File name:

SlimDrivers-setup.zip

Full analysis: https://app.any.run/tasks/7d92ec28-ade2-47f1-ac32-55884f5444d6
Verdict: Malicious activity
Analysis date: March 06, 2024, 01:56:19
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

023D56FE02780BCA51D46B9FB8ACE4BE

SHA1:

B48FA146239D58B007822DCAD0D0F373134C67E4

SHA256:

B9F819CF67BF7860EECD03DC626F9548F96F8E739863FFC39AAB6E1A3D24A478

SSDEEP:

24576:e1lHKAKS4iRsPeM99eAbGlicjaFc1K/U0R2UFFx:e1lHKAKS4iRsPeM99eAbGIcjEc1K/U0v

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3864)
    • Connects to the CnC server

      • SlimDrivers-setup.exe (PID: 2636)
      • SlimDrivers-setup.exe (PID: 2152)
  • SUSPICIOUS

    • Reads settings of System Certificates

      • SlimDrivers-setup.exe (PID: 2636)
      • SlimDrivers-setup.exe (PID: 2152)
    • Reads the Internet Settings

      • SlimDrivers-setup.exe (PID: 2152)
      • SlimDrivers-setup.exe (PID: 2636)
    • Reads security settings of Internet Explorer

      • SlimDrivers-setup.exe (PID: 2152)
      • SlimDrivers-setup.exe (PID: 2636)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3864)
    • Create files in a temporary directory

      • SlimDrivers-setup.exe (PID: 2636)
      • SlimDrivers-setup.exe (PID: 2152)
    • Manual execution by a user

      • SlimDrivers-setup.exe (PID: 3708)
      • SlimDrivers-setup.exe (PID: 2152)
      • SlimDrivers-setup.exe (PID: 2756)
      • SlimDrivers-setup.exe (PID: 2636)
    • Checks proxy server information

      • SlimDrivers-setup.exe (PID: 2636)
      • SlimDrivers-setup.exe (PID: 2152)
    • Checks supported languages

      • SlimDrivers-setup.exe (PID: 2636)
      • SlimDrivers-setup.exe (PID: 2152)
    • Reads the software policy settings

      • SlimDrivers-setup.exe (PID: 2636)
      • SlimDrivers-setup.exe (PID: 2152)
    • Reads the computer name

      • SlimDrivers-setup.exe (PID: 2152)
      • SlimDrivers-setup.exe (PID: 2636)
    • Reads the machine GUID from the registry

      • SlimDrivers-setup.exe (PID: 2152)
      • SlimDrivers-setup.exe (PID: 2636)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2016:02:19 11:56:40
ZipCRC: 0x62df21f5
ZipCompressedSize: 436690
ZipUncompressedSize: 981592
ZipFileName: SlimDrivers-setup.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe slimdrivers-setup.exe no specs slimdrivers-setup.exe slimdrivers-setup.exe no specs slimdrivers-setup.exe

Process information

PID
CMD
Path
Indicators
Parent process
2152"C:\Users\admin\AppData\Local\Temp\SlimDrivers-setup\SlimDrivers-setup.exe" C:\Users\admin\AppData\Local\Temp\SlimDrivers-setup\SlimDrivers-setup.exe
explorer.exe
User:
admin
Company:
SlimWare Utilities, Inc.
Integrity Level:
HIGH
Description:
SlimDrivers Setup Wizard
Exit code:
0
Version:
2.0.0
Modules
Images
c:\users\admin\appdata\local\temp\slimdrivers-setup\slimdrivers-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2636"C:\Users\admin\AppData\Local\Temp\SlimDrivers-setup\SlimDrivers-setup.exe" C:\Users\admin\AppData\Local\Temp\SlimDrivers-setup\SlimDrivers-setup.exe
explorer.exe
User:
admin
Company:
SlimWare Utilities, Inc.
Integrity Level:
HIGH
Description:
SlimDrivers Setup Wizard
Exit code:
0
Version:
2.0.0
Modules
Images
c:\users\admin\appdata\local\temp\slimdrivers-setup\slimdrivers-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2756"C:\Users\admin\AppData\Local\Temp\SlimDrivers-setup\SlimDrivers-setup.exe" C:\Users\admin\AppData\Local\Temp\SlimDrivers-setup\SlimDrivers-setup.exeexplorer.exe
User:
admin
Company:
SlimWare Utilities, Inc.
Integrity Level:
MEDIUM
Description:
SlimDrivers Setup Wizard
Exit code:
3221226540
Version:
2.0.0
Modules
Images
c:\users\admin\appdata\local\temp\slimdrivers-setup\slimdrivers-setup.exe
c:\windows\system32\ntdll.dll
3708"C:\Users\admin\AppData\Local\Temp\SlimDrivers-setup\SlimDrivers-setup.exe" C:\Users\admin\AppData\Local\Temp\SlimDrivers-setup\SlimDrivers-setup.exeexplorer.exe
User:
admin
Company:
SlimWare Utilities, Inc.
Integrity Level:
MEDIUM
Description:
SlimDrivers Setup Wizard
Exit code:
3221226540
Version:
2.0.0
Modules
Images
c:\users\admin\appdata\local\temp\slimdrivers-setup\slimdrivers-setup.exe
c:\windows\system32\ntdll.dll
3864"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\SlimDrivers-setup.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
10 715
Read events
10 593
Write events
103
Delete events
19

Modification events

(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3864) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\SlimDrivers-setup.zip
(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
1
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3864WinRAR.exeC:\Users\admin\AppData\Local\Temp\SlimDrivers-setup\SlimDrivers-setup.exeexecutable
MD5:713570610228C38DAE67A649632CAE15
SHA256:2AAD06624E9B698EC0DC0276B433C606A4858D6585028CD658AE7C697358FFEC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
12
DNS requests
4
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2636
SlimDrivers-setup.exe
POST
301
50.19.130.29:80
http://www.slimwareutilities.com/installer/init_v2.php
unknown
html
134 b
unknown
2636
SlimDrivers-setup.exe
GET
404
34.199.228.134:80
http://driverupdate.net/downloads/SlimDrivers-setup.msi.bz2
unknown
html
153 b
unknown
2152
SlimDrivers-setup.exe
POST
301
50.19.130.29:80
http://www.slimwareutilities.com/installer/init_v2.php
unknown
html
134 b
unknown
2152
SlimDrivers-setup.exe
GET
404
34.199.228.134:80
http://driverupdate.net/downloads/SlimDrivers-setup.msi.bz2
unknown
html
153 b
unknown
2152
SlimDrivers-setup.exe
POST
405
52.217.163.37:80
http://stats.slimwareutilities.com/api/flow/action
unknown
html
422 b
unknown
2636
SlimDrivers-setup.exe
POST
405
52.217.163.37:80
http://stats.slimwareutilities.com/api/flow/action
unknown
html
422 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2636
SlimDrivers-setup.exe
50.19.130.29:80
www.slimwareutilities.com
AMAZON-AES
US
unknown
2636
SlimDrivers-setup.exe
34.199.228.134:80
driverupdate.net
AMAZON-AES
US
unknown
2636
SlimDrivers-setup.exe
50.19.130.29:443
www.slimwareutilities.com
AMAZON-AES
US
unknown
2636
SlimDrivers-setup.exe
52.217.163.37:80
stats.slimwareutilities.com
AMAZON-02
US
unknown
2152
SlimDrivers-setup.exe
50.19.130.29:80
www.slimwareutilities.com
AMAZON-AES
US
unknown
2152
SlimDrivers-setup.exe
34.199.228.134:80
driverupdate.net
AMAZON-AES
US
unknown
2152
SlimDrivers-setup.exe
50.19.130.29:443
www.slimwareutilities.com
AMAZON-AES
US
unknown

DNS requests

Domain
IP
Reputation
trk.slimwareutilities.com
unknown
www.slimwareutilities.com
  • 50.19.130.29
unknown
driverupdate.net
  • 34.199.228.134
unknown
stats.slimwareutilities.com
  • 52.217.163.37
unknown

Threats

Found threats are available for the paid subscriptions
4 ETPRO signatures available at the full report
No debug info