Loading ...

Analysis Report

Overview

General Information

Joe Sandbox Version:19.0.0
Analysis ID:37141
Start time:09:30:59
Joe Sandbox Product:Cloud
Start date:05.05.2017
Overall analysis duration:0h 12m 30s
Report type:full
Sample file name:d5ea79632a1a67abbf9fb1c2813b899c90a5fb9442966ed4f530e92715087ee2.app
Cookbook file name:default.jbs
Analysis system description:Mac Mini, El Capitan 10.11.6 (MS Office 15.25, Java 1.8.0_25)
Detection:MAL
Classification:mal56.evad.macAPP@0/16@3/0


Detection

StrategyScoreRangeReportingDetection
Threshold560 - 100Report FP / FNmalicious


Classification

Signature Overview

Click to jump to signature section


Networking:

barindex
Downloads files from webservers via HTTPShow sources
Source: global trafficHTTP traffic detected: GET /b/ss/adbacdcprod/1/H.25.4/s16858227509073?AQB=1&ndh=1&t=5%2F4%2F2017%2011%3A31%3A45%205%20-120&fid=4B76F615E0EAA111-1B973BAC35CD768D&ce=UTF-8&ns=adobecorp&pageName=acdc_fp_adm_launched&g=file%3A%2F%2F%2FUsers%2Fvreni%2FDesktop%2Funpack%2FInstall%2520Adobe%2520Flash%2520Player.app%2Fmain.html&ch=acdc_flashplayer&events=event96%2Cevent19&products=%3Bflashplayer_adm&c1=adm&c2=acdc%20downloads&c3=get.adobe.com&c4=en_us&c5=en_us%3Aacdc_fp_adm_launched&v18=new&v22=friday%20-%203%3A30am&v73=acdc_flashplayer&s=1280x1024&c=24&j=1.6&v=Y&k=Y&bw=620&bh=355&AQE=1 HTTP/1.1Host: stats.adobe.comConnection: closeUser-Agent: Install%20Adobe%20Flash%20Player/2.0.0.135s CFNetwork/760.6.3 Darwin/15.6.0 (x86_64)
Source: global trafficHTTP traffic detected: HTTP/1.1 302 FoundDate: Fri, 05 May 2017 07:31:47 GMTServer: Omniture DC/2.0.0Access-Control-Allow-Origin: *Set-Cookie: s_vi=[CS]v1|2C8615318507AA04-4000010780002A00[CE]; Expires=Sun, 5 May 2019 07:31:47 GMT; Domain=adobe.com; Path=/Location: http://stats.adobe.com/b/ss/adbacdcprod/1/H.25.4/s16858227509073?AQB=1&pccr=true&vidn=2C8615318507AA04-4000010780002A00&&ndh=1&t=5%2F4%2F2017%2011%3A31%3A45%205%20-120&fid=4B76F615E0EAA111-1B973BAC35CD768D&ce=UTF-8&ns=adobecorp&pageName=acdc_fp_adm_launched&g=file%3A%2F%2F%2FUsers%2Fvreni%2FDesktop%2Funpack%2FInstall%2520Adobe%2520Flash%2520Player.app%2Fmain.html&ch=acdc_flashplayer&events=event96%2Cevent19&products=%3Bflashplayer_adm&c1=adm&c2=acdc%20downloads&c3=get.adobe.com&c4=en_us&c5=en_us%3Aacdc_fp_adm_launched&v18=new&v22=friday%20-%203%3A30am&v73=acdc_flashplayer&s=1280x1024&c=24&j=1.6&v=Y&k=Y&bw=620&bh=355&AQE=1X-C: ms-5.2.0Expires: Thu, 04 May 2017 07:31:47 GMTLast-Modified: Sat, 06 May 2017 07:31:47 GMTCache-Control: no-cache, no-store, max-
Source: global trafficHTTP traffic detected: GET /b/ss/adbacdcprod/1/H.25.4/s16858227509073?AQB=1&pccr=true&vidn=2C8615318507AA04-4000010780002A00&&ndh=1&t=5%2F4%2F2017%2011%3A31%3A45%205%20-120&fid=4B76F615E0EAA111-1B973BAC35CD768D&ce=UTF-8&ns=adobecorp&pageName=acdc_fp_adm_launched&g=file%3A%2F%2F%2FUsers%2Fvreni%2FDesktop%2Funpack%2FInstall%2520Adobe%2520Flash%2520Player.app%2Fmain.html&ch=acdc_flashplayer&events=event96%2Cevent19&products=%3Bflashplayer_adm&c1=adm&c2=acdc%20downloads&c3=get.adobe.com&c4=en_us&c5=en_us%3Aacdc_fp_adm_launched&v18=new&v22=friday%20-%203%3A30am&v73=acdc_flashplayer&s=1280x1024&c=24&j=1.6&v=Y&k=Y&bw=620&bh=355&AQE=1 HTTP/1.1Host: stats.adobe.comConnection: closeUser-Agent: Install%20Adobe%20Flash%20Player/2.0.0.135s CFNetwork/760.6.3 Darwin/15.6.0 (x86_64)
Performs DNS lookupsShow sources
Source: unknownDNS traffic detected: queries for: get.adobe.com
Reads from file descriptors related to (network) socketsShow sources
Source: /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/Install Adobe Flash Player (PID: 599)Reads from socket in process:
Uses HTTPSShow sources
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49310
Source: unknownNetwork traffic detected: HTTP traffic on port 49310 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49308 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49308
Writes from file descriptors related to (network) socketsShow sources
Source: /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/Install Adobe Flash Player (PID: 599)Writes from socket in process:

System Summary:

barindex
Classification labelShow sources
Source: classification engineClassification label: mal56.evad.macAPP@0/16@3/0

Persistence and Installation Behavior:

barindex
Reads data from the local random generatorShow sources
Source: /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/Install (PID: 575)Random device file read: /dev/random
Source: /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/Install (PID: 575)Random device file read: /dev/random
Source: /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/Install Adobe Flash Player (PID: 599)Random device file read: /dev/random
Source: /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/Install Adobe Flash Player (PID: 599)Random device file read: /dev/random
Uses AppleKeyboardLayouts bundle containing keyboard layoutsShow sources
Source: /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/Install (PID: 575)AppleKeyboardLayouts info plist opened: /System/Library/Keyboard Layouts/AppleKeyboardLayouts.bundle/Contents/Info.plist
Source: /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/Install Adobe Flash Player (PID: 599)AppleKeyboardLayouts info plist opened: /System/Library/Keyboard Layouts/AppleKeyboardLayouts.bundle/Contents/Info.plist
Writes log files to diskShow sources
Source: /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/Install Adobe Flash Player (PID: 599)Log file created: /private/var/root/Library/Logs/Adobe_ADMLogs/Adobe_ADM.log
Source: /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/Install Adobe Flash Player (PID: 599)Log file created: /Users/vreni/Library/Logs/Adobe_ADMLogs/Adobe_GDE.log
Writes property list (.plist) files to diskShow sources
Source: /bin/cp (PID: 590)Binary plist file created: /Library/LaunchDaemons/com.adobe.update.plist
Source: /bin/cp (PID: 607)XML plist file created: /Library/Preferences/SystemConfiguration/preferences.plist.old
Source: /bin/cp (PID: 609)XML plist file created: /Library/Preferences/SystemConfiguration/preferences.plist.old
Source: /bin/cp (PID: 611)XML plist file created: /Library/Preferences/SystemConfiguration/preferences.plist.old
Source: /bin/cp (PID: 613)XML plist file created: /Library/Preferences/SystemConfiguration/preferences.plist.old
Source: /bin/cp (PID: 615)XML plist file created: /Library/Preferences/SystemConfiguration/preferences.plist.old
Source: /bin/cp (PID: 617)XML plist file created: /Library/Preferences/SystemConfiguration/preferences.plist.old
App bundle is code signedShow sources
Source: Submitted file: d5ea79632a1a67abbf9fb1c2813b899c90a5fb9442966ed4f530e92715087ee2.appCodeResources XML file: CodeResources
Source: Submitted file: d5ea79632a1a67abbf9fb1c2813b899c90a5fb9442966ed4f530e92715087ee2.appCodeResources XML file: CodeResources
Changes permissions of written Mach-O filesShow sources
Source: /bin/cp (PID: 588)Permissions modifiied for written 64-bit Mach-O /Library/Scripts/installdp: bits: - usr: rx grp: rx all: rwx
Creates hidden files, links and/or directoriesShow sources
Source: /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/Install Adobe Flash Player (PID: 599)Hidden Directory created: /Users/vreni/Library/Application Support/Adobe/.F7D9D727-552E-4F92-A000-3A5D8661F4B0 -> /Users/vreni/Library/Application Support/Adobe/.F7D9D727-552E-4F92-A000-3A5D8661F4B0
Executes commands using a shell command-line interpreterShow sources
Source: /System/Library/ScriptingAdditions/StandardAdditions.osax/Contents/MacOS/uid (PID: 585)Shell command executed: /bin/sh -c '/Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/install.sh'
Source: /Library/Scripts/installdp (PID: 598)Shell command executed: sh -c networksetup -getwebproxy Ethernet
Source: /Library/Scripts/installdp (PID: 598)Shell command executed: sh -c networksetup -getsecurewebproxy Ethernet
Source: /Library/Scripts/installdp (PID: 598)Shell command executed: sh -c networksetup -getsocksfirewallproxy Ethernet
Source: /usr/sbin/networksetup (PID: 606)Shell command executed: sh -c cp /Library/Preferences/SystemConfiguration/preferences.plist /Library/Preferences/SystemConfiguration/preferences.plist.old
Source: /usr/sbin/networksetup (PID: 608)Shell command executed: sh -c cp /Library/Preferences/SystemConfiguration/preferences.plist /Library/Preferences/SystemConfiguration/preferences.plist.old
Source: /usr/sbin/networksetup (PID: 610)Shell command executed: sh -c cp /Library/Preferences/SystemConfiguration/preferences.plist /Library/Preferences/SystemConfiguration/preferences.plist.old
Source: /usr/sbin/networksetup (PID: 612)Shell command executed: sh -c cp /Library/Preferences/SystemConfiguration/preferences.plist /Library/Preferences/SystemConfiguration/preferences.plist.old
Source: /usr/sbin/networksetup (PID: 614)Shell command executed: sh -c cp /Library/Preferences/SystemConfiguration/preferences.plist /Library/Preferences/SystemConfiguration/preferences.plist.old
Source: /usr/sbin/networksetup (PID: 616)Shell command executed: sh -c cp /Library/Preferences/SystemConfiguration/preferences.plist /Library/Preferences/SystemConfiguration/preferences.plist.old
Executes the "grep" command used to find patterns in files or piped streamsShow sources
Source: /bin/bash (PID: 595)Grep executable: /usr/bin/grep -> grep installdp
Source: /bin/bash (PID: 596)Grep executable: /usr/bin/grep -> grep -o ^[ ]*[0-9]*
Executes the "ps" command used to list the status of processesShow sources
Source: /bin/bash (PID: 594)Ps executable: /bin/ps -> ps cax
Executes the "security_authtrampoline" command used to authorize execution with root priviliges (GUI prompt)Show sources
Source: /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/Install (PID: 585)Security_authtrampoline executable: /usr/libexec/security_authtrampoline -> /usr/libexec/security_authtrampoline /System/Library/ScriptingAdditions/StandardAdditions.osax/Contents/MacOS/uid auth 10 /System/Library/ScriptingAdditions/StandardAdditions.osax/Contents/MacOS/uid /bin/sh -c '/Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/install.sh'
Uses AppleScript framework/components containing Apple Script related functionalitiesShow sources
Source: /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/Install (PID: 575)AppleScript framework/component info plist opened: /System/Library/Components/AppleScript.component/Contents/Info.plist
Source: /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/Install (PID: 575)AppleScript framework/component info plist opened: /System/Library/PrivateFrameworks/AppleScript.framework/Resources/Info.plist
Uses AppleScript scripting additions containing additional functionalities for Apple ScriptsShow sources
Source: /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/Install (PID: 575)AppleScript scripting addition info plist opened: /System/Library/ScriptingAdditions/Digital Hub Scripting.osax/Contents/Info.plist
Source: /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/Install (PID: 575)AppleScript scripting addition info plist opened: /System/Library/ScriptingAdditions/StandardAdditions.osax/Contents/Info.plist
Uses CFNetwork bundle containing interfaces for network communication (HTTP, sockets, and Bonjour)Show sources
Source: /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/Install Adobe Flash Player (PID: 599)CFNetwork info plist opened: /System/Library/Frameworks/CFNetwork.framework/Resources/Info.plist
Writes 64-bit Mach-O files to diskShow sources
Source: /bin/cp (PID: 588)File written: /Library/Scripts/installdp
Writes shell script files to diskShow sources
Source: /bin/cp (PID: 589)Shell script file created: /Library/Scripts/installd.sh
Many shell processes execute programs via execve syscall (may be indicative for malicious behaviour)Show sources
Source: /bin/sh (PID: 585)Shell process: /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/install.sh
Source: /bin/sh (PID: 586)Shell process: dirname /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/install.sh
Source: /bin/sh (PID: 587)Shell process: cp -f /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/queue /Library/Scripts/queue
Source: /bin/sh (PID: 588)Shell process: cp -f /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/installdp /Library/Scripts/installdp
Source: /bin/sh (PID: 589)Shell process: cp -f /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/installd.sh /Library/Scripts/installd.sh
Source: /bin/sh (PID: 590)Shell process: cp -f /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/com.adobe.update /Library/LaunchDaemons/com.adobe.update.plist
Source: /bin/sh (PID: 591)Shell process: /Library/Scripts/installd.sh
Source: /bin/sh (PID: 606)Shell process: networksetup -getwebproxy Ethernet
Source: /bin/sh (PID: 607)Shell process: cp /Library/Preferences/SystemConfiguration/preferences.plist /Library/Preferences/SystemConfiguration/preferences.plist.old
Source: /bin/sh (PID: 608)Shell process: networksetup -getsecurewebproxy Ethernet
Source: /bin/sh (PID: 609)Shell process: cp /Library/Preferences/SystemConfiguration/preferences.plist /Library/Preferences/SystemConfiguration/preferences.plist.old
Source: /bin/sh (PID: 610)Shell process: networksetup -getsocksfirewallproxy Ethernet
Source: /bin/sh (PID: 611)Shell process: cp /Library/Preferences/SystemConfiguration/preferences.plist /Library/Preferences/SystemConfiguration/preferences.plist.old
Source: /bin/sh (PID: 612)Shell process: networksetup -getwebproxy Ethernet
Source: /bin/sh (PID: 613)Shell process: cp /Library/Preferences/SystemConfiguration/preferences.plist /Library/Preferences/SystemConfiguration/preferences.plist.old
Source: /bin/sh (PID: 614)Shell process: networksetup -getsecurewebproxy Ethernet
Source: /bin/sh (PID: 615)Shell process: cp /Library/Preferences/SystemConfiguration/preferences.plist /Library/Preferences/SystemConfiguration/preferences.plist.old
Source: /bin/sh (PID: 616)Shell process: networksetup -getsocksfirewallproxy Ethernet
Source: /bin/sh (PID: 617)Shell process: cp /Library/Preferences/SystemConfiguration/preferences.plist /Library/Preferences/SystemConfiguration/preferences.plist.old
Source: /bin/sh (PID: 599)Shell process: /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/Install Adobe Flash Player

Boot Survival:

barindex
Creates memory-persistent launch servicesShow sources
Source: /bin/cp (PID: 590)Launch agent/daemon created with KeepAlive and/or RunAtLoad, file created: /Library/LaunchDaemons/com.adobe.update.plist
Creates system-wide 'launchd' managed services aka launch daemonsShow sources
Source: /bin/cp (PID: 590)Launch daemon created file created: /Library/LaunchDaemons/com.adobe.update.plist

HIPS / PFW / Operating System Protection Evasion:

barindex
Reads the sysctl safe boot value (probably to check if the system is in safe boot mode)Show sources
Source: /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/Install (PID: 575)Sysctl read request: kern.safeboot (1.66)

Language, Device and Operating System Detection:

barindex
Reads the system or server version plist fileShow sources
Source: /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/Install (PID: 575)System or server version plist file read: /System/Library/CoreServices/SystemVersion.plist
Source: /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/Install Adobe Flash Player (PID: 599)System or server version plist file read: /System/Library/CoreServices/SystemVersion.plist
Reads hardware related sysctl valuesShow sources
Source: /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/Install Adobe Flash Player (PID: 599)Sysctl read request: hw.availcpu (6.25)
Source: /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/Install Adobe Flash Player (PID: 599)Sysctl read request: hw.ncpu (6.3)
Source: /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/Install Adobe Flash Player (PID: 599)Sysctl read request: hw.cpu_freq (6.15)
Reads the kernel OS version valueShow sources
Source: /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/Install Adobe Flash Player (PID: 599)Sysctl read request: kern.osversion (1.65)
Reads the systems OS release and/or typeShow sources
Source: /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/Install (PID: 575)Sysctl requested: kern.ostype (1.1)
Source: /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/Install (PID: 575)Sysctl requested: kern.osrelease (1.2)
Source: /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/Install Adobe Flash Player (PID: 599)Sysctl requested: kern.ostype (1.1)
Source: /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/Install Adobe Flash Player (PID: 599)Sysctl requested: kern.osrelease (1.2)
Reads the systems hostnameShow sources
Source: /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/Install (PID: 575)Sysctl requested: kern.hostname (1.10)
Source: /bin/sh (PID: 585)Sysctl requested: kern.hostname (1.10)
Source: /Users/vreni/Desktop/unpack/Install Adobe Flash Player.app/install.sh (PID: 585)Sysctl requested: kern.hostname (1.10)
Source: /Library/Scripts/installd.sh (PID: 591)Sysctl requested: kern.hostname (1.10)
Source: /bin/sh (PID: 606)Sysctl requested: kern.hostname (1.10)
Source: /bin/sh (PID: 607)Sysctl requested: kern.hostname (1.10)
Source: /bin/sh (PID: 608)Sysctl requested: kern.hostname (1.10)
Source: /bin/sh (PID: 609)Sysctl requested: kern.hostname (1.10)
Source: /bin/sh (PID: 610)Sysctl requested: kern.hostname (1.10)
Source: /bin/sh (PID: 611)Sysctl requested: kern.hostname (1.10)
Source: /bin/sh (PID: 612)Sysctl requested: kern.hostname (1.10)
Source: /bin/sh (PID: 613)Sysctl requested: kern.hostname (1.10)
Source: /bin/sh (PID: 614)Sysctl requested: kern.hostname (1.10)
Source: /bin/sh (PID: 615)Sysctl requested: kern.hostname (1.10)
Source: /bin/sh (PID: 616)Sysctl requested: kern.hostname (1.10)
Source: /bin/sh (PID: 617)Sysctl requested: kern.hostname (1.10)
Reads process information of other processesShow sources
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.596 -> queries PID 596
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.595 -> queries PID 595
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.593 -> queries PID 593
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.591 -> queries PID 591
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.585 -> queries PID 585
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.584 -> queries PID 584
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.583 -> queries PID 583
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.582 -> queries PID 582
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.581 -> queries PID 581
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.580 -> queries PID 580
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.579 -> queries PID 579
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.578 -> queries PID 578
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.577 -> queries PID 577
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.576 -> queries PID 576
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.575 -> queries PID 575
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.571 -> queries PID 571
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.569 -> queries PID 569
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.567 -> queries PID 567
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.566 -> queries PID 566
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.565 -> queries PID 565
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.562 -> queries PID 562
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.559 -> queries PID 559
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.558 -> queries PID 558
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.551 -> queries PID 551
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.541 -> queries PID 541
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.539 -> queries PID 539
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.535 -> queries PID 535
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.518 -> queries PID 518
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.515 -> queries PID 515
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.514 -> queries PID 514
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.512 -> queries PID 512
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.445 -> queries PID 445
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.442 -> queries PID 442
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.436 -> queries PID 436
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.431 -> queries PID 431
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.430 -> queries PID 430
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.426 -> queries PID 426
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.416 -> queries PID 416
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.415 -> queries PID 415
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.414 -> queries PID 414
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.413 -> queries PID 413
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.412 -> queries PID 412
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.410 -> queries PID 410
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.409 -> queries PID 409
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.407 -> queries PID 407
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.406 -> queries PID 406
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.405 -> queries PID 405
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.403 -> queries PID 403
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.402 -> queries PID 402
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.401 -> queries PID 401
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.396 -> queries PID 396
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.395 -> queries PID 395
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.394 -> queries PID 394
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.393 -> queries PID 393
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.392 -> queries PID 392
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.391 -> queries PID 391
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.390 -> queries PID 390
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.389 -> queries PID 389
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.385 -> queries PID 385
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.384 -> queries PID 384
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.383 -> queries PID 383
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.382 -> queries PID 382
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.378 -> queries PID 378
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.377 -> queries PID 377
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.375 -> queries PID 375
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.372 -> queries PID 372
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.369 -> queries PID 369
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.368 -> queries PID 368
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.366 -> queries PID 366
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.364 -> queries PID 364
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.363 -> queries PID 363
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.362 -> queries PID 362
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.361 -> queries PID 361
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.360 -> queries PID 360
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.358 -> queries PID 358
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.353 -> queries PID 353
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.352 -> queries PID 352
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.351 -> queries PID 351
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.350 -> queries PID 350
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.349 -> queries PID 349
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.348 -> queries PID 348
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.347 -> queries PID 347
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.343 -> queries PID 343
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.342 -> queries PID 342
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.341 -> queries PID 341
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.340 -> queries PID 340
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.339 -> queries PID 339
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.338 -> queries PID 338
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.335 -> queries PID 335
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.334 -> queries PID 334
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.333 -> queries PID 333
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.330 -> queries PID 330
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.328 -> queries PID 328
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.324 -> queries PID 324
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.323 -> queries PID 323
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.322 -> queries PID 322
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.321 -> queries PID 321
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.320 -> queries PID 320
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.319 -> queries PID 319
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.317 -> queries PID 317
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.315 -> queries PID 315
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.314 -> queries PID 314
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.313 -> queries PID 313
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.312 -> queries PID 312
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.311 -> queries PID 311
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.309 -> queries PID 309
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.307 -> queries PID 307
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.305 -> queries PID 305
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.303 -> queries PID 303
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.302 -> queries PID 302
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.301 -> queries PID 301
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.300 -> queries PID 300
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.299 -> queries PID 299
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.298 -> queries PID 298
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.297 -> queries PID 297
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.295 -> queries PID 295
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.293 -> queries PID 293
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.292 -> queries PID 292
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.291 -> queries PID 291
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.289 -> queries PID 289
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.287 -> queries PID 287
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.286 -> queries PID 286
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.284 -> queries PID 284
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.282 -> queries PID 282
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.278 -> queries PID 278
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.265 -> queries PID 265
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.264 -> queries PID 264
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.223 -> queries PID 223
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.196 -> queries PID 196
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.195 -> queries PID 195
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.194 -> queries PID 194
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.193 -> queries PID 193
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.187 -> queries PID 187
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.186 -> queries PID 186
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.185 -> queries PID 185
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.184 -> queries PID 184
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.182 -> queries PID 182
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.181 -> queries PID 181
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.180 -> queries PID 180
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.179 -> queries PID 179
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.177 -> queries PID 177
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.176 -> queries PID 176
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.175 -> queries PID 175
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.160 -> queries PID 160
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.159 -> queries PID 159
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.157 -> queries PID 157
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.156 -> queries PID 156
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.154 -> queries PID 154
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.153 -> queries PID 153
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.152 -> queries PID 152
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.151 -> queries PID 151
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.146 -> queries PID 146
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.137 -> queries PID 137
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.134 -> queries PID 134
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.133 -> queries PID 133
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.126 -> queries PID 126
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.125 -> queries PID 125
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.103 -> queries PID 103
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.101 -> queries PID 101
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.99 -> queries PID 99
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.98 -> queries PID 98
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.97 -> queries PID 97
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.96 -> queries PID 96
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.95 -> queries PID 95
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.93 -> queries PID 93
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.92 -> queries PID 92
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.91 -> queries PID 91
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.90 -> queries PID 90
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.88 -> queries PID 88
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.83 -> queries PID 83
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.82 -> queries PID 82
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.77 -> queries PID 77
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.76 -> queries PID 76
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.75 -> queries PID 75
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.74 -> queries PID 74
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.72 -> queries PID 72
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.71 -> queries PID 71
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.69 -> queries PID 69
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.68 -> queries PID 68
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.66 -> queries PID 66
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.65 -> queries PID 65
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.64 -> queries PID 64
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.61 -> queries PID 61
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.60 -> queries PID 60
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.58 -> queries PID 58
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.52 -> queries PID 52
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.51 -> queries PID 51
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.50 -> queries PID 50
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.49 -> queries PID 49
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.45 -> queries PID 45
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.44 -> queries PID 44
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.42 -> queries PID 42
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.41 -> queries PID 41
Source: /bin/ps (PID: 594)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.1 -> queries PID 1

Lowering of HIPS / PFW / Operating System Security Settings:

barindex
Executes the "networksetup" command used to configure network settingsShow sources
Source: /bin/sh (PID: 606)Networksetup executable: /usr/sbin/networksetup -> networksetup -getwebproxy Ethernet
Source: /bin/sh (PID: 608)Networksetup executable: /usr/sbin/networksetup -> networksetup -getsecurewebproxy Ethernet
Source: /bin/sh (PID: 610)Networksetup executable: /usr/sbin/networksetup -> networksetup -getsocksfirewallproxy Ethernet
Source: /bin/sh (PID: 612)Networksetup executable: /usr/sbin/networksetup -> networksetup -getwebproxy Ethernet
Source: /bin/sh (PID: 614)Networksetup executable: /usr/sbin/networksetup -> networksetup -getsecurewebproxy Ethernet
Source: /bin/sh (PID: 616)Networksetup executable: /usr/sbin/networksetup -> networksetup -getsocksfirewallproxy Ethernet
Explicitly retrieves the SOCKS firewall proxy configurationShow sources
Source: /bin/sh (PID: 610)Networksetup with SOCKS firewall proxy args: networksetup -getsocksfirewallproxy Ethernet
Source: /bin/sh (PID: 616)Networksetup with SOCKS firewall proxy args: networksetup -getsocksfirewallproxy Ethernet
Explicitly retrieves the web proxy configurationShow sources
Source: /bin/sh (PID: 606)Networksetup with web proxy args: networksetup -getwebproxy Ethernet
Source: /bin/sh (PID: 608)Networksetup with web proxy args: networksetup -getsecurewebproxy Ethernet
Source: /bin/sh (PID: 612)Networksetup with web proxy args: networksetup -getwebproxy Ethernet
Source: /bin/sh (PID: 614)Networksetup with web proxy args: networksetup -getsecurewebproxy Ethernet


Runtime Messages

Command:open
Exitcode:0
Killed:False
Standard Output:
Standard Error:

Yara Overview

No Yara matches

Screenshot