URL:

https://pivotanimator.net/

Full analysis: https://app.any.run/tasks/f64d2c6d-f838-4d01-abf1-ff211bf7f026
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: April 27, 2021, 01:52:30
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
Indicators:
MD5:

FB759B0ACD84A6CF32E6E23A50846A67

SHA1:

4CD9435C99B1C00DCE672FF4275C38C7AF1D7D76

SHA256:

CDEE5620CD3ABB05766CBA2E0E11CAF37A9EF205B43F71CF69EC505CD4324AE5

SSDEEP:

3:N8IGlKX:2IqKX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • pivotAnimator_v2-2.exe (PID: 3932)
      • pivotAnimator_v2-2.exe (PID: 1408)
      • pivot_v2-2.exe (PID: 3924)
      • Secure BrowserUpdateSetup.exe (PID: 1344)
      • cookie_mmm_irs_ppi_005_888_d.exe (PID: 2924)
      • Secure BrowserUpdate.exe (PID: 2300)
      • Secure BrowserUpdate.exe (PID: 1220)
      • pivot.exe (PID: 668)
      • Secure BrowserUpdate.exe (PID: 828)
      • Secure BrowserUpdate.exe (PID: 1780)
      • Secure BrowserUpdate.exe (PID: 3752)
      • avast_free_antivirus_setup_online.exe (PID: 2568)
      • Secure BrowserUpdate.exe (PID: 3000)
      • instup.exe (PID: 2364)
      • setup.exe (PID: 3944)
      • setup.exe (PID: 2628)
      • sbr.exe (PID: 1584)
      • instup.exe (PID: 1648)
      • SecureBrowser.exe (PID: 2316)
      • SecureBrowser.exe (PID: 2468)
      • SecureBrowser.exe (PID: 3848)
      • SecureBrowser.exe (PID: 3232)
      • SecureBrowser.exe (PID: 1504)
      • SecureBrowser.exe (PID: 2624)
      • SecureBrowser.exe (PID: 3048)
      • SecureBrowser.exe (PID: 1880)
      • SecureBrowser.exe (PID: 2184)
      • SecureBrowser.exe (PID: 3692)
      • SecureBrowser.exe (PID: 3764)
      • SecureBrowser.exe (PID: 700)
      • SecureBrowser.exe (PID: 3644)
      • SecureBrowser.exe (PID: 524)
      • SecureBrowser.exe (PID: 2888)
      • chrmstp.exe (PID: 3336)
      • chrmstp.exe (PID: 3828)
      • SecureBrowser.exe (PID: 1800)
      • SecureBrowser.exe (PID: 1872)
      • SecureBrowser.exe (PID: 2512)
      • SecureBrowser.exe (PID: 3840)
      • SecureBrowser.exe (PID: 3996)
      • SecureBrowser.exe (PID: 3240)
      • SecureBrowser.exe (PID: 3036)
      • SecureBrowser.exe (PID: 3444)
      • SecureBrowser.exe (PID: 3920)
      • SecureBrowser.exe (PID: 3140)
      • SecureBrowser.exe (PID: 2660)
      • SecureBrowser.exe (PID: 1948)
      • SecureBrowser.exe (PID: 1496)
      • SecureBrowser.exe (PID: 1956)
      • SecureBrowser.exe (PID: 3292)
      • SecureBrowser.exe (PID: 2996)
      • SecureBrowser.exe (PID: 3632)
      • SecureBrowser.exe (PID: 396)
      • SecureBrowser.exe (PID: 3812)
      • SecureBrowser.exe (PID: 2644)
      • SecureBrowser.exe (PID: 1336)
      • SecureBrowser.exe (PID: 3520)
      • SecureBrowser.exe (PID: 996)
      • SecureBrowser.exe (PID: 1036)
      • SecureBrowser.exe (PID: 2980)
      • SecureBrowser.exe (PID: 3388)
      • SecureBrowser.exe (PID: 2092)
      • SecureBrowser.exe (PID: 1556)
      • SecureBrowser.exe (PID: 3816)
      • SecureBrowser.exe (PID: 3840)
      • SecureBrowser.exe (PID: 1824)
      • SecureBrowser.exe (PID: 2900)
      • Secure BrowserUpdate.exe (PID: 3128)
      • SecureBrowser.exe (PID: 2640)
    • Changes settings of System certificates

      • pivotAnimator_v2-2.exe (PID: 1408)
      • cookie_mmm_irs_ppi_005_888_d.exe (PID: 2924)
      • Secure BrowserUpdate.exe (PID: 3000)
      • instup.exe (PID: 2364)
    • Drops executable file immediately after starts

      • pivot_v2-2.exe (PID: 3924)
      • Secure BrowserUpdateSetup.exe (PID: 1344)
      • pivot_v2-2.tmp (PID: 1804)
      • mini_installer_86.0.4194.10.exe (PID: 2428)
    • Loads dropped or rewritten executable

      • Secure BrowserUpdate.exe (PID: 2300)
      • Secure BrowserUpdate.exe (PID: 3752)
      • Secure BrowserUpdate.exe (PID: 1220)
      • Secure BrowserUpdate.exe (PID: 1780)
      • Secure BrowserUpdate.exe (PID: 828)
      • Secure BrowserUpdate.exe (PID: 3000)
      • instup.exe (PID: 2364)
      • SecureBrowser.exe (PID: 2624)
      • SecureBrowser.exe (PID: 524)
      • SecureBrowser.exe (PID: 1880)
      • SecureBrowser.exe (PID: 1504)
      • SecureBrowser.exe (PID: 2316)
      • SecureBrowser.exe (PID: 3848)
      • SecureBrowser.exe (PID: 3048)
      • SecureBrowser.exe (PID: 3232)
      • SecureBrowser.exe (PID: 2468)
      • SecureBrowser.exe (PID: 3764)
      • SecureBrowser.exe (PID: 2184)
      • SecureBrowser.exe (PID: 3692)
      • SecureBrowser.exe (PID: 700)
      • SecureBrowser.exe (PID: 3644)
      • SecureBrowser.exe (PID: 2888)
      • SecureBrowser.exe (PID: 1800)
      • SecureBrowser.exe (PID: 1872)
      • SecureBrowser.exe (PID: 2512)
      • SecureBrowser.exe (PID: 3840)
      • SecureBrowser.exe (PID: 3996)
      • SecureBrowser.exe (PID: 3240)
      • SecureBrowser.exe (PID: 3036)
      • SecureBrowser.exe (PID: 3444)
      • SecureBrowser.exe (PID: 3920)
      • SecureBrowser.exe (PID: 3140)
      • SecureBrowser.exe (PID: 2660)
      • SecureBrowser.exe (PID: 1948)
      • SecureBrowser.exe (PID: 1956)
      • SecureBrowser.exe (PID: 1496)
      • SecureBrowser.exe (PID: 3292)
      • SecureBrowser.exe (PID: 2996)
      • SecureBrowser.exe (PID: 3632)
      • SecureBrowser.exe (PID: 1336)
      • SecureBrowser.exe (PID: 396)
      • SecureBrowser.exe (PID: 3812)
      • SecureBrowser.exe (PID: 2644)
      • SecureBrowser.exe (PID: 3520)
      • SecureBrowser.exe (PID: 996)
      • SecureBrowser.exe (PID: 3388)
      • SecureBrowser.exe (PID: 2980)
      • SecureBrowser.exe (PID: 2092)
      • SecureBrowser.exe (PID: 1556)
      • SecureBrowser.exe (PID: 3816)
      • SecureBrowser.exe (PID: 3840)
      • SecureBrowser.exe (PID: 1824)
      • SecureBrowser.exe (PID: 1036)
      • Secure BrowserUpdate.exe (PID: 3128)
      • SecureBrowser.exe (PID: 2900)
    • Loads the Task Scheduler COM API

      • Secure BrowserUpdate.exe (PID: 2300)
    • Actions looks like stealing of personal data

      • mini_installer_86.0.4194.10.exe (PID: 2428)
      • setup.exe (PID: 3944)
    • Changes the autorun value in the registry

      • instup.exe (PID: 1648)
      • setup.exe (PID: 3944)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 2456)
      • iexplore.exe (PID: 2132)
      • pivotAnimator_v2-2.exe (PID: 1408)
      • pivot_v2-2.exe (PID: 3924)
      • pivot_v2-2.tmp (PID: 1804)
      • Secure BrowserUpdateSetup.exe (PID: 1344)
      • Secure BrowserUpdate.exe (PID: 2300)
      • cookie_mmm_irs_ppi_005_888_d.exe (PID: 2924)
      • avast_free_antivirus_setup_online.exe (PID: 2568)
      • mini_installer_86.0.4194.10.exe (PID: 2428)
      • instup.exe (PID: 2364)
      • setup.exe (PID: 3944)
      • SecureBrowser.exe (PID: 1496)
    • Adds / modifies Windows certificates

      • pivotAnimator_v2-2.exe (PID: 1408)
      • cookie_mmm_irs_ppi_005_888_d.exe (PID: 2924)
      • Secure BrowserUpdate.exe (PID: 3000)
      • instup.exe (PID: 2364)
    • Drops a file with too old compile date

      • pivot_v2-2.exe (PID: 3924)
      • pivot_v2-2.tmp (PID: 1804)
      • setup.exe (PID: 3944)
    • Drops a file that was compiled in debug mode

      • pivotAnimator_v2-2.exe (PID: 1408)
      • pivot_v2-2.tmp (PID: 1804)
      • Secure BrowserUpdateSetup.exe (PID: 1344)
      • Secure BrowserUpdate.exe (PID: 2300)
      • cookie_mmm_irs_ppi_005_888_d.exe (PID: 2924)
      • avast_free_antivirus_setup_online.exe (PID: 2568)
      • mini_installer_86.0.4194.10.exe (PID: 2428)
      • setup.exe (PID: 3944)
      • instup.exe (PID: 2364)
      • SecureBrowser.exe (PID: 1496)
    • Creates a directory in Program Files

      • pivot_v2-2.tmp (PID: 1804)
      • Secure BrowserUpdateSetup.exe (PID: 1344)
      • Secure BrowserUpdate.exe (PID: 2300)
      • Secure BrowserUpdate.exe (PID: 3000)
      • setup.exe (PID: 3944)
      • instup.exe (PID: 1648)
    • Low-level read access rights to disk partition

      • cookie_mmm_irs_ppi_005_888_d.exe (PID: 2924)
      • avast_free_antivirus_setup_online.exe (PID: 2568)
      • instup.exe (PID: 2364)
      • instup.exe (PID: 1648)
    • Creates files in the Windows directory

      • cookie_mmm_irs_ppi_005_888_d.exe (PID: 2924)
      • avast_free_antivirus_setup_online.exe (PID: 2568)
      • instup.exe (PID: 2364)
      • Secure BrowserUpdate.exe (PID: 3000)
      • instup.exe (PID: 1648)
    • Creates files in the program directory

      • Secure BrowserUpdate.exe (PID: 2300)
      • avast_free_antivirus_setup_online.exe (PID: 2568)
      • Secure BrowserUpdateSetup.exe (PID: 1344)
      • instup.exe (PID: 2364)
      • Secure BrowserUpdate.exe (PID: 3000)
      • setup.exe (PID: 3944)
      • instup.exe (PID: 1648)
    • Disables SEHOP

      • Secure BrowserUpdate.exe (PID: 2300)
    • Starts itself from another location

      • Secure BrowserUpdate.exe (PID: 2300)
      • instup.exe (PID: 2364)
    • Changes default file association

      • pivot_v2-2.tmp (PID: 1804)
      • setup.exe (PID: 3944)
    • Creates/Modifies COM task schedule object

      • Secure BrowserUpdate.exe (PID: 3752)
    • Executed as Windows Service

      • Secure BrowserUpdate.exe (PID: 3000)
    • Drops a file with a compile date too recent

      • cookie_mmm_irs_ppi_005_888_d.exe (PID: 2924)
      • avast_free_antivirus_setup_online.exe (PID: 2568)
      • instup.exe (PID: 2364)
    • Creates or modifies windows services

      • instup.exe (PID: 2364)
    • Removes files from Windows directory

      • instup.exe (PID: 2364)
      • instup.exe (PID: 1648)
      • setup.exe (PID: 3944)
    • Application launched itself

      • setup.exe (PID: 3944)
      • SecureBrowser.exe (PID: 2624)
      • chrmstp.exe (PID: 3336)
      • Secure BrowserUpdate.exe (PID: 3000)
    • Creates a software uninstall entry

      • setup.exe (PID: 3944)
    • Executed via COM

      • explorer.exe (PID: 3300)
    • Creates files in the user directory

      • setup.exe (PID: 3944)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 2132)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 2132)
      • pivotAnimator_v2-2.exe (PID: 1408)
      • instup.exe (PID: 1648)
      • SecureBrowser.exe (PID: 3848)
    • Changes internet zones settings

      • iexplore.exe (PID: 2132)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 2132)
    • Reads internet explorer settings

      • iexplore.exe (PID: 2456)
    • Changes settings of System certificates

      • iexplore.exe (PID: 2132)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 2132)
    • Loads dropped or rewritten executable

      • pivot_v2-2.tmp (PID: 1804)
    • Creates files in the program directory

      • pivot_v2-2.tmp (PID: 1804)
    • Application was dropped or rewritten from another process

      • pivot_v2-2.tmp (PID: 1804)
    • Creates a software uninstall entry

      • pivot_v2-2.tmp (PID: 1804)
    • Creates files in the user directory

      • iexplore.exe (PID: 2132)
    • Reads the hosts file

      • instup.exe (PID: 2364)
      • instup.exe (PID: 1648)
      • SecureBrowser.exe (PID: 2624)
      • SecureBrowser.exe (PID: 3848)
    • Dropped object may contain Bitcoin addresses

      • SecureBrowser.exe (PID: 3920)
      • SecureBrowser.exe (PID: 3812)
      • instup.exe (PID: 1648)
    • Dropped object may contain TOR URL's

      • SecureBrowser.exe (PID: 3920)
      • SecureBrowser.exe (PID: 3812)
      • SecureBrowser.exe (PID: 2624)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
118
Monitored processes
75
Malicious processes
20
Suspicious processes
22

Behavior graph

Click at the process to see the details
drop and start drop and start start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start iexplore.exe iexplore.exe pivotanimator_v2-2.exe no specs pivotanimator_v2-2.exe pivot_v2-2.exe cookie_mmm_irs_ppi_005_888_d.exe secure browserupdatesetup.exe pivot_v2-2.tmp secure browserupdate.exe secure browserupdate.exe no specs pivot.exe no specs secure browserupdate.exe no specs secure browserupdate.exe secure browserupdate.exe no specs secure browserupdate.exe avast_free_antivirus_setup_online.exe instup.exe mini_installer_86.0.4194.10.exe setup.exe setup.exe no specs instup.exe sbr.exe no specs explorer.exe no specs explorer.exe no specs securebrowser.exe securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs chrmstp.exe no specs chrmstp.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs securebrowser.exe no specs secure browserupdate.exe no specs securebrowser.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
396"C:\Program Files\Secure Browser\Secure Browser\Application\SecureBrowser.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --field-trial-handle=1000,11780271180205524636,9101158143489019941,131072 --lang=en-US --service-sandbox-type=utility --enable-audio-service-sandbox --mojo-platform-channel-handle=2356 /prefetch:8C:\Program Files\Secure Browser\Secure Browser\Application\SecureBrowser.exeSecureBrowser.exe
User:
admin
Company:
The Secure Browser Authors
Integrity Level:
LOW
Description:
Secure Browser
Exit code:
0
Version:
86.0.4194.10
Modules
Images
c:\program files\secure browser\secure browser\application\securebrowser.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\secure browser\secure browser\application\86.0.4194.10\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\shell32.dll
524"C:\Program Files\Secure Browser\Secure Browser\Application\SecureBrowser.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Secure Browser\Secure Browser\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Secure Browser\Secure Browser\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Secure Browser\Secure Browser\User Data" --annotation=plat=Win32 "--annotation=prod=Secure Browser" --annotation=ver=86.0.4194.10-devel --initial-client-data=0xc0,0xc4,0xc8,0x94,0xcc,0x68ae29f0,0x68ae2a00,0x68ae2a0cC:\Program Files\Secure Browser\Secure Browser\Application\SecureBrowser.exeSecureBrowser.exe
User:
admin
Company:
The Secure Browser Authors
Integrity Level:
MEDIUM
Description:
Secure Browser
Exit code:
0
Version:
86.0.4194.10
Modules
Images
c:\program files\secure browser\secure browser\application\securebrowser.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\secure browser\secure browser\application\86.0.4194.10\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\shell32.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
668"C:\Program Files\Pivot Stickfigure Animator\pivot.exe" C:\Program Files\Pivot Stickfigure Animator\pivot.exepivotAnimator_v2-2.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\pivot stickfigure animator\pivot.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
700"C:\Program Files\Secure Browser\Secure Browser\Application\SecureBrowser.exe" --type=gpu-process --field-trial-handle=1000,11780271180205524636,9101158143489019941,131072 --gpu-preferences=MAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAQAAAAAAAAAAAAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAA= --use-gl=swiftshader-webgl --mojo-platform-channel-handle=2488 /prefetch:2C:\Program Files\Secure Browser\Secure Browser\Application\SecureBrowser.exeSecureBrowser.exe
User:
admin
Company:
The Secure Browser Authors
Integrity Level:
LOW
Description:
Secure Browser
Exit code:
0
Version:
86.0.4194.10
Modules
Images
c:\program files\secure browser\secure browser\application\securebrowser.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\secure browser\secure browser\application\86.0.4194.10\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\shell32.dll
828"C:\Program Files\Secure Browser\Update\Secure BrowserUpdate.exe" /handoff "bundlename=SecureBrowser&appguid={EF691ED4-68F6-4754-B1C0-C337E73D042C}&appname=SecureBrowser&needsadmin=True&lang=en&installdataindex=prefs&client=user_id%3D50bec48158c2945e87535b24eacb71c38f41370d%26sup%3D6f32%26tg%3D00" /installsource otherinstallcmd /sessionid "{136B6201-01E4-422E-9B62-48B13087D2DD}" /silentC:\Program Files\Secure Browser\Update\Secure BrowserUpdate.exeSecure BrowserUpdate.exe
User:
admin
Company:
Secure Browser.
Integrity Level:
HIGH
Description:
Secure Browser Update
Exit code:
0
Version:
1.3.105.7
Modules
Images
c:\program files\secure browser\update\secure browserupdate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
996"C:\Program Files\Secure Browser\Secure Browser\Application\SecureBrowser.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --field-trial-handle=1000,11780271180205524636,9101158143489019941,131072 --lang=en-US --service-sandbox-type=utility --enable-audio-service-sandbox --mojo-platform-channel-handle=2812 /prefetch:8C:\Program Files\Secure Browser\Secure Browser\Application\SecureBrowser.exeSecureBrowser.exe
User:
admin
Company:
The Secure Browser Authors
Integrity Level:
LOW
Description:
Secure Browser
Exit code:
0
Version:
86.0.4194.10
Modules
Images
c:\program files\secure browser\secure browser\application\securebrowser.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\secure browser\secure browser\application\86.0.4194.10\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\shell32.dll
1036"C:\Program Files\Secure Browser\Secure Browser\Application\SecureBrowser.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --field-trial-handle=1000,11780271180205524636,9101158143489019941,131072 --lang=en-US --service-sandbox-type=utility --enable-audio-service-sandbox --mojo-platform-channel-handle=3508 /prefetch:8C:\Program Files\Secure Browser\Secure Browser\Application\SecureBrowser.exeSecureBrowser.exe
User:
admin
Company:
The Secure Browser Authors
Integrity Level:
LOW
Description:
Secure Browser
Exit code:
0
Version:
86.0.4194.10
Modules
Images
c:\program files\secure browser\secure browser\application\securebrowser.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\secure browser\secure browser\application\86.0.4194.10\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\shell32.dll
1220"C:\Program Files\Secure Browser\Update\Secure BrowserUpdate.exe" /regsvcC:\Program Files\Secure Browser\Update\Secure BrowserUpdate.exeSecure BrowserUpdate.exe
User:
admin
Company:
Secure Browser.
Integrity Level:
HIGH
Description:
Secure Browser Update
Exit code:
0
Version:
1.3.105.7
Modules
Images
c:\program files\secure browser\update\secure browserupdate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1336"C:\Program Files\Secure Browser\Secure Browser\Application\SecureBrowser.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --field-trial-handle=1000,11780271180205524636,9101158143489019941,131072 --lang=en-US --service-sandbox-type=utility --enable-audio-service-sandbox --mojo-platform-channel-handle=2684 /prefetch:8C:\Program Files\Secure Browser\Secure Browser\Application\SecureBrowser.exeSecureBrowser.exe
User:
admin
Company:
The Secure Browser Authors
Integrity Level:
LOW
Description:
Secure Browser
Exit code:
0
Version:
86.0.4194.10
Modules
Images
c:\program files\secure browser\secure browser\application\securebrowser.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\secure browser\secure browser\application\86.0.4194.10\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\shell32.dll
1344"C:\Users\admin\AppData\Local\Temp\Pivot_Animator_files\Secure BrowserUpdateSetup.exe" /silent /install bundlename=SecureBrowser&appguid={EF691ED4-68F6-4754-B1C0-C337E73D042C}&appname=SecureBrowser&needsadmin=True&lang=en&installdataindex=prefs&client=user_id%3D50bec48158c2945e87535b24eacb71c38f41370d%26sup%3D6f32%26tg%3D00C:\Users\admin\AppData\Local\Temp\Pivot_Animator_files\Secure BrowserUpdateSetup.exe
svchost.exe
User:
admin
Company:
Secure Browser.
Integrity Level:
HIGH
Description:
Secure Browser Update Setup
Exit code:
0
Version:
1.3.105.7
Modules
Images
c:\users\admin\appdata\local\temp\pivot_animator_files\secure browserupdatesetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
Total events
9 426
Read events
2 876
Write events
6 527
Delete events
23

Modification events

(PID) Process:(2132) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
416843872
(PID) Process:(2132) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30882568
(PID) Process:(2132) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2132) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2132) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2132) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2132) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2132) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
46000000A6000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(2132) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2132) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
80
Suspicious files
145
Text files
714
Unknown types
107

Dropped files

PID
Process
Filename
Type
2456iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\CabC3E.tmp
MD5:
SHA256:
2456iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\TarC4F.tmp
MD5:
SHA256:
2456iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\644B8874112055B5E195ECB0E8F243A4der
MD5:
SHA256:
2456iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\644B8874112055B5E195ECB0E8F243A4binary
MD5:
SHA256:
2456iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\DD69E8BA22BFF7F5CC55FFFB984866CFbinary
MD5:
SHA256:
2456iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\7MMTH91E.htmhtml
MD5:
SHA256:
2456iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CFE86DBBE02D859DC92F1E17E0574EE8_46766FC45507C0B9E264E4C18BC7288Bder
MD5:
SHA256:
2456iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\DD69E8BA22BFF7F5CC55FFFB984866CFder
MD5:
SHA256:
2456iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_28DEA62A0AE77228DD387E155AD0BA27der
MD5:
SHA256:
2456iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CC197601BE0898B7B0FCC91FA15D8A69_B121B36398E3075386664ABDAC5E9443der
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
56
TCP/UDP connections
112
DNS requests
83
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2456
iexplore.exe
GET
200
172.217.16.131:80
http://ocsp.pki.goog/gsr2/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBTgXIsxbvr2lBkPpoIEVRE6gHlCnAQUm%2BIHV2ccHsBqBt5ZtJot39wZhi4CDQHjtJqhjYqpgSVpULg%3D
US
der
468 b
whitelisted
2456
iexplore.exe
GET
200
23.55.163.73:80
http://crl.identrust.com/DSTROOTCAX3CRL.crl
US
der
1.16 Kb
whitelisted
2456
iexplore.exe
GET
200
172.217.16.131:80
http://ocsp.pki.goog/gsr2/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBTgXIsxbvr2lBkPpoIEVRE6gHlCnAQUm%2BIHV2ccHsBqBt5ZtJot39wZhi4CDQHjtJqhjYqpgSVpULg%3D
US
der
468 b
whitelisted
2456
iexplore.exe
GET
200
23.51.123.27:80
http://s.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEGMYDTj7gJd4qdA1oxYY%2BEA%3D
NL
der
1.71 Kb
shared
2456
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAyO4MkNaokViAQGHuJB%2Ba8%3D
US
der
471 b
whitelisted
2924
cookie_mmm_irs_ppi_005_888_d.exe
POST
204
5.62.40.214:80
http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
DE
whitelisted
2456
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D
US
der
1.47 Kb
whitelisted
2132
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
der
471 b
whitelisted
2132
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
der
471 b
whitelisted
2132
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8Ull8gIGmZT9XHrHiJQeI%3D
US
der
1.47 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2456
iexplore.exe
23.55.163.73:80
crl.identrust.com
Akamai International B.V.
US
unknown
2456
iexplore.exe
172.217.16.131:80
ocsp.pki.goog
Google Inc.
US
whitelisted
2132
iexplore.exe
13.107.21.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
2132
iexplore.exe
66.96.149.23:443
pivotanimator.net
The Endurance International Group, Inc.
US
suspicious
2456
iexplore.exe
13.224.194.41:443
d9xefsrx7pfhx.cloudfront.net
US
suspicious
2456
iexplore.exe
23.51.123.27:80
s.symcd.com
Akamai Technologies, Inc.
NL
whitelisted
1408
pivotAnimator_v2-2.exe
65.9.69.209:443
d11yiezpmoyd9g.cloudfront.net
AT&T Services, Inc.
US
unknown
2132
iexplore.exe
152.199.19.161:443
iecvlist.microsoft.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2132
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2924
cookie_mmm_irs_ppi_005_888_d.exe
2.16.107.50:443
iavs9x.u.avast.com
Akamai International B.V.
suspicious

DNS requests

Domain
IP
Reputation
pivotanimator.net
  • 66.96.149.23
whitelisted
crl.identrust.com
  • 23.55.163.73
  • 23.55.163.57
whitelisted
r3.o.lencr.org
  • 23.55.163.58
  • 23.55.163.48
shared
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 13.107.21.200
  • 204.79.197.200
whitelisted
maxcdn.bootstrapcdn.com
  • 104.18.11.207
  • 104.18.10.207
whitelisted
ajax.googleapis.com
  • 172.217.19.106
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
ocsp.pki.goog
  • 172.217.16.131
whitelisted
d9xefsrx7pfhx.cloudfront.net
  • 13.224.194.41
  • 13.224.194.16
  • 13.224.194.77
  • 13.224.194.37
suspicious

Threats

PID
Process
Class
Message
2924
cookie_mmm_irs_ppi_005_888_d.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
No debug info