at System.ServiceModel.ServiceHostBase.OnOpen(TimeSpan timeout)
at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout)
at WebCompanionInstaller.App.OpenInstallerWcfHost()
|
WebCompanion-Installer.exe | Detecting windows culture
|
WebCompanion-Installer.exe | Failed to OpenWcfHost: System.ServiceModel.AddressAccessDeniedException: HTTP could not register URL http://+:9008/webcompanion/. Your process does not have access rights to this namespace (see http://go.microsoft.com/fwlink/?LinkId=70353 for details). ---> System.Net.HttpListenerException: Access is denied
at System.Net.HttpListener.AddAllPrefixes()
at System.Net.HttpListener.Start()
at System.ServiceModel.Channels.SharedHttpTransportManager.OnOpen()
--- End of inner exception stack trace ---
at System.ServiceModel.Channels.SharedHttpTransportManager.OnOpen()
at System.ServiceModel.Channels.TransportManager.Open(TransportChannelListener channelListener)
at System.ServiceModel.Channels.TransportManagerContainer.Open(SelectTransportManagersCallback selectTransportManagerCallback)
at System.ServiceModel.Channels.TransportChannelListener.OnOpen(TimeSpan timeout)
at System.ServiceModel.Channels.HttpChannelListener`1.OnOpen(TimeSpan timeout)
at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout)
at System.ServiceModel.Dispatcher.ChannelDispatcher.OnOpen(TimeSpan timeout)
at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout)
at System.ServiceModel.ServiceHostBase.OnOpen(TimeSpan timeout)
at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout)
at WebCompanionInstaller.App.OpenInstallerWcfHost()
|
WebCompanion-Installer.exe | Detecting windows culture
|