defensorsafra.exe

Diagnóstico Safra

Banco Safra SA

This is a setup program which is used to install the application. The file has been seen being downloaded from md.safra.com.br.
Publisher:
Banco Safra  (signed by Banco Safra SA)

Product:
Diagnóstico Safra

Version:
1,4,0,0

MD5:
45ba295b9874554e06cf33f673cc23f5

SHA-1:
7b76988e86ac586a47daaa8c600cc3327917bc65

SHA-256:
9e38f401644c1b76f077bf6705063171b35a412342b669971e651c9ec7a1e2ee

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/4/2024 12:42:24 PM UTC  (today)

File size:
2.3 MB (2,450,408 bytes)

Product version:
1,4,0,0

Copyright:
Copyright © 2015, Banco Safra

Original file name:
DiagnosticoSafra

File type:
Executable application (Win32 EXE)

Language:
Português

Common path:
C:\users\{user}\downloads\defensorsafra.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
10/21/2015 9:00:00 PM

Valid to:
12/20/2016 8:59:59 PM

Subject:
CN=Banco Safra SA, OU=Banco Safra SA, O=Banco Safra SA, L=Sao Paulo, S=Sao Paulo, C=BR

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
016D5D6B4B1DD44C216241C805FB8645

File PE Metadata
Compilation timestamp:
12/29/2014 4:37:02 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:D+87ELbQSypwvZ+kjkt1SiqXsbsJe3gkIqxzeAPDOwTSn4L8oW2w2rMbTDYJWo33:Dn+SwBPHEIEHPzSn8MbT0gQR0o3Lu0

Entry address:
0x11AA02

Entry point:
E8, 86, E5, 00, 00, E9, 78, FE, FF, FF, 6A, 14, 68, 70, 3F, 59, 00, E8, B8, 77, 00, 00, 8B, 45, 08, 85, C0, 75, 1B, 68, 38, E2, 56, 00, 8D, 4D, DC, E8, FA, A2, FF, FF, 68, 60, 3F, 59, 00, 8D, 45, DC, 50, E8, EC, BE, FF, FF, 83, 65, FC, 00, 8B, 00, 8B, 40, FC, 8B, 40, 0C, 85, C0, 74, 0D, C7, 45, FC, FE, FF, FF, FF, E8, BF, 77, 00, 00, C3, 68, 14, E2, 56, 00, 8D, 4D, DC, E8, 08, A3, FF, FF, 68, 50, 3F, 59, 00, EB, C6, 8B, 45, EC, 8B, 00, 8B, 00, 33, C9, 3D, 05, 00, 00, C0, 0F, 94, C1, 8B, C1, C3, 8B, 65, E8...
 
[+]

Code size:
1.3 MB (1,404,928 bytes)

The file defensorsafra.exe has been seen being distributed by the following URL.

Scan defensorsafra.exe - Powered by Reason Core Security