| File name: | gbpcef.exe |
| Full analysis: | https://app.any.run/tasks/eb379e82-9dcc-431d-960b-4085ce912350 |
| Verdict: | Malicious activity |
| Analysis date: | June 05, 2021, 05:06:06 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 97E04E7498F51014E0745CEC9E85CEA6 |
| SHA1: | 4603F52EEC487E7DE45FB90A03217F50E13204E8 |
| SHA256: | 9803A9EF11EEBDD87B948F892924C8CBA93FDD62A303E85CC9FB5E0438C532B2 |
| SSDEEP: | 98304:xvzdpCuVCALwdebHSEgiaZZk8ymjcvnvXUU7uSmnhRXQX:1CuTJ1aZulnvXtDOhRC |
| .exe | | | Win64 Executable (generic) (76.4) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) |
| .exe | | | Generic Win/DOS Executable (5.5) |
| .exe | | | DOS Executable Generic (5.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2020:02:07 19:22:54+01:00 |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 2447872 |
| InitializedDataSize: | 3428864 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1d145c |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.6.0.11 |
| ProductVersionNumber: | 2.6.0.11 |
| FileFlagsMask: | 0x001f |
| FileFlags: | Private build |
| FileOS: | Win32 |
| ObjectFileType: | Unknown |
| FileSubtype: | - |
| LanguageCode: | Unknown (0016) |
| CharacterSet: | Unicode |
| CompanyName: | CAIXA |
| FileDescription: | Instalação do Módulo Adicional de Segurança CAIXA |
| FileVersion: | 2,6,0,11 |
| InternalName: | HDA |
| LegalCopyright: | Copyright © 2020, Diebold Nixdorf |
| OriginalFileName: | DiagnosticoCEF_NoEULA |
| PrivateBuild: | 2,6,0,11 |
| ProductName: | Instalação do Módulo Adicional de Segurança CAIXA |
| ProductVersion: | 2,6,0,11 |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 07-Feb-2020 18:22:54 |
| Detected languages: |
|
| TLS Callbacks: | 1 callback(s) detected. |
| Debug artifacts: |
|
| CompanyName: | CAIXA |
| FileDescription: | Instalação do Módulo Adicional de Segurança CAIXA |
| FileVersion: | 2,6,0,11 |
| InternalName: | HDA |
| LegalCopyright: | Copyright © 2020, Diebold Nixdorf |
| OriginalFilename: | DiagnosticoCEF_NoEULA |
| PrivateBuild: | 2,6,0,11 |
| ProductName: | Instalação do Módulo Adicional de Segurança CAIXA |
| ProductVersion: | 2,6,0,11 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x00000100 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 9 |
| Time date stamp: | 07-Feb-2020 18:22:54 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x00234A4A | 0x00234C00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.66641 |
CODE | 0x00236000 | 0x00020DA0 | 0x00020E00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.58405 |
.rdata | 0x00257000 | 0x0004A952 | 0x0004AA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.44495 |
.data | 0x002A2000 | 0x000100E8 | 0x00009600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.17424 |
DATA | 0x002B3000 | 0x000014E0 | 0x00001600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.98815 |
BSS | 0x002B5000 | 0x00000761 | 0x00000800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.tls | 0x002B6000 | 0x00000002 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.rsrc | 0x002B7000 | 0x002C2FFC | 0x002C3000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.67409 |
.reloc | 0x0057A000 | 0x0002C162 | 0x0002C200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.14299 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 4.87512 | 900 | Latin 1 / Western European | Portuguese - Brazil | RT_MANIFEST |
2 | 4.08937 | 4264 | Latin 1 / Western European | Portuguese - Brazil | RT_ICON |
3 | 4.57242 | 1128 | Latin 1 / Western European | Portuguese - Brazil | RT_ICON |
101 | 7.50854 | 1189 | Latin 1 / Western European | Portuguese - Brazil | FILE |
104 | 7.74086 | 6116 | Latin 1 / Western European | Portuguese - Brazil | IMG |
105 | 7.70094 | 1236 | Latin 1 / Western European | Portuguese - Brazil | IMG |
106 | 7.70452 | 1129 | Latin 1 / Western European | Portuguese - Brazil | IMG |
107 | 7.68178 | 1065 | Latin 1 / Western European | Portuguese - Brazil | IMG |
108 | 7.63592 | 1156 | Latin 1 / Western European | Portuguese - Brazil | IMG |
112 | 7.86794 | 3305 | Latin 1 / Western European | Portuguese - Brazil | FILE |
ADVAPI32.dll |
COMCTL32.dll |
CRYPT32.dll |
GDI32.dll |
IPHLPAPI.DLL |
KERNEL32.dll |
MSIMG32.dll |
NETAPI32.dll |
OLEAUT32.dll |
PSAPI.DLL |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 336 | cmd /c tasklist /? | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 568 | "C:\Users\admin\AppData\Local\Temp\gbpcef.exe" service_service | C:\Users\admin\AppData\Local\Temp\gbpcef.exe | — | services.exe | |||||||||||
User: SYSTEM Company: CAIXA Integrity Level: SYSTEM Description: Instala磯 do Mo Adicional de Seguran硠CAIXA Exit code: 0 Version: 2,6,0,11 Modules
| |||||||||||||||
| 740 | "C:\Windows\TEMP\is-LJEHN.tmp\get_version.exe" "C:\Windows\system32\config\systemprofile\AppData\Local\Diebold\Warsaw\features.dat" "C:\Windows\TEMP\is-LJEHN.tmp\version.txt" | C:\Windows\TEMP\is-LJEHN.tmp\get_version.exe | — | warsaw_setup_32.tmp | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Exit code: 0 Modules
| |||||||||||||||
| 1272 | "C:\Windows\TEMP\is-LJEHN.tmp\get_version.exe" "C:\Program Files\Diebold\Warsaw\features.dat" "C:\Windows\TEMP\is-LJEHN.tmp\version.txt" | C:\Windows\TEMP\is-LJEHN.tmp\get_version.exe | — | warsaw_setup_32.tmp | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Exit code: 0 Modules
| |||||||||||||||
| 1504 | "sc.exe" start "Warsaw Technology" | C:\Windows\system32\sc.exe | — | warsaw_setup_32.tmp | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: A tool to aid in developing services for WindowsNT Exit code: 1056 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1692 | "C:\Windows\system32\rundll32.exe" "C:\Program Files\Diebold\Warsaw\wslbmid.dll", Function6 C:\Program Files\Diebold\Warsaw | C:\Windows\system32\rundll32.exe | — | warsaw_setup_32.tmp | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1752 | "C:\Windows\TEMP\is-LJEHN.tmp\corefixer.exe" /nocert | C:\Windows\TEMP\is-LJEHN.tmp\corefixer.exe | — | warsaw_setup_32.tmp | |||||||||||
User: SYSTEM Company: GAS Tecnologia LTDA Integrity Level: SYSTEM Description: GAS Tecnologia - Warsaw Fixer Exit code: 0 Version: 1.7.2.127 Modules
| |||||||||||||||
| 2056 | C:\ProgramData\Temp\warsaw_setup_32.exe /verysilent /sp- /norestart /suppressmsgboxes /restartexitcode=3010 /nocancel /accepteula /log="C:\ProgramData\Temp\wslog.dat" | C:\ProgramData\Temp\warsaw_setup_32.exe | gbpcef.exe | ||||||||||||
User: SYSTEM Company: Diebold Nixdorf Integrity Level: SYSTEM Description: Warsaw Exit code: 0 Version: 2.11.1.9 Modules
| |||||||||||||||
| 2104 | "C:\Program Files\Diebold\Warsaw\core.exe" --install-service | C:\Program Files\Diebold\Warsaw\core.exe | — | warsaw_setup_32.tmp | |||||||||||
User: SYSTEM Company: Diebold Nixdorf Integrity Level: SYSTEM Description: Diebold Nixdorf - Protection Module Exit code: 0 Version: 2.9.0.54 Modules
| |||||||||||||||
| 2208 | "C:\Users\admin\AppData\Local\Temp\gbpcef.exe" | C:\Users\admin\AppData\Local\Temp\gbpcef.exe | Explorer.EXE | ||||||||||||
User: admin Company: CAIXA Integrity Level: MEDIUM Description: Instala磯 do Mo Adicional de Seguran硠CAIXA Exit code: 0 Version: 2,6,0,11 Modules
| |||||||||||||||
| (PID) Process: | (2208) gbpcef.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2208) gbpcef.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2208) gbpcef.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2208) gbpcef.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (568) gbpcef.exe | Key: | HKEY_USERS\NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | SecureProtocols |
Value: 2560 | |||
| (PID) Process: | (568) gbpcef.exe | Key: | HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | SecureProtocols |
Value: 2560 | |||
| (PID) Process: | (568) gbpcef.exe | Key: | HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | SecureProtocols |
Value: 2560 | |||
| (PID) Process: | (568) gbpcef.exe | Key: | HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | SecureProtocols |
Value: 2560 | |||
| (PID) Process: | (568) gbpcef.exe | Key: | HKEY_USERS\NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | SecureProtocols |
Value: 672 | |||
| (PID) Process: | (568) gbpcef.exe | Key: | HKEY_USERS\NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | SecureProtocols |
Value: 512 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3620 | warsaw_setup_32.tmp | C:\Program Files\Diebold\Warsaw:z2fzaw5z | — | |
MD5:— | SHA256:— | |||
| 568 | gbpcef.exe | C:\Users\Administrator\NTUSER.DAT | hiv | |
MD5:— | SHA256:— | |||
| 2208 | gbpcef.exe | C:\Users\admin\AppData\Local\Temp\Instala磯 do Mo Adicional de Seguran硠CAIXA.log | text | |
MD5:— | SHA256:— | |||
| 568 | gbpcef.exe | C:\Windows\system32\config\systemprofile\NTUSER.DAT | hiv | |
MD5:— | SHA256:— | |||
| 568 | gbpcef.exe | C:\ProgramData\Temp\cert_temp\cert0.cer | der | |
MD5:87CE0B7B2A0E4900E158719B37A89372 | SHA256:3E9099B5015E8F486C00BCEA9D111EE721FABA355A89BCF1DF69561E3DC6325C | |||
| 568 | gbpcef.exe | C:\ProgramData\Temp\cert_temp\cert1.cer | der | |
MD5:D474DE575C39B2D39C8583C5C065498A | SHA256:7431E5F4C3C1CE4690774F0B61E05440883BA9A01ED00BA6ABD7806ED3B118CF | |||
| 2208 | gbpcef.exe | C:\ProgramData\Temp\warsaw_setup_32.exe | executable | |
MD5:B563F5D386B80A06BF3CBF233BDCF8DF | SHA256:1D9A25333BA69EEA3A09D3131268306CC76BDB612B02156F619761BC516D9151 | |||
| 2056 | warsaw_setup_32.exe | C:\Windows\TEMP\is-HUB78.tmp\warsaw_setup_32.tmp | executable | |
MD5:A74730D904ABD23F218ACB0BAEA76EF5 | SHA256:18A44BEB2082ADFA8E0302DAA8BEEB2BA6E4C0EB2D002FF0CF825E2648D066B2 | |||
| 3620 | warsaw_setup_32.tmp | C:\Program Files\Diebold\Warsaw\is-HLBTR.tmp | executable | |
MD5:94D5E15B9E0F51C93EFF6417096A8FD9 | SHA256:9A78C0ACBF32F3F7D830F03BA1FADA3341158A966A4FF62C0D2E37A9F02DCAC8 | |||
| 1272 | get_version.exe | C:\Windows\TEMP\is-LJEHN.tmp\version.txt | text | |
MD5:81051BCC2CF1BEDF378224B0A93E2877 | SHA256:7EB70257593DA06F682A3DDDA54A9D260D4FC514F645237F5CA74B08F8DA61A6 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2208 | gbpcef.exe | 13.225.87.124:443 | dn.gastecnologia.com.br | — | US | unknown |
2208 | gbpcef.exe | 13.225.82.17:443 | cloud.gastecnologia.com.br | — | US | unknown |
Domain | IP | Reputation |
|---|---|---|
dn.gastecnologia.com.br |
| shared |
cloud.gastecnologia.com.br |
| suspicious |