macOS Analysis Report
pwm_3.3.1.1_x86-64.dmg

Overview

General Information

Sample Name: pwm_3.3.1.1_x86-64.dmg
Analysis ID: 752916
MD5: 26e236876eb64279f77d118fbac3f06d
SHA1: 5519ff231aedc7394c5dd350b0b6058f253874c7
SHA256: bd03a05dc21fa6ed0a3b35165df535896966f0f28279e07e7934d5e9e9ade8d8
Infos:

Detection

Score: 3
Range: 0 - 100
Whitelisted: false

Signatures

Reads the systems hostname
Reads hardware related sysctl values
Creates hidden files, links and/or directories
Reads the sysctl safe boot value (probably to check if the system is in safe boot mode)
Reads the systems OS release and/or type
Reads launchservices plist files

Classification

Source: unknown DNS traffic detected: queries for: etappservices.appspot.com
Source: /Volumes/PWMinder_3.3.1.1/PWMinder.app/Contents/MacOS/PWMinder (PID: 901) Writes from socket in process: data Jump to behavior
Source: unknown TCP traffic detected without corresponding DNS query: 17.253.15.202
Source: unknown TCP traffic detected without corresponding DNS query: 88.221.168.210
Source: unknown TCP traffic detected without corresponding DNS query: 17.253.15.202
Source: unknown TCP traffic detected without corresponding DNS query: 88.221.168.210
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown HTTP traffic detected: POST /expiryCheck HTTP/1.1Content-Type: application/x-www-form-urlencodedContent-Length: 168Host: etappservices.appspot.comConnection: Keep-AliveUser-Agent: Apache-HttpClient/4.5.13 (Java/17.0.5)Accept-Encoding: gzip,deflateData Raw: 61 70 70 6c 69 63 61 74 69 6f 6e 49 64 3d 30 26 61 70 70 6c 69 63 61 74 69 6f 6e 56 65 72 69 6f 6e 3d 33 2e 33 2e 31 26 6f 70 65 72 61 74 69 6e 67 53 79 73 74 65 6d 3d 4d 61 63 2b 4f 53 2b 58 2b 25 32 38 31 30 2e 31 33 2e 32 25 32 39 26 6d 61 63 68 69 6e 65 55 69 64 3d 66 30 34 32 63 64 35 37 31 61 39 65 62 35 66 39 63 34 62 31 65 36 39 34 64 63 61 31 38 64 36 66 26 65 78 70 69 72 79 54 69 6d 65 73 74 61 6d 70 3d 31 36 37 31 38 34 35 32 38 35 33 39 36 26 61 73 73 75 6d 65 64 46 74 75 3d 74 72 75 65 Data Ascii: applicationId=0&applicationVerion=3.3.1&operatingSystem=Mac+OS+X+%2810.13.2%29&machineUid=f042cd571a9eb5f9c4b1e694dca18d6f&expiryTimestamp=1671845285396&assumedFtu=true
Source: /Volumes/PWMinder_3.3.1.1/PWMinder.app/Contents/MacOS/PWMinder (PID: 901) Reads from socket in process: data Jump to behavior
Source: classification engine Classification label: clean3.macDMG@0/24@2/0
Source: pwm_3.3.1.1_x86-64.dmg Binary or memory string: !eL.VbP
Source: /Volumes/PWMinder_3.3.1.1/PWMinder.app/Contents/MacOS/PWMinder (PID: 901) Hidden Directory created: /Users/berri/.pwminder -> /Users/berri/.pwminder Jump to behavior
Source: /usr/bin/open (PID: 900) Launchservices plist file read: /System/Library/Preferences/Logging/Subsystems/com.apple.launchservices.plist Jump to behavior
Source: /Volumes/PWMinder_3.3.1.1/PWMinder.app/Contents/MacOS/PWMinder (PID: 901) Launchservices plist file read: /System/Library/Preferences/Logging/Subsystems/com.apple.launchservices.plist Jump to behavior
Source: /Volumes/PWMinder_3.3.1.1/PWMinder.app/Contents/MacOS/PWMinder (PID: 901) AppleKeyboardLayouts info plist opened: /System/Library/Keyboard Layouts/AppleKeyboardLayouts.bundle/Contents/Info.plist Jump to behavior
Source: /Volumes/PWMinder_3.3.1.1/PWMinder.app/Contents/MacOS/PWMinder (PID: 901) Random device file read: /dev/urandom Jump to behavior
Source: /Volumes/PWMinder_3.3.1.1/PWMinder.app/Contents/MacOS/PWMinder (PID: 901) Random device file read: /dev/urandom Jump to behavior
Source: /Volumes/PWMinder_3.3.1.1/PWMinder.app/Contents/MacOS/PWMinder (PID: 901) Random device file read: /dev/random Jump to behavior
Source: /Volumes/PWMinder_3.3.1.1/PWMinder.app/Contents/MacOS/PWMinder (PID: 901) Log file created: /Users/berri/.pwminder/log/PWMinder.log Jump to dropped file
Source: submission CodeSign Info: Executable=/Volumes/PWMinder_3.3.1.1/PWMinder.app/Contents/MacOS/PWMinder
Source: /Volumes/PWMinder_3.3.1.1/PWMinder.app/Contents/MacOS/PWMinder (PID: 901) Sysctl read request: kern.safeboot (1.66) Jump to behavior
Source: /Volumes/PWMinder_3.3.1.1/PWMinder.app/Contents/MacOS/PWMinder (PID: 901) Sysctl requested: kern.hostname (1.10) Jump to behavior
Source: /Volumes/PWMinder_3.3.1.1/PWMinder.app/Contents/MacOS/PWMinder (PID: 901) Sysctl read request: hw.ncpu (6.3) Jump to behavior
Source: /Volumes/PWMinder_3.3.1.1/PWMinder.app/Contents/MacOS/PWMinder (PID: 901) Sysctl read request: hw.memsize (6.24) Jump to behavior
Source: /Volumes/PWMinder_3.3.1.1/PWMinder.app/Contents/MacOS/PWMinder (PID: 901) Sysctl read request: hw.availcpu (6.25) Jump to behavior
Source: /Volumes/PWMinder_3.3.1.1/PWMinder.app/Contents/MacOS/PWMinder (PID: 901) Sysctl requested: kern.ostype (1.1) Jump to behavior
Source: /Volumes/PWMinder_3.3.1.1/PWMinder.app/Contents/MacOS/PWMinder (PID: 901) Sysctl requested: kern.osrelease (1.2) Jump to behavior
Source: /usr/bin/open (PID: 900) System or server version plist file read: /System/Library/CoreServices/SystemVersion.plist Jump to behavior
Source: /Volumes/PWMinder_3.3.1.1/PWMinder.app/Contents/MacOS/PWMinder (PID: 901) System or server version plist file read: /System/Library/CoreServices/SystemVersion.plist Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs