| URL: | http://cdn.slimcleaner.com/downloads/silentdownloader/SlimCleanerPlus-Downloader.exe.bz2 |
| Full analysis: | https://app.any.run/tasks/f7f9c532-c72a-4954-afd6-37d61575dbcf |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | April 10, 2020, 18:47:37 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 8451260378BA4990582830311CF7A625 |
| SHA1: | F1CB1DC80AEE368A752C4287C39C924705531FD4 |
| SHA256: | 689D80091D6D0C082A8B48CCEB966A7314EAA470165954CD73D8EEED334E0174 |
| SSDEEP: | 3:N1KdBLqIfAXZMXKLJeZuXtevWIc4EE2X06fXn:CX02aMZ/W0/u |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 332 | "C:\Program Files\SlimServices\SlimService.exe" /regserver | C:\Program Files\SlimServices\SlimService.exe | — | msiexec.exe | |||||||||||
User: admin Company: SlimWare Utilities, Inc. Integrity Level: HIGH Description: SlimService Exit code: 0 Version: 1.8.0 Modules
| |||||||||||||||
| 344 | %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 | C:\Windows\System32\csrss.exe | — | — | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Client Server Runtime Process Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 628 | taskkill /f /im slimservicefactory.exe | C:\Windows\system32\taskkill.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Terminates Processes Exit code: 128 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1228 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Downloads\SlimCleanerPlus-Downloader.exe.bz2" | C:\Program Files\WinRAR\WinRAR.exe | firefox.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 1720 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1784.20.2039971616\1426014855" -childID 3 -isForBrowser -prefsHandle 3636 -prefMapHandle 3628 -prefsLen 6718 -prefMapSize 191824 -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 1784 "\\.\pipe\gecko-crash-server-pipe.1784" 3688 tab | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 68.0.1 Modules
| |||||||||||||||
| 1760 | "C:\Program Files\SlimCleaner Plus\SlimCleanerPlus.exe" | C:\Program Files\SlimCleaner Plus\SlimCleanerPlus.exe | explorer.exe | ||||||||||||
User: admin Company: SlimWare Utilities Inc Integrity Level: HIGH Description: SlimCleaner Plus Exit code: 0 Version: 4.2.2.73 Modules
| |||||||||||||||
| 1784 | "C:\Program Files\Mozilla Firefox\firefox.exe" http://cdn.slimcleaner.com/downloads/silentdownloader/SlimCleanerPlus-Downloader.exe.bz2 | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 4294967295 Version: 68.0.1 Modules
| |||||||||||||||
| 2060 | "C:\Windows\system32\cmd.exe" | C:\Windows\system32\cmd.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 3221225786 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2276 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2512 | "C:\Users\admin\Downloads\SlimCleanerPlus-Downloader.exe\SlimCleanerPlus-Downloader.exe" | C:\Users\admin\Downloads\SlimCleanerPlus-Downloader.exe\SlimCleanerPlus-Downloader.exe | — | explorer.exe | |||||||||||
User: admin Company: SlimWare Utilities Holdings, Inc. Integrity Level: MEDIUM Description: SlimCleaner Plus SlimWare Downloader Exit code: 3221226540 Version: 2.4.2 Modules
| |||||||||||||||
| (PID) Process: | (3888) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: 2E270EF408000000 | |||
| (PID) Process: | (1784) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: 50DA10F408000000 | |||
| (PID) Process: | (1784) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 1 | |||
| (PID) Process: | (1784) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (1784) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 46000000A1000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1784) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (1784) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (1228) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (1228) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (1784) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bz2\OpenWithProgids |
| Operation: | write | Name: | WinRAR |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1784 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 1784 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm | — | |
MD5:— | SHA256:— | |||
| 1784 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js | — | |
MD5:— | SHA256:— | |||
| 1784 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp | — | |
MD5:— | SHA256:— | |||
| 1784 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4.tmp | — | |
MD5:— | SHA256:— | |||
| 1784 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-child-current.bin | binary | |
MD5:— | SHA256:— | |||
| 1784 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js | text | |
MD5:— | SHA256:— | |||
| 1784 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.bin | binary | |
MD5:— | SHA256:— | |||
| 1784 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4 | jsonlz4 | |
MD5:— | SHA256:— | |||
| 1784 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json | text | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1784 | firefox.exe | POST | 200 | 172.217.21.195:80 | http://ocsp.pki.goog/gts1o1 | US | der | 471 b | whitelisted |
3220 | SlimCleanerPlus-Downloader.exe | GET | 200 | 143.204.101.61:80 | http://cdn.slimcleaner.com/downloads/4.2.2.73/x86/SlimCleaner-setup.exe | US | executable | 7.75 Mb | whitelisted |
3252 | SlimService.exe | GET | 200 | 143.204.101.197:80 | http://cdn.slimcleaner.com/slimcleanerdb/cleaner.active.file | US | binary | 750 Kb | whitelisted |
1784 | firefox.exe | GET | 200 | 143.204.101.4:80 | http://cdn.slimcleaner.com/downloads/silentdownloader/SlimCleanerPlus-Downloader.exe.bz2 | US | compressed | 136 Kb | whitelisted |
1784 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
3596 | pingsender.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D | US | der | 471 b | whitelisted |
3220 | SlimCleanerPlus-Downloader.exe | GET | 200 | 52.7.3.6:80 | http://trk.slimwareutilities.com/ulc.php?ev=InstallerInvoked&platformOSVersion=6.1&ul_stubid=C6A08AB3-6B0D-4AAC-979E-1FD32DB44F3D&installer=SD0&product=SW1&installerVersion=2.4.2&machineId=DCB7F85C-2B4B-4072-8B18-6F9B5D6F6ECD&platformOS=Windows | US | text | 2 b | malicious |
3596 | pingsender.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQQX6Z6gAidtSefNc6DC0OInqPHDQQUD4BhHIIxYdUvKOeNRji0LOHG2eICEAd1LOvlIi%2FPXH0gOJhMUZg%3D | US | der | 471 b | whitelisted |
1784 | firefox.exe | GET | 200 | 23.53.41.48:80 | http://detectportal.firefox.com/success.txt | NL | text | 8 b | whitelisted |
3220 | SlimCleanerPlus-Downloader.exe | GET | 200 | 52.7.3.6:80 | http://trk.slimwareutilities.com/ulc.php?ev=InstallerFinished&platformOSVersion=6.1&installId=8E9E45D4-87E4-48B8-85A9-6800F3D2FEDF&ul_stubid=C6A08AB3-6B0D-4AAC-979E-1FD32DB44F3D&installer=SD0&product=SW1&installerVersion=2.4.2&machineId=DCB7F85C-2B4B-4072-8B18-6F9B5D6F6ECD&platformOS=Windows | US | text | 2 b | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1784 | firefox.exe | 143.204.101.4:80 | cdn.slimcleaner.com | — | US | suspicious |
1784 | firefox.exe | 23.53.41.48:80 | detectportal.firefox.com | Telia Company AB | NL | suspicious |
1784 | firefox.exe | 52.11.143.45:443 | search.services.mozilla.com | Amazon.com, Inc. | US | unknown |
1784 | firefox.exe | 52.25.16.81:443 | push.services.mozilla.com | Amazon.com, Inc. | US | unknown |
1784 | firefox.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
1784 | firefox.exe | 143.204.97.29:443 | snippets.cdn.mozilla.net | — | US | unknown |
1784 | firefox.exe | 172.217.18.106:443 | safebrowsing.googleapis.com | Google Inc. | US | whitelisted |
1784 | firefox.exe | 172.217.21.195:80 | ocsp.pki.goog | Google Inc. | US | whitelisted |
1784 | firefox.exe | 143.204.97.41:443 | firefox.settings.services.mozilla.com | — | US | unknown |
1784 | firefox.exe | 143.204.97.3:443 | content-signature-2.cdn.mozilla.net | — | US | unknown |
Domain | IP | Reputation |
|---|---|---|
cdn.slimcleaner.com |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
a1089.dscd.akamai.net |
| whitelisted |
search.services.mozilla.com |
| whitelisted |
search.r53-2.services.mozilla.com |
| whitelisted |
push.services.mozilla.com |
| whitelisted |
autopush.prod.mozaws.net |
| whitelisted |
snippets.cdn.mozilla.net |
| whitelisted |
d228z91au11ukj.cloudfront.net |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1052 | svchost.exe | Potentially Bad Traffic | ET INFO Observed DNS Query to .cloud TLD |
1052 | svchost.exe | Potentially Bad Traffic | ET INFO Observed DNS Query to .cloud TLD |
3220 | SlimCleanerPlus-Downloader.exe | Potentially Bad Traffic | ET POLICY Executable served from Amazon S3 |
3220 | SlimCleanerPlus-Downloader.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |