Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 594) | Writes from socket in process: |
Source: global traffic | TCP traffic: 192.168.0.50:49327 -> 185.68.93.74:4545 |
Source: classification engine | Classification label: mal72.troj.evad.macZIP@0/18@0/0 |
Source: /usr/bin/base64 (PID: 586) | Python file created: /private/tmp/AppStore |
Source: MD5 0e48346ebd57b1b6dbaa0bbad4d579dc | Submitted blacklisted sample: Spyware Dok.B |
Source: /bin/sh (PID: 599) | Sysctl executable: /usr/sbin/sysctl -> sysctl hw.model |
Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | Random device file read: /dev/random |
Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | Random device file read: /dev/random |
Source: /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 590) | Random device file read: /dev/urandom |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 594) | Random device file read: /dev/urandom |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 594) | Random device file read: /dev/urandom |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 594) | Random device file read: /dev/urandom |
Source: /Users/vreni/Desktop/unpack/Dokument.app/Contents/MacOS/AppStore (PID: 570) | CodeSignature CodeResources file read: /Users/vreni/Desktop/unpack/Dokument.app/Contents/_CodeSignature/CodeResources |
Source: /Users/vreni/Desktop/unpack/Dokument.app/Contents/MacOS/AppStore (PID: 570) | CodeSignature CodeResources file read: /Users/vreni/Desktop/unpack/Dokument.app/Contents/_CodeSignature/CodeResources |
Source: /Users/vreni/Desktop/unpack/Dokument.app/Contents/MacOS/AppStore (PID: 570) | AppleKeyboardLayouts info plist opened: /System/Library/Keyboard Layouts/AppleKeyboardLayouts.bundle/Contents/Info.plist |
Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | AppleKeyboardLayouts info plist opened: /System/Library/Keyboard Layouts/AppleKeyboardLayouts.bundle/Contents/Info.plist |
Source: /Library/Frameworks/Python.framework/Versions/2.7/bin/python (PID: 590) | Python framework application: /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python |
Source: /usr/bin/python (PID: 594) | Python framework application: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python |
Source: /Users/vreni/Desktop/unpack/Dokument.app/Contents/MacOS/AppStore (PID: 570) | Log file created: /private/tmp/loader.log |
Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | Log file created: /private/tmp/loader.log |
Source: /Users/vreni/Desktop/unpack/Dokument.app/Contents/MacOS/AppStore (PID: 570) | XML plist file created: /Users/Shared/AppStore.app/Contents/_CodeSignature/CodeResources |
Source: /Users/vreni/Desktop/unpack/Dokument.app/Contents/MacOS/AppStore (PID: 570) | XML plist file created: /Users/Shared/AppStore.app/Contents/Info.plist |
Source: /Users/vreni/Desktop/unpack/Dokument.app/Contents/MacOS/AppStore (PID: 570) | Binary plist file created: /Users/Shared/AppStore.app/Contents/Resources/Base.lproj/MainMenu.nib |
Source: /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 590) | XML plist file created: /Users/vreni/Library/LaunchAgents/com.apple.iTunes.plist |
Source: /Users/vreni/Desktop/unpack/Dokument.app/Contents/MacOS/AppStore (PID: 570) | Permissions modifiied for written 64-bit Mach-O /Users/Shared/AppStore.app/Contents/MacOS/AppStore: bits: - usr: rx grp: rx all: rwx |
Source: /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 590) | Hidden Directory created: /Users/vreni/Library/Containers/.bella/ -> /Users/vreni/Library/Containers/.bella/ |
Source: /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 590) | Launch agent/daemon created with StartInterval and/or StartCalendarInterval, file created: /Users/vreni/Library/LaunchAgents/com.apple.iTunes.plist |
Source: /Users/vreni/Desktop/unpack/Dokument.app/Contents/MacOS/AppStore (PID: 570) | Shell command executed: /bin/bash -c chmod +x /Users/Shared/AppStore.app |
Source: /Users/vreni/Desktop/unpack/Dokument.app/Contents/MacOS/AppStore (PID: 570) | Shell command executed: /bin/bash -c sleep 5 && rm -fR '/Users/vreni/Downloads/Dokument.app' && '/Users/Shared/AppStore.app/Contents/MacOS/AppStore' Dokument |
Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | Shell command executed: /bin/bash -c base64 -i /tmp/tmp123 -o /tmp/AppStore -D |
Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | Shell command executed: /bin/bash -c chmod +x /tmp/AppStore && rm -f /tmp/tmp123 |
Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | Shell command executed: /bin/bash -c /tmp/AppStore |
Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | Shell command executed: /bin/bash -c sleep 5 && rm -fR '/Users/Shared/AppStore.app' |
Source: /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 591) | Shell command executed: /bin/sh -c scutil --get LocalHostName |
Source: /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 592) | Shell command executed: /bin/sh -c launchctl load -w /Users/vreni/Library/LaunchAgents/com.apple.iTunes.plist |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 598) | Shell command executed: /bin/sh -c scutil --get LocalHostName |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 599) | Shell command executed: /bin/sh -c sysctl hw.model |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 600) | Shell command executed: /bin/sh -c /usr/libexec/PlistBuddy -c 'Print :'Macmini6,1'' /System/Library/PrivateFrameworks/ServerInformation.framework/Versions/A/Resources/English.lproj/SIMachineAttributes.plist | grep marketingModel |
Source: /bin/bash (PID: 572) | Chmod executable: /bin/chmod -> chmod +x /Users/Shared/AppStore.app |
Source: /bin/bash (PID: 588) | Chmod executable: /bin/chmod -> chmod +x /tmp/AppStore |
Source: /bin/sh (PID: 602) | Grep executable: /usr/bin/grep -> grep marketingModel |
Source: /tmp/AppStore (PID: 590) | Python executable: /Library/Frameworks/Python.framework/Versions/2.7/bin/python -> python /tmp/AppStore |
Source: /Users/vreni/Library/Containers/.bella/Bella (PID: 594) | Python executable: /usr/bin/python -> python /Users/vreni/Library/Containers/.bella/Bella |
Source: /bin/sh (PID: 599) | Sysctl executable: /usr/sbin/sysctl -> sysctl hw.model |
Source: /bin/sh (PID: 592) | Launch agent/daemon loaded: launchctl load -w /Users/vreni/Library/LaunchAgents/com.apple.iTunes.plist |
Source: /Users/vreni/Desktop/unpack/Dokument.app/Contents/MacOS/AppStore (PID: 570) | Launchservices plist file read: /Users/vreni/Library/Preferences/com.apple.LaunchServices.plist |
Source: /Users/vreni/Desktop/unpack/Dokument.app/Contents/MacOS/AppStore (PID: 570) | Launchservices plist file read: /Users/vreni/Library/Preferences/com.apple.LaunchServices/com.apple.launchservices.secure.plist |
Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | Launchservices plist file read: /Users/vreni/Library/Preferences/com.apple.LaunchServices.plist |
Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | Launchservices plist file read: /Users/vreni/Library/Preferences/com.apple.LaunchServices/com.apple.launchservices.secure.plist |
Source: /Users/vreni/Desktop/unpack/Dokument.app/Contents/MacOS/AppStore (PID: 570) | Preferences launchservices plist file read: /Users/vreni/Library/Preferences/com.apple.LaunchServices/com.apple.launchservices.secure.plist |
Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | Preferences launchservices plist file read: /Users/vreni/Library/Preferences/com.apple.LaunchServices/com.apple.launchservices.secure.plist |
Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | AppleScript framework/component info plist opened: /System/Library/Components/AppleScript.component/Contents/Info.plist |
Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | AppleScript framework/component info plist opened: /System/Library/PrivateFrameworks/AppleScript.framework/Resources/Info.plist |
Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | AppleScript scripting addition info plist opened: /System/Library/ScriptingAdditions/Digital Hub Scripting.osax/Contents/Info.plist |
Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | AppleScript scripting addition info plist opened: /System/Library/ScriptingAdditions/StandardAdditions.osax/Contents/Info.plist |
Source: /Users/vreni/Desktop/unpack/Dokument.app/Contents/MacOS/AppStore (PID: 570) | File written: /Users/Shared/AppStore.app/Contents/MacOS/AppStore |
Source: /Users/vreni/Desktop/unpack/Dokument.app/Contents/MacOS/AppStore (PID: 570) | File written: /Users/Shared/AppStore.app/Contents/Resources/AppIcon.icns |
Source: /bin/rm (PID: 603) | File deleted: AppIcon.icns |
Source: /bin/bash (PID: 576) | Rm executable: /bin/rm -> rm -fR /Users/vreni/Downloads/Dokument.app |
Source: /bin/bash (PID: 589) | Rm executable: /bin/rm -> rm -f /tmp/tmp123 |
Source: /bin/bash (PID: 603) | Rm executable: /bin/rm -> rm -fR /Users/Shared/AppStore.app |
Source: /bin/sh (PID: 591) | Scutil executable: /usr/sbin/scutil -> scutil --get LocalHostName |
Source: /bin/sh (PID: 598) | Scutil executable: /usr/sbin/scutil -> scutil --get LocalHostName |
Source: /System/Library/CoreServices/sharedfilelistd (PID: 578) | Sfltool executed with keyword 'loginitems': /usr/bin/sfltool -> /usr/bin/sfltool com.apple.loginitems SessionItems |
Source: /System/Library/CoreServices/sharedfilelistd (PID: 579) | Sfltool executed with keyword 'loginitems': /usr/bin/sfltool -> /usr/bin/sfltool com.apple.loginitems SessionItems |
Source: /System/Library/CoreServices/sharedfilelistd (PID: 580) | Sfltool executed with keyword 'loginitems': /usr/bin/sfltool -> /usr/bin/sfltool save-lists com.apple.loginitems |
Source: /System/Library/CoreServices/sharedfilelistd (PID: 595) | Sfltool executed with keyword 'loginitems': /usr/bin/sfltool -> /usr/bin/sfltool com.apple.loginitems SessionItems |
Source: /System/Library/CoreServices/sharedfilelistd (PID: 604) | Sfltool executed with keyword 'loginitems': /usr/bin/sfltool -> /usr/bin/sfltool save-lists com.apple.loginitems |
Source: /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 590) | Launch agent created file created: /Users/vreni/Library/LaunchAgents/com.apple.iTunes.plist |
Source: /bin/bash (PID: 586) | Base64 executable: /usr/bin/base64 -> base64 -i /tmp/tmp123 -o /tmp/AppStore -D |
Source: /bin/rm (PID: 603) | Directory deleted: /Users/Shared/AppStore.app |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 594) | File deleted: /Users/vreni/Library/Containers/.bella/bella.db-journal |
Source: /bin/bash (PID: 574) | Sleep executable: /bin/sleep -> sleep 5 |
Source: /bin/bash (PID: 597) | Sleep executable: /bin/sleep -> sleep 5 |
Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | Sysctl read request: kern.safeboot (1.66) |
Source: /Users/vreni/Desktop/unpack/Dokument.app/Contents/MacOS/AppStore (PID: 570) | System or server version plist file read: /System/Library/CoreServices/SystemVersion.plist |
Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | System or server version plist file read: /System/Library/CoreServices/SystemVersion.plist |
Source: /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 590) | System or server version plist file read: /System/Library/CoreServices/SystemVersion.plist |
Source: /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 590) | System or server version plist file read: /System/Library/CoreServices/SystemVersion.plist |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 594) | System or server version plist file read: /System/Library/CoreServices/SystemVersion.plist |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 594) | System or server version plist file read: /System/Library/CoreServices/SystemVersion.plist |
Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | Sysctl read request: hw.availcpu (6.25) |
Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | Sysctl read request: hw.ncpu (6.3) |
Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | Sysctl read request: hw.cpu_freq (6.15) |
Source: /Users/Shared/AppStore.app/Contents/MacOS/AppStore (PID: 577) | Sysctl read request: kern.osversion (1.65) |
Source: /bin/bash (PID: 572) | Sysctl requested: kern.hostname (1.10) |
Source: /bin/bash (PID: 573) | Sysctl requested: kern.hostname (1.10) |
Source: /bin/bash (PID: 586) | Sysctl requested: kern.hostname (1.10) |
Source: /bin/bash (PID: 587) | Sysctl requested: kern.hostname (1.10) |
Source: /bin/bash (PID: 590) | Sysctl requested: kern.hostname (1.10) |
Source: /bin/sh (PID: 591) | Sysctl requested: kern.hostname (1.10) |
Source: /bin/sh (PID: 592) | Sysctl requested: kern.hostname (1.10) |
Source: /bin/bash (PID: 596) | Sysctl requested: kern.hostname (1.10) |
Source: /bin/sh (PID: 598) | Sysctl requested: kern.hostname (1.10) |
Source: /bin/sh (PID: 599) | Sysctl requested: kern.hostname (1.10) |
Source: /bin/sh (PID: 600) | Sysctl requested: kern.hostname (1.10) |
Source: PIDs 590 and 586 | Behaviour pattern found: /Users/vreni/Library/Containers/.bella/ and /private/tmp/AppStore created |
Source: global traffic and dropped files | IP 185.68.93.74 found in file: /private/tmp/AppStore |