Loading ...

Play interactive tourEdit tour

macOS Analysis Report J5RBhmpBtw

Overview

General Information

Sample Name:J5RBhmpBtw
Analysis ID:551503
MD5:e06e06752509f9cd8bc85aa1aa24dba2
SHA1:554aef8bf44e7fa941e1190e41c8770e90f07254
SHA256:1a9a5c797777f37463b44de2b49a7f95abca786db3977dcdac0f79da739c08ac
Infos:

Most interesting Screenshot:

Detection

SysJoker
Score:56
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Yara detected SysJoker
Executes commands using a shell command-line interpreter
Reads the systems hostname

Classification

Analysis Advice

Exit code suggests that the sample could not be started, try looking at standard streams or writes to anonymous pipes for possible reason
Exit code information suggests that the sample terminated abnormally, try to lookup the sample's target architecture
Non-zero exit code suggests an error during the execution. Lookup the error code for hints.

General Information

Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:551503
Start date:12.01.2022
Start time:09:23:51
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 3m 34s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:J5RBhmpBtw
Cookbook file name:defaultmacfilecookbook.jbs
Analysis system description:Virtual Machine, High Sierra (Office 2016 16.16, Java 11.0.2+9, Adobe Reader 2019.010.20099)
Analysis Mode:default
Detection:MAL
Classification:mal56.troj.mac@0/0@0/0
Warnings:
Show All
  • Excluded IPs from analysis (whitelisted): 104.92.88.33, 2.22.33.179
  • Excluded domains from analysis (whitelisted): cds-cdn.v.aaplimg.com, cds.apple.com.edgekey.net, e11408.d.akamaiedge.net, cds.apple.com.akadns.net, help.origin-apple.com.akadns.net, cds.apple.com, help.apple.com, e14768.dscb.akamaiedge.net, help-ar.apple.com.edgekey.net, lb._dns-sd._udp.0.11.168.192.in-addr.arpa

Process Tree

  • System is macvm-highsierra
  • J5RBhmpBtw (MD5: e06e06752509f9cd8bc85aa1aa24dba2) Arguments: /Users/berri/Desktop/J5RBhmpBtw
    • sh New Fork (PID: 830, Parent: 829)
    • whoami (MD5: 24c45eb23e1aae68c572939d1a906018) Arguments: whoami
  • cleanup

Yara Overview

Initial Sample

SourceRuleDescriptionAuthorStrings
J5RBhmpBtwJoeSecurity_SysJokerYara detected SysJokerJoe Security

    Memory Dumps

    SourceRuleDescriptionAuthorStrings
    00000829.00000279.1.000000010409b000.00000001040b3000.r-x.sdmpJoeSecurity_SysJokerYara detected SysJokerJoe Security
      Process Memory Space: J5RBhmpBtw PID: 829JoeSecurity_SysJokerYara detected SysJokerJoe Security

        Jbx Signature Overview

        Click to jump to signature section

        Show All Signature Results

        AV Detection:

        barindex
        Multi AV Scanner detection for submitted fileShow sources
        Source: J5RBhmpBtwVirustotal: Detection: 16%Perma Link
        Source: J5RBhmpBtwReversingLabs: Detection: 13%
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49276
        Source: unknownNetwork traffic detected: HTTP traffic on port 49276 -> 443
        Source: J5RBhmpBtw, 00000829.00000279.1.000000010f7a8000.000000010f7c3000.r--.sdmpString found in binary or memory: http://crl.apple.com/codesigning.crl0
        Source: J5RBhmpBtwString found in binary or memory: http://www.apple.com/DTDs/PropertyList-1.0.dtd
        Source: J5RBhmpBtw, 00000829.00000279.1.000000010f7a8000.000000010f7c3000.r--.sdmpString found in binary or memory: http://www.apple.com/appleca/root.crl0
        Source: J5RBhmpBtw, 00000829.00000279.1.000000010f7a8000.000000010f7c3000.r--.sdmpString found in binary or memory: http://www.apple.com/certificateauthority0
        Source: J5RBhmpBtwString found in binary or memory: https://drive.google.com/uc?export=download&id=1W64PQQxrwY3XjBnv_QAeBQu-ePr537eu
        Source: J5RBhmpBtwString found in binary or memory: https://drive.google.com/uc?export=download&id=1W64PQQxrwY3XjBnv_QAeBQu-ePr537eus
        Source: J5RBhmpBtw, 00000829.00000279.1.000000010f7a8000.000000010f7c3000.r--.sdmpString found in binary or memory: https://www.apple.com/appleca/0
        Source: unknownTCP traffic detected without corresponding DNS query: 17.171.27.65
        Source: unknownTCP traffic detected without corresponding DNS query: 17.171.27.65
        Source: unknownTCP traffic detected without corresponding DNS query: 17.171.27.65
        Source: unknownTCP traffic detected without corresponding DNS query: 17.171.27.65
        Source: unknownTCP traffic detected without corresponding DNS query: 17.253.55.202
        Source: unknownTCP traffic detected without corresponding DNS query: 104.90.164.244
        Source: unknownTCP traffic detected without corresponding DNS query: 17.253.55.202
        Source: unknownTCP traffic detected without corresponding DNS query: 104.90.164.244
        Source: classification engineClassification label: mal56.troj.mac@0/0@0/0
        Source: /Users/berri/Desktop/J5RBhmpBtw (PID: 829)Shell command executed: sh -c whoami
        Source: /bin/sh (PID: 830)Sysctl requested: kern.hostname (1.10)

        Stealing of Sensitive Information:

        barindex
        Yara detected SysJokerShow sources
        Source: Yara matchFile source: J5RBhmpBtw, type: SAMPLE
        Source: Yara matchFile source: 00000829.00000279.1.000000010409b000.00000001040b3000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: J5RBhmpBtw PID: 829, type: MEMORYSTR

        Remote Access Functionality:

        barindex
        Yara detected SysJokerShow sources
        Source: Yara matchFile source: J5RBhmpBtw, type: SAMPLE
        Source: Yara matchFile source: 00000829.00000279.1.000000010409b000.00000001040b3000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: J5RBhmpBtw PID: 829, type: MEMORYSTR

        Mitre Att&ck Matrix

        Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
        Valid AccountsScripting1Path InterceptionPath InterceptionScripting1OS Credential DumpingSystem Information Discovery1Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
        Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothApplication Layer Protocol1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout

        Behavior Graph

        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Number of created Files
        • Shell
        • Is malicious
        • Internet

        Screenshots

        Thumbnails

        This section contains all screenshots as thumbnails, including those not shown in the slideshow.

        cam-macmac-stand

        Antivirus, Machine Learning and Genetic Malware Detection

        Initial Sample

        SourceDetectionScannerLabelLink
        J5RBhmpBtw17%VirustotalBrowse
        J5RBhmpBtw14%ReversingLabsMacOS.Backdoor.SysJoker

        Dropped Files

        No Antivirus matches

        Domains

        No Antivirus matches

        URLs

        No Antivirus matches

        Domains and IPs

        Contacted Domains

        No contacted domains info

        Contacted IPs

        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs

        Public

        IPDomainCountryFlagASNASN NameMalicious
        104.90.164.244
        unknownUnited States
        16625AKAMAI-ASUSfalse

        Joe Sandbox View / Context

        IPs

        No context

        Domains

        No context

        ASN

        No context

        JA3 Fingerprints

        No context

        Dropped Files

        No context


        Runtime Messages

        Command:/Users/berri/Desktop/J5RBhmpBtw
        Exit Code:134
        Exit Code Info:SIGABRT (6) Abort signal from abort
        Killed:False
        Standard Output:

        Standard Error:dyld: lazy symbol binding failed: Symbol not found: __ZNSt3__14__fs10filesystem8__statusERKNS1_4pathEPNS_10error_codeE
        Referenced from: /Users/berri/Desktop/J5RBhmpBtw (which was built for Mac OS X 11.3)
        Expected in: /usr/lib/libc++.1.dylib

        dyld: Symbol not found: __ZNSt3__14__fs10filesystem8__statusERKNS1_4pathEPNS_10error_codeE
        Referenced from: /Users/berri/Desktop/J5RBhmpBtw (which was built for Mac OS X 11.3)
        Expected in: /usr/lib/libc++.1.dylib

        Created / dropped Files

        No created / dropped files found

        Static File Info

        General

        File type:Mach-O universal binary with 2 architectures: [x86_64:Mach-O 64-bit x86_64 executable, flags:<NOUNDEFS|DYLDLINK|TWOLEVEL|WEAK_DEFINES|BINDS_TO_WEAK|PIE>] [arm64:Mach-O 64-bit arm64 executable, flags:<NOUNDEFS|DYLDLINK|TWOLEVEL|WEAK_DEFINES|BINDS_TO_WEAK|PIE>]
        Entropy (8bit):4.67371613955121
        TrID:
        • Mac OS X Universal Binary executable (4004/1) 75.96%
        • HSC music composer song (1267/141) 24.04%
        File name:J5RBhmpBtw
        File size:360176
        MD5:e06e06752509f9cd8bc85aa1aa24dba2
        SHA1:554aef8bf44e7fa941e1190e41c8770e90f07254
        SHA256:1a9a5c797777f37463b44de2b49a7f95abca786db3977dcdac0f79da739c08ac
        SHA512:78a210c5fd1ac8c601fbb4ed226e7aaf1cc5bda187807ba3020997862fd54b59081f0b7f4fdc720acfa8e3d6a35dbe9309e0b2fe38088f493a02717a1057a56e
        SSDEEP:6144:5xw19koSAgvRyrnN5ft9A7pIHWhT5FixbxLZ:CvgMrnN51qaH+T5wl
        File Content Preview:..................@.......................~....................................................................................................................................................................................................................
        Static Mach Info
        General Information for header 1
        Endian:<
        Size:64-bit
        Architecture:x86_64
        Filetype:execute
        Nbr. of load commands:19
        Entry point:0x6884
        segment_command_64 aggregated: 5
        NameValue
        segname__PAGEZERO
        vmaddr0x0
        vmsize0x100000000
        fileoff0x0
        filesize0x0
        maxprot0x0
        initprot0x0
        nsects0
        flags0x0
        NameValue
        segname__TEXT
        vmaddr0x100000000
        vmsize0x18000
        fileoff0x0
        filesize0x18000
        maxprot0x5
        initprot0x5
        nsects7
        flags0x0
        Datas
        sectnamesegnameaddrsizeoffsetentropyalignreloffnrelocflags
        __text__TEXT0x100001EF00x124F70x1EF06.21230x40x000x80000400
        __stubs__TEXT0x1000143E80x2400x143E83.33520x10x000x80000408
        __stub_helper__TEXT0x1000146280x3A80x146284.52660x20x000x80000400
        __gcc_except_tab__TEXT0x1000149D00x129C0x149D06.06750x20x000x0
        __const__TEXT0x100015C700x2C00x15C702.48480x40x000x0
        __cstring__TEXT0x100015F300x1A7F0x15F305.32350x40x000x2
        __unwind_info__TEXT0x1000179B00x6440x179B05.42380x20x000x0
        NameValue
        segname__DATA_CONST
        vmaddr0x100018000
        vmsize0x4000
        fileoff0x18000
        filesize0x4000
        maxprot0x3
        initprot0x3
        nsects3
        flags0x10
        Datas
        sectnamesegnameaddrsizeoffsetentropyalignreloffnrelocflags
        __got__DATA_CONST0x1000180000xB80x180000.88620x30x000x6
        __mod_init_func__DATA_CONST0x1000180B80x80x180B81.75000x30x000x9
        __const__DATA_CONST0x1000180C00x3C80x180C02.48480x30x000x0
        NameValue
        segname__DATA
        vmaddr0x10001C000
        vmsize0x4000
        fileoff0x1C000
        filesize0x4000
        maxprot0x3
        initprot0x3
        nsects3
        flags0x0
        Datas
        sectnamesegnameaddrsizeoffsetentropyalignreloffnrelocflags
        __la_symbol_ptr__DATA0x10001C0000x3000x1C0002.71640x30x000x7
        __data__DATA0x10001C3000xC0x1C3000.41380x30x000x0
        __common__DATA0x10001C3100xF00x0-0.00000x30x000x1
        NameValue
        segname__LINKEDIT
        vmaddr0x100020000
        vmsize0xC000
        fileoff0x20000
        filesize0x8310
        maxprot0x1
        initprot0x1
        nsects0
        flags0x0
        dyld_info_command aggregated: 1
        NameValue
        rebase_off131072
        rebase_size56
        bind_off131128
        bind_size1360
        weak_bind_off132488
        weak_bind_size456
        lazy_bind_off132944
        lazy_bind_size3752
        export_off136696
        export_size312
        symtab_command aggregated: 1
        NameValue
        symoff137440
        nsyms131
        stroff140400
        strsize4432
        dysymtab_command aggregated: 1
        NameValue
        ilocalsym0
        nlocalsym1
        iextdefsym1
        nextdefsym7
        iundefsym8
        nundefsym123
        tocoff0
        ntoc0
        modtaboff0
        nmodtab0
        extrefsymoff0
        nextrefsyms0
        indirectsymoff139536
        nindirectsyms215
        extreloff0
        nextrel0
        locreloff0
        nlocrel0
        dylinker_command aggregated: 1
        NameValue
        name12
        Datas/usr/lib/dyld
        uuid_command aggregated: 1
        NameValue
        uuidb'\x81t\x81~\xf4\xcf9\x8d\x97[x`Fn\xae\xc7'
        build_version_command aggregated: 1
        NameValue
        platform1
        minos721664
        sdk721664
        ntools1
        Datas.
        source_version_command aggregated: 1
        NameValue
        version0
        entry_point_command aggregated: 1
        NameValue
        entryoff26756
        stacksize0
        dylib_command aggregated: 3
        NameValue
        name24
        timestampThu Jan 1 01:00:02 1970
        current_version9.0.0
        compatibility_version7.0.0
        Datas/usr/lib/libcurl.4.dylib
        NameValue
        name24
        timestampThu Jan 1 01:00:02 1970
        current_version905.6.0
        compatibility_version1.0.0
        Datas/usr/lib/libc++.1.dylib
        NameValue
        name24
        timestampThu Jan 1 01:00:02 1970
        current_version1292.100.5
        compatibility_version1.0.0
        Datas/usr/lib/libSystem.B.dylib
        linkedit_data_command aggregated: 3
        NameValue
        dataoff137008
        datasize360
        NameValue
        dataoff137368
        datasize72
        NameValue
        dataoff144832
        datasize19792
        Internal Symbols
        __NSGetExecutablePath
        __Unwind_Resume
        __ZNKSt13runtime_error4whatEv
        __ZNKSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE7compareEPKc
        __ZNKSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE7compareEmmPKcm
        __ZNKSt3__120__vector_base_commonILb1EE20__throw_length_errorEv
        __ZNKSt3__121__basic_string_commonILb1EE20__throw_length_errorEv
        __ZNKSt3__16locale9has_facetERNS0_2idE
        __ZNKSt3__16locale9use_facetERNS0_2idE
        __ZNKSt3__18ios_base6getlocEv
        __ZNKSt9exception4whatEv
        __ZNSt11logic_errorC2EPKc
        __ZNSt12length_errorD1Ev
        __ZNSt13runtime_errorC1EPKc
        __ZNSt13runtime_errorC1ERKS_
        __ZNSt13runtime_errorD1Ev
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE5eraseEmm
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6appendEPKc
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6appendEPKcm
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6assignEPKc
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6insertEmPKc
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6resizeEmc
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE9__grow_byEmmmmmm
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE9push_backEc
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEEC1ERKS5_
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEEC1ERKS5_mmRKS4_
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEED1Ev
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEEaSERKS5_
        __ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEE5flushEv
        __ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEE5writeEPKcl
        __ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEE6sentryC1ERS3_
        __ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEE6sentryD1Ev
        __ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEED0Ev
        __ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEED1Ev
        __ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEED2Ev
        __ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEElsEi
        __ZNSt3__115basic_streambufIcNS_11char_traitsIcEEE5uflowEv
        __ZNSt3__115basic_streambufIcNS_11char_traitsIcEEE6xsgetnEPcl
        __ZNSt3__115basic_streambufIcNS_11char_traitsIcEEE6xsputnEPKcl
        __ZNSt3__115basic_streambufIcNS_11char_traitsIcEEE9showmanycEv
        __ZNSt3__115basic_streambufIcNS_11char_traitsIcEEEC2Ev
        __ZNSt3__115basic_streambufIcNS_11char_traitsIcEEED2Ev
        __ZNSt3__14__fs10filesystem14__current_pathEPNS_10error_codeE
        __ZNSt3__14__fs10filesystem18__create_directoryERKNS1_4pathEPNS_10error_codeE
        __ZNSt3__14__fs10filesystem8__removeERKNS1_4pathEPNS_10error_codeE
        __ZNSt3__14__fs10filesystem8__statusERKNS1_4pathEPNS_10error_codeE
        __ZNSt3__14cerrE
        __ZNSt3__14coutE
        __ZNSt3__15ctypeIcE2idE
        __ZNSt3__16localeC1ERKS0_
        __ZNSt3__16localeD1Ev
        __ZNSt3__17codecvtIcc11__mbstate_tE2idE
        __ZNSt3__18ios_base33__set_badbit_and_consider_rethrowEv
        __ZNSt3__18ios_base4initEPv
        __ZNSt3__18ios_base5clearEj
        __ZNSt3__19basic_iosIcNS_11char_traitsIcEEED2Ev
        __ZNSt3__19to_stringEi
        __ZNSt3__19to_stringEm
        __ZNSt3__1plIcNS_11char_traitsIcEENS_9allocatorIcEEEENS_12basic_stringIT_T0_T1_EEPKS6_RKS9_
        __ZNSt8bad_castC1Ev
        __ZNSt8bad_castD1Ev
        __ZNSt9exceptionD1Ev
        __ZNSt9exceptionD2Ev
        __ZSt9terminatev
        __ZTINSt3__113basic_filebufIcNS_11char_traitsIcEEEE
        __ZTINSt3__113basic_ostreamIcNS_11char_traitsIcEEEE
        __ZTINSt3__114basic_ofstreamIcNS_11char_traitsIcEEEE
        __ZTINSt3__115basic_streambufIcNS_11char_traitsIcEEEE
        __ZTINSt3__117bad_function_callE
        __ZTISt12length_error
        __ZTISt13runtime_error
        __ZTISt8bad_cast
        __ZTISt9exception
        __ZTSNSt3__113basic_filebufIcNS_11char_traitsIcEEEE
        __ZTSNSt3__114basic_ofstreamIcNS_11char_traitsIcEEEE
        __ZTSNSt3__117bad_function_callE
        __ZTVN10__cxxabiv120__si_class_type_infoE
        __ZTVSt12length_error
        __ZTVSt9exception
        __ZTv0_n24_NSt3__113basic_ostreamIcNS_11char_traitsIcEEED0Ev
        __ZTv0_n24_NSt3__113basic_ostreamIcNS_11char_traitsIcEEED1Ev
        __ZdaPv
        __ZdlPv
        __Znam
        __Znwm
        ___assert_rtn
        ___bzero
        ___cxa_allocate_exception
        ___cxa_atexit
        ___cxa_begin_catch
        ___cxa_end_catch
        ___cxa_free_exception
        ___cxa_get_exception_ptr
        ___cxa_throw
        ___error
        ___gxx_personality_v0
        ___stack_chk_fail
        ___stack_chk_guard
        __mh_execute_header
        _curl_easy_cleanup
        _curl_easy_getinfo
        _curl_easy_init
        _curl_easy_perform
        _curl_easy_setopt
        _fclose
        _fflush
        _fgets
        _fopen
        _fread
        _fseek
        _fseeko
        _ftello
        _fwrite
        _localeconv
        _memchr
        _memcmp
        _memcpy
        _memmove
        _memset
        _pclose
        _popen
        _rand
        _sleep
        _snprintf
        _strlen
        _strtod
        _strtoll
        _strtoull
        _system
        dyld_stub_binder
        radr://5614542
        External symbols
        __NSGetExecutablePath
        __Unwind_Resume
        __ZNKSt13runtime_error4whatEv
        __ZNKSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE7compareEPKc
        __ZNKSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE7compareEmmPKcm
        __ZNKSt3__120__vector_base_commonILb1EE20__throw_length_errorEv
        __ZNKSt3__121__basic_string_commonILb1EE20__throw_length_errorEv
        __ZNKSt3__16locale9has_facetERNS0_2idE
        __ZNKSt3__16locale9use_facetERNS0_2idE
        __ZNKSt3__18ios_base6getlocEv
        __ZNSt11logic_errorC2EPKc
        __ZNSt13runtime_errorC1EPKc
        __ZNSt13runtime_errorC1ERKS_
        __ZNSt13runtime_errorD1Ev
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE5eraseEmm
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6appendEPKc
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6appendEPKcm
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6assignEPKc
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6insertEmPKc
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6resizeEmc
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE9__grow_byEmmmmmm
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE9push_backEc
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEEC1ERKS5_
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEEC1ERKS5_mmRKS4_
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEED1Ev
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEEaSERKS5_
        __ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEE5flushEv
        __ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEE5writeEPKcl
        __ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEE6sentryC1ERS3_
        __ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEE6sentryD1Ev
        __ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEED2Ev
        __ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEElsEi
        __ZNSt3__115basic_streambufIcNS_11char_traitsIcEEEC2Ev
        __ZNSt3__115basic_streambufIcNS_11char_traitsIcEEED2Ev
        __ZNSt3__14__fs10filesystem14__current_pathEPNS_10error_codeE
        __ZNSt3__14__fs10filesystem18__create_directoryERKNS1_4pathEPNS_10error_codeE
        __ZNSt3__14__fs10filesystem8__removeERKNS1_4pathEPNS_10error_codeE
        __ZNSt3__14__fs10filesystem8__statusERKNS1_4pathEPNS_10error_codeE
        __ZNSt3__16localeC1ERKS0_
        __ZNSt3__16localeD1Ev
        __ZNSt3__18ios_base33__set_badbit_and_consider_rethrowEv
        __ZNSt3__18ios_base4initEPv
        __ZNSt3__18ios_base5clearEj
        __ZNSt3__19basic_iosIcNS_11char_traitsIcEEED2Ev
        __ZNSt3__19to_stringEi
        __ZNSt3__19to_stringEm
        __ZNSt3__1plIcNS_11char_traitsIcEENS_9allocatorIcEEEENS_12basic_stringIT_T0_T1_EEPKS6_RKS9_
        __ZNSt8bad_castC1Ev
        __ZNSt9exceptionD1Ev
        __ZNSt9exceptionD2Ev
        __ZSt9terminatev
        ___assert_rtn
        ___bzero
        ___cxa_allocate_exception
        ___cxa_atexit
        ___cxa_begin_catch
        ___cxa_end_catch
        ___cxa_free_exception
        ___cxa_get_exception_ptr
        ___cxa_throw
        ___error
        ___stack_chk_fail
        _curl_easy_cleanup
        _curl_easy_getinfo
        _curl_easy_init
        _curl_easy_perform
        _curl_easy_setopt
        _fclose
        _fflush
        _fgets
        _fopen
        _fread
        _fseek
        _fseeko
        _ftello
        _fwrite
        _localeconv
        _memchr
        _memcmp
        _memcpy
        _memmove
        _memset
        _pclose
        _popen
        _rand
        _sleep
        _snprintf
        _strlen
        _strtod
        _strtoll
        _strtoull
        _system
        General Information for header 2
        Endian:<
        Size:32-bit
        Architecture:ARM64
        Filetype:execute
        Nbr. of load commands:19
        Entry point:
        segment_command_64 aggregated: 5
        NameValue
        segname__PAGEZERO
        vmaddr0x0
        vmsize0x100000000
        fileoff0x0
        filesize0x0
        maxprot0x0
        initprot0x0
        nsects0
        flags0x0
        NameValue
        segname__TEXT
        vmaddr0x100000000
        vmsize0x18000
        fileoff0x0
        filesize0x18000
        maxprot0x5
        initprot0x5
        nsects8
        flags0x0
        Datas
        sectnamesegnameaddrsizeoffsetentropyalignreloffnrelocflags
        __text__TEXT0x100001EF00x11F600x1EF06.40520x20x000x80000400
        __stubs__TEXT0x100013E500x4800x13E503.86800x20x000x80000408
        __stub_helper__TEXT0x1000142D00x4680x142D04.10990x20x000x80000400
        __gcc_except_tab__TEXT0x1000147380x13580x147385.41220x20x000x0
        __const__TEXT0x100015A900x4480x15A902.47110x40x000x0
        __cstring__TEXT0x100015ED80x1A780x15ED85.32410x00x000x2
        __unwind_info__TEXT0x1000179500x62C0x179505.23470x20x000x0
        __eh_frame__TEXT0x100017F800x800x17F803.34560x30x000x0
        NameValue
        segname__DATA_CONST
        vmaddr0x100018000
        vmsize0x4000
        fileoff0x18000
        filesize0x4000
        maxprot0x3
        initprot0x3
        nsects3
        flags0x10
        Datas
        sectnamesegnameaddrsizeoffsetentropyalignreloffnrelocflags
        __got__DATA_CONST0x1000180000xB00x180000.78620x30x000x6
        __mod_init_func__DATA_CONST0x1000180B00x80x180B01.75000x30x000x9
        __const__DATA_CONST0x1000180B80x3C80x180B82.47110x30x000x0
        NameValue
        segname__DATA
        vmaddr0x10001C000
        vmsize0x4000
        fileoff0x1C000
        filesize0x4000
        maxprot0x3
        initprot0x3
        nsects3
        flags0x0
        Datas
        sectnamesegnameaddrsizeoffsetentropyalignreloffnrelocflags
        __la_symbol_ptr__DATA0x10001C0000x3000x1C0002.66750x30x000x7
        __data__DATA0x10001C3000xC0x1C3000.41380x30x000x0
        __common__DATA0x10001C3100xF00x0-0.00000x30x000x1
        NameValue
        segname__LINKEDIT
        vmaddr0x100020000
        vmsize0x8000
        fileoff0x20000
        filesize0x7EF0
        maxprot0x1
        initprot0x1
        nsects0
        flags0x0
        dyld_info_command aggregated: 1
        NameValue
        rebase_off131072
        rebase_size56
        bind_off131128
        bind_size1360
        weak_bind_off132488
        weak_bind_size120
        lazy_bind_off132608
        lazy_bind_size3744
        export_off136352
        export_size32
        symtab_command aggregated: 1
        NameValue
        symoff136752
        nsyms125
        stroff139608
        strsize4160
        dysymtab_command aggregated: 1
        NameValue
        ilocalsym0
        nlocalsym1
        iextdefsym1
        nextdefsym1
        iundefsym2
        nundefsym123
        tocoff0
        ntoc0
        modtaboff0
        nmodtab0
        extrefsymoff0
        nextrefsyms0
        indirectsymoff138752
        nindirectsyms214
        extreloff0
        nextrel0
        locreloff0
        nlocrel0
        dylinker_command aggregated: 1
        NameValue
        name12
        Datas/usr/lib/dyld
        uuid_command aggregated: 1
        NameValue
        uuidb'\xec\x10\xd8Nr?=\x9a\x85$\xcd\xc7\x06t\x9dh'
        build_version_command aggregated: 1
        NameValue
        platform1
        minos721664
        sdk721664
        ntools1
        Datas.
        source_version_command aggregated: 1
        NameValue
        version0
        entry_point_command aggregated: 1
        NameValue
        entryoff25300
        stacksize0
        dylib_command aggregated: 3
        NameValue
        name24
        timestampThu Jan 1 01:00:02 1970
        current_version9.0.0
        compatibility_version7.0.0
        Datas/usr/lib/libcurl.4.dylib
        NameValue
        name24
        timestampThu Jan 1 01:00:02 1970
        current_version905.6.0
        compatibility_version1.0.0
        Datas/usr/lib/libc++.1.dylib
        NameValue
        name24
        timestampThu Jan 1 01:00:02 1970
        current_version1292.100.5
        compatibility_version1.0.0
        Datas/usr/lib/libSystem.B.dylib
        linkedit_data_command aggregated: 3
        NameValue
        dataoff136384
        datasize368
        NameValue
        dataoff136752
        datasize0
        NameValue
        dataoff143776
        datasize19792
        Internal Symbols
        __NSGetExecutablePath
        __Unwind_Resume
        __ZNKSt13runtime_error4whatEv
        __ZNKSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE7compareEPKc
        __ZNKSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE7compareEmmPKcm
        __ZNKSt3__120__vector_base_commonILb1EE20__throw_length_errorEv
        __ZNKSt3__121__basic_string_commonILb1EE20__throw_length_errorEv
        __ZNKSt3__16locale9has_facetERNS0_2idE
        __ZNKSt3__16locale9use_facetERNS0_2idE
        __ZNKSt3__18ios_base6getlocEv
        __ZNKSt9exception4whatEv
        __ZNSt11logic_errorC2EPKc
        __ZNSt12length_errorD1Ev
        __ZNSt13runtime_errorC1EPKc
        __ZNSt13runtime_errorC1ERKS_
        __ZNSt13runtime_errorD1Ev
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE5eraseEmm
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6appendEPKc
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6appendEPKcm
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6assignEPKc
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6insertEmPKc
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6resizeEmc
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE9__grow_byEmmmmmm
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE9push_backEc
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEEC1ERKS5_
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEEC1ERKS5_mmRKS4_
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEED1Ev
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEEaSERKS5_
        __ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEE5flushEv
        __ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEE5writeEPKcl
        __ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEE6sentryC1ERS3_
        __ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEE6sentryD1Ev
        __ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEED0Ev
        __ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEED1Ev
        __ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEED2Ev
        __ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEElsEi
        __ZNSt3__115basic_streambufIcNS_11char_traitsIcEEE5uflowEv
        __ZNSt3__115basic_streambufIcNS_11char_traitsIcEEE6xsgetnEPcl
        __ZNSt3__115basic_streambufIcNS_11char_traitsIcEEE6xsputnEPKcl
        __ZNSt3__115basic_streambufIcNS_11char_traitsIcEEE9showmanycEv
        __ZNSt3__115basic_streambufIcNS_11char_traitsIcEEEC2Ev
        __ZNSt3__115basic_streambufIcNS_11char_traitsIcEEED2Ev
        __ZNSt3__14__fs10filesystem14__current_pathEPNS_10error_codeE
        __ZNSt3__14__fs10filesystem18__create_directoryERKNS1_4pathEPNS_10error_codeE
        __ZNSt3__14__fs10filesystem8__removeERKNS1_4pathEPNS_10error_codeE
        __ZNSt3__14__fs10filesystem8__statusERKNS1_4pathEPNS_10error_codeE
        __ZNSt3__14cerrE
        __ZNSt3__14coutE
        __ZNSt3__15ctypeIcE2idE
        __ZNSt3__16localeC1ERKS0_
        __ZNSt3__16localeD1Ev
        __ZNSt3__17codecvtIcc11__mbstate_tE2idE
        __ZNSt3__18ios_base33__set_badbit_and_consider_rethrowEv
        __ZNSt3__18ios_base4initEPv
        __ZNSt3__18ios_base5clearEj
        __ZNSt3__19basic_iosIcNS_11char_traitsIcEEED2Ev
        __ZNSt3__19to_stringEi
        __ZNSt3__19to_stringEm
        __ZNSt3__1plIcNS_11char_traitsIcEENS_9allocatorIcEEEENS_12basic_stringIT_T0_T1_EEPKS6_RKS9_
        __ZNSt8bad_castC1Ev
        __ZNSt8bad_castD1Ev
        __ZNSt9exceptionD1Ev
        __ZNSt9exceptionD2Ev
        __ZSt9terminatev
        __ZTINSt3__113basic_ostreamIcNS_11char_traitsIcEEEE
        __ZTINSt3__115basic_streambufIcNS_11char_traitsIcEEEE
        __ZTISt12length_error
        __ZTISt13runtime_error
        __ZTISt8bad_cast
        __ZTISt9exception
        __ZTVN10__cxxabiv120__si_class_type_infoE
        __ZTVSt12length_error
        __ZTVSt9exception
        __ZTv0_n24_NSt3__113basic_ostreamIcNS_11char_traitsIcEEED0Ev
        __ZTv0_n24_NSt3__113basic_ostreamIcNS_11char_traitsIcEEED1Ev
        __ZdaPv
        __ZdlPv
        __Znam
        __Znwm
        ___assert_rtn
        ___cxa_allocate_exception
        ___cxa_atexit
        ___cxa_begin_catch
        ___cxa_end_catch
        ___cxa_free_exception
        ___cxa_get_exception_ptr
        ___cxa_throw
        ___error
        ___gxx_personality_v0
        ___stack_chk_fail
        ___stack_chk_guard
        __mh_execute_header
        _bzero
        _curl_easy_cleanup
        _curl_easy_getinfo
        _curl_easy_init
        _curl_easy_perform
        _curl_easy_setopt
        _fclose
        _fflush
        _fgets
        _fopen
        _fread
        _fseek
        _fseeko
        _ftello
        _fwrite
        _localeconv
        _memchr
        _memcmp
        _memcpy
        _memmove
        _memset
        _pclose
        _popen
        _rand
        _sleep
        _snprintf
        _strlen
        _strtod
        _strtoll
        _strtoull
        _system
        dyld_stub_binder
        radr://5614542
        External symbols
        __NSGetExecutablePath
        __Unwind_Resume
        __ZNKSt13runtime_error4whatEv
        __ZNKSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE7compareEPKc
        __ZNKSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE7compareEmmPKcm
        __ZNKSt3__120__vector_base_commonILb1EE20__throw_length_errorEv
        __ZNKSt3__121__basic_string_commonILb1EE20__throw_length_errorEv
        __ZNKSt3__16locale9has_facetERNS0_2idE
        __ZNKSt3__16locale9use_facetERNS0_2idE
        __ZNKSt3__18ios_base6getlocEv
        __ZNSt11logic_errorC2EPKc
        __ZNSt13runtime_errorC1EPKc
        __ZNSt13runtime_errorC1ERKS_
        __ZNSt13runtime_errorD1Ev
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE5eraseEmm
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6appendEPKc
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6appendEPKcm
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6assignEPKc
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6insertEmPKc
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6resizeEmc
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE9__grow_byEmmmmmm
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE9push_backEc
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEEC1ERKS5_
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEEC1ERKS5_mmRKS4_
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEED1Ev
        __ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEEaSERKS5_
        __ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEE5flushEv
        __ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEE5writeEPKcl
        __ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEE6sentryC1ERS3_
        __ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEE6sentryD1Ev
        __ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEED2Ev
        __ZNSt3__113basic_ostreamIcNS_11char_traitsIcEEElsEi
        __ZNSt3__115basic_streambufIcNS_11char_traitsIcEEEC2Ev
        __ZNSt3__115basic_streambufIcNS_11char_traitsIcEEED2Ev
        __ZNSt3__14__fs10filesystem14__current_pathEPNS_10error_codeE
        __ZNSt3__14__fs10filesystem18__create_directoryERKNS1_4pathEPNS_10error_codeE
        __ZNSt3__14__fs10filesystem8__removeERKNS1_4pathEPNS_10error_codeE
        __ZNSt3__14__fs10filesystem8__statusERKNS1_4pathEPNS_10error_codeE
        __ZNSt3__16localeC1ERKS0_
        __ZNSt3__16localeD1Ev
        __ZNSt3__18ios_base33__set_badbit_and_consider_rethrowEv
        __ZNSt3__18ios_base4initEPv
        __ZNSt3__18ios_base5clearEj
        __ZNSt3__19basic_iosIcNS_11char_traitsIcEEED2Ev
        __ZNSt3__19to_stringEi
        __ZNSt3__19to_stringEm
        __ZNSt3__1plIcNS_11char_traitsIcEENS_9allocatorIcEEEENS_12basic_stringIT_T0_T1_EEPKS6_RKS9_
        __ZNSt8bad_castC1Ev
        __ZNSt9exceptionD1Ev
        __ZNSt9exceptionD2Ev
        __ZSt9terminatev
        ___assert_rtn
        ___cxa_allocate_exception
        ___cxa_atexit
        ___cxa_begin_catch
        ___cxa_end_catch
        ___cxa_free_exception
        ___cxa_get_exception_ptr
        ___cxa_throw
        ___error
        ___stack_chk_fail
        _bzero
        _curl_easy_cleanup
        _curl_easy_getinfo
        _curl_easy_init
        _curl_easy_perform
        _curl_easy_setopt
        _fclose
        _fflush
        _fgets
        _fopen
        _fread
        _fseek
        _fseeko
        _ftello
        _fwrite
        _localeconv
        _memchr
        _memcmp
        _memcpy
        _memmove
        _memset
        _pclose
        _popen
        _rand
        _sleep
        _snprintf
        _strlen
        _strtod
        _strtoll
        _strtoull
        _system

        Network Behavior

        Network Port Distribution

        TCP Packets

        TimestampSource PortDest PortSource IPDest IP
        Jan 12, 2022 09:24:43.187191010 CET49276443192.168.11.1117.171.27.65
        Jan 12, 2022 09:24:43.187468052 CET49276443192.168.11.1117.171.27.65
        Jan 12, 2022 09:24:43.290016890 CET4434927617.171.27.65192.168.11.11
        Jan 12, 2022 09:24:43.290086031 CET4434927617.171.27.65192.168.11.11
        Jan 12, 2022 09:24:43.290134907 CET4434927617.171.27.65192.168.11.11
        Jan 12, 2022 09:24:43.290559053 CET49276443192.168.11.1117.171.27.65
        Jan 12, 2022 09:24:43.290651083 CET49276443192.168.11.1117.171.27.65
        Jan 12, 2022 09:25:10.926685095 CET4928580192.168.11.1117.253.55.202
        Jan 12, 2022 09:25:10.926788092 CET4928680192.168.11.11104.90.164.244
        Jan 12, 2022 09:25:10.936388969 CET804928517.253.55.202192.168.11.11
        Jan 12, 2022 09:25:10.937376022 CET4928580192.168.11.1117.253.55.202
        Jan 12, 2022 09:25:10.945956945 CET8049286104.90.164.244192.168.11.11
        Jan 12, 2022 09:25:10.947089911 CET4928680192.168.11.11104.90.164.244

        UDP Packets

        TimestampSource PortDest PortSource IPDest IP
        Jan 12, 2022 09:25:13.600723028 CET53545231.1.1.1192.168.11.11

        System Behavior

        General

        Start time:09:24:44
        Start date:12/01/2022
        Path:/Library/Frameworks/Mono.framework/Versions/4.4.2/bin/mono-sgen32
        Arguments:n/a
        File size:3722408 bytes
        MD5 hash:8910349f44a940d8d79318367855b236

        General

        Start time:09:24:44
        Start date:12/01/2022
        Path:/Users/berri/Desktop/J5RBhmpBtw
        Arguments:/Users/berri/Desktop/J5RBhmpBtw
        File size:360176 bytes
        MD5 hash:e06e06752509f9cd8bc85aa1aa24dba2

        General

        Start time:09:24:44
        Start date:12/01/2022
        Path:/bin/sh
        Arguments:n/a
        File size:618512 bytes
        MD5 hash:8aa60b22a5d30418a002b340989384dc

        General

        Start time:09:24:44
        Start date:12/01/2022
        Path:/usr/bin/whoami
        Arguments:whoami
        File size:23248 bytes
        MD5 hash:24c45eb23e1aae68c572939d1a906018