pivot_v4-1.exe

Mogafa

Motus Software Ltd

The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from www.safechucklenew.com and multiple other hosts.
Publisher:
Pufacagut   (signed by Motus Software Ltd)

Product:
Mogafa

Description:
Mogafa Setup

MD5:
8508fd15b866e1d18f8d527a487d136f

SHA-1:
57f3c0ede2e5a15a5a8846d0ea744a82375f48b5

SHA-256:
300969a173e1f9718426477cb97be44ebdad294223002f262672d4cb1d1ebada

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
2/25/2025 4:23:51 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/InstallCore.AIB.gen potentially unwanted application
8.0.319.0

File size:
970.5 KB (993,784 bytes)

Product version:
3.2.2

Copyright:
Stub

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\downloads\pivot_v4-1.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
1/8/2016 7:48:52 AM

Valid to:
1/8/2017 7:48:52 AM

Subject:
CN=Motus Software Ltd, O=Motus Software Ltd, L=Lewes, S=East Sussex, C=GB

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121B33255C25F08D556D0D742D2C9C32DE3

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:7/i+bE5WUCVjB3MZPmybVLRSxgG0+1Lpel2EcQ5n+rfy0nq:7KmZU6FgPDJLQ6Y1Lc4qn+rf

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file pivot_v4-1.exe has been seen being distributed by the following 44 URLs.

http://www.safechucklenew.com/WVl6OTRQU1V5UWpCSU5uUlVVVFZoV1hOcVdUZFJZMlE1UjJGTk0zSnZjSEJLVUVrelVqWnhXVTFRU0haTVZ6RTVaeVV6UkNaalBXRnlXWHB5WnpKbFFXbFlNVGQwSlRKQ1RGTkphVFIzYzBsTFJtaDBhU1V5UW5ONVpVeHlKVEpDSlRKR01XOXdkVGs0Y1VGYVRscFVPVGxUVVc5dk1rUmlObmN3Y3poTVpIbE1WMWszZVRscFdHMVBNMUFsTWtKSFNGbHBiazU1Tkc5bFMxbFJjblpOUldObmFHWjJRMjk0UVRGemNpVXlRbWhZWmsxWFRtd3hVM0U0ZVVzeWJVWjFPVzlGUWtweWNYUnNWelJvWVdONlVGY3pWVzlYVTBwSGR5VXpSQ1V6UkNabFBUQW1aRzkzYm14dllXUkJjejF3YVhadmRGOTJOQzB4TG1WNFpTWm1ZV3hzWW1GamExOTFjbXc5YUhSMGNDVXpRU1V5UmlVeVJuZDNkeTVwY205dWMzSmpMbU52YlNVeVJuUmxjM1F1WlhobA==

http://www.safechucklenew.com/c?x=5oOfegYyLG5r/VU83EheTm3Vqng0Xh/ywCQSa8eIv1k=&c=Q9f9zou3LwdOtQjHO6pphsOkJ7 kzP9NMHZdc/FTZrKTMjreN4EtoprXn8UwEGgkEcVvyT9dc3xJ8AUchu40r 52EgqHebgKMSYOJnlx2MBOB0lM/2KEY3wz3ro2KC4kRwecH1D/yED3PFaEyQQtw5Py5ejP9gPz29FeiECoeOs=&e=0&downloadAs=pivot_v4-1.exe&fallback_url=http://.../test.exe

http://www.safechucklenew.com/WVl6OTRQV05YYW14UlZVczVKVEpDTlVkWmJVVnVUamxMY2pjMFFtSm9XVGxyZVdGQ2JXUjNSM0Z1UjNaSFVqUmlVU1V6UkNaalBXWkNlR1FsTWtaUU1XWlRRemhvVVdkeGRXbEhVM1pYWjNnNGFFRkNXbFI1ZWpjeWRsUXpNRzBsTWtKblZIUmhjWE0yUWpkQ1IxZGhlWGs0VjA1d1RrZHVZM1ZQTm00M1VVWldXRk55Y2lVeVFqTnJUVmxvVEhGdVJWUjRWbkJuU1hseVRubE9Na1JEU21kTFFrZzFPR3hwTmxwMlkxZG1iakI1WWt0bWMzSkdaRFJKWkZFeVFqa3dlWGhrU0hKRVVFZHpZbkpMT0hGaWF6RlNRU1V6UkNVelJDWmxQVEFtWkc5M2JteHZZV1JCY3oxd2FYWnZkRjkyTkMweExtVjRaU1ptWVd4c1ltRmphMTkxY213OWFIUjBjQ1V6UVNVeVJpVXlSbmQzZHk1cGNtOXVjM0pqTG1OdmJTVXlSblJsYzNRdVpYaGw=

http://www.safechucklenew.com/c?x=6JWr493A3jpPOIzdYev/Y5M0gPucFz9sgwTODjJBKV8=&c=pQZKlgve45xjRTbMA8SrufwG7ZbN8WBVchOTOvi /B1vFX7lix0kNKIim6rkc suKjI K30GQdAu9H9eBXzMtHoaTMELIfW/IInINClkZGofe60McyRf0H Vc6xgpnOuvY9KtTeqwX5YuNzh6m fGSdYITYHUbhKinFD B5JYA=&e=0&downloadAs=pivot_v4-1.exe&fallback_url=http://.../test.exe

Latest 30 of 44 download URLs

Scan pivot_v4-1.exe - Powered by Reason Core Security