top title background image
flash

http://slimware.com/download/driverupdate?upl=c1:eJx1jU1vgkAURX-N7DAziiKLWYxCExJbNDRaV-QBT5wGZsh8lLa_vqix6aa7e0_uO8-1hbGuFDVb4TyAaAE-PVfUD2hE_DKikR8gQhmF8xCW1HNtUalSg6xZfpzdKnQ9iEayz94SGlyRufkSnkK6V-Xm8pzOsux9eRJvYZMeLH-JNhfyzfckTXhy4jnnSbNdqV1crIfE67WqXWXvfoM6x6ZDac1ksc6FxckiHlOsOhByzMy0ohtA47RS3f_7HTTXxCazp1oNslVQ-2CMMPZKtPhA7foaLHqlVsNoef3qkaXJox5QG6Eko3RKHmwLsnGjl6H0nfH6FuxZ6S7L2VHI8ctf9HtPpuQHQNp-6Q

Status: finished
Submission Time: 2021-01-12 21:01:18 +01:00
Malicious
Evader

Comments

Tags

Details

  • Analysis ID:
    338796
  • API (Web) ID:
    579501
  • Analysis Started:
    2021-01-12 21:04:20 +01:00
  • Analysis Finished:
    2021-01-12 21:16:36 +01:00
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 88
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 8/36
malicious
Score: 16/29
malicious
malicious

IPs

IP Country Detection
143.204.15.12
United States
143.204.11.124
United States
54.146.150.241
United States
Click to see the 8 hidden entries
143.204.15.13
United States
54.152.189.42
United States
34.236.109.30
United States
34.236.116.104
United States
3.222.62.255
United States
34.206.211.11
United States
54.205.104.89
United States
34.230.114.166
United States

Domains

Name IP Detection
cdn.slimcleaner.com
143.204.15.12
cdn.ywxi.net
0.0.0.0
bam-cell.nr-data.net
0.0.0.0
Click to see the 35 hidden entries
insight-566961044.eu-west-1.elb.amazonaws.com
18.203.124.74
slimware.com
34.236.109.30
www.google.co.uk
108.177.127.94
dtx9pzf7ji0d9.cloudfront.net
143.204.11.41
cdn.cookielaw.org
104.16.148.64
geolocation.onetrust.com
104.20.185.68
edge.gycpi.b.yahoodns.net
87.248.118.22
sp.analytics.yahoo.com
0.0.0.0
stats.g.doubleclick.net
0.0.0.0
insight.adsrvr.org
0.0.0.0
px.steelhousemedia.com
0.0.0.0
www.facebook.com
0.0.0.0
ad.doubleclick.net
0.0.0.0
js-agent.newrelic.com
0.0.0.0
s.yimg.com
0.0.0.0
googleads.g.doubleclick.net
0.0.0.0
cdn-3.convertexperiments.com
0.0.0.0
s3-us-west-2.amazonaws.com
52.218.252.16
apps-api.slimwareutilities.com
34.230.114.166
spdc-global.pbp.gysm.yahoodns.net
212.82.100.181
pagead.l.doubleclick.net
108.177.126.154
dx.steelhousemedia.com
44.236.162.197
stc.slimwareutilities.com
54.152.189.42
trk.slimwareutilities.com
34.236.116.104
download.driverupdate.net
143.204.11.124
messaging.slimware.com
34.206.211.11
dart.l.doubleclick.net
108.177.126.148
pxtm.steelhousemedia.com
52.10.121.135
star-mini.c10r.facebook.com
31.13.92.36
pagead46.l.doubleclick.net
108.177.127.157
stats.l.doubleclick.net
108.177.126.156
cdn.slimwareutilities.com
99.86.159.72
ww.steelhousemedia.com
44.238.216.23
driverrpc.driverupdate.net
54.146.150.241
www.trustedsite.com
44.239.103.44

URLs

Name Detection
http://cdn.slimcleaner.com/downloads/silentdownloader/SlimCleanerPlus-Downloader.exe.bz2
http://slimcleaner.com/init_dl.php?secondOfferOrigin=%1
https://corp.roblox.com/parents/
Click to see the 97 hidden entries
https://dev.virtualearth.net/REST/v1/JsonFilter/VenueMaps/data/
http://www.slimware.com?lang=%1
http://crl.rootg2.amazontrust.com/rootg2.crl0
http://www.hulu.com/privacy
http://crl.godaddy.com/gdroot-g2.crl0F
https://slimware.com/register/driverupdate/trial
https://apps-api.slimwareutilities.com/rpc/version-infoD
https://ecn.dev.virtualearth.net/mapcontrol/mapconfiguration.ashx?name=native&v=
http://www.symauth.com/cps0(
http://terrainformatica.comD
http://crl.godaddy.com/gdig2s5-0.crl0S
https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gd?pv=1&r=
https://driverrpc.driverupdate.net/SlimWare
https://certs.godaddy.com/repository/0
https://apps-api.slimwareutilities.com/rpc/version-info
http://ocsp.rootca1.amazontrust.com0:
http://crl.rootca1.amazontrust.com/rootca1.crl0
https://www.research.net/s/NB8NTKK
https://slimware.com/register/driverupdate?
https://slimware.com/purchase/driverupdate%sIFSID=%s%sinstaller_data=%sInstallerOverlay%sinstpl=%sic
http://trk.slimwareutilities.com/ulc.php?ev=%%s&upl=%s&machineId=%s&%s&installer=%s&installerVersion
http://certs.godaddy.com/repository/1301
https://www.roblox.com/develop
https://driverrpc.driverupdate.net/
http://www.slimwareutilities.com/slimdrivers_after_download_avg.php_
http://crt.rootg2.amazontrust.com/rootg2.cer0=
https://apps-api.slimwareutilities.com/x
https://t0.ssl.ak.dynamic.tiles.virtualearth.net/comp/gen.ashx
https://dev.virtualearth.net/REST/v1/Routes/Driving
http://trk.slimwareutilities.com/ulc.php?ev=InstallerFinished&upl=YToxMTp7czo5OiJ1bF9zdHViaWQiO3M6MzY6IjhlMzRhOTVhLTFmYzEtNDE5MC1iOTE5LTRlZWFiOTczN2E2MSI7czoxMDoidWxfY29icmFuZCI7czozOiJTVzIiO3M6MTE6InVsX2NhbXBhaWduIjtzOjY6InhwdDAxNCI7czo4OiJ1bF9zdWJpZCI7czo1NToiRUFJYUlRb2JDaE1JMk9PajZZaVg3Z0lWdEFOOUNoMHpBUTBJRUFFWUFTQUFFZ0w4b1BEX0J3RSI7czo3OiJwcm9kdWN0IjtzOjM6IlNXMiI7czoxMjoidXNlclNlZ21lbnRzIjtPOjg6InN0ZENsYXNzIjoxOntzOjQ6IlNpdGUiO086ODoic3RkQ2xhc3MiOjI6e3M6NjoiRG9tYWluIjtzOjEyOiJzbGltd2FyZS5jb20iO3M6NDoiUGFnZSI7czoyMjoiL2Rvd25sb2FkL2RyaXZlcnVwZGF0ZSI7fX1zOjExOiJicm93c2VyVHlwZSI7czoyOiJJRSI7czoxNDoiYnJvd3NlclZlcnNpb24iO3M6NDoiMTEuMCI7czoxNToiYnJvd3Nlckxhbmd1YWdlIjtzOjU6ImVuLXVzIjtzOjEwOiJwbGF0Zm9ybU9TIjtzOjc6IldpbmRvd3MiO3M6MTc6InBsYXRmb3JtT1NWZXJzaW9uIjtzOjQ6IjEwLjAiO30%3D&machineId=C77C19AD-C027-494E-AA46-160806C3F78F&platformOS=Windows&platformOSVersion=10.0&installer=LI0&installerVersion=2.24.7.44&product=SW2&installId=1F1F7906-7931-4B4E-817E-DD837E8F1CE2&productVersion=5.8.16.0
https://dynamic.api.tiles.ditu.live.com/odvs/gd?pv=1&r=
https://slimware.com/privacy
https://slimware.secure.force.com/apex/NewPrechat?endpoint=https%3A%2F%2Fslimware.secure.force.com%2
http://terrainformatica.com/forums/topic.php?id=1772
https://dynamic.api.tiles.ditu.live.com/odvs/gdv?pv=1&r=
https://slimware.com/register/driverupdate?newgui=1~3
https://dynamic.t
http://trk.slimwareutilities.com/ulc.php?ev=TrackEvent&platformOSVersion=10.0&installId=1F1F7906-7931-4B4E-817E-DD837E8F1CE2&browser=ie&productVersion=5.8.16&product=SW2&sessionid=666CFED6-3AAB-4487-AFB8-6508051A9C3E&description=InstallerScan-DU&upl=YToxMTp7czo5OiJ1bF9zdHViaWQiO3M6MzY6IjhlMzRhOTVhLTFmYzEtNDE5MC1iOTE5LTRlZWFiOTczN2E2MSI7czoxMDoidWxfY29icmFuZCI7czozOiJTVzIiO3M6MTE6InVsX2NhbXBhaWduIjtzOjY6InhwdDAxNCI7czo4OiJ1bF9zdWJpZCI7czo1NToiRUFJYUlRb2JDaE1JMk9PajZZaVg3Z0lWdEFOOUNoMHpBUTBJRUFFWUFTQUFFZ0w4b1BEX0J3RSI7czo3OiJwcm9kdWN0IjtzOjM6IlNXMiI7czoxMjoidXNlclNlZ21lbnRzIjtPOjg6InN0ZENsYXNzIjoxOntzOjQ6IlNpdGUiO086ODoic3RkQ2xhc3MiOjI6e3M6NjoiRG9tYWluIjtzOjEyOiJzbGltd2FyZS5jb20iO3M6NDoiUGFnZSI7czoyMjoiL2Rvd25sb2FkL2RyaXZlcnVwZGF0ZSI7fX1zOjExOiJicm93c2VyVHlwZSI7czoyOiJJRSI7czoxNDoiYnJvd3NlclZlcnNpb24iO3M6NDoiMTEuMCI7czoxNToiYnJvd3Nlckxhbmd1YWdlIjtzOjU6ImVuLXVzIjtzOjEwOiJwbGF0Zm9ybU9TIjtzOjc6IldpbmRvd3MiO3M6MTc6InBsYXRmb3JtT1NWZXJzaW9uIjtzOjQ6IjEwLjAiO30%3D&machineId=C77C19AD-C027-494E-AA46-160806C3F78F&result=driverRPCRequestCompleted&platformOS=Windows
https://slimware.com/in-app-shop/driverupdateF
http://o.ss2.us/0
https://slimware.com/slimcleaner
https://dev.virtualearth.net/REST/v1/Routes/Transit
http://cdn.slimcleaner.com/downloads/silentdownloader/SlimCleanerPlus-Downloader.exe.bz2PageOrderCWe
http://www.youtube.com/driverhub
http://trk.slimwareutilities.com/ulc.php?ev=TrackEvent&upl=YToxMTp7czo5OiJ1bF9zdHViaWQiO3M6MzY6IjhlMzRhOTVhLTFmYzEtNDE5MC1iOTE5LTRlZWFiOTczN2E2MSI7czoxMDoidWxfY29icmFuZCI7czozOiJTVzIiO3M6MTE6InVsX2NhbXBhaWduIjtzOjY6InhwdDAxNCI7czo4OiJ1bF9zdWJpZCI7czo1NToiRUFJYUlRb2JDaE1JMk9PajZZaVg3Z0lWdEFOOUNoMHpBUTBJRUFFWUFTQUFFZ0w4b1BEX0J3RSI7czo3OiJwcm9kdWN0IjtzOjM6IlNXMiI7czoxMjoidXNlclNlZ21lbnRzIjtPOjg6InN0ZENsYXNzIjoxOntzOjQ6IlNpdGUiO086ODoic3RkQ2xhc3MiOjI6e3M6NjoiRG9tYWluIjtzOjEyOiJzbGltd2FyZS5jb20iO3M6NDoiUGFnZSI7czoyMjoiL2Rvd25sb2FkL2RyaXZlcnVwZGF0ZSI7fX1zOjExOiJicm93c2VyVHlwZSI7czoyOiJJRSI7czoxNDoiYnJvd3NlclZlcnNpb24iO3M6NDoiMTEuMCI7czoxNToiYnJvd3Nlckxhbmd1YWdlIjtzOjU6ImVuLXVzIjtzOjEwOiJwbGF0Zm9ybU9TIjtzOjc6IldpbmRvd3MiO3M6MTc6InBsYXRmb3JtT1NWZXJzaW9uIjtzOjQ6IjEwLjAiO30%3D&machineId=C77C19AD-C027-494E-AA46-160806C3F78F&platformOS=Windows&platformOSVersion=10.0&installer=LI0&installerVersion=2.24.7.44&product=SW2&installId=1F1F7906-7931-4B4E-817E-DD837E8F1CE2&description=InstallerScan-LI&result=installScanCompleted
http://www.symauth.com/rpa00
http://support.slimware.com/SlimwareContactUs?pType=dUpdate&sctype=Driver_Update&pName=Driver%20Upda
http://sftwr.s3.amazonaws.com/Windows
http://appa.slimwareutilities.com/rest/authenticate_user_app
http://cdn.slimcleaner.com/downloads/4.3.0.82/x64/SlimCleaner-setup.exe
https://slimware.com/eula
http://crl.nmsu.edu/~mleisher/ucdata.html)
http://www.hulu.com/terms
http://fixcleaner.com/scplus_upgrade.php
https://dev.virtualearth.net/REST/v1/Transit/Schedules/
https://twitter.com/slimwarehq
http://ocsp.rootg2.amazontrust.com08
http://www.slimwareutilities.com/slimdrivers_after_download.php
https://dev.ditu.live.com/REST/v1/Imagery/Copyright/
https://driverrpc.driverupdate.net/updates/Vr
http://trk.slimwareutilities.com/ulc.php?ev=Startup&platformOSVersion=10.0&installId=1F1F7906-7931-4B4E-817E-DD837E8F1CE2&browser=ie&productVersion=5.8.16&product=SW2&hasUI=no&upl=YToxMTp7czo5OiJ1bF9zdHViaWQiO3M6MzY6IjhlMzRhOTVhLTFmYzEtNDE5MC1iOTE5LTRlZWFiOTczN2E2MSI7czoxMDoidWxfY29icmFuZCI7czozOiJTVzIiO3M6MTE6InVsX2NhbXBhaWduIjtzOjY6InhwdDAxNCI7czo4OiJ1bF9zdWJpZCI7czo1NToiRUFJYUlRb2JDaE1JMk9PajZZaVg3Z0lWdEFOOUNoMHpBUTBJRUFFWUFTQUFFZ0w4b1BEX0J3RSI7czo3OiJwcm9kdWN0IjtzOjM6IlNXMiI7czoxMjoidXNlclNlZ21lbnRzIjtPOjg6InN0ZENsYXNzIjoxOntzOjQ6IlNpdGUiO086ODoic3RkQ2xhc3MiOjI6e3M6NjoiRG9tYWluIjtzOjEyOiJzbGltd2FyZS5jb20iO3M6NDoiUGFnZSI7czoyMjoiL2Rvd25sb2FkL2RyaXZlcnVwZGF0ZSI7fX1zOjExOiJicm93c2VyVHlwZSI7czoyOiJJRSI7czoxNDoiYnJvd3NlclZlcnNpb24iO3M6NDoiMTEuMCI7czoxNToiYnJvd3Nlckxhbmd1YWdlIjtzOjU6ImVuLXVzIjtzOjEwOiJwbGF0Zm9ybU9TIjtzOjc6IldpbmRvd3MiO3M6MTc6InBsYXRmb3JtT1NWZXJzaW9uIjtzOjQ6IjEwLjAiO30%3D&machineId=C77C19AD-C027-494E-AA46-160806C3F78F&isRegistered=no&platformOS=Windows&eventSource=SYSTEM
https://slimware.com/premium-support?chat=1x
http://www.slimcleaner.com/services/activate.php?product=%s&email=%s
https://slimware.com/driverupdate/renewal?email=%1
https://slimware.com/members
https://dev.virtualearth.net/REST/v1/Routes/Walking
http://trk.slimwareutilities.com/ulc.php?ev=InstallerFinished&upl=YToxMTp7czo5OiJ1bF9zdHViaWQiO3M6Mz
http://apps-api.slimwareutilities.com/install/scp/10.0/x64/SlimCleaner-setup.exe?machineId=C77C19AD-
https://t0.tiles.ditu.live.com/tiles/gen
https://corp.roblox.com/contact/
http://appa.slimwareutilities.com/rest/facebook_post_sink--%s
https://dev.ditu.live.com/REST/v1/Routes/
https://www.slimwareutilities.com/fb_app_auth.phpb9
https://www.research.net/s/NNY6GHZ
http://trk.slimwareutilities.com/ulc.php?ev=InstallerAccepted&upl=YToxMTp7czo5OiJ1bF9zdHViaWQiO3M6MzY6IjhlMzRhOTVhLTFmYzEtNDE5MC1iOTE5LTRlZWFiOTczN2E2MSI7czoxMDoidWxfY29icmFuZCI7czozOiJTVzIiO3M6MTE6InVsX2NhbXBhaWduIjtzOjY6InhwdDAxNCI7czo4OiJ1bF9zdWJpZCI7czo1NToiRUFJYUlRb2JDaE1JMk9PajZZaVg3Z0lWdEFOOUNoMHpBUTBJRUFFWUFTQUFFZ0w4b1BEX0J3RSI7czo3OiJwcm9kdWN0IjtzOjM6IlNXMiI7czoxMjoidXNlclNlZ21lbnRzIjtPOjg6InN0ZENsYXNzIjoxOntzOjQ6IlNpdGUiO086ODoic3RkQ2xhc3MiOjI6e3M6NjoiRG9tYWluIjtzOjEyOiJzbGltd2FyZS5jb20iO3M6NDoiUGFnZSI7czoyMjoiL2Rvd25sb2FkL2RyaXZlcnVwZGF0ZSI7fX1zOjExOiJicm93c2VyVHlwZSI7czoyOiJJRSI7czoxNDoiYnJvd3NlclZlcnNpb24iO3M6NDoiMTEuMCI7czoxNToiYnJvd3Nlckxhbmd1YWdlIjtzOjU6ImVuLXVzIjtzOjEwOiJwbGF0Zm9ybU9TIjtzOjc6IldpbmRvd3MiO3M6MTc6InBsYXRmb3JtT1NWZXJzaW9uIjtzOjQ6IjEwLjAiO30%3D&machineId=C77C19AD-C027-494E-AA46-160806C3F78F&platformOS=Windows&platformOSVersion=10.0&installer=LI0&installerVersion=2.24.7.44&product=SW2
https://slimware.com/eula#driverupdate
http://trk.slimwareutilities.com/ulc.php
http://ocsp.sca1b.amazontrust.com06
https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gdv?pv=1&r=
http://www.driverhub.com/downloads/DriverHub%20User%20Manual.pdfY
https://slimware.com/purchase/driverupdate/trial?email=%1
https://www.hulu.com/do-not-sell-my-info
https://www.slimwareutilities.com/fb_app_auth.phpbTpbTX
https://apps-api.slimwareutilities.com/rpc/start-session/https://messaging.slimware.com/rpc/message-
http://crt.rootca1.amazontg
https://dev.virtualearth.net/REST/v1/Routes/
http://www.slimwareutilities.com/R
https://dev.virtualearth.net/REST/v1/Imagery/Copyright/
http://www.bingmapsportal.com
http://certificates.godaddy.com/repository/gdig2.crt0
http://www.slimwareutilities.com/request_password.phpUse
https://www.research.net/r/9CSTHQM
http://trk.slimwareutilities.com/ulc.php?ev=Error&upl=YToxMTp7czo5OiJ1bF9zdHViaWQiO3M6MzY6IjhlMzRhOT
http://crl.sca1b.amazontrust.com/sca1b.crl0
https://en.help.roblox.com/hc/en-us
http://www.driverhub.com/downloads/DriverHub%20User%20Manual.pdf
https://appexmapsappupdate.blob.core.windows.net

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0MX4YUS9\DriverUpdate-setup-8eae2188-2fbe-4ed8-b5e9-286b1c6b3afa.exe.h4szrim.partial
PE32 executable (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0MX4YUS9\DriverUpdate-setup-8eae2188-2fbe-4ed8-b5e9-286b1c6b3afa[1].exe
PE32 executable (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Temp\SWIF790.tmp
PE32 executable (GUI) Intel 80386, for MS Windows
#
Click to see the 2 hidden entries
C:\Users\user\AppData\Local\Temp\scp25A1.tmp
bzip2 compressed data, block size = 900k
#
C:\Users\user\AppData\Local\Temp\scp25A1.tmp.exe
PE32 executable (GUI) Intel 80386, for MS Windows
#