analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

http://wcdownloadercdn.lavasoft.com/4.5.1957.3838/WebCompanion-4.5.1957.3838-prod.zip

Full analysis: https://app.any.run/tasks/ea0f8ddc-949c-4610-bc86-4425337a3514
Verdict: Malicious activity
Analysis date: February 10, 2019, 16:01:34
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

878DD52B5FE88270689C327B67EFE1FC

SHA1:

0BEB1B3FD892CC156AC51476607ADEA92DB43864

SHA256:

ECD3D5601DF8D7E443F8169E076B6284FB261E30288246ECB2E3549F64929A89

SSDEEP:

196608:cVTPgN79xT/cEYJy2R4AvpWPlFJAy5YyQPQhr5F5ZpudK:cdIN7Ti4A4ZAHQdJzf

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • WebCompanion.exe (PID: 3428)
      • SearchProtocolHost.exe (PID: 1576)
      • explorer.exe (PID: 116)
    • Application was dropped or rewritten from another process

      • WebCompanion.exe (PID: 3428)
      • Ad-Aware Web Companion.exe (PID: 3140)
      • WebCompanionInstaller.exe (PID: 3796)
  • SUSPICIOUS

    • Creates files in the user directory

      • explorer.exe (PID: 116)
    • Reads Internet Cache Settings

      • explorer.exe (PID: 116)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3736)
    • Creates files in the program directory

      • WebCompanion.exe (PID: 3428)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • WinRAR.exe (PID: 3736)
    • Application was crashed

      • WebCompanionInstaller.exe (PID: 3796)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Application/Ad-Aware Web Companion.exe
ZipUncompressedSize: 129312
ZipCompressedSize: 64866
ZipCRC: 0x0a3bab5f
ZipModifyDate: 2018:12:14 08:46:22
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
7
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs ad-aware web companion.exe no specs webcompanion.exe webcompanioninstaller.exe dw20.exe no specs explorer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3736"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
1576"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe6_ Global\UsGthrCtrlFltPipeMssGthrPipe6 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
3140"C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Ad-Aware Web Companion.exe" C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Ad-Aware Web Companion.exeexplorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Ad-Aware Web Companion.exe
Exit code:
0
Version:
4.5.1957.3838
3428"C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\WebCompanion.exe" C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\WebCompanion.exe
explorer.exe
User:
admin
Company:
Lavasoft
Integrity Level:
MEDIUM
Description:
Web Companion
Exit code:
0
Version:
4.5.1957.3838
3796"C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\WebCompanionInstaller.exe" C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\WebCompanionInstaller.exe
explorer.exe
User:
admin
Company:
Lavasoft
Integrity Level:
MEDIUM
Description:
Web Companion
Exit code:
3762507597
Version:
4.5.1957.3838
3360dw20.exe -x -s 2004C:\Windows\Microsoft.NET\Framework\v2.0.50727\dw20.exeWebCompanionInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Error Reporting Shim
Exit code:
0
Version:
2.0.50727.4927 (NetFXspW7.050727-4900)
116C:\Windows\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Total events
3 009
Read events
2 826
Write events
0
Delete events
0

Modification events

No data
Executable files
62
Suspicious files
3
Text files
21
Unknown types
5

Dropped files

PID
Process
Filename
Type
116explorer.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\290532160612e071.automaticDestinations-msautomaticdestinations-ms
MD5:66D4D18C2900D06C74C84F82A73F455B
SHA256:DE24FF0EE8C95B706BE7FD31EAE739D57DB18C0E3427530B72E74C4412E58576
3736WinRAR.exeC:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Esent.Interop.dllexecutable
MD5:D88C833B390E85FA4FEC243BA8C10C67
SHA256:914F735626912A1CFBB6ED11504D375CF4BD55E8A7814F6DEF3C1216FFC0686C
116explorer.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\WebCompanion-4.5.1957.3838-prod.zip.lnklnk
MD5:77DD6A3D469D7533D7F4A26EC0EADD05
SHA256:673E99DF65A0C6629FCCD87CA2715CFAACA37AB87E1F8C62F20B8069F76D52F7
3736WinRAR.exeC:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Lavasoft.CSharp.Utilities.dllexecutable
MD5:A4F1BD8C28676040198B9E7A479E4EA8
SHA256:3673820228173C6104565EEBB8F737BAA965FD9CA47234B75F727B17AC39C425
116explorer.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\1b4dd67f29cb1962.automaticDestinations-msautomaticdestinations-ms
MD5:095A93B69956320D95DB8400F74E2C2D
SHA256:0015427E7A3F9F2CDB3985E187F59AB7D33BB40F2ACBCF3280BCCD1DD758B5E6
3736WinRAR.exeC:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Lavasoft.Automation.dllexecutable
MD5:0BB90CFA68900451292A12FB126314D8
SHA256:AE39B4543E6628ACAE520114CFD61CB46FFF73CAB78A5A348548D6EB0F4A0724
3736WinRAR.exeC:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Lavasoft.adblocker.dllexecutable
MD5:C88591046C523D07996B10125363D5CA
SHA256:C11CB02ED0ADFBB9E6C291C5E623AF8E74F4DD77EABAF614E3E94F32A4C3F78F
3736WinRAR.exeC:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Lavasoft.Events.dllexecutable
MD5:0BEFF872855BA1BC7D18F3476E5C7666
SHA256:F705CB2F2AC5C8CFDB354BD660713C433865B26F06D5984BC197FAEE12CD5096
3736WinRAR.exeC:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Interop.LavasoftTcpServiceLib.dllexecutable
MD5:138F15A09476A2B209531315E8228B90
SHA256:3989BEF039965CDED5E491894D3C8EB567108E043675B0D94496A4FBCEF3CA67
116explorer.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019021020190211\index.datdat
MD5:F12C51B12B7E0C73B085489C285BC75A
SHA256:0EA5E76D5B2D630C27B2FEFA08A7F94D8B1BC1EA215763C186E95739D6E089AB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
2
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3428
WebCompanion.exe
GET
200
104.17.177.102:80
http://rt.webcompanion.com/notifications/download/rt/ActiveFeatures.zip
US
compressed
7.96 Kb
malicious
3428
WebCompanion.exe
GET
200
104.17.177.102:80
http://webcompanion.com/version_logs?json=true&version=4.5.1957.3838
US
text
4 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3428
WebCompanion.exe
104.17.177.102:80
webcompanion.com
Cloudflare Inc
US
shared

DNS requests

Domain
IP
Reputation
webcompanion.com
  • 104.17.177.102
  • 104.17.178.102
malicious
rt.webcompanion.com
  • 104.17.177.102
  • 104.17.178.102
malicious

Threats

No threats detected
Process
Message
WebCompanionInstaller.exe
Detecting windows culture