URL:

http://wcdownloadercdn.lavasoft.com/9.1.0.993/WcInstaller.exe

Full analysis: https://app.any.run/tasks/34d72cc5-c7df-4338-bd55-5af3c8e42c53
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: December 18, 2023, 14:28:43
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
adware
adaware
Indicators:
MD5:

9256CFDE97F72FF60706BF5EABCA4564

SHA1:

18993C1BBB29E995F10098FE0A6F14C04E245097

SHA256:

CABB61454230F0627015C1E1D4F58128DAC635DC2D359A65EED55FB9E6909EF7

SSDEEP:

3:N1KJGDodXGpJEraRcLULVoKcDJOXLNn:CIAQcLULVoKcVOXLN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WcInstaller.exe (PID: 1784)
      • WebCompanionInstaller.exe (PID: 1928)
      • WcInstaller.exe (PID: 2328)
    • ADAWARE has been detected (SURICATA)

      • WebCompanionInstaller.exe (PID: 1928)
      • WebCompanionInstaller.exe (PID: 2620)
  • SUSPICIOUS

    • Checks Windows Trust Settings

      • WebCompanionInstaller.exe (PID: 1928)
      • WebCompanionInstaller.exe (PID: 2620)
    • Reads security settings of Internet Explorer

      • WebCompanionInstaller.exe (PID: 1928)
      • WebCompanionInstaller.exe (PID: 2620)
    • Reads settings of System Certificates

      • WebCompanionInstaller.exe (PID: 1928)
      • WebCompanionInstaller.exe (PID: 2620)
    • Adds/modifies Windows certificates

      • WebCompanionInstaller.exe (PID: 1928)
    • Searches for installed software

      • WebCompanionInstaller.exe (PID: 1928)
    • Reads the Internet Settings

      • WebCompanionInstaller.exe (PID: 1928)
      • WebCompanionInstaller.exe (PID: 2620)
    • Process requests binary or script from the Internet

      • WebCompanionInstaller.exe (PID: 1928)
    • Reads Microsoft Outlook installation path

      • WebCompanionInstaller.exe (PID: 2620)
    • Executes as Windows Service

      • PresentationFontCache.exe (PID: 148)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 116)
    • Checks supported languages

      • WcInstaller.exe (PID: 1784)
      • WebCompanionInstaller.exe (PID: 1928)
      • WcInstaller.exe (PID: 2328)
      • WebCompanionInstaller.exe (PID: 2620)
      • PresentationFontCache.exe (PID: 148)
    • The process uses the downloaded file

      • iexplore.exe (PID: 116)
    • Drops the executable file immediately after the start

      • iexplore.exe (PID: 2204)
      • iexplore.exe (PID: 116)
    • Create files in a temporary directory

      • WcInstaller.exe (PID: 1784)
      • WebCompanionInstaller.exe (PID: 1928)
      • WcInstaller.exe (PID: 2328)
    • Reads the machine GUID from the registry

      • WebCompanionInstaller.exe (PID: 1928)
      • WebCompanionInstaller.exe (PID: 2620)
      • PresentationFontCache.exe (PID: 148)
    • Reads the computer name

      • WebCompanionInstaller.exe (PID: 1928)
      • WebCompanionInstaller.exe (PID: 2620)
      • PresentationFontCache.exe (PID: 148)
    • Reads Environment values

      • WebCompanionInstaller.exe (PID: 1928)
      • WebCompanionInstaller.exe (PID: 2620)
    • Creates files in the program directory

      • WebCompanionInstaller.exe (PID: 1928)
    • Checks proxy server information

      • WebCompanionInstaller.exe (PID: 2620)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
8
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe wcinstaller.exe no specs wcinstaller.exe #ADAWARE webcompanioninstaller.exe wcinstaller.exe no specs #ADAWARE webcompanioninstaller.exe presentationfontcache.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
116"C:\Program Files\Internet Explorer\iexplore.exe" "http://wcdownloadercdn.lavasoft.com/9.1.0.993/WcInstaller.exe"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
148C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exeC:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exeservices.exe
User:
LOCAL SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
PresentationFontCache.exe
Exit code:
0
Version:
3.0.6920.4902 built by: NetFXw7
Modules
Images
c:\windows\microsoft.net\framework\v3.0\wpf\presentationfontcache.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1216"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\WcInstaller.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\WcInstaller.exeiexplore.exe
User:
admin
Company:
Lavasoft
Integrity Level:
MEDIUM
Description:
Web Companion Installer
Exit code:
3221226540
Version:
9.1.0.993
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\po2hn1x2\wcinstaller.exe
c:\windows\system32\ntdll.dll
1784"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\WcInstaller.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\WcInstaller.exe
iexplore.exe
User:
admin
Company:
Lavasoft
Integrity Level:
HIGH
Description:
Web Companion Installer
Exit code:
0
Version:
9.1.0.993
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\po2hn1x2\wcinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1928.\WebCompanionInstaller.exe --prodC:\Users\admin\AppData\Local\Temp\7zS8F620D3E\WebCompanionInstaller.exe
WcInstaller.exe
User:
admin
Company:
Lavasoft
Integrity Level:
HIGH
Description:
Web Companion
Exit code:
0
Version:
9.1.0.993
Modules
Images
c:\users\admin\appdata\local\temp\7zs8f620d3e\webcompanioninstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2204"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:116 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2328"C:\Users\admin\AppData\Local\Temp\wctmp_1835336155\WcInstaller.exe" --nanouniqueid=1702909743150 --prodC:\Users\admin\AppData\Local\Temp\wctmp_1835336155\WcInstaller.exeWebCompanionInstaller.exe
User:
admin
Company:
Lavasoft
Integrity Level:
HIGH
Description:
Web Companion Installer
Exit code:
0
Version:
7.0.2417.4248
Modules
Images
c:\users\admin\appdata\local\temp\wctmp_1835336155\wcinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2620.\WebCompanionInstaller.exe --prod --nanouniqueid=1702909743150 --prodC:\Users\admin\AppData\Local\Temp\7zS8192596E\WebCompanionInstaller.exe
WcInstaller.exe
User:
admin
Company:
Lavasoft
Integrity Level:
HIGH
Description:
Web Companion
Exit code:
0
Version:
7.0.2417.4248
Modules
Images
c:\users\admin\appdata\local\temp\7zs8192596e\webcompanioninstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
22 123
Read events
21 952
Write events
167
Delete events
4

Modification events

(PID) Process:(116) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(116) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(116) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(116) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(116) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(116) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(116) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(116) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(116) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(116) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
30
Suspicious files
13
Text files
7
Unknown types
1

Dropped files

PID
Process
Filename
Type
116iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
116iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:22E710232BE03B2CE171A1DFC65AEDAF
SHA256:4040C5DD72CABDCD2B6F4B7EA4A5F1CBA824D84B7D742C438F32A715121A6BD4
116iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.icoimage
MD5:DA597791BE3B6E732F0BC8B20E38EE62
SHA256:5B2C34B3C4E8DD898B664DBA6C3786E2FF9869EFF55D673AA48361F11325ED07
116iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\EAF8AA29A62AB29E614331747385D816_F9E4DC0B9D5C777357D7DB8DEF51118Ader
MD5:91F5EB94663F5BD73A29FB771DE337A4
SHA256:7D6BD6B21BFD3E45E52A1EA4A046E5F0D5C9747D54462BEDD127E14D739523D5
116iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\EAF8AA29A62AB29E614331747385D816_F9E4DC0B9D5C777357D7DB8DEF51118Abinary
MD5:C1B6789D84D903073572F65EFA396A64
SHA256:6CC80A5CA15C4B219C28C5FB3E42878EA8843A6966A692AB0BBF38A893B2F534
116iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF71FF2D6A5AA3DE6A.TMPbinary
MD5:7D33D9CEE567D57DFD955B10D1AFD0BB
SHA256:D7D29387F17F02FE7C4E288E7C41F836C3D94EEB5899D72815E914ADBBB88C82
116iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\favicon[1].icoimage
MD5:DA597791BE3B6E732F0BC8B20E38EE62
SHA256:5B2C34B3C4E8DD898B664DBA6C3786E2FF9869EFF55D673AA48361F11325ED07
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\WcInstaller.exe.uffet9b.partialexecutable
MD5:1F1218A4F5AB8EC58A217DE06404B86C
SHA256:7DC5FC24BE9A8531F51C47243D0BBE5B8655CFBA6080ADEA23A4E3308F59DDBA
1784WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS8F620D3E\WebCompanionInstaller.exe.configxml
MD5:1103E1618F5BB75851E0F0C753EC8EC5
SHA256:133F4FCE3A299387263F849250CCEE387B137EE3FF36C6B44B4C02328EDFAAF3
1784WcInstaller.exeC:\Users\admin\AppData\Local\Temp\7zS8F620D3E\en-US\WebCompanionInstaller.resources.dllexecutable
MD5:A38A454C58268F7D7E515E05B630FD15
SHA256:7927D35DB9171A88EA7DF1C2F604B4E139F5E34A661ABF5366BB3EA67E3C9035
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
23
DNS requests
20
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
116
iexplore.exe
GET
200
184.24.77.194:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a85e8d0c2f0a71a5
unknown
compressed
4.66 Kb
unknown
116
iexplore.exe
GET
200
184.24.77.194:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?08d91df001b427ad
unknown
compressed
4.66 Kb
unknown
2204
iexplore.exe
GET
200
104.17.9.52:80
http://wcdownloadercdn.lavasoft.com/9.1.0.993/WcInstaller.exe
unknown
executable
552 Kb
unknown
116
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D
unknown
binary
313 b
unknown
1928
WebCompanionInstaller.exe
POST
200
104.17.9.52:80
http://flow.lavasoft.com/v1/event-stat-wc?Type=ProgressInstall&ProductID=wc&EventVersion=1
unknown
binary
29 b
unknown
1928
WebCompanionInstaller.exe
POST
200
64.18.87.82:80
http://wc-update-service.lavasoft.com/update.asmx
unknown
xml
1.45 Kb
unknown
1928
WebCompanionInstaller.exe
GET
200
104.17.8.52:80
http://wcdownloadercdn.lavasoft.com/7.0.2417.4248/WcInstaller.exe
unknown
executable
494 Kb
unknown
2620
WebCompanionInstaller.exe
POST
200
104.17.9.52:80
http://flow.lavasoft.com/v1/event-stat-wc?Type=ProgressInstall&ProductID=wc&EventVersion=1
unknown
binary
29 b
unknown
2620
WebCompanionInstaller.exe
GET
104.18.212.25:80
http://www.webcompanion.com/installerview/consent_2?culture=en&hp=1&se=1
unknown
unknown
2620
WebCompanionInstaller.exe
POST
200
64.18.87.82:80
http://wc-update-service.lavasoft.com/update.asmx
unknown
xml
1.45 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2204
iexplore.exe
104.17.9.52:80
wcdownloadercdn.lavasoft.com
CLOUDFLARENET
shared
116
iexplore.exe
104.126.37.162:443
www.bing.com
Akamai International B.V.
DE
unknown
116
iexplore.exe
184.24.77.194:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
116
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1928
WebCompanionInstaller.exe
104.17.9.52:80
wcdownloadercdn.lavasoft.com
CLOUDFLARENET
shared
1928
WebCompanionInstaller.exe
64.18.87.82:80
wc-update-service.lavasoft.com
MTO
CA
malicious
1928
WebCompanionInstaller.exe
104.17.8.52:80
wcdownloadercdn.lavasoft.com
CLOUDFLARENET
shared

DNS requests

Domain
IP
Reputation
wcdownloadercdn.lavasoft.com
  • 104.17.8.52
  • 104.17.9.52
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 104.126.37.162
  • 104.126.37.161
  • 104.126.37.155
  • 104.126.37.170
  • 104.126.37.163
  • 104.126.37.145
  • 104.126.37.171
  • 104.126.37.176
  • 104.126.37.160
whitelisted
ctldl.windowsupdate.com
  • 184.24.77.194
  • 184.24.77.202
  • 173.222.108.226
  • 173.222.108.210
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
flow.lavasoft.com
  • 104.17.9.52
  • 104.17.8.52
whitelisted
wc-update-service.lavasoft.com
  • 64.18.87.82
  • 64.18.87.81
whitelisted
www.webcompanion.com
  • 104.18.212.25
  • 104.18.211.25
unknown
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted

Threats

PID
Process
Class
Message
2204
iexplore.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
1928
WebCompanionInstaller.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
1928
WebCompanionInstaller.exe
Potential Corporate Privacy Violation
AV POLICY HTTP request for .exe file with no User-Agent
1928
WebCompanionInstaller.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
1928
WebCompanionInstaller.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
2620
WebCompanionInstaller.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
Process
Message
WebCompanionInstaller.exe
Detecting windows culture
WebCompanionInstaller.exe
12/18/2023 2:29:03 PM :-> Starting installer 9.1.0.993 with: .\WebCompanionInstaller.exe --prod, Run as admin: True
WebCompanionInstaller.exe
Detecting windows culture
WebCompanionInstaller.exe
12/18/2023 2:29:12 PM :-> Starting installer 7.0.2417.4248 with: .\WebCompanionInstaller.exe --prod --nanouniqueid=1702909743150 --prod, Run as admin: True