File name:

WebCompanionInstaller-12.901.5.1061-prod.exe

Full analysis: https://app.any.run/tasks/0649f2b5-b7ef-4280-84bf-ad6bf65ab249
Verdict: Malicious activity
Analysis date: July 30, 2024, 13:36:13
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
installer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

9F56D40A9B201CBB5598DA5055A18367

SHA1:

A00F23D64DC668B2F311D816B77C1154C559A24B

SHA256:

DC040E4C051687E4B27236F1A2340524B498443EA58CDC87769B818930F01535

SSDEEP:

24576:o6VnvKLzsPkL8yeII//rjZ47hwSeU+Ad4TdZwxTwaxty:o6VnvK8PkLjeIInrjZ47hwSeU+Ad4TdP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WebCompanionInstaller-12.901.5.1061-prod.exe (PID: 2340)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WebCompanionInstaller-12.901.5.1061-prod.exe (PID: 2340)
    • Executes application which crashes

      • WebCompanion-Installer.exe (PID: 7104)
  • INFO

    • Create files in a temporary directory

      • WebCompanionInstaller-12.901.5.1061-prod.exe (PID: 2340)
      • WebCompanion-Installer.exe (PID: 7104)
    • Checks supported languages

      • WebCompanionInstaller-12.901.5.1061-prod.exe (PID: 2340)
      • WebCompanion-Installer.exe (PID: 7104)
    • Reads the machine GUID from the registry

      • WebCompanion-Installer.exe (PID: 7104)
    • Reads the computer name

      • WebCompanion-Installer.exe (PID: 7104)
    • Reads Environment values

      • WebCompanion-Installer.exe (PID: 7104)
    • Checks proxy server information

      • slui.exe (PID: 3848)
      • WerFault.exe (PID: 2928)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 2928)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (36.8)
.exe | Win32 Executable MS Visual C++ (generic) (26.6)
.exe | Win64 Executable (generic) (23.6)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2011:04:18 18:54:06+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 104448
InitializedDataSize: 60416
UninitializedDataSize: -
EntryPoint: 0x148d4
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 12.901.5.1061
ProductVersionNumber: 12.901.5.1061
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileVersion: 12.901.5.1061
ProductVersion: 12.901.5.1061
CompanyName: Lavasoft
FileDescription: Web Companion Installer
InternalName: Installer.exe
LegalCopyright: c Lavasoft Limited. All Rights Reserved.
OriginalFileName: Installer.exe
ProductName: Web Companion Installer
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
143
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start webcompanioninstaller-12.901.5.1061-prod.exe webcompanion-installer.exe werfault.exe slui.exe

Process information

PID
CMD
Path
Indicators
Parent process
2340"C:\Users\admin\AppData\Local\Temp\WebCompanionInstaller-12.901.5.1061-prod.exe" C:\Users\admin\AppData\Local\Temp\WebCompanionInstaller-12.901.5.1061-prod.exe
explorer.exe
User:
admin
Company:
Lavasoft
Integrity Level:
MEDIUM
Description:
Web Companion Installer
Exit code:
0
Version:
12.901.5.1061
Modules
Images
c:\users\admin\appdata\local\temp\webcompanioninstaller-12.901.5.1061-prod.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
2928C:\WINDOWS\SysWOW64\WerFault.exe -u -p 7104 -s 1212C:\Windows\SysWOW64\WerFault.exe
WebCompanion-Installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
3848C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7104.\WebCompanion-Installer.exeC:\Users\admin\AppData\Local\Temp\7zS4296CE2C\WebCompanion-Installer.exe
WebCompanionInstaller-12.901.5.1061-prod.exe
User:
admin
Company:
Lavasoft
Integrity Level:
MEDIUM
Description:
Web Companion
Exit code:
3762504530
Version:
12.901.5.1061
Modules
Images
c:\users\admin\appdata\local\temp\7zs4296ce2c\webcompanion-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
Total events
6 300
Read events
6 300
Write events
0
Delete events
0

Modification events

No data
Executable files
13
Suspicious files
1
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
2928WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_WebCompanion-Ins_2d3b9a4fb151cfae222416f192877d29238ab7_7cb5bf0e_b7a5ee8c-ff7d-4171-8988-6adab0d24631\Report.wer
MD5:
SHA256:
2928WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\WebCompanion-Installer.exe.7104.dmp
MD5:
SHA256:
2340WebCompanionInstaller-12.901.5.1061-prod.exeC:\Users\admin\AppData\Local\Temp\7zS4296CE2C\WebCompanion-Installer.exe.configxml
MD5:44B1970376FBA163AA49B183915D0EAA
SHA256:13C41E9C66B82DC0BAA0B2762AA7B91FFD418F2C9FCB9DC35DFB40A5C555414C
2340WebCompanionInstaller-12.901.5.1061-prod.exeC:\Users\admin\AppData\Local\Temp\7zS4296CE2C\de-DE\WebCompanion-Installer.resources.dllexecutable
MD5:B0DC52BB18BBA0D07ECDE9D6C8D258C7
SHA256:F18DE12839E91CC00BA2BB922385E547D1E411651CECC9911778BBFA6D7E01A6
2340WebCompanionInstaller-12.901.5.1061-prod.exeC:\Users\admin\AppData\Local\Temp\7zS4296CE2C\Newtonsoft.Json.dllexecutable
MD5:CF415AB5A5A0BF6A80EA910CEA0025D4
SHA256:E3FF89C26921FDCCDC604F30CAF3CDE6D36B4F22435EEC8F7DD9C8DAEB833BB1
2928WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER3244.tmp.WERInternalMetadata.xmlxml
MD5:676639706EC4F2A828B06A4C4662B4C5
SHA256:28E201D89214BDB1649329693DB3DCEA6D8B923B53A1884E990DF88DCA2636C5
2928WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER263C.tmp.dmpbinary
MD5:1E79DEA84AD01A93EBE885367212B437
SHA256:EF69FDEF4F4AEF8AC1FF5226B51A54B8922A2506A2E5BC815FAF9D3BBA403AA1
7104WebCompanion-Installer.exeC:\Users\admin\AppData\Local\Temp\WcInstaller.logtext
MD5:47C0C2975CA86EFC63AAC7491E3AD873
SHA256:38ED07D05CD8E04025929081CD45C8B82113522172A3BC09E1287748C131EE69
2340WebCompanionInstaller-12.901.5.1061-prod.exeC:\Users\admin\AppData\Local\Temp\7zS4296CE2C\WebCompanion-Installer.exeexecutable
MD5:F6DFE983850039A9EC8DD2F93E2D25CC
SHA256:2BCDB38E9BDD47E5CA87A683FDCB45CB8D3B95ADA15A7C7610618D02FC112660
2340WebCompanionInstaller-12.901.5.1061-prod.exeC:\Users\admin\AppData\Local\Temp\7zS4296CE2C\fr-CA\WebCompanion-Installer.resources.dllexecutable
MD5:A818A9C320F78A222E5EC02B35F93830
SHA256:64772244ECB4CC37B2A0AF361881D47CD971FDDF1B7F288D6810FA35A56B39B7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
50
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5368
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4132
OfficeClickToRun.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
4424
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
3676
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1028
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:138
whitelisted
3952
svchost.exe
239.255.255.250:1900
whitelisted
5368
SearchApp.exe
131.253.33.254:443
a-ring-fallback.msedge.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
5368
SearchApp.exe
104.126.37.154:443
www.bing.com
Akamai International B.V.
DE
unknown
3656
slui.exe
20.83.72.98:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6012
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
6716
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:137
whitelisted
1620
slui.exe
20.83.72.98:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.104.136.2
whitelisted
t-ring-fdv2.msedge.net
  • 13.107.237.254
unknown
a-ring-fallback.msedge.net
  • 131.253.33.254
unknown
www.bing.com
  • 104.126.37.154
  • 104.126.37.130
  • 104.126.37.139
  • 104.126.37.128
  • 104.126.37.131
  • 104.126.37.144
  • 104.126.37.153
  • 104.126.37.161
  • 104.126.37.146
whitelisted
google.com
  • 142.250.186.142
whitelisted
watson.events.data.microsoft.com
  • 20.42.73.29
whitelisted
fp-afd-nocache-ccp.azureedge.net
  • 13.107.253.45
whitelisted
login.live.com
  • 20.190.160.14
  • 20.190.160.22
  • 40.126.32.138
  • 20.190.160.20
  • 20.190.160.17
  • 40.126.32.140
  • 40.126.32.72
  • 40.126.32.74
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted

Threats

No threats detected
Process
Message
WebCompanion-Installer.exe
Failed to OpenWcfHost: System.ServiceModel.AddressAccessDeniedException: HTTP could not register URL http://+:9008/webcompanion/. Your process does not have access rights to this namespace (see http://go.microsoft.com/fwlink/?LinkId=70353 for details). ---> System.Net.HttpListenerException: Access is denied at System.Net.HttpListener.AddAllPrefixes() at System.Net.HttpListener.Start() at System.ServiceModel.Channels.SharedHttpTransportManager.OnOpen() --- End of inner exception stack trace --- at System.ServiceModel.Channels.SharedHttpTransportManager.OnOpen() at System.ServiceModel.Channels.TransportManager.Open(TransportChannelListener channelListener) at System.ServiceModel.Channels.TransportManagerContainer.Open(SelectTransportManagersCallback selectTransportManagerCallback) at System.ServiceModel.Channels.TransportChannelListener.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.HttpChannelListener`1.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at System.ServiceModel.Dispatcher.ChannelDispatcher.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at System.ServiceModel.ServiceHostBase.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at WebCompanionInstaller.App.OpenInstallerWcfHost()
WebCompanion-Installer.exe
Detecting windows culture