File name:

WebCompanionInstaller-12.901.5.1061-prod.exe

Full analysis: https://app.any.run/tasks/0649f2b5-b7ef-4280-84bf-ad6bf65ab249
Verdict: Malicious activity
Analysis date: July 30, 2024, 13:36:13
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
installer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

9F56D40A9B201CBB5598DA5055A18367

SHA1:

A00F23D64DC668B2F311D816B77C1154C559A24B

SHA256:

DC040E4C051687E4B27236F1A2340524B498443EA58CDC87769B818930F01535

SSDEEP:

24576:o6VnvKLzsPkL8yeII//rjZ47hwSeU+Ad4TdZwxTwaxty:o6VnvK8PkLjeIInrjZ47hwSeU+Ad4TdP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WebCompanionInstaller-12.901.5.1061-prod.exe (PID: 2340)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WebCompanionInstaller-12.901.5.1061-prod.exe (PID: 2340)
    • Executes application which crashes

      • WebCompanion-Installer.exe (PID: 7104)
  • INFO

    • Checks supported languages

      • WebCompanion-Installer.exe (PID: 7104)
      • WebCompanionInstaller-12.901.5.1061-prod.exe (PID: 2340)
    • Create files in a temporary directory

      • WebCompanionInstaller-12.901.5.1061-prod.exe (PID: 2340)
      • WebCompanion-Installer.exe (PID: 7104)
    • Reads the machine GUID from the registry

      • WebCompanion-Installer.exe (PID: 7104)
    • Reads the computer name

      • WebCompanion-Installer.exe (PID: 7104)
    • Reads Environment values

      • WebCompanion-Installer.exe (PID: 7104)
    • Checks proxy server information

      • slui.exe (PID: 3848)
      • WerFault.exe (PID: 2928)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 2928)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (36.8)
.exe | Win32 Executable MS Visual C++ (generic) (26.6)
.exe | Win64 Executable (generic) (23.6)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2011:04:18 18:54:06+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 104448
InitializedDataSize: 60416
UninitializedDataSize: -
EntryPoint: 0x148d4
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 12.901.5.1061
ProductVersionNumber: 12.901.5.1061
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileVersion: 12.901.5.1061
ProductVersion: 12.901.5.1061
CompanyName: Lavasoft
FileDescription: Web Companion Installer
InternalName: Installer.exe
LegalCopyright: c Lavasoft Limited. All Rights Reserved.
OriginalFileName: Installer.exe
ProductName: Web Companion Installer
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
143
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start webcompanioninstaller-12.901.5.1061-prod.exe webcompanion-installer.exe werfault.exe slui.exe

Process information

PID
CMD
Path
Indicators
Parent process
2340"C:\Users\admin\AppData\Local\Temp\WebCompanionInstaller-12.901.5.1061-prod.exe" C:\Users\admin\AppData\Local\Temp\WebCompanionInstaller-12.901.5.1061-prod.exe
explorer.exe
User:
admin
Company:
Lavasoft
Integrity Level:
MEDIUM
Description:
Web Companion Installer
Exit code:
0
Version:
12.901.5.1061
Modules
Images
c:\users\admin\appdata\local\temp\webcompanioninstaller-12.901.5.1061-prod.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
2928C:\WINDOWS\SysWOW64\WerFault.exe -u -p 7104 -s 1212C:\Windows\SysWOW64\WerFault.exe
WebCompanion-Installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
3848C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7104.\WebCompanion-Installer.exeC:\Users\admin\AppData\Local\Temp\7zS4296CE2C\WebCompanion-Installer.exe
WebCompanionInstaller-12.901.5.1061-prod.exe
User:
admin
Company:
Lavasoft
Integrity Level:
MEDIUM
Description:
Web Companion
Exit code:
3762504530
Version:
12.901.5.1061
Modules
Images
c:\users\admin\appdata\local\temp\7zs4296ce2c\webcompanion-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
Total events
6 300
Read events
6 300
Write events
0
Delete events
0

Modification events

No data
Executable files
13
Suspicious files
1
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
2928WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_WebCompanion-Ins_2d3b9a4fb151cfae222416f192877d29238ab7_7cb5bf0e_b7a5ee8c-ff7d-4171-8988-6adab0d24631\Report.wer
MD5:
SHA256:
2928WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\WebCompanion-Installer.exe.7104.dmp
MD5:
SHA256:
2340WebCompanionInstaller-12.901.5.1061-prod.exeC:\Users\admin\AppData\Local\Temp\7zS4296CE2C\en-US\WebCompanion-Installer.resources.dllexecutable
MD5:C3960A3BAB680030553F7E6487923CE1
SHA256:86D292BA352431FB0B634BAA6DA34B2F609EFAFE85E437C008D619943D93B0E2
2340WebCompanionInstaller-12.901.5.1061-prod.exeC:\Users\admin\AppData\Local\Temp\7zS4296CE2C\it-IT\WebCompanion-Installer.resources.dllexecutable
MD5:5C1FDC78B09BD8AAA1300448D76F1478
SHA256:0CBA22A6A949DF65346E668E1E159D8E66C88BA0F613AD4CDD3D14D564E80BCE
2340WebCompanionInstaller-12.901.5.1061-prod.exeC:\Users\admin\AppData\Local\Temp\7zS4296CE2C\WebCompanion-Installer.exeexecutable
MD5:F6DFE983850039A9EC8DD2F93E2D25CC
SHA256:2BCDB38E9BDD47E5CA87A683FDCB45CB8D3B95ADA15A7C7610618D02FC112660
2340WebCompanionInstaller-12.901.5.1061-prod.exeC:\Users\admin\AppData\Local\Temp\7zS4296CE2C\WebCompanion-Installer.exe.configxml
MD5:44B1970376FBA163AA49B183915D0EAA
SHA256:13C41E9C66B82DC0BAA0B2762AA7B91FFD418F2C9FCB9DC35DFB40A5C555414C
2340WebCompanionInstaller-12.901.5.1061-prod.exeC:\Users\admin\AppData\Local\Temp\7zS4296CE2C\pt-BR\WebCompanion-Installer.resources.dllexecutable
MD5:6A1420991FC822A287EA8BBF26A62A32
SHA256:E64740ABA131EEC078A387435A762F92161B32881EDBC72BD874E5199CA97502
2340WebCompanionInstaller-12.901.5.1061-prod.exeC:\Users\admin\AppData\Local\Temp\7zS4296CE2C\Newtonsoft.Json.dllexecutable
MD5:CF415AB5A5A0BF6A80EA910CEA0025D4
SHA256:E3FF89C26921FDCCDC604F30CAF3CDE6D36B4F22435EEC8F7DD9C8DAEB833BB1
2340WebCompanionInstaller-12.901.5.1061-prod.exeC:\Users\admin\AppData\Local\Temp\7zS4296CE2C\ru-RU\WebCompanion-Installer.resources.dllexecutable
MD5:5738AD57B29ABA8364C4A58B8A4F9E10
SHA256:C6D0A0EB5E780AAA7F9C55E4676930B69EBF60905782080FF54DD530370ADB43
2340WebCompanionInstaller-12.901.5.1061-prod.exeC:\Users\admin\AppData\Local\Temp\7zS4296CE2C\ICSharpCode.SharpZipLib.dllexecutable
MD5:AA46F1AAC968484C82CD1316A3CE7015
SHA256:16DC00D1D39A153B915E5BAC309F51C11980924CC378B3EB23FF127B875EE754
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
50
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4424
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
3676
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5368
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4132
OfficeClickToRun.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1028
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:138
whitelisted
3952
svchost.exe
239.255.255.250:1900
whitelisted
5368
SearchApp.exe
131.253.33.254:443
a-ring-fallback.msedge.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
5368
SearchApp.exe
104.126.37.154:443
www.bing.com
Akamai International B.V.
DE
unknown
3656
slui.exe
20.83.72.98:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6012
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
6716
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:137
whitelisted
1620
slui.exe
20.83.72.98:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.104.136.2
whitelisted
t-ring-fdv2.msedge.net
  • 13.107.237.254
unknown
a-ring-fallback.msedge.net
  • 131.253.33.254
unknown
www.bing.com
  • 104.126.37.154
  • 104.126.37.130
  • 104.126.37.139
  • 104.126.37.128
  • 104.126.37.131
  • 104.126.37.144
  • 104.126.37.153
  • 104.126.37.161
  • 104.126.37.146
whitelisted
google.com
  • 142.250.186.142
whitelisted
watson.events.data.microsoft.com
  • 20.42.73.29
whitelisted
fp-afd-nocache-ccp.azureedge.net
  • 13.107.253.45
whitelisted
login.live.com
  • 20.190.160.14
  • 20.190.160.22
  • 40.126.32.138
  • 20.190.160.20
  • 20.190.160.17
  • 40.126.32.140
  • 40.126.32.72
  • 40.126.32.74
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted

Threats

No threats detected
Process
Message
WebCompanion-Installer.exe
Failed to OpenWcfHost: System.ServiceModel.AddressAccessDeniedException: HTTP could not register URL http://+:9008/webcompanion/. Your process does not have access rights to this namespace (see http://go.microsoft.com/fwlink/?LinkId=70353 for details). ---> System.Net.HttpListenerException: Access is denied at System.Net.HttpListener.AddAllPrefixes() at System.Net.HttpListener.Start() at System.ServiceModel.Channels.SharedHttpTransportManager.OnOpen() --- End of inner exception stack trace --- at System.ServiceModel.Channels.SharedHttpTransportManager.OnOpen() at System.ServiceModel.Channels.TransportManager.Open(TransportChannelListener channelListener) at System.ServiceModel.Channels.TransportManagerContainer.Open(SelectTransportManagersCallback selectTransportManagerCallback) at System.ServiceModel.Channels.TransportChannelListener.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.HttpChannelListener`1.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at System.ServiceModel.Dispatcher.ChannelDispatcher.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at System.ServiceModel.ServiceHostBase.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at WebCompanionInstaller.App.OpenInstallerWcfHost()
WebCompanion-Installer.exe
Detecting windows culture