Play interactive tourEdit tour
macOS Analysis Report J5RBhmpBtw
Overview
General Information
Detection
SysJoker
Score: | 56 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Multi AV Scanner detection for submitted file
Yara detected SysJoker
Executes commands using a shell command-line interpreter
Reads the systems hostname
Classification
Analysis Advice |
---|
Exit code suggests that the sample could not be started, try looking at standard streams or writes to anonymous pipes for possible reason |
Exit code information suggests that the sample terminated abnormally, try to lookup the sample's target architecture |
Non-zero exit code suggests an error during the execution. Lookup the error code for hints. |
General Information |
---|
Joe Sandbox Version: | 34.0.0 Boulder Opal |
Analysis ID: | 551503 |
Start date: | 12.01.2022 |
Start time: | 09:23:51 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 3m 34s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Sample file name: | J5RBhmpBtw |
Cookbook file name: | defaultmacfilecookbook.jbs |
Analysis system description: | Virtual Machine, High Sierra (Office 2016 16.16, Java 11.0.2+9, Adobe Reader 2019.010.20099) |
Analysis Mode: | default |
Detection: | MAL |
Classification: | mal56.troj.mac@0/0@0/0 |
Warnings: | Show All
|
Process Tree |
---|
|
Yara Overview |
---|
Initial Sample |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_SysJoker | Yara detected SysJoker | Joe Security |
Memory Dumps |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_SysJoker | Yara detected SysJoker | Joe Security | ||
JoeSecurity_SysJoker | Yara detected SysJoker | Joe Security |
Jbx Signature Overview |
---|
Click to jump to signature section
Show All Signature Results
AV Detection: |
---|
Multi AV Scanner detection for submitted file | Show sources |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | Classification label: |
Source: | Shell command executed: | Jump to behavior |
Source: | Sysctl requested: | Jump to behavior |
Stealing of Sensitive Information: |
---|
Yara detected SysJoker | Show sources |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality: |
---|
Yara detected SysJoker | Show sources |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Mitre Att&ck Matrix |
---|
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Scripting1 | Path Interception | Path Interception | Scripting1 | OS Credential Dumping | System Information Discovery1 | Remote Services | Data from Local System | Exfiltration Over Other Network Medium | Encrypted Channel1 | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | Application Layer Protocol1 | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Behavior Graph |
---|
Screenshots |
---|
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Antivirus, Machine Learning and Genetic Malware Detection |
---|
Initial Sample |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
17% | Virustotal | Browse | ||
14% | ReversingLabs | MacOS.Backdoor.SysJoker |
Dropped Files |
---|
No Antivirus matches |
---|
Domains |
---|
No Antivirus matches |
---|
URLs |
---|
No Antivirus matches |
---|
Domains and IPs |
---|
Contacted Domains |
---|
No contacted domains info |
---|
Contacted IPs |
---|
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
Public |
---|
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
104.90.164.244 | unknown | United States | 16625 | AKAMAI-ASUS | false |
Joe Sandbox View / Context |
---|
IPs |
---|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
104.90.164.244 | Get hash | malicious | Browse | ||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse |
Domains |
---|
No context |
---|
ASN |
---|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
AKAMAI-ASUS | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
JA3 Fingerprints |
---|
No context |
---|
Dropped Files |
---|
No context |
---|
Runtime Messages |
---|
Command: | /Users/berri/Desktop/J5RBhmpBtw |
Exit Code: | 134 |
Exit Code Info: | SIGABRT (6) Abort signal from abort |
Killed: | False |
Standard Output: | |
Standard Error: | dyld: lazy symbol binding failed: Symbol not found: __ZNSt3__14__fs10filesystem8__statusERKNS1_4pathEPNS_10error_codeE Referenced from: /Users/berri/Desktop/J5RBhmpBtw (which was built for Mac OS X 11.3) Expected in: /usr/lib/libc++.1.dylib dyld: Symbol not found: __ZNSt3__14__fs10filesystem8__statusERKNS1_4pathEPNS_10error_codeE Referenced from: /Users/berri/Desktop/J5RBhmpBtw (which was built for Mac OS X 11.3) Expected in: /usr/lib/libc++.1.dylib |
Created / dropped Files |
---|
No created / dropped files found |
---|
Static File Info |
---|
General | |
---|---|
File type: | |
Entropy (8bit): | 4.67371613955121 |
TrID: |
|
File name: | J5RBhmpBtw |
File size: | 360176 |
MD5: | e06e06752509f9cd8bc85aa1aa24dba2 |
SHA1: | 554aef8bf44e7fa941e1190e41c8770e90f07254 |
SHA256: | 1a9a5c797777f37463b44de2b49a7f95abca786db3977dcdac0f79da739c08ac |
SHA512: | 78a210c5fd1ac8c601fbb4ed226e7aaf1cc5bda187807ba3020997862fd54b59081f0b7f4fdc720acfa8e3d6a35dbe9309e0b2fe38088f493a02717a1057a56e |
SSDEEP: | 6144:5xw19koSAgvRyrnN5ft9A7pIHWhT5FixbxLZ:CvgMrnN51qaH+T5wl |
File Content Preview: | ..................@.......................~.................................................................................................................................................................................................................... |
Static Mach Info |
---|
General Information for header 1 | |
---|---|
Endian: | |
Size: | |
Architecture: | |
Filetype: | |
Nbr. of load commands: | |
Entry point: |
segment_command_64 aggregated: 5 |
---|
Name | Value |
---|---|
segname | __PAGEZERO |
vmaddr | 0x0 |
vmsize | 0x100000000 |
fileoff | 0x0 |
filesize | 0x0 |
maxprot | 0x0 |
initprot | 0x0 |
nsects | 0 |
flags | 0x0 |
Name | Value | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
segname | __TEXT | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
vmaddr | 0x100000000 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
vmsize | 0x18000 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
fileoff | 0x0 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
filesize | 0x18000 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
maxprot | 0x5 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
initprot | 0x5 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
nsects | 7 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
flags | 0x0 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Datas |
|
Name | Value | ||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
segname | __DATA_CONST | ||||||||||||||||||||||||||||||||||||||||
vmaddr | 0x100018000 | ||||||||||||||||||||||||||||||||||||||||
vmsize | 0x4000 | ||||||||||||||||||||||||||||||||||||||||
fileoff | 0x18000 | ||||||||||||||||||||||||||||||||||||||||
filesize | 0x4000 | ||||||||||||||||||||||||||||||||||||||||
maxprot | 0x3 | ||||||||||||||||||||||||||||||||||||||||
initprot | 0x3 | ||||||||||||||||||||||||||||||||||||||||
nsects | 3 | ||||||||||||||||||||||||||||||||||||||||
flags | 0x10 | ||||||||||||||||||||||||||||||||||||||||
Datas |
|
Name | Value | ||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
segname | __DATA | ||||||||||||||||||||||||||||||||||||||||
vmaddr | 0x10001C000 | ||||||||||||||||||||||||||||||||||||||||
vmsize | 0x4000 | ||||||||||||||||||||||||||||||||||||||||
fileoff | 0x1C000 | ||||||||||||||||||||||||||||||||||||||||
filesize | 0x4000 | ||||||||||||||||||||||||||||||||||||||||
maxprot | 0x3 | ||||||||||||||||||||||||||||||||||||||||
initprot | 0x3 | ||||||||||||||||||||||||||||||||||||||||
nsects | 3 | ||||||||||||||||||||||||||||||||||||||||
flags | 0x0 | ||||||||||||||||||||||||||||||||||||||||
Datas |
|
Name | Value |
---|---|
segname | __LINKEDIT |
vmaddr | 0x100020000 |
vmsize | 0xC000 |
fileoff | 0x20000 |
filesize | 0x8310 |
maxprot | 0x1 |
initprot | 0x1 |
nsects | 0 |
flags | 0x0 |
dyld_info_command aggregated: 1 |
---|
Name | Value |
---|---|
rebase_off | 131072 |
rebase_size | 56 |
bind_off | 131128 |
bind_size | 1360 |
weak_bind_off | 132488 |
weak_bind_size | 456 |
lazy_bind_off | 132944 |
lazy_bind_size | 3752 |
export_off | 136696 |
export_size | 312 |
symtab_command aggregated: 1 |
---|
Name | Value |
---|---|
symoff | 137440 |
nsyms | 131 |
stroff | 140400 |
strsize | 4432 |
dysymtab_command aggregated: 1 |
---|
Name | Value |
---|---|
ilocalsym | 0 |
nlocalsym | 1 |
iextdefsym | 1 |
nextdefsym | 7 |
iundefsym | 8 |
nundefsym | 123 |
tocoff | 0 |
ntoc | 0 |
modtaboff | 0 |
nmodtab | 0 |
extrefsymoff | 0 |
nextrefsyms | 0 |
indirectsymoff | 139536 |
nindirectsyms | 215 |
extreloff | 0 |
nextrel | 0 |
locreloff | 0 |
nlocrel | 0 |
dylinker_command aggregated: 1 |
---|
Name | Value |
---|---|
name | 12 |
Datas |
uuid_command aggregated: 1 |
---|
Name | Value |
---|---|
uuid | b'\x81t\x81~\xf4\xcf9\x8d\x97[x`Fn\xae\xc7' |
build_version_command aggregated: 1 |
---|
Name | Value |
---|---|
platform | 1 |
minos | 721664 |
sdk | 721664 |
ntools | 1 |
Datas |
source_version_command aggregated: 1 |
---|
Name | Value |
---|---|
version | 0 |
entry_point_command aggregated: 1 |
---|
Name | Value |
---|---|
entryoff | 26756 |
stacksize | 0 |
dylib_command aggregated: 3 |
---|
Name | Value |
---|---|
name | 24 |
timestamp | Thu Jan 1 01:00:02 1970 |
current_version | 9.0.0 |
compatibility_version | 7.0.0 |
Datas |
Name | Value |
---|---|
name | 24 |
timestamp | Thu Jan 1 01:00:02 1970 |
current_version | 905.6.0 |
compatibility_version | 1.0.0 |
Datas |
Name | Value |
---|---|
name | 24 |
timestamp | Thu Jan 1 01:00:02 1970 |
current_version | 1292.100.5 |
compatibility_version | 1.0.0 |
Datas |
linkedit_data_command aggregated: 3 |
---|
Name | Value |
---|---|
dataoff | 137008 |
datasize | 360 |
Name | Value |
---|---|
dataoff | 137368 |
datasize | 72 |
Name | Value |
---|---|
dataoff | 144832 |
datasize | 19792 |
Internal Symbols |
---|
__NSGetExecutablePath |
__Unwind_Resume |
__ZNKSt13runtime_error4whatEv |
__ZNKSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE7compareEPKc |
__ZNKSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE7compareEmmPKcm |
__ZNKSt3__120__vector_base_commonILb1EE20__throw_length_errorEv |
__ZNKSt3__121__basic_string_commonILb1EE20__throw_length_errorEv |
__ZNKSt3__16locale9has_facetERNS0_2idE |
__ZNKSt3__16locale9use_facetERNS0_2idE |
__ZNKSt3__18ios_base6getlocEv |
__ZNKSt9exception4whatEv |
__ZNSt11logic_errorC2EPKc |
__ZNSt12length_errorD1Ev |
__ZNSt13runtime_errorC1EPKc |
__ZNSt13runtime_errorC1ERKS_ |
__ZNSt13runtime_errorD1Ev |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE5eraseEmm |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6appendEPKc |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6appendEPKcm |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6assignEPKc |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6insertEmPKc |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6resizeEmc |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE9__grow_byEmmmmmm |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE9push_backEc |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEEC1ERKS5_ |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEEC1ERKS5_mmRKS4_ |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEED1Ev |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEEaSERKS5_ |
__ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEE5flushEv |
__ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEE5writeEPKcl |
__ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEE6sentryC1ERS3_ |
__ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEE6sentryD1Ev |
__ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEED0Ev |
__ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEED1Ev |
__ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEED2Ev |
__ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEElsEi |
__ZNSt3__115basic_streambufIcNS_11char_traitsIcEEE5uflowEv |
__ZNSt3__115basic_streambufIcNS_11char_traitsIcEEE6xsgetnEPcl |
__ZNSt3__115basic_streambufIcNS_11char_traitsIcEEE6xsputnEPKcl |
__ZNSt3__115basic_streambufIcNS_11char_traitsIcEEE9showmanycEv |
__ZNSt3__115basic_streambufIcNS_11char_traitsIcEEEC2Ev |
__ZNSt3__115basic_streambufIcNS_11char_traitsIcEEED2Ev |
__ZNSt3__14__fs10filesystem14__current_pathEPNS_10error_codeE |
__ZNSt3__14__fs10filesystem18__create_directoryERKNS1_4pathEPNS_10error_codeE |
__ZNSt3__14__fs10filesystem8__removeERKNS1_4pathEPNS_10error_codeE |
__ZNSt3__14__fs10filesystem8__statusERKNS1_4pathEPNS_10error_codeE |
__ZNSt3__14cerrE |
__ZNSt3__14coutE |
__ZNSt3__15ctypeIcE2idE |
__ZNSt3__16localeC1ERKS0_ |
__ZNSt3__16localeD1Ev |
__ZNSt3__17codecvtIcc11__mbstate_tE2idE |
__ZNSt3__18ios_base33__set_badbit_and_consider_rethrowEv |
__ZNSt3__18ios_base4initEPv |
__ZNSt3__18ios_base5clearEj |
__ZNSt3__19basic_iosIcNS_11char_traitsIcEEED2Ev |
__ZNSt3__19to_stringEi |
__ZNSt3__19to_stringEm |
__ZNSt3__1plIcNS_11char_traitsIcEENS_9allocatorIcEEEENS_12basic_stringIT_T0_T1_EEPKS6_RKS9_ |
__ZNSt8bad_castC1Ev |
__ZNSt8bad_castD1Ev |
__ZNSt9exceptionD1Ev |
__ZNSt9exceptionD2Ev |
__ZSt9terminatev |
__ZTINSt3__113basic_filebufIcNS_11char_traitsIcEEEE |
__ZTINSt3__113basic_ostreamIcNS_11char_traitsIcEEEE |
__ZTINSt3__114basic_ofstreamIcNS_11char_traitsIcEEEE |
__ZTINSt3__115basic_streambufIcNS_11char_traitsIcEEEE |
__ZTINSt3__117bad_function_callE |
__ZTISt12length_error |
__ZTISt13runtime_error |
__ZTISt8bad_cast |
__ZTISt9exception |
__ZTSNSt3__113basic_filebufIcNS_11char_traitsIcEEEE |
__ZTSNSt3__114basic_ofstreamIcNS_11char_traitsIcEEEE |
__ZTSNSt3__117bad_function_callE |
__ZTVN10__cxxabiv120__si_class_type_infoE |
__ZTVSt12length_error |
__ZTVSt9exception |
__ZTv0_n24_NSt3__113basic_ostreamIcNS_11char_traitsIcEEED0Ev |
__ZTv0_n24_NSt3__113basic_ostreamIcNS_11char_traitsIcEEED1Ev |
__ZdaPv |
__ZdlPv |
__Znam |
__Znwm |
___assert_rtn |
___bzero |
___cxa_allocate_exception |
___cxa_atexit |
___cxa_begin_catch |
___cxa_end_catch |
___cxa_free_exception |
___cxa_get_exception_ptr |
___cxa_throw |
___error |
___gxx_personality_v0 |
___stack_chk_fail |
___stack_chk_guard |
__mh_execute_header |
_curl_easy_cleanup |
_curl_easy_getinfo |
_curl_easy_init |
_curl_easy_perform |
_curl_easy_setopt |
_fclose |
_fflush |
_fgets |
_fopen |
_fread |
_fseek |
_fseeko |
_ftello |
_fwrite |
_localeconv |
_memchr |
_memcmp |
_memcpy |
_memmove |
_memset |
_pclose |
_popen |
_rand |
_sleep |
_snprintf |
_strlen |
_strtod |
_strtoll |
_strtoull |
_system |
dyld_stub_binder |
radr://5614542 |
External symbols |
---|
__NSGetExecutablePath |
__Unwind_Resume |
__ZNKSt13runtime_error4whatEv |
__ZNKSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE7compareEPKc |
__ZNKSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE7compareEmmPKcm |
__ZNKSt3__120__vector_base_commonILb1EE20__throw_length_errorEv |
__ZNKSt3__121__basic_string_commonILb1EE20__throw_length_errorEv |
__ZNKSt3__16locale9has_facetERNS0_2idE |
__ZNKSt3__16locale9use_facetERNS0_2idE |
__ZNKSt3__18ios_base6getlocEv |
__ZNSt11logic_errorC2EPKc |
__ZNSt13runtime_errorC1EPKc |
__ZNSt13runtime_errorC1ERKS_ |
__ZNSt13runtime_errorD1Ev |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE5eraseEmm |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6appendEPKc |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6appendEPKcm |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6assignEPKc |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6insertEmPKc |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6resizeEmc |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE9__grow_byEmmmmmm |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE9push_backEc |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEEC1ERKS5_ |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEEC1ERKS5_mmRKS4_ |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEED1Ev |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEEaSERKS5_ |
__ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEE5flushEv |
__ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEE5writeEPKcl |
__ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEE6sentryC1ERS3_ |
__ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEE6sentryD1Ev |
__ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEED2Ev |
__ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEElsEi |
__ZNSt3__115basic_streambufIcNS_11char_traitsIcEEEC2Ev |
__ZNSt3__115basic_streambufIcNS_11char_traitsIcEEED2Ev |
__ZNSt3__14__fs10filesystem14__current_pathEPNS_10error_codeE |
__ZNSt3__14__fs10filesystem18__create_directoryERKNS1_4pathEPNS_10error_codeE |
__ZNSt3__14__fs10filesystem8__removeERKNS1_4pathEPNS_10error_codeE |
__ZNSt3__14__fs10filesystem8__statusERKNS1_4pathEPNS_10error_codeE |
__ZNSt3__16localeC1ERKS0_ |
__ZNSt3__16localeD1Ev |
__ZNSt3__18ios_base33__set_badbit_and_consider_rethrowEv |
__ZNSt3__18ios_base4initEPv |
__ZNSt3__18ios_base5clearEj |
__ZNSt3__19basic_iosIcNS_11char_traitsIcEEED2Ev |
__ZNSt3__19to_stringEi |
__ZNSt3__19to_stringEm |
__ZNSt3__1plIcNS_11char_traitsIcEENS_9allocatorIcEEEENS_12basic_stringIT_T0_T1_EEPKS6_RKS9_ |
__ZNSt8bad_castC1Ev |
__ZNSt9exceptionD1Ev |
__ZNSt9exceptionD2Ev |
__ZSt9terminatev |
___assert_rtn |
___bzero |
___cxa_allocate_exception |
___cxa_atexit |
___cxa_begin_catch |
___cxa_end_catch |
___cxa_free_exception |
___cxa_get_exception_ptr |
___cxa_throw |
___error |
___stack_chk_fail |
_curl_easy_cleanup |
_curl_easy_getinfo |
_curl_easy_init |
_curl_easy_perform |
_curl_easy_setopt |
_fclose |
_fflush |
_fgets |
_fopen |
_fread |
_fseek |
_fseeko |
_ftello |
_fwrite |
_localeconv |
_memchr |
_memcmp |
_memcpy |
_memmove |
_memset |
_pclose |
_popen |
_rand |
_sleep |
_snprintf |
_strlen |
_strtod |
_strtoll |
_strtoull |
_system |
General Information for header 2 | |
---|---|
Endian: | |
Size: | |
Architecture: | |
Filetype: | |
Nbr. of load commands: | |
Entry point: |
segment_command_64 aggregated: 5 |
---|
Name | Value |
---|---|
segname | __PAGEZERO |
vmaddr | 0x0 |
vmsize | 0x100000000 |
fileoff | 0x0 |
filesize | 0x0 |
maxprot | 0x0 |
initprot | 0x0 |
nsects | 0 |
flags | 0x0 |
Name | Value | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
segname | __TEXT | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
vmaddr | 0x100000000 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
vmsize | 0x18000 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
fileoff | 0x0 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
filesize | 0x18000 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
maxprot | 0x5 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
initprot | 0x5 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
nsects | 8 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
flags | 0x0 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Datas |
|
Name | Value | ||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
segname | __DATA_CONST | ||||||||||||||||||||||||||||||||||||||||
vmaddr | 0x100018000 | ||||||||||||||||||||||||||||||||||||||||
vmsize | 0x4000 | ||||||||||||||||||||||||||||||||||||||||
fileoff | 0x18000 | ||||||||||||||||||||||||||||||||||||||||
filesize | 0x4000 | ||||||||||||||||||||||||||||||||||||||||
maxprot | 0x3 | ||||||||||||||||||||||||||||||||||||||||
initprot | 0x3 | ||||||||||||||||||||||||||||||||||||||||
nsects | 3 | ||||||||||||||||||||||||||||||||||||||||
flags | 0x10 | ||||||||||||||||||||||||||||||||||||||||
Datas |
|
Name | Value | ||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
segname | __DATA | ||||||||||||||||||||||||||||||||||||||||
vmaddr | 0x10001C000 | ||||||||||||||||||||||||||||||||||||||||
vmsize | 0x4000 | ||||||||||||||||||||||||||||||||||||||||
fileoff | 0x1C000 | ||||||||||||||||||||||||||||||||||||||||
filesize | 0x4000 | ||||||||||||||||||||||||||||||||||||||||
maxprot | 0x3 | ||||||||||||||||||||||||||||||||||||||||
initprot | 0x3 | ||||||||||||||||||||||||||||||||||||||||
nsects | 3 | ||||||||||||||||||||||||||||||||||||||||
flags | 0x0 | ||||||||||||||||||||||||||||||||||||||||
Datas |
|
Name | Value |
---|---|
segname | __LINKEDIT |
vmaddr | 0x100020000 |
vmsize | 0x8000 |
fileoff | 0x20000 |
filesize | 0x7EF0 |
maxprot | 0x1 |
initprot | 0x1 |
nsects | 0 |
flags | 0x0 |
dyld_info_command aggregated: 1 |
---|
Name | Value |
---|---|
rebase_off | 131072 |
rebase_size | 56 |
bind_off | 131128 |
bind_size | 1360 |
weak_bind_off | 132488 |
weak_bind_size | 120 |
lazy_bind_off | 132608 |
lazy_bind_size | 3744 |
export_off | 136352 |
export_size | 32 |
symtab_command aggregated: 1 |
---|
Name | Value |
---|---|
symoff | 136752 |
nsyms | 125 |
stroff | 139608 |
strsize | 4160 |
dysymtab_command aggregated: 1 |
---|
Name | Value |
---|---|
ilocalsym | 0 |
nlocalsym | 1 |
iextdefsym | 1 |
nextdefsym | 1 |
iundefsym | 2 |
nundefsym | 123 |
tocoff | 0 |
ntoc | 0 |
modtaboff | 0 |
nmodtab | 0 |
extrefsymoff | 0 |
nextrefsyms | 0 |
indirectsymoff | 138752 |
nindirectsyms | 214 |
extreloff | 0 |
nextrel | 0 |
locreloff | 0 |
nlocrel | 0 |
dylinker_command aggregated: 1 |
---|
Name | Value |
---|---|
name | 12 |
Datas |
uuid_command aggregated: 1 |
---|
Name | Value |
---|---|
uuid | b'\xec\x10\xd8Nr?=\x9a\x85$\xcd\xc7\x06t\x9dh' |
build_version_command aggregated: 1 |
---|
Name | Value |
---|---|
platform | 1 |
minos | 721664 |
sdk | 721664 |
ntools | 1 |
Datas |
source_version_command aggregated: 1 |
---|
Name | Value |
---|---|
version | 0 |
entry_point_command aggregated: 1 |
---|
Name | Value |
---|---|
entryoff | 25300 |
stacksize | 0 |
dylib_command aggregated: 3 |
---|
Name | Value |
---|---|
name | 24 |
timestamp | Thu Jan 1 01:00:02 1970 |
current_version | 9.0.0 |
compatibility_version | 7.0.0 |
Datas |
Name | Value |
---|---|
name | 24 |
timestamp | Thu Jan 1 01:00:02 1970 |
current_version | 905.6.0 |
compatibility_version | 1.0.0 |
Datas |
Name | Value |
---|---|
name | 24 |
timestamp | Thu Jan 1 01:00:02 1970 |
current_version | 1292.100.5 |
compatibility_version | 1.0.0 |
Datas |
linkedit_data_command aggregated: 3 |
---|
Name | Value |
---|---|
dataoff | 136384 |
datasize | 368 |
Name | Value |
---|---|
dataoff | 136752 |
datasize | 0 |
Name | Value |
---|---|
dataoff | 143776 |
datasize | 19792 |
Internal Symbols |
---|
__NSGetExecutablePath |
__Unwind_Resume |
__ZNKSt13runtime_error4whatEv |
__ZNKSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE7compareEPKc |
__ZNKSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE7compareEmmPKcm |
__ZNKSt3__120__vector_base_commonILb1EE20__throw_length_errorEv |
__ZNKSt3__121__basic_string_commonILb1EE20__throw_length_errorEv |
__ZNKSt3__16locale9has_facetERNS0_2idE |
__ZNKSt3__16locale9use_facetERNS0_2idE |
__ZNKSt3__18ios_base6getlocEv |
__ZNKSt9exception4whatEv |
__ZNSt11logic_errorC2EPKc |
__ZNSt12length_errorD1Ev |
__ZNSt13runtime_errorC1EPKc |
__ZNSt13runtime_errorC1ERKS_ |
__ZNSt13runtime_errorD1Ev |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE5eraseEmm |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6appendEPKc |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6appendEPKcm |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6assignEPKc |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6insertEmPKc |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6resizeEmc |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE9__grow_byEmmmmmm |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE9push_backEc |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEEC1ERKS5_ |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEEC1ERKS5_mmRKS4_ |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEED1Ev |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEEaSERKS5_ |
__ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEE5flushEv |
__ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEE5writeEPKcl |
__ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEE6sentryC1ERS3_ |
__ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEE6sentryD1Ev |
__ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEED0Ev |
__ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEED1Ev |
__ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEED2Ev |
__ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEElsEi |
__ZNSt3__115basic_streambufIcNS_11char_traitsIcEEE5uflowEv |
__ZNSt3__115basic_streambufIcNS_11char_traitsIcEEE6xsgetnEPcl |
__ZNSt3__115basic_streambufIcNS_11char_traitsIcEEE6xsputnEPKcl |
__ZNSt3__115basic_streambufIcNS_11char_traitsIcEEE9showmanycEv |
__ZNSt3__115basic_streambufIcNS_11char_traitsIcEEEC2Ev |
__ZNSt3__115basic_streambufIcNS_11char_traitsIcEEED2Ev |
__ZNSt3__14__fs10filesystem14__current_pathEPNS_10error_codeE |
__ZNSt3__14__fs10filesystem18__create_directoryERKNS1_4pathEPNS_10error_codeE |
__ZNSt3__14__fs10filesystem8__removeERKNS1_4pathEPNS_10error_codeE |
__ZNSt3__14__fs10filesystem8__statusERKNS1_4pathEPNS_10error_codeE |
__ZNSt3__14cerrE |
__ZNSt3__14coutE |
__ZNSt3__15ctypeIcE2idE |
__ZNSt3__16localeC1ERKS0_ |
__ZNSt3__16localeD1Ev |
__ZNSt3__17codecvtIcc11__mbstate_tE2idE |
__ZNSt3__18ios_base33__set_badbit_and_consider_rethrowEv |
__ZNSt3__18ios_base4initEPv |
__ZNSt3__18ios_base5clearEj |
__ZNSt3__19basic_iosIcNS_11char_traitsIcEEED2Ev |
__ZNSt3__19to_stringEi |
__ZNSt3__19to_stringEm |
__ZNSt3__1plIcNS_11char_traitsIcEENS_9allocatorIcEEEENS_12basic_stringIT_T0_T1_EEPKS6_RKS9_ |
__ZNSt8bad_castC1Ev |
__ZNSt8bad_castD1Ev |
__ZNSt9exceptionD1Ev |
__ZNSt9exceptionD2Ev |
__ZSt9terminatev |
__ZTINSt3__113basic_ostreamIcNS_11char_traitsIcEEEE |
__ZTINSt3__115basic_streambufIcNS_11char_traitsIcEEEE |
__ZTISt12length_error |
__ZTISt13runtime_error |
__ZTISt8bad_cast |
__ZTISt9exception |
__ZTVN10__cxxabiv120__si_class_type_infoE |
__ZTVSt12length_error |
__ZTVSt9exception |
__ZTv0_n24_NSt3__113basic_ostreamIcNS_11char_traitsIcEEED0Ev |
__ZTv0_n24_NSt3__113basic_ostreamIcNS_11char_traitsIcEEED1Ev |
__ZdaPv |
__ZdlPv |
__Znam |
__Znwm |
___assert_rtn |
___cxa_allocate_exception |
___cxa_atexit |
___cxa_begin_catch |
___cxa_end_catch |
___cxa_free_exception |
___cxa_get_exception_ptr |
___cxa_throw |
___error |
___gxx_personality_v0 |
___stack_chk_fail |
___stack_chk_guard |
__mh_execute_header |
_bzero |
_curl_easy_cleanup |
_curl_easy_getinfo |
_curl_easy_init |
_curl_easy_perform |
_curl_easy_setopt |
_fclose |
_fflush |
_fgets |
_fopen |
_fread |
_fseek |
_fseeko |
_ftello |
_fwrite |
_localeconv |
_memchr |
_memcmp |
_memcpy |
_memmove |
_memset |
_pclose |
_popen |
_rand |
_sleep |
_snprintf |
_strlen |
_strtod |
_strtoll |
_strtoull |
_system |
dyld_stub_binder |
radr://5614542 |
External symbols |
---|
__NSGetExecutablePath |
__Unwind_Resume |
__ZNKSt13runtime_error4whatEv |
__ZNKSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE7compareEPKc |
__ZNKSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE7compareEmmPKcm |
__ZNKSt3__120__vector_base_commonILb1EE20__throw_length_errorEv |
__ZNKSt3__121__basic_string_commonILb1EE20__throw_length_errorEv |
__ZNKSt3__16locale9has_facetERNS0_2idE |
__ZNKSt3__16locale9use_facetERNS0_2idE |
__ZNKSt3__18ios_base6getlocEv |
__ZNSt11logic_errorC2EPKc |
__ZNSt13runtime_errorC1EPKc |
__ZNSt13runtime_errorC1ERKS_ |
__ZNSt13runtime_errorD1Ev |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE5eraseEmm |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6appendEPKc |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6appendEPKcm |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6assignEPKc |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6insertEmPKc |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6resizeEmc |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE9__grow_byEmmmmmm |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE9push_backEc |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEEC1ERKS5_ |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEEC1ERKS5_mmRKS4_ |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEED1Ev |
__ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEEaSERKS5_ |
__ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEE5flushEv |
__ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEE5writeEPKcl |
__ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEE6sentryC1ERS3_ |
__ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEE6sentryD1Ev |
__ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEED2Ev |
__ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEElsEi |
__ZNSt3__115basic_streambufIcNS_11char_traitsIcEEEC2Ev |
__ZNSt3__115basic_streambufIcNS_11char_traitsIcEEED2Ev |
__ZNSt3__14__fs10filesystem14__current_pathEPNS_10error_codeE |
__ZNSt3__14__fs10filesystem18__create_directoryERKNS1_4pathEPNS_10error_codeE |
__ZNSt3__14__fs10filesystem8__removeERKNS1_4pathEPNS_10error_codeE |
__ZNSt3__14__fs10filesystem8__statusERKNS1_4pathEPNS_10error_codeE |
__ZNSt3__16localeC1ERKS0_ |
__ZNSt3__16localeD1Ev |
__ZNSt3__18ios_base33__set_badbit_and_consider_rethrowEv |
__ZNSt3__18ios_base4initEPv |
__ZNSt3__18ios_base5clearEj |
__ZNSt3__19basic_iosIcNS_11char_traitsIcEEED2Ev |
__ZNSt3__19to_stringEi |
__ZNSt3__19to_stringEm |
__ZNSt3__1plIcNS_11char_traitsIcEENS_9allocatorIcEEEENS_12basic_stringIT_T0_T1_EEPKS6_RKS9_ |
__ZNSt8bad_castC1Ev |
__ZNSt9exceptionD1Ev |
__ZNSt9exceptionD2Ev |
__ZSt9terminatev |
___assert_rtn |
___cxa_allocate_exception |
___cxa_atexit |
___cxa_begin_catch |
___cxa_end_catch |
___cxa_free_exception |
___cxa_get_exception_ptr |
___cxa_throw |
___error |
___stack_chk_fail |
_bzero |
_curl_easy_cleanup |
_curl_easy_getinfo |
_curl_easy_init |
_curl_easy_perform |
_curl_easy_setopt |
_fclose |
_fflush |
_fgets |
_fopen |
_fread |
_fseek |
_fseeko |
_ftello |
_fwrite |
_localeconv |
_memchr |
_memcmp |
_memcpy |
_memmove |
_memset |
_pclose |
_popen |
_rand |
_sleep |
_snprintf |
_strlen |
_strtod |
_strtoll |
_strtoull |
_system |
Network Behavior |
---|
Network Port Distribution |
---|
TCP Packets |
---|
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 12, 2022 09:24:43.187191010 CET | 49276 | 443 | 192.168.11.11 | 17.171.27.65 |
Jan 12, 2022 09:24:43.187468052 CET | 49276 | 443 | 192.168.11.11 | 17.171.27.65 |
Jan 12, 2022 09:24:43.290016890 CET | 443 | 49276 | 17.171.27.65 | 192.168.11.11 |
Jan 12, 2022 09:24:43.290086031 CET | 443 | 49276 | 17.171.27.65 | 192.168.11.11 |
Jan 12, 2022 09:24:43.290134907 CET | 443 | 49276 | 17.171.27.65 | 192.168.11.11 |
Jan 12, 2022 09:24:43.290559053 CET | 49276 | 443 | 192.168.11.11 | 17.171.27.65 |
Jan 12, 2022 09:24:43.290651083 CET | 49276 | 443 | 192.168.11.11 | 17.171.27.65 |
Jan 12, 2022 09:25:10.926685095 CET | 49285 | 80 | 192.168.11.11 | 17.253.55.202 |
Jan 12, 2022 09:25:10.926788092 CET | 49286 | 80 | 192.168.11.11 | 104.90.164.244 |
Jan 12, 2022 09:25:10.936388969 CET | 80 | 49285 | 17.253.55.202 | 192.168.11.11 |
Jan 12, 2022 09:25:10.937376022 CET | 49285 | 80 | 192.168.11.11 | 17.253.55.202 |
Jan 12, 2022 09:25:10.945956945 CET | 80 | 49286 | 104.90.164.244 | 192.168.11.11 |
Jan 12, 2022 09:25:10.947089911 CET | 49286 | 80 | 192.168.11.11 | 104.90.164.244 |
UDP Packets |
---|
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 12, 2022 09:25:13.600723028 CET | 53 | 54523 | 1.1.1.1 | 192.168.11.11 |
System Behavior |
---|
General |
---|
Start time: | 09:24:44 |
Start date: | 12/01/2022 |
Path: | /Library/Frameworks/Mono.framework/Versions/4.4.2/bin/mono-sgen32 |
Arguments: | n/a |
File size: | 3722408 bytes |
MD5 hash: | 8910349f44a940d8d79318367855b236 |
General |
---|
Start time: | 09:24:44 |
Start date: | 12/01/2022 |
Path: | /Users/berri/Desktop/J5RBhmpBtw |
Arguments: | /Users/berri/Desktop/J5RBhmpBtw |
File size: | 360176 bytes |
MD5 hash: | e06e06752509f9cd8bc85aa1aa24dba2 |
General |
---|
Start time: | 09:24:44 |
Start date: | 12/01/2022 |
Path: | /bin/sh |
Arguments: | n/a |
File size: | 618512 bytes |
MD5 hash: | 8aa60b22a5d30418a002b340989384dc |
General |
---|
Start time: | 09:24:44 |
Start date: | 12/01/2022 |
Path: | /usr/bin/whoami |
Arguments: | whoami |
File size: | 23248 bytes |
MD5 hash: | 24c45eb23e1aae68c572939d1a906018 |