File name:

Setup.exe

Full analysis: https://app.any.run/tasks/6fa37429-ee03-4171-9d8c-b7f79dfe9d75
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: December 05, 2023, 16:03:59
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
adaware
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

3289861D18B10D81C43FAD3FB74474AE

SHA1:

D20FA8358A21FA8B4F1644C0FF9E32BEE8504917

SHA256:

B4B691E506CCF0BA2230FA9E41DA2C9CD391620840FC2F90EA9C2EC083001BC9

SSDEEP:

24576:s6VnvK6nNCRpBdV8IP+X+welQi2/Hcydn3o20Co4LSRl:s6VnvKSNCRLdV8IP+X+welQiEHc+3o2i

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Setup.exe (PID: 564)
      • WebCompanionInstaller.exe (PID: 2412)
    • ADAWARE has been detected (SURICATA)

      • WebCompanionInstaller.exe (PID: 2412)
  • SUSPICIOUS

    • Reads settings of System Certificates

      • WebCompanionInstaller.exe (PID: 2412)
    • Reads security settings of Internet Explorer

      • WebCompanionInstaller.exe (PID: 2412)
    • Checks Windows Trust Settings

      • WebCompanionInstaller.exe (PID: 2412)
    • Searches for installed software

      • WebCompanionInstaller.exe (PID: 2412)
    • Reads the Internet Settings

      • WebCompanionInstaller.exe (PID: 2412)
    • Executes as Windows Service

      • PresentationFontCache.exe (PID: 280)
    • Drops 7-zip archiver for unpacking

      • WebCompanionInstaller.exe (PID: 2412)
    • Process drops legitimate windows executable

      • WebCompanionInstaller.exe (PID: 2412)
    • The process drops C-runtime libraries

      • WebCompanionInstaller.exe (PID: 2412)
  • INFO

    • Checks supported languages

      • Setup.exe (PID: 564)
      • WebCompanionInstaller.exe (PID: 2412)
      • PresentationFontCache.exe (PID: 280)
      • wmpnscfg.exe (PID: 3344)
      • wmpnscfg.exe (PID: 2136)
    • Reads the machine GUID from the registry

      • WebCompanionInstaller.exe (PID: 2412)
      • PresentationFontCache.exe (PID: 280)
    • Create files in a temporary directory

      • Setup.exe (PID: 564)
      • WebCompanionInstaller.exe (PID: 2412)
    • Reads Environment values

      • WebCompanionInstaller.exe (PID: 2412)
    • Reads the computer name

      • WebCompanionInstaller.exe (PID: 2412)
      • PresentationFontCache.exe (PID: 280)
      • wmpnscfg.exe (PID: 2136)
      • wmpnscfg.exe (PID: 3344)
    • Creates files or folders in the user directory

      • WebCompanionInstaller.exe (PID: 2412)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 2136)
      • wmpnscfg.exe (PID: 3344)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (33)
.exe | Win32 Executable MS Visual C++ (generic) (23.9)
.exe | Win64 Executable (generic) (21.2)
.scr | Windows screen saver (10)
.dll | Win32 Dynamic Link Library (generic) (5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2011:04:18 20:54:06+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 104448
InitializedDataSize: 60416
UninitializedDataSize: -
EntryPoint: 0x148d4
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 10.901.2.519
ProductVersionNumber: 10.901.2.519
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileVersion: 10.901.2.519
ProductVersion: 10.901.2.519
CompanyName: Lavasoft
FileDescription: Web Companion Installer
InternalName: Installer.exe
LegalCopyright: c Lavasoft Limited. All Rights Reserved.
OriginalFileName: Installer.exe
ProductName: Web Companion Installer
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start setup.exe no specs #ADAWARE webcompanioninstaller.exe presentationfontcache.exe no specs wmpnscfg.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
280C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exeC:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exeservices.exe
User:
LOCAL SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
PresentationFontCache.exe
Exit code:
0
Version:
3.0.6920.4902 built by: NetFXw7
Modules
Images
c:\windows\microsoft.net\framework\v3.0\wpf\presentationfontcache.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
564"C:\Users\admin\AppData\Local\Temp\Setup.exe" C:\Users\admin\AppData\Local\Temp\Setup.exeexplorer.exe
User:
admin
Company:
Lavasoft
Integrity Level:
MEDIUM
Description:
Web Companion Installer
Exit code:
0
Version:
10.901.2.519
Modules
Images
c:\users\admin\appdata\local\temp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2136"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2412.\WebCompanionInstaller.exe --savename=Setup.exe --partner=IN220101 --nonadmin --direct --tych --campaign=20398341592 --version=10.901.2.519C:\Users\admin\AppData\Local\Temp\7zS432E9240\WebCompanionInstaller.exe
Setup.exe
User:
admin
Company:
Lavasoft
Integrity Level:
MEDIUM
Description:
Web Companion
Exit code:
0
Version:
10.901.2.519
Modules
Images
c:\users\admin\appdata\local\temp\7zs432e9240\webcompanioninstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3344"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
6 729
Read events
6 716
Write events
13
Delete events
0

Modification events

(PID) Process:(2412) WebCompanionInstaller.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2412) WebCompanionInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
Explorer.EXE
Executable files
76
Suspicious files
8
Text files
8
Unknown types
0

Dropped files

PID
Process
Filename
Type
564Setup.exeC:\Users\admin\AppData\Local\Temp\7zS432E9240\pt-BR\WebCompanionInstaller.resources.dllexecutable
MD5:0ADD586EA8B12D274D453BEF1DC09A4B
SHA256:59122B50D3C6CC5C9C3CB6548041F1A468717A44DF38EB8864D95F3B5837448B
564Setup.exeC:\Users\admin\AppData\Local\Temp\7zS432E9240\tr-TR\WebCompanionInstaller.resources.dllexecutable
MD5:D0B891BDD8A9CB2ECEF467043456B896
SHA256:B6876B549DB6AAACFA023DC9B26730DBA139B44203918CE98A633BF35E4BFA9F
564Setup.exeC:\Users\admin\AppData\Local\Temp\7zS432E9240\fr-CA\WebCompanionInstaller.resources.dllexecutable
MD5:F818537B70C4CB6ABC4949FA6A1AA4A8
SHA256:8D14E0B8847D9C5D71EAB73115F0FBE89798B4B0E84FBC2AD81C411AC2F5AFEC
564Setup.exeC:\Users\admin\AppData\Local\Temp\7zS432E9240\es-ES\WebCompanionInstaller.resources.dllexecutable
MD5:09681EF51303E2E6CD5E6713FF294435
SHA256:38EB66E04D8EEF91D6EBF0808D76E55DE1F347D4D464BBD5BF545E11900DE6C6
564Setup.exeC:\Users\admin\AppData\Local\Temp\7zS432E9240\en-US\WebCompanionInstaller.resources.dllexecutable
MD5:D3105E9DB5AAC25193D6C6D2D99349F6
SHA256:86B3513221F9D1EDAC50AFB7A43CDEEE1599CDC69F37D6C52BE7F2A0BF014E66
564Setup.exeC:\Users\admin\AppData\Local\Temp\7zS432E9240\ICSharpCode.SharpZipLib.dllexecutable
MD5:1E16BAD4F6A563C46161BB4FB0CFEC4F
SHA256:C7B5080EA8B2753751CB6252A3E9EDD2A292D8A141DE9E65CD3D0005EBE041E9
564Setup.exeC:\Users\admin\AppData\Local\Temp\7zS432E9240\zh-CHS\WebCompanionInstaller.resources.dllexecutable
MD5:581CC2E4A7B67F04B3736AFE592C3BA5
SHA256:EB2384F4871B5DBA83FD3F5B076442B4AEAD1E57ED10E9095C1E13B45AC8BCC5
564Setup.exeC:\Users\admin\AppData\Local\Temp\7zS432E9240\Newtonsoft.Json.dllexecutable
MD5:6FE086F542AE0DDE2AB0162A87B63192
SHA256:484A60598618C20E518C0ACB0A2D5296FB64D15DEA2EDDA698A178CABA16CE27
564Setup.exeC:\Users\admin\AppData\Local\Temp\7zS432E9240\ja-JP\WebCompanionInstaller.resources.dllexecutable
MD5:C93DB8A30F016DDC963592B9EC8DB51A
SHA256:48C6F0C8E5323ACD383BFF4B9407854B1ABE3B7CD88F81E7B41139C88167D73D
564Setup.exeC:\Users\admin\AppData\Local\Temp\7zS432E9240\ru-RU\WebCompanionInstaller.resources.dllexecutable
MD5:A8EB23DA5A7A026FC40FC80D45773930
SHA256:4CF40997858BC1919BF704B322642A7024D71EB41CD9339D9C62F583CB7B3713
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
8
DNS requests
3
Threats
16

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2412
WebCompanionInstaller.exe
POST
104.17.8.52:80
http://flow.lavasoft.com/v1/event-stat-wc?Type=ProgressInstall&ProductID=wc&EventVersion=1
unknown
unknown
2412
WebCompanionInstaller.exe
POST
200
104.17.8.52:80
http://flow.lavasoft.com/v1/event-stat-wc?Type=ProgressInstall&ProductID=wc&EventVersion=1
unknown
binary
29 b
unknown
2412
WebCompanionInstaller.exe
POST
200
104.17.8.52:80
http://flow.lavasoft.com/v1/event-stat-wc?Type=ProgressInstall&ProductID=wc&EventVersion=1
unknown
binary
29 b
unknown
2412
WebCompanionInstaller.exe
POST
200
104.17.8.52:80
http://flow.lavasoft.com/v1/event-stat-wc?Type=ProgressInstall&ProductID=wc&EventVersion=1
unknown
binary
29 b
unknown
2412
WebCompanionInstaller.exe
POST
200
104.17.8.52:80
http://flow.lavasoft.com/v1/event-stat-wc?Type=ProgressInstall&ProductID=wc&EventVersion=1
unknown
binary
29 b
unknown
2412
WebCompanionInstaller.exe
POST
200
104.17.8.52:80
http://flow.lavasoft.com/v1/event-stat-wc?Type=ProgressInstall&ProductID=wc&EventVersion=1
unknown
binary
29 b
unknown
2412
WebCompanionInstaller.exe
POST
200
104.17.8.52:80
http://flow.lavasoft.com/v1/event-stat-wc?Type=ProgressInstall&ProductID=wc&EventVersion=1
unknown
binary
29 b
unknown
2412
WebCompanionInstaller.exe
GET
200
104.17.8.52:80
http://wcdownloadercdn.lavasoft.com/10.1.2.519/WebCompanion-10.1.2.519-prod.zip
unknown
compressed
10.6 Mb
unknown
2412
WebCompanionInstaller.exe
POST
200
104.17.8.52:80
http://flow.lavasoft.com/v1/event-stat-wc?Type=ProgressInstall&ProductID=wc&EventVersion=1
unknown
binary
29 b
unknown
2412
WebCompanionInstaller.exe
POST
200
104.17.8.52:80
http://flow.lavasoft.com/v1/event-stat-wc?Type=ProgressInstall&ProductID=wc&EventVersion=1
unknown
binary
29 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
2412
WebCompanionInstaller.exe
104.17.8.52:80
flow.lavasoft.com
CLOUDFLARENET
shared

DNS requests

Domain
IP
Reputation
flow.lavasoft.com
  • 104.17.8.52
  • 104.17.9.52
whitelisted
wcdownloadercdn.lavasoft.com
  • 104.17.8.52
  • 104.17.9.52
whitelisted

Threats

PID
Process
Class
Message
2412
WebCompanionInstaller.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
2412
WebCompanionInstaller.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
2412
WebCompanionInstaller.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
2412
WebCompanionInstaller.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
2412
WebCompanionInstaller.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
2412
WebCompanionInstaller.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
2412
WebCompanionInstaller.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
2412
WebCompanionInstaller.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
2412
WebCompanionInstaller.exe
Potentially Bad Traffic
ET HUNTING Terse Request for Zip File (GET)
2412
WebCompanionInstaller.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
Process
Message
WebCompanionInstaller.exe
Detecting windows culture
WebCompanionInstaller.exe
12/5/2023 4:04:08 PM :-> Starting installer 10.901.2.519 with: .\WebCompanionInstaller.exe --savename=Setup.exe --partner=IN220101 --nonadmin --direct --tych --campaign=20398341592 --version=10.901.2.519, Run as admin: False
WebCompanionInstaller.exe
Preparing for installing Web Companion
WebCompanionInstaller.exe
12/5/2023 4:05:55 PM :-> Machine Id and Install Id has been generated
WebCompanionInstaller.exe
12/5/2023 4:05:55 PM :-> Generating Machine and Install Id ...
WebCompanionInstaller.exe
Failed to report progress in SendPostRequest: System.Net.WebException: The operation has timed out at System.Net.HttpWebRequest.GetResponse() at WebCompanionInstaller.Utils.RestUtils.SendPostRequest(String url, String body)
WebCompanionInstaller.exe
12/5/2023 4:05:55 PM :-> Checking prerequisites ...
WebCompanionInstaller.exe
12/5/2023 4:05:55 PM :-> Antivirus not detected
WebCompanionInstaller.exe
12/5/2023 4:05:56 PM :-> vm_check False
WebCompanionInstaller.exe
12/5/2023 4:06:11 PM :-> reg_check :False