Analysis Report
Overview
General Information |
|---|
| Joe Sandbox Version: | 19.0.0 |
| Analysis ID: | 37008 |
| Start time: | 09:40:01 |
| Joe Sandbox Product: | Cloud |
| Start date: | 03.05.2017 |
| Overall analysis duration: | 0h 9m 40s |
| Report type: | full |
| Sample file name: | 54ee71f6ad1f91a6f162bd5712d1a2e3d3111c352a0f52db630dcb4638101938.zip |
| Cookbook file name: | default.jbs |
| Analysis system description: | Mac Mini, El Capitan 10.11.6 (MS Office 15.25, Java 1.8.0_25) |
| Detection: | MAL |
| Classification: | mal72.troj.evad.macZIP@0/18@0/0 |
Detection |
|---|
| Strategy | Score | Range | Reporting | Detection | |
|---|---|---|---|---|---|
| Threshold | 72 | 0 - 100 | Report FP / FN | ||
Classification |
|---|
Signature Overview |
|---|
Click to jump to signature section
Networking: |
|---|
| Writes from file descriptors related to (network) sockets | Show sources | ||
| Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 594) | Writes from socket in process: | ||
| Detected TCP or UDP traffic on non-standard ports | Show sources | ||
| Source: global traffic | TCP traffic: | ||
System Summary: |
|---|
| Classification label | Show sources | ||
| Source: classification engine | Classification label: | ||
| Writes Python scripts without typical Python file extensions | Show sources | ||
| Source: /usr/bin/base64 (PID: 586) | Python file created: | ||
| Submitted sample is a known malware sample | Show sources | ||
| Source: MD5 0e48346ebd57b1b6dbaa0bbad4d579dc | Submitted blacklisted sample: | ||
Persistence and Installation Behavior: |
|---|
| Executes the "PlistBuddy" command used to read and write values to plists | Show sources | ||
| Source: /bin/sh (PID: 599) | Sysctl executable: | ||
| Reads data from the local random generator | Show sources | ||
| Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | Random device file read: | ||
| Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | Random device file read: | ||
| Source: /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 590) | Random device file read: | ||
| Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 594) | Random device file read: | ||
| Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 594) | Random device file read: | ||
| Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 594) | Random device file read: | ||
| Submitted sample is a bundle that is signed | Show sources | ||
| Source: /Users/vreni/Desktop/unpack/Dokument.app/Contents/MacOS/AppStore (PID: 570) | CodeSignature CodeResources file read: | ||
| Source: /Users/vreni/Desktop/unpack/Dokument.app/Contents/MacOS/AppStore (PID: 570) | CodeSignature CodeResources file read: | ||
| Uses AppleKeyboardLayouts bundle containing keyboard layouts | Show sources | ||
| Source: /Users/vreni/Desktop/unpack/Dokument.app/Contents/MacOS/AppStore (PID: 570) | AppleKeyboardLayouts info plist opened: | ||
| Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | AppleKeyboardLayouts info plist opened: | ||
| Uses the Python framework | Show sources | ||
| Source: /Library/Frameworks/Python.framework/Versions/2.7/bin/python (PID: 590) | Python framework application: | ||
| Source: /usr/bin/python (PID: 594) | Python framework application: | ||
| Writes log files to disk | Show sources | ||
| Source: /Users/vreni/Desktop/unpack/Dokument.app/Contents/MacOS/AppStore (PID: 570) | Log file created: | ||
| Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | Log file created: | ||
| Writes property list (.plist) files to disk | Show sources | ||
| Source: /Users/vreni/Desktop/unpack/Dokument.app/Contents/MacOS/AppStore (PID: 570) | XML plist file created: | ||
| Source: /Users/vreni/Desktop/unpack/Dokument.app/Contents/MacOS/AppStore (PID: 570) | XML plist file created: | ||
| Source: /Users/vreni/Desktop/unpack/Dokument.app/Contents/MacOS/AppStore (PID: 570) | Binary plist file created: | ||
| Source: /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 590) | XML plist file created: | ||
| Changes permissions of written Mach-O files | Show sources | ||
| Source: /Users/vreni/Desktop/unpack/Dokument.app/Contents/MacOS/AppStore (PID: 570) | Permissions modifiied for written 64-bit Mach-O /Users/Shared/AppStore.app/Contents/MacOS/AppStore: | ||
| Creates hidden files, links and/or directories | Show sources | ||
| Source: /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 590) | Hidden Directory created: | ||
| Creates launch services that start periodically | Show sources | ||
| Source: /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 590) | Launch agent/daemon created with StartInterval and/or StartCalendarInterval, file created: | ||
| Executes commands using a shell command-line interpreter | Show sources | ||
| Source: /Users/vreni/Desktop/unpack/Dokument.app/Contents/MacOS/AppStore (PID: 570) | Shell command executed: | ||
| Source: /Users/vreni/Desktop/unpack/Dokument.app/Contents/MacOS/AppStore (PID: 570) | Shell command executed: | ||
| Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | Shell command executed: | ||
| Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | Shell command executed: | ||
| Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | Shell command executed: | ||
| Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | Shell command executed: | ||
| Source: /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 591) | Shell command executed: | ||
| Source: /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 592) | Shell command executed: | ||
| Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 598) | Shell command executed: | ||
| Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 599) | Shell command executed: | ||
| Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 600) | Shell command executed: | ||
| Executes the "chmod" command used to modify permissions | Show sources | ||
| Source: /bin/bash (PID: 572) | Chmod executable: | ||
| Source: /bin/bash (PID: 588) | Chmod executable: | ||
| Executes the "grep" command used to find patterns in files or piped streams | Show sources | ||
| Source: /bin/sh (PID: 602) | Grep executable: | ||
| Executes the "python" command used to interprete Python scripts | Show sources | ||
| Source: /tmp/AppStore (PID: 590) | Python executable: | ||
| Source: /Users/vreni/Library/Containers/.bella/Bella (PID: 594) | Python executable: | ||
| Executes the "sysctl" command used to retrieve or modify kernel settings | Show sources | ||
| Source: /bin/sh (PID: 599) | Sysctl executable: | ||
| Explicitly loads/starts launch services | Show sources | ||
| Source: /bin/sh (PID: 592) | Launch agent/daemon loaded: | ||
| Reads launchservices plist files | Show sources | ||
| Source: /Users/vreni/Desktop/unpack/Dokument.app/Contents/MacOS/AppStore (PID: 570) | Launchservices plist file read: | ||
| Source: /Users/vreni/Desktop/unpack/Dokument.app/Contents/MacOS/AppStore (PID: 570) | Launchservices plist file read: | ||
| Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | Launchservices plist file read: | ||
| Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | Launchservices plist file read: | ||
| Reads user launchservices plist file containing default apps for corresponding filetypes | Show sources | ||
| Source: /Users/vreni/Desktop/unpack/Dokument.app/Contents/MacOS/AppStore (PID: 570) | Preferences launchservices plist file read: | ||
| Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | Preferences launchservices plist file read: | ||
| Uses AppleScript framework/components containing Apple Script related functionalities | Show sources | ||
| Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | AppleScript framework/component info plist opened: | ||
| Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | AppleScript framework/component info plist opened: | ||
| Uses AppleScript scripting additions containing additional functionalities for Apple Scripts | Show sources | ||
| Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | AppleScript scripting addition info plist opened: | ||
| Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | AppleScript scripting addition info plist opened: | ||
| Writes 64-bit Mach-O files to disk | Show sources | ||
| Source: /Users/vreni/Desktop/unpack/Dokument.app/Contents/MacOS/AppStore (PID: 570) | File written: | ||
| Writes icon files to disk | Show sources | ||
| Source: /Users/vreni/Desktop/unpack/Dokument.app/Contents/MacOS/AppStore (PID: 570) | File written: | ||
| Deletes icon files | Show sources | ||
| Source: /bin/rm (PID: 603) | File deleted: | ||
| Executes the "rm" command used to delete files or directories | Show sources | ||
| Source: /bin/bash (PID: 576) | Rm executable: | ||
| Source: /bin/bash (PID: 589) | Rm executable: | ||
| Source: /bin/bash (PID: 603) | Rm executable: | ||
| Executes the "scutil" command used to manage network related system configuration parameters | Show sources | ||
| Source: /bin/sh (PID: 591) | Scutil executable: | ||
| Source: /bin/sh (PID: 598) | Scutil executable: | ||
| Uses sfltool in order to modify login item settings | Show sources | ||
| Source: /System/Library/CoreServices/sharedfilelistd (PID: 578) | Sfltool executed with keyword 'loginitems': | ||
| Source: /System/Library/CoreServices/sharedfilelistd (PID: 579) | Sfltool executed with keyword 'loginitems': | ||
| Source: /System/Library/CoreServices/sharedfilelistd (PID: 580) | Sfltool executed with keyword 'loginitems': | ||
| Source: /System/Library/CoreServices/sharedfilelistd (PID: 595) | Sfltool executed with keyword 'loginitems': | ||
| Source: /System/Library/CoreServices/sharedfilelistd (PID: 604) | Sfltool executed with keyword 'loginitems': | ||
Boot Survival: |
|---|
| Creates user-wide 'launchd' managed services aka launch agents | Show sources | ||
| Source: /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 590) | Launch agent created file created: | ||
Hooking and other Techniques for Hiding and Protection: |
|---|
| Executes the "base64" command used to encode or decode data (e.g. files, payloads) | Show sources | ||
| Source: /bin/bash (PID: 586) | Base64 executable: | ||
| Moves itself during installation or deletes itself after installation | Show sources | ||
| Source: /bin/rm (PID: 603) | Directory deleted: | ||
| Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 594) | File deleted: | ||
Malware Analysis System Evasion: |
|---|
| Executes the "sleep" command used to delay execution and potentially evade sandboxes | Show sources | ||
| Source: /bin/bash (PID: 574) | Sleep executable: | ||
| Source: /bin/bash (PID: 597) | Sleep executable: | ||
HIPS / PFW / Operating System Protection Evasion: |
|---|
| Reads the sysctl safe boot value (probably to check if the system is in safe boot mode) | Show sources | ||
| Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | Sysctl read request: | ||
Language, Device and Operating System Detection: |
|---|
| Reads the system or server version plist file | Show sources | ||
| Source: /Users/vreni/Desktop/unpack/Dokument.app/Contents/MacOS/AppStore (PID: 570) | System or server version plist file read: | ||
| Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | System or server version plist file read: | ||
| Source: /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 590) | System or server version plist file read: | ||
| Source: /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 590) | System or server version plist file read: | ||
| Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 594) | System or server version plist file read: | ||
| Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 594) | System or server version plist file read: | ||
| Reads hardware related sysctl values | Show sources | ||
| Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | Sysctl read request: | ||
| Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | Sysctl read request: | ||
| Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | Sysctl read request: | ||
| Reads the kernel OS version value | Show sources | ||
| Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | Sysctl read request: | ||
| Reads the systems hostname | Show sources | ||
| Source: /bin/bash (PID: 572) | Sysctl requested: | ||
| Source: /bin/bash (PID: 573) | Sysctl requested: | ||
| Source: /bin/bash (PID: 586) | Sysctl requested: | ||
| Source: /bin/bash (PID: 587) | Sysctl requested: | ||
| Source: /bin/bash (PID: 590) | Sysctl requested: | ||
| Source: /bin/sh (PID: 591) | Sysctl requested: | ||
| Source: /bin/sh (PID: 592) | Sysctl requested: | ||
| Source: /bin/bash (PID: 596) | Sysctl requested: | ||
| Source: /bin/sh (PID: 598) | Sysctl requested: | ||
| Source: /bin/sh (PID: 599) | Sysctl requested: | ||
| Source: /bin/sh (PID: 600) | Sysctl requested: | ||
Remote Access Functionality: |
|---|
| Installs Bella RAT | Show sources | ||
| Source: PIDs 590 and 586 | Behaviour pattern found: | ||
| Writes files containing IP addresses of contacted hosts (e.g. command and control server) | Show sources | ||
| Source: global traffic and dropped files | IP 185.68.93.74 found in file: | ||
Runtime Messages |
|---|
| Command: | open |
| Exitcode: | 0 |
| Killed: | False |
| Standard Output: | |
| Standard Error: |
Yara Overview |
|---|
| No Yara matches |
|---|
Screenshot |
|---|
Startup |
|---|
|
Created / dropped Files |
|---|
| File Path | Type and Hashes | Malicious |
|---|---|---|
| false | |
| false | |
| false | |
| false | |
| false | |
| false | |
| false | |
| false | |
| false | |
| false | |
| true | |
| false | |
| false |
Contacted Domains/Contacted IPs |
|---|
Contacted Domains |
|---|
| No contacted domains info |
|---|
Contacted IPs |
|---|
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
| IP | Country | Flag | ASN | ASN Name | Malicious |
|---|---|---|---|---|---|
| 8.8.8.8 | United States | 15169 | GoogleInc | false | |
| 17.252.76.100 | United States | 714 | AppleInc | false | |
| 17.188.165.205 | United States | 714 | AppleInc | false | |
| 17.253.20.125 | United States | 6185 | AppleInc | false | |
| 224.0.0.251 | Reserved | 2541 | JumpManagementSRL | false | |
| 185.68.93.74 | Russian Federation | 56577 | RelinkLTD | true |
Static File Info |
|---|
General | |
|---|---|
| File type: | |
| TrID: |
|
| File name: | 54ee71f6ad1f91a6f162bd5712d1a2e3d3111c352a0f52db630dcb4638101938.zip |
| File size: | 96065 |
| MD5: | 0e48346ebd57b1b6dbaa0bbad4d579dc |
| SHA1: | 1e7be91179410a9d78cc4401aa3f9a7b62e8a59a |
| SHA256: | 54ee71f6ad1f91a6f162bd5712d1a2e3d3111c352a0f52db630dcb4638101938 |
| SHA512: | 0725cd1b8d1902ca18cae6f3443d288e60ab81455dc4fb268b56b2b6443e66b09d904a9f47ce47b06c65a3b840506ecf752f77bb5063e587744d5aeb5aabb44b |
| File Content Preview: | PK.........\.J................Dokument.app/PK.........\.J................Dokument.app/Contents/PK.........\.J............%...Dokument.app/Contents/_CodeSignature/PK.........\.J.m$N........2...Dokument.app/Contents/_CodeSignature/CodeResources..]S.@....W.. |
Static App Info |
|---|
General Informations | |
|---|---|
| Package Info: | |
| Property List File: | |
Resources |
|---|
| Name | Type |
|---|---|
| Info.plist | XML document text |
| PkgInfo | ASCII text, with no line terminators |
| AppStore | Mach-O 64-bit executable |
| AppIcon.icns | data |
| MainMenu.nib | Apple binary property list |
| MainMenu.strings | UTF-8 Unicode text |
| MainMenu.strings | UTF-8 Unicode text |
| CodeResources | XML document text |
| Info.plist | XML document text |
| PkgInfo | ASCII text, with no line terminators |
| AppStore | Mach-O 64-bit executable |
| AppIcon.icns | data |
| MainMenu.nib | Apple binary property list |
| MainMenu.strings | UTF-8 Unicode text |
| MainMenu.strings | UTF-8 Unicode text |
| CodeResources | XML document text |
Static Mach Info |
|---|
General Informations for header0 | |
|---|---|
| Endian: | |
| Size: | |
| Architecture: | |
| Filetype: | |
| Nbr. of load commands: | 22 |
segment_command_64 |
|---|
| Name | Value | |
|---|---|---|
| segname | __PAGEZERO | |
| fileoff | 0 | |
| maxprot | 0 | |
| vmsize | 4294967296 | |
| nsects | 0 | |
| flags | 0 | |
| filesize | 0 | |
| vmaddr | 0 | |
| initprot | 0 | |
segment_command_64 |
|---|
| Name | Value | |
|---|---|---|
| segname | __TEXT | |
| fileoff | 0 | |
| maxprot | 7 | |
| vmsize | 20480 | |
| nsects | 12 | |
| flags | 0 | |
| filesize | 20480 | |
| vmaddr | 4294967296 | |
| initprot | 5 | |
| Datas | sectname | __text |
| segname | __TEXT | |
| reloff | 0 | |
| addr | 4294971134 | |
| align | 0 | |
| nreloc | 0 | |
| flags | 2147484672 | |
| offset | 3838 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 8956 | |
| sectname | __stubs | |
| segname | __TEXT | |
| reloff | 0 | |
| addr | 4294980090 | |
| align | 1 | |
| nreloc | 0 | |
| flags | 2147484680 | |
| offset | 12794 | |
| reserved2 | 6 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 150 | |
| sectname | __stub_helper | |
| segname | __TEXT | |
| reloff | 0 | |
| addr | 4294980240 | |
| align | 2 | |
| nreloc | 0 | |
| flags | 2147484672 | |
| offset | 12944 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 266 | |
| sectname | __objc_methname | |
| segname | __TEXT | |
| reloff | 0 | |
| addr | 4294980506 | |
| align | 0 | |
| nreloc | 0 | |
| flags | 2 | |
| offset | 13210 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 2749 | |
| sectname | __cstring | |
| segname | __TEXT | |
| reloff | 0 | |
| addr | 4294983255 | |
| align | 0 | |
| nreloc | 0 | |
| flags | 2 | |
| offset | 15959 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 1214 | |
| sectname | __objc_classname | |
| segname | __TEXT | |
| reloff | 0 | |
| addr | 4294984469 | |
| align | 0 | |
| nreloc | 0 | |
| flags | 2 | |
| offset | 17173 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 106 | |
| sectname | __objc_methtype | |
| segname | __TEXT | |
| reloff | 0 | |
| addr | 4294984575 | |
| align | 0 | |
| nreloc | 0 | |
| flags | 2 | |
| offset | 17279 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 1177 | |
| sectname | __const | |
| segname | __TEXT | |
| reloff | 0 | |
| addr | 4294985752 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 0 | |
| offset | 18456 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 8 | |
| sectname | __gcc_except_tab | |
| segname | __TEXT | |
| reloff | 0 | |
| addr | 4294985760 | |
| align | 2 | |
| nreloc | 0 | |
| flags | 0 | |
| offset | 18464 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 1508 | |
| sectname | __ustring | |
| segname | __TEXT | |
| reloff | 0 | |
| addr | 4294987268 | |
| align | 1 | |
| nreloc | 0 | |
| flags | 0 | |
| offset | 19972 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 212 | |
| sectname | __unwind_info | |
| segname | __TEXT | |
| reloff | 0 | |
| addr | 4294987480 | |
| align | 2 | |
| nreloc | 0 | |
| flags | 0 | |
| offset | 20184 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 164 | |
| sectname | __eh_frame | |
| segname | __TEXT | |
| reloff | 0 | |
| addr | 4294987648 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 0 | |
| offset | 20352 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 128 | |
segment_command_64 |
|---|
| Name | Value | |
|---|---|---|
| segname | __DATA | |
| fileoff | 20480 | |
| maxprot | 7 | |
| vmsize | 155648 | |
| nsects | 16 | |
| flags | 0 | |
| filesize | 155648 | |
| vmaddr | 4294987776 | |
| initprot | 3 | |
| Datas | sectname | __nl_symbol_ptr |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4294987776 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 6 | |
| offset | 20480 | |
| reserved2 | 0 | |
| reserved1 | 25 | |
| reserved3 | 0 | |
| size | 16 | |
| sectname | __got | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4294987792 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 6 | |
| offset | 20496 | |
| reserved2 | 0 | |
| reserved1 | 27 | |
| reserved3 | 0 | |
| size | 48 | |
| sectname | __la_symbol_ptr | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4294987840 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 7 | |
| offset | 20544 | |
| reserved2 | 0 | |
| reserved1 | 33 | |
| reserved3 | 0 | |
| size | 200 | |
| sectname | __cfstring | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4294988040 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 0 | |
| offset | 20744 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 1312 | |
| sectname | __objc_classlist | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4294989352 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 268435456 | |
| offset | 22056 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 16 | |
| sectname | __objc_catlist | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4294989368 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 268435456 | |
| offset | 22072 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 8 | |
| sectname | __objc_protolist | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4294989376 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 0 | |
| offset | 22080 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 24 | |
| sectname | __objc_imageinfo | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4294989400 | |
| align | 2 | |
| nreloc | 0 | |
| flags | 0 | |
| offset | 22104 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 8 | |
| sectname | __objc_const | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4294989408 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 0 | |
| offset | 22112 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 3392 | |
| sectname | __objc_selrefs | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4294992800 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 268435461 | |
| offset | 25504 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 448 | |
| sectname | __objc_classrefs | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4294993248 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 268435456 | |
| offset | 25952 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 112 | |
| sectname | __objc_superrefs | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4294993360 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 268435456 | |
| offset | 26064 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 8 | |
| sectname | __objc_ivar | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4294993368 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 0 | |
| offset | 26072 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 72 | |
| sectname | __objc_data | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4294993440 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 0 | |
| offset | 26144 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 160 | |
| sectname | __data | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4294993600 | |
| align | 4 | |
| nreloc | 0 | |
| flags | 0 | |
| offset | 26304 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 149792 | |
| sectname | __bss | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4295143392 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 1 | |
| offset | 0 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 8 | |
segment_command_64 |
|---|
| Name | Value | |
|---|---|---|
| segname | __LINKEDIT | |
| fileoff | 176128 | |
| maxprot | 7 | |
| vmsize | 16384 | |
| nsects | 0 | |
| flags | 0 | |
| filesize | 14304 | |
| vmaddr | 4295143424 | |
| initprot | 1 | |
dyld_info_command |
|---|
| Name | Value | |
|---|---|---|
| lazy_bind_size | 600 | |
| lazy_bind_off | 177112 | |
| weak_bind_size | 0 | |
| rebase_size | 224 | |
| export_off | 177712 | |
| export_size | 32 | |
| bind_off | 176352 | |
| rebase_off | 176128 | |
| bind_size | 760 | |
| weak_bind_off | 0 | |
symtab_command |
|---|
| Name | Value | |
|---|---|---|
| strsize | 1016 | |
| symoff | 177856 | |
| stroff | 178904 | |
| nsyms | 51 | |
dysymtab_command |
|---|
| Name | Value | |
|---|---|---|
| extreloff | 0 | |
| nlocrel | 0 | |
| indirectsymoff | 178672 | |
| modtaboff | 0 | |
| nextrel | 0 | |
| iundefsym | 2 | |
| nmodtab | 0 | |
| ilocalsym | 0 | |
| nundefsym | 49 | |
| nextrefsyms | 0 | |
| locreloff | 0 | |
| ntoc | 0 | |
| nlocalsym | 1 | |
| tocoff | 0 | |
| extrefsymoff | 0 | |
| nindirectsyms | 58 | |
| iextdefsym | 1 | |
| nextdefsym | 1 | |
dylinker_command |
|---|
| Name | Value | |
|---|---|---|
| name | 12 | Data | /usr/lib/dyld |
uuid_command |
|---|
| Name | Value | |
|---|---|---|
| uuid | aa5e23e769d236e89aa0415a3e4291bb | |
version_min_command |
|---|
| Name | Value | |
|---|---|---|
| version | 657664 | |
| reserved | 657920 | |
source_version_command |
|---|
| Name | Value | |
|---|---|---|
| version | 0 | |
entry_point_command |
|---|
| Name | Value | |
|---|---|---|
| stacksize | 0 | |
| entryoff | 4519 | |
dylib_command |
|---|
| Name | Value | |
|---|---|---|
| compatibility_version | 0.44.1 | |
| timestamp | Thu Jan 01 01:00:02 1970 | |
| name | 24 | |
| current_version | 4096.127.4 | Data | /System/Library/Frameworks/Foundation.framework/Versions/C/Foundation |
dylib_command |
|---|
| Name | Value | |
|---|---|---|
| compatibility_version | 0.1.0 | |
| timestamp | Thu Jan 01 01:00:02 1970 | |
| name | 24 | |
| current_version | 0.228.0 | Data | /usr/lib/libobjc.A.dylib |
dylib_command |
|---|
| Name | Value | |
|---|---|---|
| compatibility_version | 0.1.0 | |
| timestamp | Thu Jan 01 01:00:02 1970 | |
| name | 24 | |
| current_version | 0.189.4 | Data | /usr/lib/libSystem.B.dylib |
dylib_command |
|---|
| Name | Value | |
|---|---|---|
| compatibility_version | 0.45.0 | |
| timestamp | Thu Jan 01 01:00:02 1970 | |
| name | 24 | |
| current_version | 3584.63.5 | Data | /System/Library/Frameworks/AppKit.framework/Versions/C/AppKit |
dylib_command |
|---|
| Name | Value | |
|---|---|---|
| compatibility_version | 0.150.0 | |
| timestamp | Thu Jan 01 01:00:02 1970 | |
| name | 24 | |
| current_version | 4096.127.4 | Data | /System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation |
rpath_command |
|---|
| Name | Value | |
|---|---|---|
| path | 12 | Data | @executable_path/../Frameworks |
linkedit_data_command |
|---|
| Name | Value | |
|---|---|---|
| dataoff | 177744 | |
| datassize | 40 | |
linkedit_data_command |
|---|
| Name | Value | |
|---|---|---|
| dataoff | 177784 | |
| datassize | 0 | |
linkedit_data_command |
|---|
| Name | Value | |
|---|---|---|
| dataoff | 177784 | |
| datassize | 72 | |
linkedit_data_command |
|---|
| Name | Value | |
|---|---|---|
| dataoff | 179920 | |
| datassize | 10512 | |
Network Behavior |
|---|
Network Port Distribution |
|---|
TCP Packets |
|---|
| Timestamp | Source Port | Dest Port | Source IP | Dest IP |
|---|---|---|---|---|
| Mai 3, 2017 09:40:32.672120094 MESZ | 53 | 54797 | 8.8.8.8 | 192.168.0.50 |
| Mai 3, 2017 09:42:41.189059973 MESZ | 5353 | 5353 | 192.168.0.50 | 224.0.0.251 |
| Mai 3, 2017 09:42:50.268868923 MESZ | 49327 | 4545 | 192.168.0.50 | 185.68.93.74 |
| Mai 3, 2017 09:42:50.268913984 MESZ | 4545 | 49327 | 185.68.93.74 | 192.168.0.50 |
| Mai 3, 2017 09:42:50.269211054 MESZ | 49327 | 4545 | 192.168.0.50 | 185.68.93.74 |
| Mai 3, 2017 09:42:50.269515038 MESZ | 49327 | 4545 | 192.168.0.50 | 185.68.93.74 |
| Mai 3, 2017 09:42:50.269526958 MESZ | 4545 | 49327 | 185.68.93.74 | 192.168.0.50 |
| Mai 3, 2017 09:44:49.014049053 MESZ | 123 | 123 | 192.168.0.50 | 17.253.20.125 |
| Mai 3, 2017 09:46:06.790956974 MESZ | 49155 | 5223 | 192.168.0.50 | 17.188.165.205 |
| Mai 3, 2017 09:46:06.790987015 MESZ | 5223 | 49155 | 17.188.165.205 | 192.168.0.50 |
| Mai 3, 2017 09:46:06.791913986 MESZ | 49211 | 5223 | 192.168.0.50 | 17.252.76.100 |
| Mai 3, 2017 09:46:06.791940928 MESZ | 5223 | 49211 | 17.252.76.100 | 192.168.0.50 |
| Mai 3, 2017 09:46:07.017128944 MESZ | 5223 | 49155 | 17.188.165.205 | 192.168.0.50 |
| Mai 3, 2017 09:46:07.017640114 MESZ | 49155 | 5223 | 192.168.0.50 | 17.188.165.205 |
| Mai 3, 2017 09:46:07.075546026 MESZ | 5223 | 49211 | 17.252.76.100 | 192.168.0.50 |
| Mai 3, 2017 09:46:07.075982094 MESZ | 49211 | 5223 | 192.168.0.50 | 17.252.76.100 |
UDP Packets |
|---|
| Timestamp | Source Port | Dest Port | Source IP | Dest IP |
|---|---|---|---|---|
| Mai 3, 2017 09:40:32.672120094 MESZ | 53 | 54797 | 8.8.8.8 | 192.168.0.50 |
| Mai 3, 2017 09:42:41.189059973 MESZ | 5353 | 5353 | 192.168.0.50 | 224.0.0.251 |
| Mai 3, 2017 09:44:49.014049053 MESZ | 123 | 123 | 192.168.0.50 | 17.253.20.125 |
ICMP Packets |
|---|
| Timestamp | Source IP | Dest IP | Checksum | Code | Type |
|---|---|---|---|---|---|
| Mai 3, 2017 09:40:32.672396898 MESZ | 192.168.0.50 | 8.8.8.8 | 2682 | (Port unreachable) | Destination Unreachable |
System Behavior |
|---|
General |
|---|
| Start time: | 09:40:35 |
| Start date: | 03/05/2017 |
| Path: | /usr/libexec/xpcproxy |
| File size: | 42656 bytes |
| MD5 hash: | d68b4c6f2056c73e1d3bd228bcd6d4ff |
General |
|---|
| Start time: | 09:40:35 |
| Start date: | 03/05/2017 |
| Path: | /Users/vreni/Desktop/unpack/Dokument.app/Contents/MacOS/AppStore |
| File size: | 190432 bytes |
| MD5 hash: | 9f25c1a359b9dae3f2c1abba45f0566d |
General |
|---|
| Start time: | 09:40:35 |
| Start date: | 03/05/2017 |
| Path: | /bin/bash |
| File size: | 628496 bytes |
| MD5 hash: | 5d7583d80e5314ac844eedc6d68c6cd7 |
General |
|---|
| Start time: | 09:40:35 |
| Start date: | 03/05/2017 |
| Path: | /bin/chmod |
| File size: | 33904 bytes |
| MD5 hash: | ecb64579c6dd0ebee31bf8e4d4cdcc6e |
General |
|---|
| Start time: | 09:40:35 |
| Start date: | 03/05/2017 |
| Path: | /bin/bash |
| File size: | 628496 bytes |
| MD5 hash: | 5d7583d80e5314ac844eedc6d68c6cd7 |
General |
|---|
| Start time: | 09:40:35 |
| Start date: | 03/05/2017 |
| Path: | /bin/bash |
| File size: | 628496 bytes |
| MD5 hash: | 5d7583d80e5314ac844eedc6d68c6cd7 |
General |
|---|
| Start time: | 09:40:35 |
| Start date: | 03/05/2017 |
| Path: | /bin/sleep |
| File size: | 17984 bytes |
| MD5 hash: | a5566195e03cbb7d5df309767a4231ae |
General |
|---|
| Start time: | 09:40:40 |
| Start date: | 03/05/2017 |
| Path: | /bin/bash |
| File size: | 628496 bytes |
| MD5 hash: | 5d7583d80e5314ac844eedc6d68c6cd7 |
General |
|---|
| Start time: | 09:40:40 |
| Start date: | 03/05/2017 |
| Path: | /bin/rm |
| File size: | 23744 bytes |
| MD5 hash: | e8926d2347850b76f57a1d5f0226de8b |
General |
|---|
| Start time: | 09:40:40 |
| Start date: | 03/05/2017 |
| Path: | /bin/bash |
| File size: | 628496 bytes |
| MD5 hash: | 5d7583d80e5314ac844eedc6d68c6cd7 |
General |
|---|
| Start time: | 09:40:40 |
| Start date: | 03/05/2017 |
| Path: | /Users/Shared/AppStore.app/Contents/MacOS/AppStore |
| File size: | 190432 bytes |
| MD5 hash: | 9f25c1a359b9dae3f2c1abba45f0566d |
General |
|---|
| Start time: | 09:42:42 |
| Start date: | 03/05/2017 |
| Path: | /bin/bash |
| File size: | 628496 bytes |
| MD5 hash: | 5d7583d80e5314ac844eedc6d68c6cd7 |
General |
|---|
| Start time: | 09:42:42 |
| Start date: | 03/05/2017 |
| Path: | /usr/bin/base64 |
| File size: | 23136 bytes |
| MD5 hash: | 5fd54d3cab0fc8cfa60ec8eab3049f1c |
General |
|---|
| Start time: | 09:42:42 |
| Start date: | 03/05/2017 |
| Path: | /bin/bash |
| File size: | 628496 bytes |
| MD5 hash: | 5d7583d80e5314ac844eedc6d68c6cd7 |
General |
|---|
| Start time: | 09:42:42 |
| Start date: | 03/05/2017 |
| Path: | /bin/bash |
| File size: | 628496 bytes |
| MD5 hash: | 5d7583d80e5314ac844eedc6d68c6cd7 |
General |
|---|
| Start time: | 09:42:42 |
| Start date: | 03/05/2017 |
| Path: | /bin/chmod |
| File size: | 33904 bytes |
| MD5 hash: | ecb64579c6dd0ebee31bf8e4d4cdcc6e |
General |
|---|
| Start time: | 09:42:42 |
| Start date: | 03/05/2017 |
| Path: | /bin/bash |
| File size: | 628496 bytes |
| MD5 hash: | 5d7583d80e5314ac844eedc6d68c6cd7 |
General |
|---|
| Start time: | 09:42:42 |
| Start date: | 03/05/2017 |
| Path: | /bin/rm |
| File size: | 23744 bytes |
| MD5 hash: | e8926d2347850b76f57a1d5f0226de8b |
General |
|---|
| Start time: | 09:42:42 |
| Start date: | 03/05/2017 |
| Path: | /bin/bash |
| File size: | 628496 bytes |
| MD5 hash: | 5d7583d80e5314ac844eedc6d68c6cd7 |
General |
|---|
| Start time: | 09:42:42 |
| Start date: | 03/05/2017 |
| Path: | /tmp/AppStore |
| File size: | 112154 bytes |
| MD5 hash: | f2f3baf7ace5d985f0ee3c9b44f5074f |
General |
|---|
| Start time: | 09:42:42 |
| Start date: | 03/05/2017 |
| Path: | /Library/Frameworks/Python.framework/Versions/2.7/bin/python |
| File size: | 25624 bytes |
| MD5 hash: | 8ec51a235078596c4b2e09b4db76e73b |
General |
|---|
| Start time: | 09:42:42 |
| Start date: | 03/05/2017 |
| Path: | /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python |
| File size: | 24960 bytes |
| MD5 hash: | 4d6dea37ae8536c5e20573905de9cf17 |
General |
|---|
| Start time: | 09:42:43 |
| Start date: | 03/05/2017 |
| Path: | /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python |
| File size: | 24960 bytes |
| MD5 hash: | 4d6dea37ae8536c5e20573905de9cf17 |
General |
|---|
| Start time: | 09:42:43 |
| Start date: | 03/05/2017 |
| Path: | /bin/sh |
| File size: | 632672 bytes |
| MD5 hash: | 2cc3c26641112c1bd0173f396b7d7662 |
General |
|---|
| Start time: | 09:42:43 |
| Start date: | 03/05/2017 |
| Path: | /usr/sbin/scutil |
| File size: | 216656 bytes |
| MD5 hash: | 606425562bb70289876036542086217c |
General |
|---|
| Start time: | 09:42:43 |
| Start date: | 03/05/2017 |
| Path: | /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python |
| File size: | 24960 bytes |
| MD5 hash: | 4d6dea37ae8536c5e20573905de9cf17 |
General |
|---|
| Start time: | 09:42:43 |
| Start date: | 03/05/2017 |
| Path: | /bin/sh |
| File size: | 632672 bytes |
| MD5 hash: | 2cc3c26641112c1bd0173f396b7d7662 |
General |
|---|
| Start time: | 09:42:43 |
| Start date: | 03/05/2017 |
| Path: | /bin/launchctl |
| File size: | 124048 bytes |
| MD5 hash: | dbfeff92b30d89c0a04dd0fbeb40ae5e |
General |
|---|
| Start time: | 09:42:44 |
| Start date: | 03/05/2017 |
| Path: | /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python |
| File size: | 24960 bytes |
| MD5 hash: | 4d6dea37ae8536c5e20573905de9cf17 |
General |
|---|
| Start time: | 09:42:44 |
| Start date: | 03/05/2017 |
| Path: | /bin/launchctl |
| File size: | 124048 bytes |
| MD5 hash: | dbfeff92b30d89c0a04dd0fbeb40ae5e |
General |
|---|
| Start time: | 09:42:49 |
| Start date: | 03/05/2017 |
| Path: | /bin/bash |
| File size: | 628496 bytes |
| MD5 hash: | 5d7583d80e5314ac844eedc6d68c6cd7 |
General |
|---|
| Start time: | 09:42:49 |
| Start date: | 03/05/2017 |
| Path: | /bin/bash |
| File size: | 628496 bytes |
| MD5 hash: | 5d7583d80e5314ac844eedc6d68c6cd7 |
General |
|---|
| Start time: | 09:42:49 |
| Start date: | 03/05/2017 |
| Path: | /bin/sleep |
| File size: | 17984 bytes |
| MD5 hash: | a5566195e03cbb7d5df309767a4231ae |
General |
|---|
| Start time: | 09:42:54 |
| Start date: | 03/05/2017 |
| Path: | /bin/bash |
| File size: | 628496 bytes |
| MD5 hash: | 5d7583d80e5314ac844eedc6d68c6cd7 |
General |
|---|
| Start time: | 09:42:54 |
| Start date: | 03/05/2017 |
| Path: | /bin/rm |
| File size: | 23744 bytes |
| MD5 hash: | e8926d2347850b76f57a1d5f0226de8b |
General |
|---|
| Start time: | 09:40:40 |
| Start date: | 03/05/2017 |
| Path: | /System/Library/CoreServices/sharedfilelistd |
| File size: | 123616 bytes |
| MD5 hash: | f27d37ceb90584465739b7527f7c7b2d |
General |
|---|
| Start time: | 09:40:41 |
| Start date: | 03/05/2017 |
| Path: | /usr/bin/sfltool |
| File size: | 79456 bytes |
| MD5 hash: | 0ced48308860d34b0e0b304d9033b6b7 |
General |
|---|
| Start time: | 09:40:44 |
| Start date: | 03/05/2017 |
| Path: | /System/Library/CoreServices/sharedfilelistd |
| File size: | 123616 bytes |
| MD5 hash: | f27d37ceb90584465739b7527f7c7b2d |
General |
|---|
| Start time: | 09:40:44 |
| Start date: | 03/05/2017 |
| Path: | /usr/bin/sfltool |
| File size: | 79456 bytes |
| MD5 hash: | 0ced48308860d34b0e0b304d9033b6b7 |
General |
|---|
| Start time: | 09:40:50 |
| Start date: | 03/05/2017 |
| Path: | /System/Library/CoreServices/sharedfilelistd |
| File size: | 123616 bytes |
| MD5 hash: | f27d37ceb90584465739b7527f7c7b2d |
General |
|---|
| Start time: | 09:40:50 |
| Start date: | 03/05/2017 |
| Path: | /usr/bin/sfltool |
| File size: | 79456 bytes |
| MD5 hash: | 0ced48308860d34b0e0b304d9033b6b7 |
General |
|---|
| Start time: | 09:42:48 |
| Start date: | 03/05/2017 |
| Path: | /usr/libexec/xpcproxy |
| File size: | 42656 bytes |
| MD5 hash: | d68b4c6f2056c73e1d3bd228bcd6d4ff |
General |
|---|
| Start time: | 09:42:48 |
| Start date: | 03/05/2017 |
| Path: | /Users/vreni/Library/Containers/.bella/Bella |
| File size: | 112154 bytes |
| MD5 hash: | f2f3baf7ace5d985f0ee3c9b44f5074f |
General |
|---|
| Start time: | 09:42:48 |
| Start date: | 03/05/2017 |
| Path: | /usr/bin/python |
| File size: | 66736 bytes |
| MD5 hash: | 071afc8e1e82e53c253a8ddc7dda8f75 |
General |
|---|
| Start time: | 09:42:48 |
| Start date: | 03/05/2017 |
| Path: | /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python |
| File size: | 25152 bytes |
| MD5 hash: | f932378ef838dcd40e9b7e55e7d7b9a0 |
General |
|---|
| Start time: | 09:42:49 |
| Start date: | 03/05/2017 |
| Path: | /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python |
| File size: | 25152 bytes |
| MD5 hash: | f932378ef838dcd40e9b7e55e7d7b9a0 |
General |
|---|
| Start time: | 09:42:49 |
| Start date: | 03/05/2017 |
| Path: | /bin/sh |
| File size: | 632672 bytes |
| MD5 hash: | 2cc3c26641112c1bd0173f396b7d7662 |
General |
|---|
| Start time: | 09:42:49 |
| Start date: | 03/05/2017 |
| Path: | /usr/sbin/scutil |
| File size: | 216656 bytes |
| MD5 hash: | 606425562bb70289876036542086217c |
General |
|---|
| Start time: | 09:42:49 |
| Start date: | 03/05/2017 |
| Path: | /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python |
| File size: | 25152 bytes |
| MD5 hash: | f932378ef838dcd40e9b7e55e7d7b9a0 |
General |
|---|
| Start time: | 09:42:49 |
| Start date: | 03/05/2017 |
| Path: | /bin/sh |
| File size: | 632672 bytes |
| MD5 hash: | 2cc3c26641112c1bd0173f396b7d7662 |
General |
|---|
| Start time: | 09:42:49 |
| Start date: | 03/05/2017 |
| Path: | /usr/sbin/sysctl |
| File size: | 60608 bytes |
| MD5 hash: | 6b5514b612e9e7ea63857c6fdcab2c5b |
General |
|---|
| Start time: | 09:42:49 |
| Start date: | 03/05/2017 |
| Path: | /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python |
| File size: | 25152 bytes |
| MD5 hash: | f932378ef838dcd40e9b7e55e7d7b9a0 |
General |
|---|
| Start time: | 09:42:49 |
| Start date: | 03/05/2017 |
| Path: | /bin/sh |
| File size: | 632672 bytes |
| MD5 hash: | 2cc3c26641112c1bd0173f396b7d7662 |
General |
|---|
| Start time: | 09:42:49 |
| Start date: | 03/05/2017 |
| Path: | /bin/sh |
| File size: | 632672 bytes |
| MD5 hash: | 2cc3c26641112c1bd0173f396b7d7662 |
General |
|---|
| Start time: | 09:42:49 |
| Start date: | 03/05/2017 |
| Path: | /usr/libexec/PlistBuddy |
| File size: | 40992 bytes |
| MD5 hash: | b9c6344ae2b0607f8fc9d102e98ede82 |
General |
|---|
| Start time: | 09:42:49 |
| Start date: | 03/05/2017 |
| Path: | /bin/sh |
| File size: | 632672 bytes |
| MD5 hash: | 2cc3c26641112c1bd0173f396b7d7662 |
General |
|---|
| Start time: | 09:42:49 |
| Start date: | 03/05/2017 |
| Path: | /usr/bin/grep |
| File size: | 33712 bytes |
| MD5 hash: | f7fe9c4af9294f2949377a12244b3d60 |
General |
|---|
| Start time: | 09:42:49 |
| Start date: | 03/05/2017 |
| Path: | /System/Library/CoreServices/sharedfilelistd |
| File size: | 123616 bytes |
| MD5 hash: | f27d37ceb90584465739b7527f7c7b2d |
General |
|---|
| Start time: | 09:42:49 |
| Start date: | 03/05/2017 |
| Path: | /usr/bin/sfltool |
| File size: | 79456 bytes |
| MD5 hash: | 0ced48308860d34b0e0b304d9033b6b7 |
General |
|---|
| Start time: | 09:42:55 |
| Start date: | 03/05/2017 |
| Path: | /System/Library/CoreServices/sharedfilelistd |
| File size: | 123616 bytes |
| MD5 hash: | f27d37ceb90584465739b7527f7c7b2d |
General |
|---|
| Start time: | 09:42:55 |
| Start date: | 03/05/2017 |
| Path: | /usr/bin/sfltool |
| File size: | 79456 bytes |
| MD5 hash: | 0ced48308860d34b0e0b304d9033b6b7 |