File name:

ae1bc5fc07b1554f935c7d0e7b6452138fb56179960eb80d6c8bfd62a1b6a773.zip

Full analysis: https://app.any.run/tasks/b7dae119-fc9f-495a-9153-cf400fb13380
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: February 10, 2024, 23:35:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
adaware
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=AES Encrypted
MD5:

557464EEE7CA1D926F27C97F754ABF30

SHA1:

87E2398C922D640410ADAED7A3FE39B999EBF24F

SHA256:

EAC03B7830F73B2AEA2D763EEC045E5E8B8992DE4C5D51626D634466989195A6

SSDEEP:

24576:+LJTCLM9LNon8Cw1O1us2cheDT1l2DGGikPyPrqqB4uC8gy:+LJTCLM9Lan8Cw1O1us2cheDT1l2DGG+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3672)
      • $R4P6CYV.exe (PID: 120)
      • WebCompanion-Installer.exe (PID: 2124)
      • WebCompanion.exe (PID: 3692)
      • WebCompanion-Installer.exe (PID: 3104)
      • WebCompanion-Installer.exe (PID: 1432)
    • ADAWARE has been detected (SURICATA)

      • WebCompanion.exe (PID: 1844)
    • Changes the autorun value in the registry

      • WebCompanion.exe (PID: 1844)
      • WebCompanion.exe (PID: 968)
      • WebCompanion.exe (PID: 3584)
      • rundll32.exe (PID: 3776)
    • Steals credentials from Web Browsers

      • WebCompanion.exe (PID: 968)
      • WebCompanion.exe (PID: 1844)
      • WebCompanion.exe (PID: 3956)
      • WebCompanion.exe (PID: 3584)
    • Actions looks like stealing of personal data

      • WebCompanion.exe (PID: 968)
      • WebCompanion.exe (PID: 1844)
      • WebCompanion.exe (PID: 3956)
      • WebCompanion.exe (PID: 3584)
    • Creates a writable file in the system directory

      • rundll32.exe (PID: 3776)
      • Lavasoft.WCAssistant.WinService.exe (PID: 4036)
    • Starts NET.EXE for service management

      • net.exe (PID: 3964)
      • WebCompanion-Installer.exe (PID: 1432)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • $R4P6CYV.exe (PID: 120)
      • WebCompanion-Installer.exe (PID: 2124)
      • WebCompanion-Installer.exe (PID: 3104)
      • WebCompanion.exe (PID: 3692)
      • WebCompanion-Installer.exe (PID: 1432)
      • rundll32.exe (PID: 3776)
    • Searches for installed software

      • WebCompanion-Installer.exe (PID: 2124)
      • WebCompanion.exe (PID: 1844)
      • WebCompanion.exe (PID: 968)
      • WebCompanion-Installer.exe (PID: 3104)
      • WebCompanion-Installer.exe (PID: 1432)
      • WebCompanion.exe (PID: 3956)
      • WebCompanion.exe (PID: 3584)
    • Reads settings of System Certificates

      • WebCompanion-Installer.exe (PID: 2124)
      • WebCompanion.exe (PID: 1844)
      • WebCompanion.exe (PID: 968)
      • WebCompanion-Installer.exe (PID: 3104)
      • WebCompanion-Installer.exe (PID: 1432)
      • WebCompanion.exe (PID: 3956)
      • WebCompanion.exe (PID: 3584)
    • Drops 7-zip archiver for unpacking

      • WebCompanion-Installer.exe (PID: 2124)
      • WebCompanion-Installer.exe (PID: 1432)
    • Reads the Internet Settings

      • WebCompanion-Installer.exe (PID: 2124)
      • WebCompanion.exe (PID: 1844)
      • WebCompanion.exe (PID: 968)
      • WebCompanion-Installer.exe (PID: 3104)
      • WebCompanion-Installer.exe (PID: 1432)
      • runonce.exe (PID: 2732)
      • WebCompanion.exe (PID: 3956)
      • WebCompanion.exe (PID: 3584)
    • The process creates files with name similar to system file names

      • WebCompanion-Installer.exe (PID: 2124)
      • WebCompanion-Installer.exe (PID: 1432)
    • Reads security settings of Internet Explorer

      • WebCompanion-Installer.exe (PID: 2124)
      • WebCompanion.exe (PID: 1844)
      • WebCompanion.exe (PID: 968)
      • WebCompanion-Installer.exe (PID: 3104)
      • WebCompanion-Installer.exe (PID: 1432)
      • Lavasoft.WCAssistant.WinService.exe (PID: 4036)
      • WebCompanion.exe (PID: 3956)
      • WebCompanion.exe (PID: 3584)
    • Starts CMD.EXE for commands execution

      • WebCompanion-Installer.exe (PID: 2124)
      • Lavasoft.WCAssistant.WinService.exe (PID: 4036)
      • WebCompanion-Installer.exe (PID: 1432)
    • The process drops C-runtime libraries

      • WebCompanion-Installer.exe (PID: 2124)
      • WebCompanion-Installer.exe (PID: 1432)
    • Changes internet zones settings

      • WebCompanion-Installer.exe (PID: 2124)
    • Suspicious use of NETSH.EXE

      • cmd.exe (PID: 3724)
      • cmd.exe (PID: 3968)
    • Creates a software uninstall entry

      • WebCompanion-Installer.exe (PID: 2124)
      • WebCompanion-Installer.exe (PID: 1432)
    • Checks Windows Trust Settings

      • WebCompanion.exe (PID: 1844)
      • WebCompanion.exe (PID: 968)
      • Lavasoft.WCAssistant.WinService.exe (PID: 4036)
      • WebCompanion.exe (PID: 3956)
      • WebCompanion.exe (PID: 3584)
    • Adds/modifies Windows certificates

      • WebCompanion.exe (PID: 1844)
    • Process drops legitimate windows executable

      • WebCompanion-Installer.exe (PID: 2124)
      • WebCompanion-Installer.exe (PID: 1432)
    • Drops a system driver (possible attempt to evade defenses)

      • WebCompanion-Installer.exe (PID: 1432)
      • rundll32.exe (PID: 3776)
    • Executes as Windows Service

      • Lavasoft.WCAssistant.WinService.exe (PID: 4036)
      • DCIService.exe (PID: 2992)
    • Creates or modifies Windows services

      • rundll32.exe (PID: 3776)
    • Uses RUNDLL32.EXE to load library

      • WebCompanion-Installer.exe (PID: 1432)
    • Executing commands from ".cmd" file

      • WebCompanion-Installer.exe (PID: 1432)
    • Starts SC.EXE for service management

      • cmd.exe (PID: 2972)
      • WebCompanion-Installer.exe (PID: 1432)
      • WebCompanion.exe (PID: 3956)
  • INFO

    • Create files in a temporary directory

      • $R4P6CYV.exe (PID: 120)
      • WebCompanion-Installer.exe (PID: 2124)
      • WebCompanion-Installer.exe (PID: 3104)
      • WebCompanion.exe (PID: 3692)
      • WebCompanion-Installer.exe (PID: 1432)
    • Manual execution by a user

      • $R4P6CYV.exe (PID: 120)
    • Reads the machine GUID from the registry

      • WebCompanion-Installer.exe (PID: 2124)
      • WebCompanion.exe (PID: 1844)
      • WebCompanion.exe (PID: 968)
      • WebCompanion-Installer.exe (PID: 3104)
      • Lavasoft.WCAssistant.WinService.exe (PID: 4036)
      • WebCompanion.exe (PID: 3956)
      • WebCompanion-Installer.exe (PID: 1432)
      • DCIService.exe (PID: 2992)
      • WebCompanion.exe (PID: 3584)
    • Checks supported languages

      • WebCompanion-Installer.exe (PID: 2124)
      • $R4P6CYV.exe (PID: 120)
      • WebCompanion.exe (PID: 1844)
      • WebCompanion.exe (PID: 968)
      • WebCompanion-Installer.exe (PID: 3104)
      • WebCompanion-Installer.exe (PID: 1432)
      • WebCompanion.exe (PID: 3692)
      • Lavasoft.WCAssistant.WinService.exe (PID: 4036)
      • DCIService.exe (PID: 2992)
      • WebCompanion.exe (PID: 3956)
      • WebCompanion.exe (PID: 3584)
    • Reads the software policy settings

      • WebCompanion-Installer.exe (PID: 2124)
      • WebCompanion.exe (PID: 1844)
      • WebCompanion.exe (PID: 968)
      • WebCompanion-Installer.exe (PID: 3104)
      • WebCompanion-Installer.exe (PID: 1432)
      • Lavasoft.WCAssistant.WinService.exe (PID: 4036)
      • WebCompanion.exe (PID: 3956)
      • WebCompanion.exe (PID: 3584)
    • Reads the computer name

      • WebCompanion-Installer.exe (PID: 2124)
      • WebCompanion.exe (PID: 1844)
      • WebCompanion.exe (PID: 968)
      • WebCompanion-Installer.exe (PID: 3104)
      • WebCompanion-Installer.exe (PID: 1432)
      • Lavasoft.WCAssistant.WinService.exe (PID: 4036)
      • WebCompanion.exe (PID: 3956)
      • DCIService.exe (PID: 2992)
      • WebCompanion.exe (PID: 3584)
    • Creates files or folders in the user directory

      • WebCompanion-Installer.exe (PID: 2124)
      • WebCompanion.exe (PID: 1844)
      • WebCompanion.exe (PID: 968)
      • WebCompanion-Installer.exe (PID: 1432)
      • DCIService.exe (PID: 2992)
      • WebCompanion.exe (PID: 3956)
      • WebCompanion.exe (PID: 3584)
    • Reads Environment values

      • WebCompanion-Installer.exe (PID: 2124)
      • WebCompanion.exe (PID: 1844)
      • WebCompanion.exe (PID: 968)
      • WebCompanion-Installer.exe (PID: 3104)
      • WebCompanion-Installer.exe (PID: 1432)
      • Lavasoft.WCAssistant.WinService.exe (PID: 4036)
      • WebCompanion.exe (PID: 3956)
      • WebCompanion.exe (PID: 3584)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3672)
    • Creates files in the program directory

      • WebCompanion.exe (PID: 1844)
      • WebCompanion-Installer.exe (PID: 3104)
      • WebCompanion-Installer.exe (PID: 1432)
      • Lavasoft.WCAssistant.WinService.exe (PID: 4036)
      • DCIService.exe (PID: 2992)
      • WebCompanion.exe (PID: 3584)
      • WebCompanion.exe (PID: 3956)
    • Reads product name

      • WebCompanion.exe (PID: 1844)
      • WebCompanion.exe (PID: 968)
      • WebCompanion.exe (PID: 3956)
      • WebCompanion.exe (PID: 3584)
    • Application launched itself

      • chrome.exe (PID: 2632)
    • Reads Microsoft Office registry keys

      • WebCompanion.exe (PID: 968)
      • WebCompanion.exe (PID: 3584)
    • Creates files in the driver directory

      • rundll32.exe (PID: 3776)
    • Drops the executable file immediately after the start

      • rundll32.exe (PID: 3776)
    • Reads security settings of Internet Explorer

      • runonce.exe (PID: 2732)
    • Reads the time zone

      • runonce.exe (PID: 2732)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0001
ZipCompression: Unknown (99)
ZipModifyDate: 2024:02:10 23:34:50
ZipCRC: 0xdc345e76
ZipCompressedSize: 456684
ZipUncompressedSize: 545160
ZipFileName: $R4P6CYV.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
94
Monitored processes
39
Malicious processes
11
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe $r4p6cyv.exe webcompanion-installer.exe cmd.exe no specs netsh.exe no specs #ADAWARE webcompanion.exe webcompanion.exe chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs webcompanion-installer.exe webcompanion.exe webcompanion-installer.exe sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs lavasoft.wcassistant.winservice.exe cmd.exe no specs netsh.exe no specs rundll32.exe runonce.exe no specs grpconv.exe no specs sc.exe no specs net.exe no specs net1.exe no specs sc.exe no specs cmd.exe no specs sc.exe no specs dciservice.exe no specs webcompanion.exe sc.exe no specs webcompanion.exe

Process information

PID
CMD
Path
Indicators
Parent process
120"C:\Users\admin\Desktop\$R4P6CYV.exe" C:\Users\admin\Desktop\$R4P6CYV.exe
explorer.exe
User:
admin
Company:
Lavasoft
Integrity Level:
HIGH
Description:
Web Companion Installer
Exit code:
0
Version:
12.901.2.991
Modules
Images
c:\users\admin\desktop\$r4p6cyv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
680"sc.exe" description "DCIService" "Webprotection Bridge service"C:\Windows\System32\sc.exeWebCompanion-Installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
A tool to aid in developing services for WindowsNT
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
900"sc.exe" Create "DCIService" binPath= "C:\Program Files\Lavasoft\Web Companion\Service\Win32\DCIService.exe" DisplayName= "DCIService" start= autoC:\Windows\System32\sc.exeWebCompanion-Installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
A tool to aid in developing services for WindowsNT
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
968"C:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Application\WebCompanion.exe" --afterinstall C:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Application\WebCompanion.exe
WebCompanion-Installer.exe
User:
admin
Company:
Lavasoft
Integrity Level:
HIGH
Description:
Web Companion
Exit code:
4294967295
Version:
12.901.4.1003
Modules
Images
c:\users\admin\appdata\roaming\lavasoft\web companion\application\webcompanion.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1432.\WebCompanion-Installer.exe --nanouniqueid=1707608305134 --enablewp --silent --installid=ce6e703d-3b8d-4cab-b3cb-9bdfeb5b4fb6 --partner=IN230901A --campaign=18022583703 --version=12.1.4.1003C:\Users\admin\AppData\Local\Temp\7zSC6EB0AFA\WebCompanion-Installer.exe
WebCompanion.exe
User:
admin
Company:
Lavasoft
Integrity Level:
HIGH
Description:
Web Companion
Exit code:
0
Version:
12.1.4.1003
Modules
Images
c:\users\admin\appdata\local\temp\7zsc6eb0afa\webcompanion-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1656"sc.exe" Create "WCAssistantService" binPath= "C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe" DisplayName= "WC Assistant" start= autoC:\Windows\System32\sc.exeWebCompanion-Installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
A tool to aid in developing services for WindowsNT
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1796"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1064 --field-trial-handle=1112,i,1693020286238810330,17215082926169375832,131072 /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1844"C:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Application\WebCompanion.exe" --install --geo= C:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Application\WebCompanion.exe
WebCompanion-Installer.exe
User:
admin
Company:
Lavasoft
Integrity Level:
HIGH
Description:
Web Companion
Exit code:
0
Version:
12.901.4.1003
Modules
Images
c:\users\admin\appdata\roaming\lavasoft\web companion\application\webcompanion.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1936"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --mojo-platform-channel-handle=1332 --field-trial-handle=1112,i,1693020286238810330,17215082926169375832,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2112C:\Windows\system32\net1 start bddciC:\Windows\System32\net1.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\net1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\netutils.dll
Total events
75 820
Read events
75 350
Write events
453
Delete events
17

Modification events

(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3672) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\ae1bc5fc07b1554f935c7d0e7b6452138fb56179960eb80d6c8bfd62a1b6a773.zip
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
299
Suspicious files
127
Text files
174
Unknown types
99

Dropped files

PID
Process
Filename
Type
120$R4P6CYV.exeC:\Users\admin\AppData\Local\Temp\7zS870A1218\pt-BR\WebCompanion-Installer.resources.dllexecutable
MD5:E2423F7E31E9D897AA80D9B71A6203DD
SHA256:7A85AC96F886D18C9D3A441E4BB73501AF7DD4DE0C45E0551FC80E10A3B6D0E9
120$R4P6CYV.exeC:\Users\admin\AppData\Local\Temp\7zS870A1218\it-IT\WebCompanion-Installer.resources.dllexecutable
MD5:B5C7FD5FCC9DF47FD4560CA3E7D15119
SHA256:39D4FEE7CA6F5191071F925D0BE3B6570438F3CC65EA697815C496F7114312BB
120$R4P6CYV.exeC:\Users\admin\AppData\Local\Temp\7zS870A1218\Newtonsoft.Json.dllexecutable
MD5:315D11848A4D33D318B0047383DDCB7F
SHA256:6EB040CE8B90CB5F0C9349420BFBE65DBF5AF2B55C15A6A289BAF453677409E1
120$R4P6CYV.exeC:\Users\admin\AppData\Local\Temp\7zS870A1218\en-US\WebCompanion-Installer.resources.dllexecutable
MD5:7C0E28A31CCD2522EFBD0A13D884737F
SHA256:573A94A782D71979F7DDDCC72376F7FE444530C0E8A260CC06314A5AA6BA4A90
2124WebCompanion-Installer.exeC:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Application\7za.exeexecutable
MD5:E983C907A0C8AA4EA37CA2A7B3FB2AE5
SHA256:7E58A8A27177D6043ACE14A124EF352119958188B60B952DC86C443F3B95967C
120$R4P6CYV.exeC:\Users\admin\AppData\Local\Temp\7zS870A1218\es-ES\WebCompanion-Installer.resources.dllexecutable
MD5:92C29A99CD97C7378A00F711D00E5B63
SHA256:7BFF5C3C3F8C71F8985DFAABCDC859D2A1465808FEC90A53681422D9CA658643
120$R4P6CYV.exeC:\Users\admin\AppData\Local\Temp\7zS870A1218\zh-CHS\WebCompanion-Installer.resources.dllexecutable
MD5:A52E2E73EAD3F119CF89D5DCDCE809DC
SHA256:99B0E9D84C8D150FF02D4AB114BED8AB22A7E15DD087A2CFF6EBD5E326396FB8
2124WebCompanion-Installer.exeC:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Options\Statistics.txtbinary
MD5:78D78B4D06171E369EEFA49F09AB968C
SHA256:B291C136EA24BE222A9B2F185A4C0C17F2044CB695961C7C291B48356A86B4E4
120$R4P6CYV.exeC:\Users\admin\AppData\Local\Temp\7zS870A1218\tr-TR\WebCompanion-Installer.resources.dllexecutable
MD5:36508BEFD079D1F5E010973E59F390E7
SHA256:449952E7C986BE0625B6D43F17D8ACCC1FF367B03D7611BCB2D3BFE9B7B47975
120$R4P6CYV.exeC:\Users\admin\AppData\Local\Temp\7zS870A1218\ja-JP\WebCompanion-Installer.resources.dllexecutable
MD5:7D06B5848CEBD17113F9BC94979CD61B
SHA256:F9D05AC726E2350429B9C91840D249E252E667E77577E01041D2DEBFF7ADECD1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
19
TCP/UDP connections
66
DNS requests
68
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2124
WebCompanion-Installer.exe
GET
200
104.17.8.52:80
http://geo.lavasoft.com/
unknown
binary
50 b
unknown
1844
WebCompanion.exe
GET
200
104.17.8.52:80
http://geo.lavasoft.com/
unknown
binary
50 b
unknown
2124
WebCompanion-Installer.exe
GET
200
104.17.8.52:80
http://geo.lavasoft.com/
unknown
binary
50 b
unknown
1844
WebCompanion.exe
GET
200
64.18.87.81:80
http://wc-partners.lavasoft.com/Partner.svc/GetPartnerInfo?partner=IN230901
unknown
binary
205 b
unknown
1844
WebCompanion.exe
GET
200
104.17.8.52:80
http://geo.lavasoft.com/
unknown
binary
50 b
unknown
3104
WebCompanion-Installer.exe
GET
200
104.17.8.52:80
http://geo.lavasoft.com/
unknown
binary
50 b
unknown
1844
WebCompanion.exe
GET
200
104.18.211.25:80
http://webcompanion.com/version_logs?json=true&version=12.901.4.1003
unknown
text
4 b
unknown
4036
Lavasoft.WCAssistant.WinService.exe
GET
200
69.192.162.201:80
http://ocsp.entrust.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTLXNCzDvBhHecWjg70iJhBW0InywQUanImetAe733nO2lR1GyNn5ASZqsCEE5A5DdU7eaMAAAAAFHTlH8%3D
unknown
binary
1.55 Kb
unknown
4036
Lavasoft.WCAssistant.WinService.exe
GET
200
69.192.162.201:80
http://ocsp.entrust.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRr2bwARTxMtEy9aspRAZg5QFhagQQUgrrWPZfOn89x6JI3r%2F2ztWk1V88CEDWvt3udNB9q%2FI%2BERqsxNSs%3D
unknown
binary
812 b
unknown
4036
Lavasoft.WCAssistant.WinService.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c9c5232b40cf9225
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
2124
WebCompanion-Installer.exe
104.17.8.52:80
geo.lavasoft.com
CLOUDFLARENET
shared
2124
WebCompanion-Installer.exe
104.17.8.52:443
geo.lavasoft.com
CLOUDFLARENET
shared
2124
WebCompanion-Installer.exe
104.18.27.149:443
flwadw.com
CLOUDFLARENET
shared
2124
WebCompanion-Installer.exe
104.17.9.52:443
geo.lavasoft.com
CLOUDFLARENET
shared
1844
WebCompanion.exe
104.17.8.52:80
geo.lavasoft.com
CLOUDFLARENET
shared
1844
WebCompanion.exe
104.17.9.52:443
geo.lavasoft.com
CLOUDFLARENET
shared
1844
WebCompanion.exe
104.18.27.149:443
flwadw.com
CLOUDFLARENET
shared

DNS requests

Domain
IP
Reputation
geo.lavasoft.com
  • 104.17.8.52
  • 104.17.9.52
unknown
featureflags.lavasoft.com
  • 104.17.8.52
  • 104.17.9.52
unknown
flwadw.com
  • 104.18.27.149
  • 104.18.26.149
unknown
wcdownloadercdn.lavasoft.com
  • 104.17.9.52
  • 104.17.8.52
whitelisted
wc-partners.lavasoft.com
  • 64.18.87.81
  • 64.18.87.82
whitelisted
webcompanion.com
  • 104.18.211.25
  • 104.18.212.25
unknown
clientservices.googleapis.com
  • 142.250.185.227
whitelisted
accounts.google.com
  • 64.233.166.84
shared
staging-partner-info.lavasoft.net
unknown
sg-bitmask.adaware.com
  • 104.18.68.73
  • 104.18.67.73
unknown

Threats

PID
Process
Class
Message
1844
WebCompanion.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
1844
WebCompanion.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
1844
WebCompanion.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
1844
WebCompanion.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
Process
Message
WebCompanion-Installer.exe
Detecting windows culture
WebCompanion-Installer.exe
Preparing request for featureflag: {"Geo":"DE","Partner":"IN230901","Campaign":"18022583703","InstallDate":"20240210","TriggerType":"install","TriggerEvent":"installer","Version":"12.901.2.991","featurewp":true,"featureal":true}
WebCompanion-Installer.exe
Getting response from featureflag: [{"sectionCode":"WAC","code":"WAC","configuration":"{\"Icon\": \"https://webcompanion.com/images/favicon.ico\", \"AppName\": \"Web Companion\", \"Settings\": [\"WCAutoUpdate\", \"EnableGranularity\", \"PostRunV2Action\", \"PostRunTimerAction\", \"EnableTelemetryScan\", \"EnableWebProtection\", \"EnableDynamicNotification\"], \"CompanyName\": \"Lavasoft\", \"ConfigVersion\": \"v1\", \"CurrentVersion\": \"9.3.0\"}","targetId":301},{"sectionCode":"WFAI","code":"WCP","configuration":"{\"Version\": \"3.0.2.12\", \"FilePath\": \"https://rt.webcompanion.com/notifications/download/rt/dci/latest/Webprotection.zip\", \"BlackList\": \"https://acs.lavasoft.com/api/v2/url/blacklist\", \"WhiteList\": \"https://acs.lavasoft.com/api/v2/url/permanentwhitelist\", \"DisplayName\": \"Web Protection\", \"FeatureName\": \"WebProtection\"}","targetId":241}]
WebCompanion-Installer.exe
2/10/2024 11:35:45 PM :-> Start
WebCompanion-Installer.exe
Failed to report progress in SendPostRequest: System.Net.WebException: The remote server returned an error: (400) Bad Request. at System.Net.HttpWebRequest.GetResponse() at WebCompanionInstaller.Utils.RestUtils.SendPostRequest(String url, String body)
WebCompanion-Installer.exe
2/10/2024 11:35:46 PM :-> Starting installer 12.901.2.991 with: .\WebCompanion-Installer.exe --savename=Setup.exe --partner=IN230901 --nonadmin --direct --tych --campaign=18022583703 --version=12.901.2.991, Run as admin: True
WebCompanion-Installer.exe
SecurityProtocol set toTls, Tls11, Tls12, Tls13
WebCompanion-Installer.exe
Preparing for installing Web Companion
WebCompanion-Installer.exe
2/10/2024 11:35:47 PM :-> Generating Machine and Install Id ...
WebCompanion-Installer.exe
2/10/2024 11:35:47 PM :-> Machine Id and Install Id has been generated