| URL: | https://pivotanimator.net/ |
| Full analysis: | https://app.any.run/tasks/f64d2c6d-f838-4d01-abf1-ff211bf7f026 |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | April 27, 2021, 01:52:30 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | FB759B0ACD84A6CF32E6E23A50846A67 |
| SHA1: | 4CD9435C99B1C00DCE672FF4275C38C7AF1D7D76 |
| SHA256: | CDEE5620CD3ABB05766CBA2E0E11CAF37A9EF205B43F71CF69EC505CD4324AE5 |
| SSDEEP: | 3:N8IGlKX:2IqKX |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 396 | "C:\Program Files\Secure Browser\Secure Browser\Application\SecureBrowser.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --field-trial-handle=1000,11780271180205524636,9101158143489019941,131072 --lang=en-US --service-sandbox-type=utility --enable-audio-service-sandbox --mojo-platform-channel-handle=2356 /prefetch:8 | C:\Program Files\Secure Browser\Secure Browser\Application\SecureBrowser.exe | — | SecureBrowser.exe | |||||||||||
User: admin Company: The Secure Browser Authors Integrity Level: LOW Description: Secure Browser Exit code: 0 Version: 86.0.4194.10 Modules
| |||||||||||||||
| 524 | "C:\Program Files\Secure Browser\Secure Browser\Application\SecureBrowser.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Secure Browser\Secure Browser\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Secure Browser\Secure Browser\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Secure Browser\Secure Browser\User Data" --annotation=plat=Win32 "--annotation=prod=Secure Browser" --annotation=ver=86.0.4194.10-devel --initial-client-data=0xc0,0xc4,0xc8,0x94,0xcc,0x68ae29f0,0x68ae2a00,0x68ae2a0c | C:\Program Files\Secure Browser\Secure Browser\Application\SecureBrowser.exe | — | SecureBrowser.exe | |||||||||||
User: admin Company: The Secure Browser Authors Integrity Level: MEDIUM Description: Secure Browser Exit code: 0 Version: 86.0.4194.10 Modules
| |||||||||||||||
| 668 | "C:\Program Files\Pivot Stickfigure Animator\pivot.exe" | C:\Program Files\Pivot Stickfigure Animator\pivot.exe | — | pivotAnimator_v2-2.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 700 | "C:\Program Files\Secure Browser\Secure Browser\Application\SecureBrowser.exe" --type=gpu-process --field-trial-handle=1000,11780271180205524636,9101158143489019941,131072 --gpu-preferences=MAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAQAAAAAAAAAAAAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAA= --use-gl=swiftshader-webgl --mojo-platform-channel-handle=2488 /prefetch:2 | C:\Program Files\Secure Browser\Secure Browser\Application\SecureBrowser.exe | — | SecureBrowser.exe | |||||||||||
User: admin Company: The Secure Browser Authors Integrity Level: LOW Description: Secure Browser Exit code: 0 Version: 86.0.4194.10 Modules
| |||||||||||||||
| 828 | "C:\Program Files\Secure Browser\Update\Secure BrowserUpdate.exe" /handoff "bundlename=SecureBrowser&appguid={EF691ED4-68F6-4754-B1C0-C337E73D042C}&appname=SecureBrowser&needsadmin=True&lang=en&installdataindex=prefs&client=user_id%3D50bec48158c2945e87535b24eacb71c38f41370d%26sup%3D6f32%26tg%3D00" /installsource otherinstallcmd /sessionid "{136B6201-01E4-422E-9B62-48B13087D2DD}" /silent | C:\Program Files\Secure Browser\Update\Secure BrowserUpdate.exe | — | Secure BrowserUpdate.exe | |||||||||||
User: admin Company: Secure Browser. Integrity Level: HIGH Description: Secure Browser Update Exit code: 0 Version: 1.3.105.7 Modules
| |||||||||||||||
| 996 | "C:\Program Files\Secure Browser\Secure Browser\Application\SecureBrowser.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --field-trial-handle=1000,11780271180205524636,9101158143489019941,131072 --lang=en-US --service-sandbox-type=utility --enable-audio-service-sandbox --mojo-platform-channel-handle=2812 /prefetch:8 | C:\Program Files\Secure Browser\Secure Browser\Application\SecureBrowser.exe | — | SecureBrowser.exe | |||||||||||
User: admin Company: The Secure Browser Authors Integrity Level: LOW Description: Secure Browser Exit code: 0 Version: 86.0.4194.10 Modules
| |||||||||||||||
| 1036 | "C:\Program Files\Secure Browser\Secure Browser\Application\SecureBrowser.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --field-trial-handle=1000,11780271180205524636,9101158143489019941,131072 --lang=en-US --service-sandbox-type=utility --enable-audio-service-sandbox --mojo-platform-channel-handle=3508 /prefetch:8 | C:\Program Files\Secure Browser\Secure Browser\Application\SecureBrowser.exe | — | SecureBrowser.exe | |||||||||||
User: admin Company: The Secure Browser Authors Integrity Level: LOW Description: Secure Browser Exit code: 0 Version: 86.0.4194.10 Modules
| |||||||||||||||
| 1220 | "C:\Program Files\Secure Browser\Update\Secure BrowserUpdate.exe" /regsvc | C:\Program Files\Secure Browser\Update\Secure BrowserUpdate.exe | — | Secure BrowserUpdate.exe | |||||||||||
User: admin Company: Secure Browser. Integrity Level: HIGH Description: Secure Browser Update Exit code: 0 Version: 1.3.105.7 Modules
| |||||||||||||||
| 1336 | "C:\Program Files\Secure Browser\Secure Browser\Application\SecureBrowser.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --field-trial-handle=1000,11780271180205524636,9101158143489019941,131072 --lang=en-US --service-sandbox-type=utility --enable-audio-service-sandbox --mojo-platform-channel-handle=2684 /prefetch:8 | C:\Program Files\Secure Browser\Secure Browser\Application\SecureBrowser.exe | — | SecureBrowser.exe | |||||||||||
User: admin Company: The Secure Browser Authors Integrity Level: LOW Description: Secure Browser Exit code: 0 Version: 86.0.4194.10 Modules
| |||||||||||||||
| 1344 | "C:\Users\admin\AppData\Local\Temp\Pivot_Animator_files\Secure BrowserUpdateSetup.exe" /silent /install bundlename=SecureBrowser&appguid={EF691ED4-68F6-4754-B1C0-C337E73D042C}&appname=SecureBrowser&needsadmin=True&lang=en&installdataindex=prefs&client=user_id%3D50bec48158c2945e87535b24eacb71c38f41370d%26sup%3D6f32%26tg%3D00 | C:\Users\admin\AppData\Local\Temp\Pivot_Animator_files\Secure BrowserUpdateSetup.exe | svchost.exe | ||||||||||||
User: admin Company: Secure Browser. Integrity Level: HIGH Description: Secure Browser Update Setup Exit code: 0 Version: 1.3.105.7 Modules
| |||||||||||||||
| (PID) Process: | (2132) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateLowDateTime |
Value: 416843872 | |||
| (PID) Process: | (2132) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 30882568 | |||
| (PID) Process: | (2132) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (2132) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (2132) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (2132) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (2132) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (2132) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 46000000A6000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2132) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2132) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2456 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\Low\CabC3E.tmp | — | |
MD5:— | SHA256:— | |||
| 2456 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\Low\TarC4F.tmp | — | |
MD5:— | SHA256:— | |||
| 2456 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\644B8874112055B5E195ECB0E8F243A4 | der | |
MD5:— | SHA256:— | |||
| 2456 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\644B8874112055B5E195ECB0E8F243A4 | binary | |
MD5:— | SHA256:— | |||
| 2456 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\DD69E8BA22BFF7F5CC55FFFB984866CF | binary | |
MD5:— | SHA256:— | |||
| 2456 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\7MMTH91E.htm | html | |
MD5:— | SHA256:— | |||
| 2456 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CFE86DBBE02D859DC92F1E17E0574EE8_46766FC45507C0B9E264E4C18BC7288B | der | |
MD5:— | SHA256:— | |||
| 2456 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\DD69E8BA22BFF7F5CC55FFFB984866CF | der | |
MD5:— | SHA256:— | |||
| 2456 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_28DEA62A0AE77228DD387E155AD0BA27 | der | |
MD5:— | SHA256:— | |||
| 2456 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CC197601BE0898B7B0FCC91FA15D8A69_B121B36398E3075386664ABDAC5E9443 | der | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2456 | iexplore.exe | GET | 200 | 172.217.16.131:80 | http://ocsp.pki.goog/gsr2/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBTgXIsxbvr2lBkPpoIEVRE6gHlCnAQUm%2BIHV2ccHsBqBt5ZtJot39wZhi4CDQHjtJqhjYqpgSVpULg%3D | US | der | 468 b | whitelisted |
2456 | iexplore.exe | GET | 200 | 23.55.163.73:80 | http://crl.identrust.com/DSTROOTCAX3CRL.crl | US | der | 1.16 Kb | whitelisted |
2456 | iexplore.exe | GET | 200 | 172.217.16.131:80 | http://ocsp.pki.goog/gsr2/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBTgXIsxbvr2lBkPpoIEVRE6gHlCnAQUm%2BIHV2ccHsBqBt5ZtJot39wZhi4CDQHjtJqhjYqpgSVpULg%3D | US | der | 468 b | whitelisted |
2456 | iexplore.exe | GET | 200 | 23.51.123.27:80 | http://s.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEGMYDTj7gJd4qdA1oxYY%2BEA%3D | NL | der | 1.71 Kb | shared |
2456 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAyO4MkNaokViAQGHuJB%2Ba8%3D | US | der | 471 b | whitelisted |
2924 | cookie_mmm_irs_ppi_005_888_d.exe | POST | 204 | 5.62.40.214:80 | http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi | DE | — | — | whitelisted |
2456 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D | US | der | 1.47 Kb | whitelisted |
2132 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | US | der | 471 b | whitelisted |
2132 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | US | der | 471 b | whitelisted |
2132 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8Ull8gIGmZT9XHrHiJQeI%3D | US | der | 1.47 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2456 | iexplore.exe | 23.55.163.73:80 | crl.identrust.com | Akamai International B.V. | US | unknown |
2456 | iexplore.exe | 172.217.16.131:80 | ocsp.pki.goog | Google Inc. | US | whitelisted |
2132 | iexplore.exe | 13.107.21.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
2132 | iexplore.exe | 66.96.149.23:443 | pivotanimator.net | The Endurance International Group, Inc. | US | suspicious |
2456 | iexplore.exe | 13.224.194.41:443 | d9xefsrx7pfhx.cloudfront.net | — | US | suspicious |
2456 | iexplore.exe | 23.51.123.27:80 | s.symcd.com | Akamai Technologies, Inc. | NL | whitelisted |
1408 | pivotAnimator_v2-2.exe | 65.9.69.209:443 | d11yiezpmoyd9g.cloudfront.net | AT&T Services, Inc. | US | unknown |
2132 | iexplore.exe | 152.199.19.161:443 | iecvlist.microsoft.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
2132 | iexplore.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
2924 | cookie_mmm_irs_ppi_005_888_d.exe | 2.16.107.50:443 | iavs9x.u.avast.com | Akamai International B.V. | — | suspicious |
Domain | IP | Reputation |
|---|---|---|
pivotanimator.net |
| whitelisted |
crl.identrust.com |
| whitelisted |
r3.o.lencr.org |
| shared |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
maxcdn.bootstrapcdn.com |
| whitelisted |
ajax.googleapis.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
ocsp.pki.goog |
| whitelisted |
d9xefsrx7pfhx.cloudfront.net |
| suspicious |
PID | Process | Class | Message |
|---|---|---|---|
2924 | cookie_mmm_irs_ppi_005_888_d.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |