| URL: | www.safra.com.br/defensor/install/defensorsafra.exe |
| Full analysis: | https://app.any.run/tasks/b56a9e4e-a449-4849-8190-821d171f4490 |
| Verdict: | Malicious activity |
| Threats: | Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns. |
| Analysis date: | March 05, 2024, 18:33:01 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | F5F4FDC5081D1821B9B92CF99B45C13B |
| SHA1: | DBB7A92B705079C0403959E168ED3207E593A9C2 |
| SHA256: | BD7EE4E07C5B0AE8C95EF3A0CEFB0AD77AB25AB0D438690395B0B9BF83B7F4F4 |
| SSDEEP: | 3:Etq3UKDJEFZXiN:ggUkEFQ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 392 | "C:\Program Files\Diebold\Warsaw\core.exe" | C:\Program Files\Diebold\Warsaw\core.exe | — | core.exe | |||||||||||
User: admin Company: Diebold Nixdorf Integrity Level: MEDIUM Description: Diebold Nixdorf - Protection Module Exit code: 0 Version: 2.9.0.54 Modules
| |||||||||||||||
| 452 | find /C "core.exe" | C:\Windows\System32\find.exe | — | cmd.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Find String (grep) Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 480 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2472.6.1166938131\1554680004" -childID 5 -isForBrowser -prefsHandle 4000 -prefMapHandle 4004 -prefsLen 29367 -prefMapSize 244195 -jsInitHandle 928 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {98d70664-e6a2-4417-b86b-31a4596bc563} 2472 "\\.\pipe\gecko-crash-server-pipe.2472" 3788 20cec280 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 572 | "C:\Program Files\Diebold\Warsaw\core.exe" | C:\Program Files\Diebold\Warsaw\core.exe | services.exe | ||||||||||||
User: SYSTEM Company: Diebold Nixdorf Integrity Level: SYSTEM Description: Diebold Nixdorf - Protection Module Exit code: 0 Version: 2.9.0.54 Modules
| |||||||||||||||
| 1000 | cmd /c tasklist /? | C:\Windows\System32\cmd.exe | — | cmd.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1068 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1316 | "C:\Users\admin\Downloads\defensorsafra.exe" | C:\Users\admin\Downloads\defensorsafra.exe | firefox.exe | ||||||||||||
User: admin Company: Banco Safra Integrity Level: MEDIUM Description: Defensor Safra Exit code: 0 Version: 2,12,0,1 Modules
| |||||||||||||||
| 1384 | "C:\Program Files\Mozilla Firefox\firefox.exe" "www.safra.com.br/defensor/install/defensorsafra.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2044 | "sc" stop wsddfac | C:\Windows\System32\sc.exe | — | warsaw_setup_32.tmp | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: A tool to aid in developing services for WindowsNT Exit code: 1060 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2096 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2472.4.700389492\2068091286" -childID 3 -isForBrowser -prefsHandle 1636 -prefMapHandle 3380 -prefsLen 34336 -prefMapSize 244195 -jsInitHandle 928 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {cee91760-ea82-48b3-b5d5-fb03873779b9} 2472 "\\.\pipe\gecko-crash-server-pipe.2472" 3616 20c93b20 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| (PID) Process: | (1384) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: AFA63E4F01000000 | |||
| (PID) Process: | (2472) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: 7547404F01000000 | |||
| (PID) Process: | (2472) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Installer\308046B0AF4A39CB |
| Operation: | delete value | Name: | installer.taskbarpin.win10.enabled |
Value: | |||
| (PID) Process: | (2472) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 0 | |||
| (PID) Process: | (2472) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (2472) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Theme |
Value: 1 | |||
| (PID) Process: | (2472) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Enabled |
Value: 1 | |||
| (PID) Process: | (2472) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableTelemetry |
Value: 1 | |||
| (PID) Process: | (2472) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent |
Value: 0 | |||
| (PID) Process: | (2472) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|SetDefaultBrowserUserChoice |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2472 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js | text | |
MD5:60E0DE9E05EC76C749D80F0D15A81B21 | SHA256:08252FA62CCCCD316474E20CC7317A6B5C932B2C972234318E8CCDA39EC2EF48 | |||
| 2472 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 2472 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js | text | |
MD5:60E0DE9E05EC76C749D80F0D15A81B21 | SHA256:08252FA62CCCCD316474E20CC7317A6B5C932B2C972234318E8CCDA39EC2EF48 | |||
| 2472 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 2472 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 2472 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 2472 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\protections.sqlite-journal | binary | |
MD5:AA8E739B64C7AC9C674712A1E801D7CB | SHA256:DF376A6BB15ABF64B47599410E0D9DA19C01DDD7E62D33C1F8C9ED6EEC68B4FB | |||
| 2472 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 2472 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 2472 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db-journal | binary | |
MD5:27281709A463F3DE9A3B01EC2EF0EC1C | SHA256:6214BEDE3C96694D2282208CF2B70FDB27A23487F4D6CE9C79C744D3C0E48566 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2472 | firefox.exe | POST | 200 | 2.19.120.133:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
2472 | firefox.exe | POST | 200 | 142.250.74.195:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 471 b | unknown |
2472 | firefox.exe | POST | 200 | 2.19.120.133:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
2472 | firefox.exe | POST | 200 | 142.250.74.195:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 471 b | unknown |
2472 | firefox.exe | POST | 200 | 2.19.120.133:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
2472 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | text | 90 b | unknown |
2472 | firefox.exe | GET | 301 | 95.101.198.137:80 | http://www.safra.com.br/defensor/install/defensorsafra.exe | unknown | — | — | unknown |
2472 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | text | 8 b | unknown |
2472 | firefox.exe | POST | 200 | 2.19.120.133:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
2472 | firefox.exe | POST | 200 | 2.19.120.133:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2472 | firefox.exe | 142.250.185.202:443 | safebrowsing.googleapis.com | — | — | whitelisted |
2472 | firefox.exe | 34.117.188.166:443 | spocs.getpocket.com | — | — | unknown |
2472 | firefox.exe | 34.117.237.239:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
2472 | firefox.exe | 34.160.144.191:443 | content-signature-2.cdn.mozilla.net | GOOGLE | US | unknown |
2472 | firefox.exe | 34.107.243.93:443 | push.services.mozilla.com | — | — | unknown |
2472 | firefox.exe | 34.149.100.209:443 | firefox.settings.services.mozilla.com | GOOGLE | US | unknown |
2472 | firefox.exe | 2.19.120.133:80 | r3.o.lencr.org | Akamai International B.V. | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
www.safra.com.br |
| unknown |
detectportal.firefox.com |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| shared |
gkegw.prod.ads.prod.webservices.mozgcp.net |
| unknown |
firefox.settings.services.mozilla.com |
| whitelisted |
r3.o.lencr.org |
| shared |
prod.remote-settings.prod.webservices.mozgcp.net |
| whitelisted |
a1887.dscq.akamai.net |
| whitelisted |
safebrowsing.googleapis.com |
| whitelisted |