Loading Joe Sandbox Report ...

Edit tour

macOS Analysis Report
DiskMaker_X_9.dmg

Overview

General Information

Sample Name:DiskMaker_X_9.dmg
Analysis ID:756104
MD5:d575c6a40278340f092a6fc4e26e4d11
SHA1:87d92610155135621014afefa88d8b6c9ad5f0ed
SHA256:96845cd375543401b822fb4e17d2ecc300fcb621f56afcdad613ae11c9afddce
Infos:

Detection

Score:8
Range:0 - 100
Whitelisted:false

Signatures

Uses AppleScript framework/components containing Apple Script related functionalities
Reads the systems hostname
Reads the kernel OS version value
Executes the "grep" command used to find patterns in files or piped streams
Reads the sysctl safe boot value (probably to check if the system is in safe boot mode)
Executes the "ps" command used to list the status of processes
Queries OS software version with shell command 'sw_vers'
Executes the "curl" command used to transfer data via the network (typically using HTTP/S)
Reads launchservices plist files
Uses AppleScript scripting additions containing additional functionalities for Apple Scripts
Reads hardware related sysctl values
Executes commands using a shell command-line interpreter
Reads the systems OS release and/or type
Executes the "defaults" command used to read or modify user specific settings
Executes the "touch" command used to create files or modify time stamps
Many shell processes execute programs via execve syscall (might be indicative for malicious behavior)

Classification

Joe Sandbox Version:36.0.0 Rainbow Opal
Analysis ID:756104
Start date and time:2022-11-29 16:37:54 +01:00
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 4m 51s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:DiskMaker_X_9.dmg
Cookbook file name:defaultmacfilecookbook.jbs
Analysis system description:Virtual Machine, High Sierra (Office 2016 16.16, Java 11.0.2+9, Adobe Reader 2019.010.20099)
Analysis Mode:default
Detection:CLEAN
Classification:clean8.macDMG@0/9@1/0
  • Excluded domains from analysis (whitelisted): b._dns-sd._udp.0.11.168.192.in-addr.arpa, db._dns-sd._udp.0.11.168.192.in-addr.arpa, lb._dns-sd._udp.0.11.168.192.in-addr.arpa
Command:open "/Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app"
PID:892
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • System is macvm-highsierra
  • open (MD5: 40ed6d8f35c9f20484b97582d296398f) Arguments:
  • applet (MD5: 0717bb720584b8dc860a0b9e235dd447) Arguments: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet
    • applet New Fork (PID: 894, Parent: 893)
    • sh (MD5: 8aa60b22a5d30418a002b340989384dc) Arguments: sh -c echo $HOME
    • applet New Fork (PID: 895, Parent: 893)
    • sh (MD5: 8aa60b22a5d30418a002b340989384dc) Arguments: sh -c touch '/Users/berri'/Library/Logs/DiskMakerX.log
    • touch (MD5: 4aacabad02929f18b00a9b6ef85e0605) Arguments: touch /Users/berri/Library/Logs/DiskMakerX.log
    • applet New Fork (PID: 896, Parent: 893)
    • sh (MD5: 8aa60b22a5d30418a002b340989384dc) Arguments: sh -c echo '--------------------------------------------------------------------------------' >> '/Users/berri'/Library/Logs/DiskMakerX.log
    • applet New Fork (PID: 897, Parent: 893)
    • sh (MD5: 8aa60b22a5d30418a002b340989384dc) Arguments: sh -c date >> '/Users/berri'/Library/Logs/DiskMakerX.log
      • sh New Fork (PID: 898, Parent: 897)
      • date (MD5: e1d20c480fcdc1ac4646170b1d9ca7c7) Arguments: date
    • applet New Fork (PID: 899, Parent: 893)
    • sh (MD5: 8aa60b22a5d30418a002b340989384dc) Arguments: sh -c echo 'Home Path: ' '/Users/berri'>> '/Users/berri'/Library/Logs/DiskMakerX.log
    • applet New Fork (PID: 900, Parent: 893)
    • sh (MD5: 8aa60b22a5d30418a002b340989384dc) Arguments: sh -c defaults read NSGlobalDomain AppleLanguages
    • defaults (MD5: 831678c94c2d9c647bf3d283b1861bda) Arguments: defaults read NSGlobalDomain AppleLanguages
    • applet New Fork (PID: 901, Parent: 893)
    • sh (MD5: 8aa60b22a5d30418a002b340989384dc) Arguments: sh -c echo 'Current Language: ' en-CH>> '/Users/berri'/Library/Logs/DiskMakerX.log
    • applet New Fork (PID: 902, Parent: 893)
    • sh (MD5: 8aa60b22a5d30418a002b340989384dc) Arguments: sh -c sw_vers -productVersion | cut -c 1-4
      • sh New Fork (PID: 903, Parent: 902)
      • sw_vers (MD5: d33f7f9efd4158694d0d58879b54f89d) Arguments: sw_vers -productVersion
      • sh New Fork (PID: 904, Parent: 902)
      • cut (MD5: e27c92637d672468ea846d377b500eb1) Arguments: cut -c 1-4
    • applet New Fork (PID: 905, Parent: 893)
    • sh (MD5: 8aa60b22a5d30418a002b340989384dc) Arguments: sh -c sw_vers -productVersion | cut -c 4-4
      • sh New Fork (PID: 906, Parent: 905)
      • sw_vers (MD5: d33f7f9efd4158694d0d58879b54f89d) Arguments: sw_vers -productVersion
      • sh New Fork (PID: 907, Parent: 905)
      • cut (MD5: e27c92637d672468ea846d377b500eb1) Arguments: cut -c 4-4
    • applet New Fork (PID: 908, Parent: 893)
    • sh (MD5: 8aa60b22a5d30418a002b340989384dc) Arguments: sh -c sw_vers -productVersion | cut -c 1-5
      • sh New Fork (PID: 909, Parent: 908)
      • sw_vers (MD5: d33f7f9efd4158694d0d58879b54f89d) Arguments: sw_vers -productVersion
      • sh New Fork (PID: 910, Parent: 908)
      • cut (MD5: e27c92637d672468ea846d377b500eb1) Arguments: cut -c 1-5
    • applet New Fork (PID: 911, Parent: 893)
    • sh (MD5: 8aa60b22a5d30418a002b340989384dc) Arguments: sh -c sw_vers -productVersion | cut -c 4-5
      • sh New Fork (PID: 912, Parent: 911)
      • sw_vers (MD5: d33f7f9efd4158694d0d58879b54f89d) Arguments: sw_vers -productVersion
      • sh New Fork (PID: 913, Parent: 911)
      • cut (MD5: e27c92637d672468ea846d377b500eb1) Arguments: cut -c 4-5
    • applet New Fork (PID: 914, Parent: 893)
    • sh (MD5: 8aa60b22a5d30418a002b340989384dc) Arguments: sh -c echo 'Current OS: ' 10.13>> '/Users/berri'/Library/Logs/DiskMakerX.log
    • applet New Fork (PID: 915, Parent: 893)
    • sh (MD5: 8aa60b22a5d30418a002b340989384dc) Arguments: sh -c id -G
    • id (MD5: 24c45eb23e1aae68c572939d1a906018) Arguments: id -G
    • applet New Fork (PID: 916, Parent: 893)
    • sh (MD5: 8aa60b22a5d30418a002b340989384dc) Arguments: sh -c echo 'Is this user an admin : ' true>> '/Users/berri'/Library/Logs/DiskMakerX.log
    • applet New Fork (PID: 917, Parent: 893)
    • sh (MD5: 8aa60b22a5d30418a002b340989384dc) Arguments: sh -c ps auxc
    • ps (MD5: 792e18b1417ac1f184680d2423206e4f) Arguments: ps auxc
    • applet New Fork (PID: 918, Parent: 893)
    • sh (MD5: 8aa60b22a5d30418a002b340989384dc) Arguments: sh -c echo 'Path Finder launched : ' false>> '/Users/berri'/Library/Logs/DiskMakerX.log
    • applet New Fork (PID: 919, Parent: 893)
    • sh (MD5: 8aa60b22a5d30418a002b340989384dc) Arguments: sh -c curl http://diskmakerx.com/CurrentLDMVersion
    • curl (MD5: 078cd73f58d3d8f875eed22522ff73f7) Arguments: curl http://diskmakerx.com/CurrentLDMVersion
    • applet New Fork (PID: 920, Parent: 893)
    • sh (MD5: 8aa60b22a5d30418a002b340989384dc) Arguments: sh -c echo 'Selected OS: ' 10.15>> '/Users/berri'/Library/Logs/DiskMakerX.log
    • applet New Fork (PID: 921, Parent: 893)
    • sh (MD5: 8aa60b22a5d30418a002b340989384dc) Arguments: sh -c mdfind -name 'Install macOS Catalina' | grep -v Library | head -1
      • sh New Fork (PID: 922, Parent: 921)
      • mdfind (MD5: 84f3a3da590e65271df7fecb27671fac) Arguments: mdfind -name Install macOS Catalina
      • sh New Fork (PID: 923, Parent: 921)
      • grep (MD5: 2b3efb273296881708ea2914c612e0eb) Arguments: grep -v Library
      • sh New Fork (PID: 924, Parent: 921)
      • head (MD5: bb2984cc21ccc7343bed41f2b577c011) Arguments: head -1
    • applet New Fork (PID: 925, Parent: 893)
    • sh (MD5: 8aa60b22a5d30418a002b340989384dc) Arguments: sh -c echo '' | wc -l
      • sh New Fork (PID: 926, Parent: 925)
      • sh New Fork (PID: 927, Parent: 925)
      • wc (MD5: b89949ce6a1929257e5c0c157027cbfe) Arguments: wc -l
  • od_user_homes (MD5: 5e56553e863563a662752de9cf98be48) Arguments: /usr/libexec/od_user_homes .localized
  • cleanup
No yara matches
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownTCP traffic detected without corresponding DNS query: 17.253.15.203
Source: unknownTCP traffic detected without corresponding DNS query: 23.3.109.8
Source: unknownTCP traffic detected without corresponding DNS query: 17.253.15.203
Source: unknownTCP traffic detected without corresponding DNS query: 23.3.109.8
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: DiskMaker_X_9.dmgString found in binary or memory: http://crl.apple.com/applerootcag3.crl0
Source: applet, 00000893.00000288.1.000000010e2f4000.000000010e30f000.r--.sdmp, applet, 00000893.00000288.1.0000000106bea000.0000000106bf6000.r--.sdmp, applet, 00000893.00000288.1.0000000105251000.0000000105254000.r--.sdmpString found in binary or memory: http://crl.apple.com/codesigning.crl0
Source: applet, 00000893.00000288.1.000000010378f000.0000000103794000.r--.sdmp, DiskMaker_X_9.dmgString found in binary or memory: http://crl.apple.com/root.crl0
Source: applet, 00000893.00000288.1.000000010378f000.0000000103794000.r--.sdmp, DiskMaker_X_9.dmgString found in binary or memory: http://crl.apple.com/timestamp.crl0
Source: applet, 00000893.00000288.1.000000010378f000.0000000103794000.r--.sdmp, DiskMaker_X_9.dmgString found in binary or memory: http://ocsp.apple.com/ocsp-devid010
Source: DiskMaker_X_9.dmgString found in binary or memory: http://ocsp.apple.com/ocsp03-applerootcag307
Source: DiskMaker_X_9.dmgString found in binary or memory: http://ocsp.apple.com/ocsp03-asica4020
Source: applet, 00000893.00000288.1.000000010e2f4000.000000010e30f000.r--.sdmp, applet, 00000893.00000288.1.000000010378f000.0000000103794000.r--.sdmp, applet, 00000893.00000288.1.0000000106bea000.0000000106bf6000.r--.sdmp, applet, 00000893.00000288.1.0000000105251000.0000000105254000.r--.sdmp, DiskMaker_X_9.dmgString found in binary or memory: http://www.apple.com/DTDs/PropertyList-1.0.dtd
Source: applet, 00000893.00000288.1.000000010e2f4000.000000010e30f000.r--.sdmp, applet, 00000893.00000288.1.0000000106bea000.0000000106bf6000.r--.sdmp, applet, 00000893.00000288.1.0000000105251000.0000000105254000.r--.sdmpString found in binary or memory: http://www.apple.com/appleca/root.crl0
Source: applet, 00000893.00000288.1.000000010378f000.0000000103794000.r--.sdmp, DiskMaker_X_9.dmgString found in binary or memory: http://www.apple.com/appleca0
Source: applet, 00000893.00000288.1.000000010e2f4000.000000010e30f000.r--.sdmp, applet, 00000893.00000288.1.0000000106bea000.0000000106bf6000.r--.sdmp, applet, 00000893.00000288.1.0000000105251000.0000000105254000.r--.sdmpString found in binary or memory: http://www.apple.com/certificateauthority0
Source: applet, 00000893.00000288.1.0000000105736000.00000001058ef000.r--.sdmpString found in binary or memory: http://www.apple.com/http://www.apple.com/Copyright
Source: applet, 00000893.00000288.1.000000010e2f4000.000000010e30f000.r--.sdmp, applet, 00000893.00000288.1.000000010378f000.0000000103794000.r--.sdmp, applet, 00000893.00000288.1.0000000106bea000.0000000106bf6000.r--.sdmp, applet, 00000893.00000288.1.0000000105251000.0000000105254000.r--.sdmp, DiskMaker_X_9.dmgString found in binary or memory: https://www.apple.com/appleca/0
Source: unknownDNS traffic detected: queries for: diskmakerx.com
Source: global trafficHTTP traffic detected: GET /CurrentLDMVersion HTTP/1.1Host: diskmakerx.comUser-Agent: curl/7.54.0Accept: */*
Source: classification engineClassification label: clean8.macDMG@0/9@1/0
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 893)AppleScript framework/component info plist opened: /System/Library/Components/AppleScript.component/Contents/Info.plistJump to behavior
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 893)AppleScript framework/component info plist opened: /System/Library/PrivateFrameworks/AppleScript.framework/Resources/Info.plistJump to behavior
Source: /bin/sh (PID: 923)Grep executable: /usr/bin/grep -> grep -v LibraryJump to behavior
Source: /bin/sh (PID: 917)Ps executable: /bin/ps -> ps auxcJump to behavior
Source: /bin/sh (PID: 919)Curl executable: /usr/bin/curl -> curl http://diskmakerx.com/CurrentLDMVersionJump to behavior
Source: /usr/bin/open (PID: 892)Launchservices plist file read: /System/Library/Preferences/Logging/Subsystems/com.apple.launchservices.plistJump to behavior
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 893)Launchservices plist file read: /System/Library/Preferences/Logging/Subsystems/com.apple.launchservices.plistJump to behavior
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 893)AppleScript scripting addition info plist opened: /System/Library/ScriptingAdditions/Digital Hub Scripting.osax/Contents/Info.plistJump to behavior
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 893)AppleScript scripting addition info plist opened: /System/Library/ScriptingAdditions/StandardAdditions.osax/Contents/Info.plistJump to behavior
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 894)Shell command executed: sh -c echo $HOMEJump to behavior
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 895)Shell command executed: sh -c touch '/Users/berri'/Library/Logs/DiskMakerX.logJump to behavior
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 896)Shell command executed: sh -c echo '--------------------------------------------------------------------------------' >> '/Users/berri'/Library/Logs/DiskMakerX.logJump to behavior
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 897)Shell command executed: sh -c date >> '/Users/berri'/Library/Logs/DiskMakerX.logJump to behavior
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 899)Shell command executed: sh -c echo 'Home Path: ' '/Users/berri'>> '/Users/berri'/Library/Logs/DiskMakerX.logJump to behavior
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 900)Shell command executed: sh -c defaults read NSGlobalDomain AppleLanguagesJump to behavior
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 901)Shell command executed: sh -c echo 'Current Language: ' en-CH>> '/Users/berri'/Library/Logs/DiskMakerX.logJump to behavior
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 902)Shell command executed: sh -c sw_vers -productVersion | cut -c 1-4Jump to behavior
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 905)Shell command executed: sh -c sw_vers -productVersion | cut -c 4-4Jump to behavior
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 908)Shell command executed: sh -c sw_vers -productVersion | cut -c 1-5Jump to behavior
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 911)Shell command executed: sh -c sw_vers -productVersion | cut -c 4-5Jump to behavior
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 914)Shell command executed: sh -c echo 'Current OS: ' 10.13>> '/Users/berri'/Library/Logs/DiskMakerX.logJump to behavior
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 915)Shell command executed: sh -c id -GJump to behavior
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 916)Shell command executed: sh -c echo 'Is this user an admin : ' true>> '/Users/berri'/Library/Logs/DiskMakerX.logJump to behavior
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 917)Shell command executed: sh -c ps auxcJump to behavior
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 918)Shell command executed: sh -c echo 'Path Finder launched : ' false>> '/Users/berri'/Library/Logs/DiskMakerX.logJump to behavior
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 919)Shell command executed: sh -c curl http://diskmakerx.com/CurrentLDMVersionJump to behavior
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 920)Shell command executed: sh -c echo 'Selected OS: ' 10.15>> '/Users/berri'/Library/Logs/DiskMakerX.logJump to behavior
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 921)Shell command executed: sh -c mdfind -name 'Install macOS Catalina' | grep -v Library | head -1Jump to behavior
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 925)Shell command executed: sh -c echo '' | wc -lJump to behavior
Source: /bin/sh (PID: 895)Touch executable: /usr/bin/touch -> touch /Users/berri/Library/Logs/DiskMakerX.logJump to behavior
Source: /bin/sh (PID: 895)Shell process: touch /Users/berri/Library/Logs/DiskMakerX.logJump to behavior
Source: /bin/sh (PID: 898)Shell process: dateJump to behavior
Source: /bin/sh (PID: 900)Shell process: defaults read NSGlobalDomain AppleLanguagesJump to behavior
Source: /bin/sh (PID: 903)Shell process: sw_vers -productVersionJump to behavior
Source: /bin/sh (PID: 904)Shell process: cut -c 1-4Jump to behavior
Source: /bin/sh (PID: 906)Shell process: sw_vers -productVersionJump to behavior
Source: /bin/sh (PID: 907)Shell process: cut -c 4-4Jump to behavior
Source: /bin/sh (PID: 909)Shell process: sw_vers -productVersionJump to behavior
Source: /bin/sh (PID: 910)Shell process: cut -c 1-5Jump to behavior
Source: /bin/sh (PID: 912)Shell process: sw_vers -productVersionJump to behavior
Source: /bin/sh (PID: 913)Shell process: cut -c 4-5Jump to behavior
Source: /bin/sh (PID: 915)Shell process: id -GJump to behavior
Source: /bin/sh (PID: 917)Shell process: ps auxcJump to behavior
Source: /bin/sh (PID: 919)Shell process: curl http://diskmakerx.com/CurrentLDMVersionJump to behavior
Source: /bin/sh (PID: 922)Shell process: mdfind -name Install macOS CatalinaJump to behavior
Source: /bin/sh (PID: 923)Shell process: grep -v LibraryJump to behavior
Source: /bin/sh (PID: 924)Shell process: head -1Jump to behavior
Source: /bin/sh (PID: 927)Shell process: wc -lJump to behavior
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 893)AppleKeyboardLayouts info plist opened: /System/Library/Keyboard Layouts/AppleKeyboardLayouts.bundle/Contents/Info.plistJump to behavior
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 893)Random device file read: /dev/randomJump to behavior
Source: /bin/sh (PID: 896)Log file created: /Users/berri/Library/Logs/DiskMakerX.log
Source: /bin/date (PID: 898)Log file created: /Users/berri/Library/Logs/DiskMakerX.log
Source: /bin/sh (PID: 899)Log file created: /Users/berri/Library/Logs/DiskMakerX.log
Source: /bin/sh (PID: 901)Log file created: /Users/berri/Library/Logs/DiskMakerX.log
Source: /bin/sh (PID: 914)Log file created: /Users/berri/Library/Logs/DiskMakerX.log
Source: /bin/sh (PID: 916)Log file created: /Users/berri/Library/Logs/DiskMakerX.log
Source: /bin/sh (PID: 918)Log file created: /Users/berri/Library/Logs/DiskMakerX.log
Source: /bin/sh (PID: 920)Log file created: /Users/berri/Library/Logs/DiskMakerX.logJump to dropped file
Source: submissionCodeSign Info: Executable=/Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 893)Sysctl read request: kern.safeboot (1.66)Jump to behavior
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 893)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 894)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 895)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 896)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 897)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 899)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 900)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 901)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 902)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 905)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 908)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 911)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 914)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 915)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 916)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 917)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 918)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 919)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 920)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 921)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 925)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 893)Sysctl read request: kern.osversion (1.65)Jump to behavior
Source: /bin/sh (PID: 903)sw_vers executed: sw_vers -productVersionJump to behavior
Source: /bin/sh (PID: 906)sw_vers executed: sw_vers -productVersionJump to behavior
Source: /bin/sh (PID: 909)sw_vers executed: sw_vers -productVersionJump to behavior
Source: /bin/sh (PID: 912)sw_vers executed: sw_vers -productVersionJump to behavior
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 893)Sysctl read request: hw.availcpu (6.25)Jump to behavior
Source: /bin/ps (PID: 917)Sysctl read request: hw.memsize (6.24)Jump to behavior
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 893)Sysctl requested: kern.ostype (1.1)Jump to behavior
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 893)Sysctl requested: kern.osrelease (1.2)Jump to behavior
Source: /usr/bin/open (PID: 892)System or server version plist file read: /System/Library/CoreServices/SystemVersion.plistJump to behavior
Source: /Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet (PID: 893)System or server version plist file read: /System/Library/CoreServices/SystemVersion.plistJump to behavior
Source: /usr/bin/sw_vers (PID: 903)System or server version plist file read: /System/Library/CoreServices/SystemVersion.plistJump to behavior
Source: /usr/bin/sw_vers (PID: 906)System or server version plist file read: /System/Library/CoreServices/SystemVersion.plistJump to behavior
Source: /usr/bin/sw_vers (PID: 909)System or server version plist file read: /System/Library/CoreServices/SystemVersion.plistJump to behavior
Source: /usr/bin/sw_vers (PID: 912)System or server version plist file read: /System/Library/CoreServices/SystemVersion.plistJump to behavior
Source: /bin/sh (PID: 900)Defaults executable: /usr/bin/defaults defaults read NSGlobalDomain AppleLanguagesJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid Accounts1
Command and Scripting Interpreter
Path InterceptionPath Interception1
Scripting
OS Credential Dumping1
Process Discovery
Remote ServicesData from Local System1
Exfiltration Over Alternative Protocol
2
Non-Application Layer Protocol
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default Accounts1
Scripting
Boot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Invalid Code Signature
LSASS Memory71
System Information Discovery
Remote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth2
Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain Accounts2
AppleScript
Logon Script (Windows)Logon Script (Windows)1
Code Signing
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration1
Ingress Tool Transfer
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)1
Indicator Removal on Host
NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Shell
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 756104 Sample: DiskMaker_X_9.dmg Startdate: 29/11/2022 Architecture: MAC Score: 8 39 diskmakerx.com 217.160.0.214, 49304, 80 ONEANDONE-ASBrauerstrasse48DE Germany 2->39 41 23.3.109.8, 49296, 80 AKAMAI-ASUS United States 2->41 7 xpcproxy applet 2->7         started        9 mono-sgen32 open 2->9         started        11 automountd od_user_homes 2->11         started        process3 process4 13 applet sh 7->13         started        15 applet sh 7->15         started        17 applet sh 7->17         started        19 17 other processes 7->19 process5 35 3 other processes 13->35 21 sh sw_vers 15->21         started        23 sh cut 15->23         started        25 sh sw_vers 17->25         started        27 sh cut 17->27         started        29 sh date 19->29         started        31 sh sw_vers 19->31         started        33 sh cut 19->33         started        37 4 other processes 19->37

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


cam-macmac-stand
SourceDetectionScannerLabelLink
DiskMaker_X_9.dmg0%VirustotalBrowse
DiskMaker_X_9.dmg0%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
diskmakerx.com
217.160.0.214
truefalse
    high
    NameMaliciousAntivirus DetectionReputation
    http://diskmakerx.com/CurrentLDMVersionfalse
      high
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      217.160.0.214
      diskmakerx.comGermany
      8560ONEANDONE-ASBrauerstrasse48DEfalse
      23.3.109.8
      unknownUnited States
      16625AKAMAI-ASUSfalse
      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
      217.160.0.214202207 Teklif.exeGet hashmaliciousBrowse
      • www.jullianben.com/kn30/?WHd0Ip=A2CLr3NqJ5giDH5gGndM/u+rAp0864k/iKLu8yoV/qSd8pIbc5GzPBzssx3Xxka+5dmG&u8GxL=0vBPlrH8bn5
      23.3.109.8Document_7690#Nov10.htmlGet hashmaliciousBrowse
        https://free.xjs.lolGet hashmaliciousBrowse
          RemittanceAdvice_Supplier_100794.HTMLGet hashmaliciousBrowse
            avEi0nNO6IGet hashmaliciousBrowse
              drfone_repair_setup_full3358.dmgGet hashmaliciousBrowse
                WormholeInstaller.dmgGet hashmaliciousBrowse
                  WormholeInstaller.dmgGet hashmaliciousBrowse
                    WormholeInstaller.dmgGet hashmaliciousBrowse
                      http://url3434.shortswitch.com/ls/click?upn=ebe1Hmbw4RyD93bj5eTRaiPZZIDB33jtTYfrb3MdsCrcr4dCbYYb0K-2BTdzzOxTpI4oM8_Zd6hRd3O-2Bi7TiTmhDOob5kTzIUhaTYEBa35jMWLJf7yg7etj3SLwCS9ESboIu6W4TRjieqqIi-2BTvzKc2dvKvaW-2FTr4rK36kHhgKqyPZhDxLGMnjuP1vCdC6g4-2FfnWVoSdEzurEWsQw8hdw-2BeIpiWkhGQf-2Bauglg-2BlPZ8zKZwMVvRwFTF2XVaspVirS0W97Fkz4g6KKSdD1HKhnC6nVG85A-3D-3DGet hashmaliciousBrowse
                        InstallerGet hashmaliciousBrowse
                          WormholeInstaller.dmgGet hashmaliciousBrowse
                            http://pxlme.me/favicon.icoGet hashmaliciousBrowse
                              No context
                              MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                              ONEANDONE-ASBrauerstrasse48DENew PO-RJ-IN-003 - Knauf Queimados.exeGet hashmaliciousBrowse
                              • 74.208.236.214
                              FCA000200010005.PDF.exeGet hashmaliciousBrowse
                              • 216.250.120.18
                              Purchase Order No. 4502717956.exeGet hashmaliciousBrowse
                              • 74.208.236.214
                              file.exeGet hashmaliciousBrowse
                              • 217.160.0.128
                              045624132441524.exeGet hashmaliciousBrowse
                              • 217.160.0.95
                              output(1)(1).jsGet hashmaliciousBrowse
                              • 217.160.0.128
                              Invoice-9273923.xllGet hashmaliciousBrowse
                              • 82.165.20.74
                              Detallemovimiento.vbeGet hashmaliciousBrowse
                              • 212.227.15.142
                              YEN#U0130 S#U0130PAR#U0130#U015e-CVEQ530334.exeGet hashmaliciousBrowse
                              • 217.160.0.211
                              file.exeGet hashmaliciousBrowse
                              • 217.160.0.128
                              justificante de transferencia.vbeGet hashmaliciousBrowse
                              • 212.227.15.158
                              DHL_29028263 documento de recepci#U00f3n de la compra.exeGet hashmaliciousBrowse
                              • 74.208.236.84
                              CTM REQUEST_USD42,000.exeGet hashmaliciousBrowse
                              • 217.160.0.159
                              Detallemovimiento.vbsGet hashmaliciousBrowse
                              • 212.227.15.158
                              proforma pdf.exeGet hashmaliciousBrowse
                              • 217.160.0.182
                              Quotation Request - 10001.exeGet hashmaliciousBrowse
                              • 74.208.236.167
                              SWIFT Transfer (103) 022FT102211200045.exeGet hashmaliciousBrowse
                              • 74.208.236.112
                              Form.exeGet hashmaliciousBrowse
                              • 74.208.236.84
                              SecuriteInfo.com.Win32.PWSX-gen.14481.368.exeGet hashmaliciousBrowse
                              • 82.223.17.94
                              Meld(1).exeGet hashmaliciousBrowse
                              • 74.208.236.178
                              No context
                              No context
                              Process:/bin/sh
                              File Type:ASCII text
                              Category:dropped
                              Size (bytes):20
                              Entropy (8bit):3.6464393446710153
                              Encrypted:false
                              SSDEEP:3:OXzXWvn:IzXo
                              MD5:5456759709FDB066DD6FC29CA0751702
                              SHA1:0253BE8E7FF5EE7F6AD9F01F95F6988E6525DF38
                              SHA-256:9E7B97BCE2F45EA25FE4BE592806D7EAE6C71356CD865C49974AC52A36EF7331
                              SHA-512:543A19CD3CCA27E49A5D9C3A53A394A908C3ECC63E5C9C8C0FAD0E3FD86725389FEBACC7E4AE36DE0BDFE402484FE56C11EA242AE2CDC2EB6CECA4238A2927A2
                              Malicious:false
                              Reputation:low
                              Preview:Selected OS: 10.15.
                              Process:/Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet
                              File Type:ASCII text
                              Category:dropped
                              Size (bytes):61
                              Entropy (8bit):4.699271510042169
                              Encrypted:false
                              SSDEEP:3:tXjtFD9VjAYeWw/3WOv:Rtt38YeIA
                              MD5:902395083896E7D5B0D0C4280499D7C3
                              SHA1:C8702D829D55507A55A9C7DA21BD7E76679966D3
                              SHA-256:4CD214575863D93C3DFAD5376B7D1E5CD60C0FC8E6CF0C8EE06D9BB0FF3F865F
                              SHA-512:8B6686383DE9497311B57D051F9CC15E39AA304AE158F8BC343D056486227A187B1488E314E2D29FAA9ACA1886B60FDD15366BD0946D3FB0D31001C0A8C07029
                              Malicious:false
                              Reputation:low
                              Preview:2022-11-29 17:39:43.539 applet[893:7154] ApplePersistence=NO.
                              File type:bzip2 compressed data, block size = 100k
                              Entropy (8bit):7.999667829376183
                              TrID:
                              • Disk Image (Macintosh), bzip2 (12509/2) 80.61%
                              • bzip2 compressed archive (3009/2) 19.39%
                              File name:DiskMaker_X_9.dmg
                              File size:6272758
                              MD5:d575c6a40278340f092a6fc4e26e4d11
                              SHA1:87d92610155135621014afefa88d8b6c9ad5f0ed
                              SHA256:96845cd375543401b822fb4e17d2ecc300fcb621f56afcdad613ae11c9afddce
                              SHA512:f18cf8eee40b9c1cfe1a2141ffd6e59e36f34fb7908ffb5383847b45bc0b5571efd4c80c2969409744274c744e6124dd3d2a62d408501d71ceb8bab7f4585d3f
                              SSDEEP:98304:SqTiPyIC9pzheDyGVPAJBajoIz82jt58wb9TmzV4C1V5zw7NSmj5TGdjFOIZRZ/d:fTiaPpAVPAJwA68wb9adjwgiFG5F7PZq
                              TLSH:F95633367A1CFC39EC61DA7657CB827FEF5B29C38A52534029766B81077B3A42B31460
                              File Content Preview:BZh11AY&SY...[...G........@.. .1....%......H.......`BZh11AY&SY"4e........P.@....BH..... .@... .u..2....i.6..P....Tq.w.&...8...:.H.... .F#.X.Ou.......-...:..@.?...cN&..K@.I/...N.$...~@BZh91AY&SYTtL...e......................................R(+..=.......yuA.
                              ["Executable=/Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet","Identifier=net.gete.diskmakerx9","Format=app bundle with Mach-O universal (i386 x86_64)","CodeDirectory v=20200 size=276 flags=0x0(none) hashes=3+3 location=embedded","OSPlatform=36","OSSDKVersion=658944","OSVersionMin=656896","Hash type=sha256 size=32","CandidateCDHash sha1=67b9d3189b9ac47dd75aacb62b20282b9a8e9409","CandidateCDHash sha256=04a0e36d088dfe3b5b706bf0cf1f0ea0a9d4d06a","Hash choices=sha1,sha256","Page size=4096","CDHash=04a0e36d088dfe3b5b706bf0cf1f0ea0a9d4d06a","Signature size=9009","Authority=Developer ID Application: Guillaume Gete (2U4ZFMT67D)","Authority=Developer ID Certification Authority","Authority=Apple Root CA","Timestamp=23 Nov 2019 at 23:49:57","Info.plist entries=27","TeamIdentifier=2U4ZFMT67D","Sealed Resources version=2 rules=13 files=18","Internal requirements count=1 size=180"]
                              TimestampSource PortDest PortSource IPDest IP
                              Nov 29, 2022 16:38:57.926403046 CET4929580192.168.11.1117.253.15.203
                              Nov 29, 2022 16:38:57.926485062 CET4929680192.168.11.1123.3.109.8
                              Nov 29, 2022 16:38:57.935100079 CET804929517.253.15.203192.168.11.11
                              Nov 29, 2022 16:38:57.935467958 CET4929580192.168.11.1117.253.15.203
                              Nov 29, 2022 16:38:57.937231064 CET804929623.3.109.8192.168.11.11
                              Nov 29, 2022 16:38:57.937644958 CET4929680192.168.11.1123.3.109.8
                              Nov 29, 2022 16:39:51.792793989 CET4930480192.168.11.11217.160.0.214
                              Nov 29, 2022 16:39:51.808228016 CET8049304217.160.0.214192.168.11.11
                              Nov 29, 2022 16:39:51.809422970 CET4930480192.168.11.11217.160.0.214
                              Nov 29, 2022 16:39:51.809694052 CET4930480192.168.11.11217.160.0.214
                              Nov 29, 2022 16:39:51.824779987 CET8049304217.160.0.214192.168.11.11
                              Nov 29, 2022 16:39:51.829534054 CET8049304217.160.0.214192.168.11.11
                              Nov 29, 2022 16:39:51.830768108 CET4930480192.168.11.11217.160.0.214
                              Nov 29, 2022 16:39:51.833475113 CET4930480192.168.11.11217.160.0.214
                              Nov 29, 2022 16:39:51.848671913 CET8049304217.160.0.214192.168.11.11
                              Nov 29, 2022 16:39:51.849123001 CET4930480192.168.11.11217.160.0.214
                              TimestampSource PortDest PortSource IPDest IP
                              Nov 29, 2022 16:39:16.869143963 CET137137192.168.11.11192.168.11.255
                              Nov 29, 2022 16:39:51.757548094 CET5475453192.168.11.111.1.1.1
                              Nov 29, 2022 16:39:51.778717041 CET53547541.1.1.1192.168.11.11
                              Nov 29, 2022 16:40:02.343899965 CET53607491.1.1.1192.168.11.11
                              Nov 29, 2022 16:40:02.344352007 CET53522931.1.1.1192.168.11.11
                              Nov 29, 2022 16:40:02.348738909 CET53607721.1.1.1192.168.11.11
                              Nov 29, 2022 16:40:02.349389076 CET53630761.1.1.1192.168.11.11
                              Nov 29, 2022 16:40:02.353365898 CET53574531.1.1.1192.168.11.11
                              Nov 29, 2022 16:40:02.356688976 CET53645691.1.1.1192.168.11.11
                              Nov 29, 2022 16:40:02.358203888 CET60014137192.168.11.11192.168.11.255
                              Nov 29, 2022 16:40:02.862602949 CET60014137192.168.11.11192.168.11.255
                              Nov 29, 2022 16:40:03.481086016 CET58377137192.168.11.11192.168.11.255
                              Nov 29, 2022 16:40:03.986871958 CET58377137192.168.11.11192.168.11.255
                              Nov 29, 2022 16:41:06.059134960 CET53574531.1.1.1192.168.11.11
                              Nov 29, 2022 16:41:06.059195995 CET53645691.1.1.1192.168.11.11
                              Nov 29, 2022 16:41:06.061727047 CET53607721.1.1.1192.168.11.11
                              TimestampSource IPDest IPChecksumCodeType
                              Nov 29, 2022 16:40:02.344682932 CET192.168.11.111.1.1.1f37(Port unreachable)Destination Unreachable
                              Nov 29, 2022 16:40:02.344683886 CET192.168.11.111.1.1.13040(Port unreachable)Destination Unreachable
                              Nov 29, 2022 16:40:02.349873066 CET192.168.11.111.1.1.1620(Port unreachable)Destination Unreachable
                              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                              Nov 29, 2022 16:39:51.757548094 CET192.168.11.111.1.1.10x6cf2Standard query (0)diskmakerx.comA (IP address)IN (0x0001)false
                              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                              Nov 29, 2022 16:39:51.778717041 CET1.1.1.1192.168.11.110x6cf2No error (0)diskmakerx.com217.160.0.214A (IP address)IN (0x0001)false
                              • diskmakerx.com
                              Session IDSource IPSource PortDestination IPDestination Port
                              0192.168.11.1149304217.160.0.21480
                              TimestampkBytes transferredDirectionData
                              Nov 29, 2022 16:39:51.809694052 CET1OUTGET /CurrentLDMVersion HTTP/1.1
                              Host: diskmakerx.com
                              User-Agent: curl/7.54.0
                              Accept: */*
                              Nov 29, 2022 16:39:51.829534054 CET1INHTTP/1.1 200 OK
                              Content-Length: 3
                              Connection: keep-alive
                              Keep-Alive: timeout=15
                              Date: Tue, 29 Nov 2022 15:39:51 GMT
                              Server: Apache
                              Last-Modified: Sun, 24 Nov 2019 12:55:52 GMT
                              ETag: "3-598172ac80353"
                              Accept-Ranges: bytes
                              Data Raw: 39 30 30
                              Data Ascii: 900


                              System Behavior

                              Start time:16:39:43
                              Start date:29/11/2022
                              Path:/Library/Frameworks/Mono.framework/Versions/4.4.2/bin/mono-sgen32
                              Arguments:n/a
                              File size:3722408 bytes
                              MD5 hash:8910349f44a940d8d79318367855b236
                              Start time:16:39:43
                              Start date:29/11/2022
                              Path:/usr/bin/open
                              Arguments:
                              File size:105952 bytes
                              MD5 hash:40ed6d8f35c9f20484b97582d296398f
                              Start time:16:39:43
                              Start date:29/11/2022
                              Path:/usr/libexec/xpcproxy
                              Arguments:n/a
                              File size:43488 bytes
                              MD5 hash:d1bb9a4899f0af921e8188218b20d744
                              Start time:16:39:43
                              Start date:29/11/2022
                              Path:/Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet
                              Arguments:/Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet
                              File size:60192 bytes
                              MD5 hash:0717bb720584b8dc860a0b9e235dd447
                              Start time:16:39:43
                              Start date:29/11/2022
                              Path:/Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet
                              Arguments:n/a
                              File size:60192 bytes
                              MD5 hash:0717bb720584b8dc860a0b9e235dd447
                              Start time:16:39:44
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:sh -c echo $HOME
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:44
                              Start date:29/11/2022
                              Path:/Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet
                              Arguments:n/a
                              File size:60192 bytes
                              MD5 hash:0717bb720584b8dc860a0b9e235dd447
                              Start time:16:39:44
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:sh -c touch '/Users/berri'/Library/Logs/DiskMakerX.log
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:44
                              Start date:29/11/2022
                              Path:/usr/bin/touch
                              Arguments:touch /Users/berri/Library/Logs/DiskMakerX.log
                              File size:23376 bytes
                              MD5 hash:4aacabad02929f18b00a9b6ef85e0605
                              Start time:16:39:44
                              Start date:29/11/2022
                              Path:/Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet
                              Arguments:n/a
                              File size:60192 bytes
                              MD5 hash:0717bb720584b8dc860a0b9e235dd447
                              Start time:16:39:44
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:sh -c echo '--------------------------------------------------------------------------------' >> '/Users/berri'/Library/Logs/DiskMakerX.log
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:44
                              Start date:29/11/2022
                              Path:/Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet
                              Arguments:n/a
                              File size:60192 bytes
                              MD5 hash:0717bb720584b8dc860a0b9e235dd447
                              Start time:16:39:44
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:sh -c date >> '/Users/berri'/Library/Logs/DiskMakerX.log
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:44
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:n/a
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:44
                              Start date:29/11/2022
                              Path:/bin/date
                              Arguments:date
                              File size:28592 bytes
                              MD5 hash:e1d20c480fcdc1ac4646170b1d9ca7c7
                              Start time:16:39:44
                              Start date:29/11/2022
                              Path:/Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet
                              Arguments:n/a
                              File size:60192 bytes
                              MD5 hash:0717bb720584b8dc860a0b9e235dd447
                              Start time:16:39:44
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:sh -c echo 'Home Path: ' '/Users/berri'>> '/Users/berri'/Library/Logs/DiskMakerX.log
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:44
                              Start date:29/11/2022
                              Path:/Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet
                              Arguments:n/a
                              File size:60192 bytes
                              MD5 hash:0717bb720584b8dc860a0b9e235dd447
                              Start time:16:39:44
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:sh -c defaults read NSGlobalDomain AppleLanguages
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:44
                              Start date:29/11/2022
                              Path:/usr/bin/defaults
                              Arguments:defaults read NSGlobalDomain AppleLanguages
                              File size:39472 bytes
                              MD5 hash:831678c94c2d9c647bf3d283b1861bda
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet
                              Arguments:n/a
                              File size:60192 bytes
                              MD5 hash:0717bb720584b8dc860a0b9e235dd447
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:sh -c echo 'Current Language: ' en-CH>> '/Users/berri'/Library/Logs/DiskMakerX.log
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet
                              Arguments:n/a
                              File size:60192 bytes
                              MD5 hash:0717bb720584b8dc860a0b9e235dd447
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:sh -c sw_vers -productVersion | cut -c 1-4
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:n/a
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/usr/bin/sw_vers
                              Arguments:sw_vers -productVersion
                              File size:18848 bytes
                              MD5 hash:d33f7f9efd4158694d0d58879b54f89d
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:n/a
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/usr/bin/cut
                              Arguments:cut -c 1-4
                              File size:23712 bytes
                              MD5 hash:e27c92637d672468ea846d377b500eb1
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet
                              Arguments:n/a
                              File size:60192 bytes
                              MD5 hash:0717bb720584b8dc860a0b9e235dd447
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:sh -c sw_vers -productVersion | cut -c 4-4
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:n/a
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/usr/bin/sw_vers
                              Arguments:sw_vers -productVersion
                              File size:18848 bytes
                              MD5 hash:d33f7f9efd4158694d0d58879b54f89d
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:n/a
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/usr/bin/cut
                              Arguments:cut -c 4-4
                              File size:23712 bytes
                              MD5 hash:e27c92637d672468ea846d377b500eb1
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet
                              Arguments:n/a
                              File size:60192 bytes
                              MD5 hash:0717bb720584b8dc860a0b9e235dd447
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:sh -c sw_vers -productVersion | cut -c 1-5
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:n/a
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/usr/bin/sw_vers
                              Arguments:sw_vers -productVersion
                              File size:18848 bytes
                              MD5 hash:d33f7f9efd4158694d0d58879b54f89d
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:n/a
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/usr/bin/cut
                              Arguments:cut -c 1-5
                              File size:23712 bytes
                              MD5 hash:e27c92637d672468ea846d377b500eb1
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet
                              Arguments:n/a
                              File size:60192 bytes
                              MD5 hash:0717bb720584b8dc860a0b9e235dd447
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:sh -c sw_vers -productVersion | cut -c 4-5
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:n/a
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/usr/bin/sw_vers
                              Arguments:sw_vers -productVersion
                              File size:18848 bytes
                              MD5 hash:d33f7f9efd4158694d0d58879b54f89d
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:n/a
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/usr/bin/cut
                              Arguments:cut -c 4-5
                              File size:23712 bytes
                              MD5 hash:e27c92637d672468ea846d377b500eb1
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet
                              Arguments:n/a
                              File size:60192 bytes
                              MD5 hash:0717bb720584b8dc860a0b9e235dd447
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:sh -c echo 'Current OS: ' 10.13>> '/Users/berri'/Library/Logs/DiskMakerX.log
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet
                              Arguments:n/a
                              File size:60192 bytes
                              MD5 hash:0717bb720584b8dc860a0b9e235dd447
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:sh -c id -G
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/usr/bin/id
                              Arguments:id -G
                              File size:23248 bytes
                              MD5 hash:24c45eb23e1aae68c572939d1a906018
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet
                              Arguments:n/a
                              File size:60192 bytes
                              MD5 hash:0717bb720584b8dc860a0b9e235dd447
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:sh -c echo 'Is this user an admin : ' true>> '/Users/berri'/Library/Logs/DiskMakerX.log
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet
                              Arguments:n/a
                              File size:60192 bytes
                              MD5 hash:0717bb720584b8dc860a0b9e235dd447
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:sh -c ps auxc
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:50
                              Start date:29/11/2022
                              Path:/bin/ps
                              Arguments:ps auxc
                              File size:51280 bytes
                              MD5 hash:792e18b1417ac1f184680d2423206e4f
                              Start time:16:39:51
                              Start date:29/11/2022
                              Path:/Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet
                              Arguments:n/a
                              File size:60192 bytes
                              MD5 hash:0717bb720584b8dc860a0b9e235dd447
                              Start time:16:39:51
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:sh -c echo 'Path Finder launched : ' false>> '/Users/berri'/Library/Logs/DiskMakerX.log
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:51
                              Start date:29/11/2022
                              Path:/Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet
                              Arguments:n/a
                              File size:60192 bytes
                              MD5 hash:0717bb720584b8dc860a0b9e235dd447
                              Start time:16:39:51
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:sh -c curl http://diskmakerx.com/CurrentLDMVersion
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:51
                              Start date:29/11/2022
                              Path:/usr/bin/curl
                              Arguments:curl http://diskmakerx.com/CurrentLDMVersion
                              File size:185104 bytes
                              MD5 hash:078cd73f58d3d8f875eed22522ff73f7
                              Start time:16:39:51
                              Start date:29/11/2022
                              Path:/Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet
                              Arguments:n/a
                              File size:60192 bytes
                              MD5 hash:0717bb720584b8dc860a0b9e235dd447
                              Start time:16:39:51
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:sh -c echo 'Selected OS: ' 10.15>> '/Users/berri'/Library/Logs/DiskMakerX.log
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:57
                              Start date:29/11/2022
                              Path:/Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet
                              Arguments:n/a
                              File size:60192 bytes
                              MD5 hash:0717bb720584b8dc860a0b9e235dd447
                              Start time:16:39:57
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:sh -c mdfind -name 'Install macOS Catalina' | grep -v Library | head -1
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:57
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:n/a
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:57
                              Start date:29/11/2022
                              Path:/usr/bin/mdfind
                              Arguments:mdfind -name Install macOS Catalina
                              File size:29280 bytes
                              MD5 hash:84f3a3da590e65271df7fecb27671fac
                              Start time:16:39:57
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:n/a
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:57
                              Start date:29/11/2022
                              Path:/usr/bin/grep
                              Arguments:grep -v Library
                              File size:33936 bytes
                              MD5 hash:2b3efb273296881708ea2914c612e0eb
                              Start time:16:39:57
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:n/a
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:57
                              Start date:29/11/2022
                              Path:/usr/bin/head
                              Arguments:head -1
                              File size:18912 bytes
                              MD5 hash:bb2984cc21ccc7343bed41f2b577c011
                              Start time:16:39:57
                              Start date:29/11/2022
                              Path:/Volumes/DiskMaker X 9/DiskMaker X 9 for macOS Catalina.app/Contents/MacOS/applet
                              Arguments:n/a
                              File size:60192 bytes
                              MD5 hash:0717bb720584b8dc860a0b9e235dd447
                              Start time:16:39:57
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:sh -c echo '' | wc -l
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:57
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:n/a
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:57
                              Start date:29/11/2022
                              Path:/bin/sh
                              Arguments:n/a
                              File size:618512 bytes
                              MD5 hash:8aa60b22a5d30418a002b340989384dc
                              Start time:16:39:57
                              Start date:29/11/2022
                              Path:/usr/bin/wc
                              Arguments:wc -l
                              File size:23072 bytes
                              MD5 hash:b89949ce6a1929257e5c0c157027cbfe
                              Start time:16:40:01
                              Start date:29/11/2022
                              Path:/usr/libexec/automountd
                              Arguments:n/a
                              File size:129632 bytes
                              MD5 hash:a02648ba58feca82fec051bdd78be4b6
                              Start time:16:40:01
                              Start date:29/11/2022
                              Path:/usr/libexec/od_user_homes
                              Arguments:/usr/libexec/od_user_homes .localized
                              File size:24656 bytes
                              MD5 hash:5e56553e863563a662752de9cf98be48