Analysis Report
Overview
General Information |
|---|
| Analysis ID: | 26 |
| Start time: | 10:02:05 |
| Start date: | 25/09/2014 |
| Overall analysis duration: | 0h 7m 14s |
| Report type: | full |
| Sample file name: | 9283c61f8cce4258c8111aaf098d21ee |
| Cookbook file name: | keylogging.jbs |
| Analysis system description: | Mac OS X, Mavericks, clean |
Detection |
|---|
| Strategy | Report FP/FN | |
|---|---|---|
| Threshold | ||
Signature Overview |
|---|
Networking: |
|---|
| Urls found in memory or binary data | Show sources | ||
| Source: 9283c61f8cce4258c8111aaf098d21ee | String found in binary or memory: | ||
| Source: 9283c61f8cce4258c8111aaf098d21ee | String found in binary or memory: | ||
Key, Mouse, Clipboard, Microphone and Screen Capturing: |
|---|
| Captures keyboard strokes that are written to a log file | Show sources | ||
| Source: /Applications/TextEdit.app/Contents/MacOS/TextEdit | Detected decoy string in file: | ||
| Writes property list (.plist) files to disk with content indicative for key loggers | Show sources | ||
| Source: /usr/bin/tar | XML plist file created with lower-case letters in tags: | ||
Persistence and Installation Behavior: |
|---|
| Writes property list (.plist) files to disk | Show sources | ||
| Source: /Users/urugan/Desktop/9283c61f8cce4258c8111aaf098d21ee | XML plist file created: | ||
| Source: /usr/bin/tar | XML plist file created: | ||
| Source: /usr/bin/tar | XML plist file created: | ||
| Source: /Applications/TextEdit.app/Contents/MacOS/TextEdit | XML plist file created: | ||
| Creates and/or modifies files and/or directories in common kernel extension directories | Show sources | ||
| Source: /bin/mv | File moved: | ||
| Source: /bin/chmod | Permissions modified: | ||
| Creates code signed kernel extensions | Show sources | ||
| Source: /usr/bin/tar | Kext code signature resource file created: | ||
| Source: /bin/mv | Kext code signature resource file created in extensions directory: | ||
| Creates hidden files, links and/or directories | Show sources | ||
| Source: /bin/mkdir | Hidden directory created: | ||
| Source: /Library/.local/EventMonitor | Hidden file created: | ||
| Executes commands using a shell command-line interpreter | Show sources | ||
| Source: /Users/urugan/Desktop/9283c61f8cce4258c8111aaf098d21ee | Shell command executed: | ||
| Source: /Users/urugan/Desktop/9283c61f8cce4258c8111aaf098d21ee | Shell command executed: | ||
| Source: /Users/urugan/Desktop/9283c61f8cce4258c8111aaf098d21ee | Shell command executed: | ||
| Source: /Users/urugan/Desktop/9283c61f8cce4258c8111aaf098d21ee | Shell command executed: | ||
| Source: /Users/urugan/Desktop/9283c61f8cce4258c8111aaf098d21ee | Shell command executed: | ||
| Source: /Users/urugan/Desktop/9283c61f8cce4258c8111aaf098d21ee | Shell command executed: | ||
| Source: /Users/urugan/Desktop/9283c61f8cce4258c8111aaf098d21ee | Shell command executed: | ||
| Source: /Users/urugan/Desktop/9283c61f8cce4258c8111aaf098d21ee | Shell command executed: | ||
| Source: /Users/urugan/Desktop/9283c61f8cce4258c8111aaf098d21ee | Shell command executed: | ||
| Source: /Users/urugan/Desktop/9283c61f8cce4258c8111aaf098d21ee | Shell command executed: | ||
| Source: /Users/urugan/Desktop/9283c61f8cce4258c8111aaf098d21ee | Shell command executed: | ||
| Source: /Users/urugan/Desktop/9283c61f8cce4258c8111aaf098d21ee | Shell command executed: | ||
| Source: /Users/urugan/Desktop/9283c61f8cce4258c8111aaf098d21ee | Shell command executed: | ||
| Source: /Users/urugan/Desktop/9283c61f8cce4258c8111aaf098d21ee | Shell command executed: | ||
| Source: /Library/.local/reweb | Shell command executed: | ||
| Source: /Library/.local/reweb | Shell command executed: | ||
| Source: /Library/.local/reweb | Shell command executed: | ||
| Source: /Library/.local/reweb | Shell command executed: | ||
| Source: /Library/.local/updated | Shell command executed: | ||
| Source: /Library/.local/updated | Shell command executed: | ||
| Source: /Library/.local/updated | Shell command executed: | ||
| Writes 64-bit Mach-O files to disk | Show sources | ||
| Source: /Users/urugan/Desktop/9283c61f8cce4258c8111aaf098d21ee | File written: | ||
| Source: /Users/urugan/Desktop/9283c61f8cce4258c8111aaf098d21ee | File written: | ||
| Source: /Users/urugan/Desktop/9283c61f8cce4258c8111aaf098d21ee | File written: | ||
| Source: /usr/bin/tar | File written: | ||
| Writes FAT Mach-O files to disk | Show sources | ||
| Source: /usr/bin/tar | File written: | ||
| Writes RTF files to disk | Show sources | ||
| Source: /Applications/TextEdit.app/Contents/MacOS/TextEdit | File written: | ||
| Terminates processes by executing the killall command | Show sources | ||
| Source: /bin/sh | Killall command executed: | ||
| Source: /bin/sh | Killall command executed: | ||
| Source: /bin/sh | Killall command executed: | ||
Boot Survival: |
|---|
| Creates memory-persistent launch services | Show sources | ||
| Source: /Users/urugan/Desktop/9283c61f8cce4258c8111aaf098d21ee | Launch agent/daemon created with KeepAlive and/or RunAtLoad, file created: | ||
| Creates system-wide 'launchd' managed services aka launch daemons | Show sources | ||
| Source: /Users/urugan/Desktop/9283c61f8cce4258c8111aaf098d21ee | Launch daemon created, file created: | ||
Hooking and other Techniques for Hiding and Protection: |
|---|
| Explicitly loads kernel extensions | Show sources | ||
| Source: /bin/sh | Kext via kextload loaded: | ||
| Creates kernel extensions | Show sources | ||
| Source: /usr/bin/tar | Kext Info.plist file created: | ||
| Source: /bin/mv | Kext Info.plist file created in extensions directory: | ||
| Moves itself during installation or deletes itself after installation | Show sources | ||
| Source: /bin/rm | File deleted: | ||
Stealing of Sensitive Information: |
|---|
| Captures keyboard strokes that are written to a log file | Show sources | ||
| Source: /Applications/TextEdit.app/Contents/MacOS/TextEdit | Detected decoy string in file: | ||
Runtime Messages |
|---|
| Command: | /Users/urugan/Desktop/9283c61f8cce4258c8111aaf098d21ee |
| Exitcode: | 0 |
| Killed: | False |
| Standard Output: | /Library/.local /Library/LaunchDaemons /proc/self/launch -> [/Users/urugan/Desktop/9283c61f8cce4258c8111aaf098d21ee] /proc/self/exe -> [/Users/urugan/Desktop/9283c61f8cce4258c8111aaf098d21ee] |
| Standard Error: | sh: /bin/chown: No such file or directory No matching processes were found No matching processes were found 2014-09-25 12:03:48.011 updated[449:c07] Hello; World! |
Yara Overview |
|---|
| No Yara matches |
|---|
Screenshot |
|---|
Startup |
|---|
|
Created / dropped Files |
|---|
| File Path | Type and Hashes |
|---|---|
| /Library/.local/.logfile |
|
| /Library/.local/EventMonitor |
|
| /Library/.local/Keymap.plist |
|
| /Library/.local/kext.tar |
|
| /Library/.local/libweb.db |
|
| /Library/.local/reweb |
|
| /Library/.local/update |
|
| /Library/.local/updated |
|
| /Library/.local/updated.kext/Contents/Info.plist |
|
| /Library/.local/updated.kext/Contents/MacOS/logKext |
|
| /Library/.local/updated.kext/Contents/Resources/English.lproj/InfoPlist.strings |
|
| /Library/LaunchDaemons/com.updated.launchagent.plist |
|
| /dev/null |
|
| /private/var/folders/6s/pncyckn14gl55c5_8kr9m_k80000gn/T/com.apple.TextEdit/TemporaryItems/(A Document Being Saved By TextEdit)/Unsaved TextEdit Document.rtf |
|
| /private/var/folders/6s/pncyckn14gl55c5_8kr9m_k80000gn/T/com.apple.TextEdit/TemporaryItems/(A Document Being Saved By TextEdit)/com.apple.TextEdit.plist |
|
| /private/var/folders/zz/zyxvpxvq6csfxvn_n0000000000000/T/tmpsqlitetruncatedbHmyDZW |
|
| /private/var/folders/zz/zyxvpxvq6csfxvn_n0000000000000/T/tmpsqlitetruncatedbHmyDZW-journal |
|
| /private/var/root/Library/Caches/update/Cache.db |
|
| /private/var/root/Library/Caches/update/Cache.db-journal |
|
| /private/var/root/Library/Caches/update/Cache.db-wal |
|
Contacted Domains/Contacted IPs |
|---|
Static File Info |
|---|
General | |
|---|---|
| File type: | Mach-O 64-bit executable |
| TrID: |
|
| File name: | 9283c61f8cce4258c8111aaf098d21ee |
| File size: | 352160 |
| MD5: | 9283c61f8cce4258c8111aaf098d21ee |
| SHA1: | cb27650db5fd999d2a599d95ad0b5ccb031ce517 |
| SHA256: | 59539ff9af82c0e4e73809a954cf2776636774e6c42c281f3b0e5f1656e93679 |
| SHA512: | 5e08bc7b3d9d8bfc769a360ad3eda745dd8a35acd1ce5067f9ffec64e5f77e3fb502a6de0159f40067b58277c81f1ead01a815ca86332e97973fd6a790c852d5 |
Static Mach Info |
|---|
General Informations for header0 | |
|---|---|
| Endian: | < |
| Size: | 64-bit |
| Architecture: | x86_64 |
| Filetype: | execute |
| Nbr. of load commands: | 13 |
segment_command_64 |
|---|
| Name | Value | |
|---|---|---|
| segname | __PAGEZERO | |
| fileoff | 0 | |
| maxprot | 0 | |
| vmsize | 4294967296 | |
| nsects | 0 | |
| flags | 0 | |
| filesize | 0 | |
| vmaddr | 0 | |
| initprot | 0 | |
segment_command_64 |
|---|
| Name | Value | |
|---|---|---|
| segname | __TEXT | |
| fileoff | 0 | |
| maxprot | 7 | |
| vmsize | 8192 | |
| nsects | 6 | |
| flags | 0 | |
| filesize | 8192 | |
| vmaddr | 4294967296 | |
| initprot | 5 | |
| Datas | sectname | __text |
| segname | __TEXT | |
| reloff | 0 | |
| addr | 4294969200 | |
| align | 4 | |
| nreloc | 0 | |
| flags | 2147484672 | |
| offset | 1904 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 4653 | |
| sectname | __stubs | |
| segname | __TEXT | |
| reloff | 0 | |
| addr | 4294973854 | |
| align | 1 | |
| nreloc | 0 | |
| flags | 2147484680 | |
| offset | 6558 | |
| reserved2 | 6 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 126 | |
| sectname | __stub_helper | |
| segname | __TEXT | |
| reloff | 0 | |
| addr | 4294973980 | |
| align | 2 | |
| nreloc | 0 | |
| flags | 2147484672 | |
| offset | 6684 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 228 | |
| sectname | __cstring | |
| segname | __TEXT | |
| reloff | 0 | |
| addr | 4294974208 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 2 | |
| offset | 6912 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 1118 | |
| sectname | __unwind_info | |
| segname | __TEXT | |
| reloff | 0 | |
| addr | 4294975326 | |
| align | 0 | |
| nreloc | 0 | |
| flags | 0 | |
| offset | 8030 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 80 | |
| sectname | __eh_frame | |
| segname | __TEXT | |
| reloff | 0 | |
| addr | 4294975408 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 0 | |
| offset | 8112 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 80 | |
segment_command_64 |
|---|
| Name | Value | |
|---|---|---|
| segname | __DATA | |
| fileoff | 8192 | |
| maxprot | 7 | |
| vmsize | 335872 | |
| nsects | 6 | |
| flags | 0 | |
| filesize | 335872 | |
| vmaddr | 4294975488 | |
| initprot | 3 | |
| Datas | sectname | __program_vars |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4294975488 | |
| align | 4 | |
| nreloc | 0 | |
| flags | 0 | |
| offset | 8192 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 40 | |
| sectname | __nl_symbol_ptr | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4294975528 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 6 | |
| offset | 8232 | |
| reserved2 | 0 | |
| reserved1 | 21 | |
| reserved3 | 0 | |
| size | 16 | |
| sectname | __got | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4294975544 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 6 | |
| offset | 8248 | |
| reserved2 | 0 | |
| reserved1 | 23 | |
| reserved3 | 0 | |
| size | 8 | |
| sectname | __la_symbol_ptr | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4294975552 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 7 | |
| offset | 8256 | |
| reserved2 | 0 | |
| reserved1 | 24 | |
| reserved3 | 0 | |
| size | 168 | |
| sectname | __data | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4294975744 | |
| align | 5 | |
| nreloc | 0 | |
| flags | 0 | |
| offset | 8448 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 332900 | |
| sectname | __common | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4295308648 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 1 | |
| offset | 0 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 32 | |
segment_command_64 |
|---|
| Name | Value | |
|---|---|---|
| segname | __LINKEDIT | |
| fileoff | 344064 | |
| maxprot | 7 | |
| vmsize | 4096 | |
| nsects | 0 | |
| flags | 0 | |
| filesize | 1948 | |
| vmaddr | 4295311360 | |
| initprot | 1 | |
dyld_info_command |
|---|
| Name | Value | |
|---|---|---|
| lazy_bind_size | 352 | |
| lazy_bind_off | 344128 | |
| weak_bind_size | 0 | |
| rebase_size | 8 | |
| export_off | 344480 | |
| export_size | 264 | |
| bind_off | 344072 | |
| rebase_off | 344064 | |
| bind_size | 56 | |
| weak_bind_off | 0 | |
symtab_command |
|---|
| Name | Value | |
|---|---|---|
| strsize | 424 | |
| symoff | 344752 | |
| stroff | 345588 | |
| nsyms | 41 | |
dysymtab_command |
|---|
| Name | Value | |
|---|---|---|
| extreloff | 0 | |
| nlocrel | 0 | |
| indirectsymoff | 345408 | |
| modtaboff | 0 | |
| nextrel | 0 | |
| iundefsym | 18 | |
| nmodtab | 0 | |
| ilocalsym | 0 | |
| nundefsym | 23 | |
| nextrefsyms | 0 | |
| locreloff | 0 | |
| ntoc | 0 | |
| nlocalsym | 1 | |
| tocoff | 0 | |
| extrefsymoff | 0 | |
| nindirectsyms | 45 | |
| iextdefsym | 1 | |
| nextdefsym | 17 | |
dylinker_command |
|---|
| Name | Value | |
|---|---|---|
| name | 12 | Data | /usr/lib/dyld |
uuid_command |
|---|
| Name | Value | |
|---|---|---|
| uuid | fZ?rF | |
version_min_command |
|---|
| Name | Value | |
|---|---|---|
| version | 657152 | |
| reserved | 0 | |
dylib_command |
|---|
| Name | Value | |
|---|---|---|
| compatibility_version | 0.1.0 | |
| timestamp | Thu Jan 01 01:00:02 1970 | |
| name | 24 | |
| current_version | 256.159.0 | Data | /usr/lib/libSystem.B.dylib |
linkedit_data_command |
|---|
| Name | Value | |
|---|---|---|
| dataoff | 344744 | |
| datassize | 8 | |
Network Behavior |
|---|
TCP Packets |
|---|
| Timestamp | Source Port | Dest Port | Source IP | Dest IP |
|---|---|---|---|---|
| Sep 25, 2014 10:04:53.023255110 MESZ | 5353 | 5353 | 192.168.50.109 | 224.0.0.251 |
UDP Packets |
|---|
| Timestamp | Source Port | Dest Port | Source IP | Dest IP |
|---|---|---|---|---|
| Sep 25, 2014 10:04:53.023255110 MESZ | 5353 | 5353 | 192.168.50.109 | 224.0.0.251 |
System Behavior |
|---|
General |
|---|
| Start time: | 10:03:31 |
| Start date: | 25/09/2014 |
| Path: | /Library/Frameworks/Mono.framework/Versions/3.4.0/bin/mono-sgen |
| File size: | 4224484 bytes |
| MD5 hash: | 36506d3dd9fa0fbfc7329e20ca1a4194 |
General |
|---|
| Start time: | 10:03:31 |
| Start date: | 25/09/2014 |
| Path: | /Users/urugan/Desktop/9283c61f8cce4258c8111aaf098d21ee |
| File size: | 352160 bytes |
| MD5 hash: | f34726c65d00492002ba8aef5cab9084 |
General |
|---|
| Start time: | 10:03:31 |
| Start date: | 25/09/2014 |
| Path: | /bin/sh |
| File size: | 1228304 bytes |
| MD5 hash: | 5e013647982463a5cde1143b88519a0b |
General |
|---|
| Start time: | 10:03:31 |
| Start date: | 25/09/2014 |
| Path: | /bin/mkdir |
| File size: | 14592 bytes |
| MD5 hash: | ef0eef7376bcd2e7254d76f8448f7cbe |
General |
|---|
| Start time: | 10:03:32 |
| Start date: | 25/09/2014 |
| Path: | /bin/sh |
| File size: | 1228304 bytes |
| MD5 hash: | 5e013647982463a5cde1143b88519a0b |
General |
|---|
| Start time: | 10:03:32 |
| Start date: | 25/09/2014 |
| Path: | /bin/mkdir |
| File size: | 14592 bytes |
| MD5 hash: | ef0eef7376bcd2e7254d76f8448f7cbe |
General |
|---|
| Start time: | 10:03:32 |
| Start date: | 25/09/2014 |
| Path: | /bin/sh |
| File size: | 1228304 bytes |
| MD5 hash: | 5e013647982463a5cde1143b88519a0b |
General |
|---|
| Start time: | 10:03:32 |
| Start date: | 25/09/2014 |
| Path: | /bin/chmod |
| File size: | 26080 bytes |
| MD5 hash: | 751c097604656513c3f35bdc6315e603 |
General |
|---|
| Start time: | 10:03:32 |
| Start date: | 25/09/2014 |
| Path: | /bin/sh |
| File size: | 1228304 bytes |
| MD5 hash: | 5e013647982463a5cde1143b88519a0b |
General |
|---|
| Start time: | 10:03:32 |
| Start date: | 25/09/2014 |
| Path: | /bin/chmod |
| File size: | 26080 bytes |
| MD5 hash: | 751c097604656513c3f35bdc6315e603 |
General |
|---|
| Start time: | 10:03:33 |
| Start date: | 25/09/2014 |
| Path: | /bin/sh |
| File size: | 1228304 bytes |
| MD5 hash: | 5e013647982463a5cde1143b88519a0b |
General |
|---|
| Start time: | 10:03:33 |
| Start date: | 25/09/2014 |
| Path: | /bin/chmod |
| File size: | 26080 bytes |
| MD5 hash: | 751c097604656513c3f35bdc6315e603 |
General |
|---|
| Start time: | 10:03:33 |
| Start date: | 25/09/2014 |
| Path: | /bin/sh |
| File size: | 1228304 bytes |
| MD5 hash: | 5e013647982463a5cde1143b88519a0b |
General |
|---|
| Start time: | 10:03:34 |
| Start date: | 25/09/2014 |
| Path: | /bin/chmod |
| File size: | 26080 bytes |
| MD5 hash: | 751c097604656513c3f35bdc6315e603 |
General |
|---|
| Start time: | 10:03:34 |
| Start date: | 25/09/2014 |
| Path: | /bin/sh |
| File size: | 1228304 bytes |
| MD5 hash: | 5e013647982463a5cde1143b88519a0b |
General |
|---|
| Start time: | 10:03:34 |
| Start date: | 25/09/2014 |
| Path: | /usr/bin/tar |
| File size: | 66992 bytes |
| MD5 hash: | aba6eaf8fb18ab0f193f4d83beef750b |
General |
|---|
| Start time: | 10:03:34 |
| Start date: | 25/09/2014 |
| Path: | /bin/sh |
| File size: | 1228304 bytes |
| MD5 hash: | 5e013647982463a5cde1143b88519a0b |
General |
|---|
| Start time: | 10:03:34 |
| Start date: | 25/09/2014 |
| Path: | /bin/mv |
| File size: | 20240 bytes |
| MD5 hash: | 7a97329a3eadefa196d30694ef25ba85 |
General |
|---|
| Start time: | 10:03:34 |
| Start date: | 25/09/2014 |
| Path: | /bin/sh |
| File size: | 1228304 bytes |
| MD5 hash: | 5e013647982463a5cde1143b88519a0b |
General |
|---|
| Start time: | 10:03:34 |
| Start date: | 25/09/2014 |
| Path: | /bin/chmod |
| File size: | 26080 bytes |
| MD5 hash: | 751c097604656513c3f35bdc6315e603 |
General |
|---|
| Start time: | 10:03:35 |
| Start date: | 25/09/2014 |
| Path: | /bin/sh |
| File size: | 1228304 bytes |
| MD5 hash: | 5e013647982463a5cde1143b88519a0b |
General |
|---|
| Start time: | 10:03:35 |
| Start date: | 25/09/2014 |
| Path: | /bin/sh |
| File size: | 1228304 bytes |
| MD5 hash: | 5e013647982463a5cde1143b88519a0b |
General |
|---|
| Start time: | 10:03:35 |
| Start date: | 25/09/2014 |
| Path: | /sbin/kextload |
| File size: | 58080 bytes |
| MD5 hash: | 2f9426e6040db0ea31df0f0a99f2a9da |
General |
|---|
| Start time: | 10:03:35 |
| Start date: | 25/09/2014 |
| Path: | /bin/sh |
| File size: | 1228304 bytes |
| MD5 hash: | 5e013647982463a5cde1143b88519a0b |
General |
|---|
| Start time: | 10:03:36 |
| Start date: | 25/09/2014 |
| Path: | /bin/chmod |
| File size: | 26080 bytes |
| MD5 hash: | 751c097604656513c3f35bdc6315e603 |
General |
|---|
| Start time: | 10:03:36 |
| Start date: | 25/09/2014 |
| Path: | /bin/sh |
| File size: | 1228304 bytes |
| MD5 hash: | 5e013647982463a5cde1143b88519a0b |
General |
|---|
| Start time: | 10:03:36 |
| Start date: | 25/09/2014 |
| Path: | /bin/rm |
| File size: | 19840 bytes |
| MD5 hash: | 4f71f779249ed438a4903ae4f3b704eb |
General |
|---|
| Start time: | 10:03:36 |
| Start date: | 25/09/2014 |
| Path: | /bin/sh |
| File size: | 1228304 bytes |
| MD5 hash: | 5e013647982463a5cde1143b88519a0b |
General |
|---|
| Start time: | 10:03:36 |
| Start date: | 25/09/2014 |
| Path: | /bin/sh |
| File size: | 1228304 bytes |
| MD5 hash: | 5e013647982463a5cde1143b88519a0b |
General |
|---|
| Start time: | 10:03:36 |
| Start date: | 25/09/2014 |
| Path: | /Library/.local/reweb |
| File size: | 18296 bytes |
| MD5 hash: | 23b06d80dd7d3799dbbe1a1333534482 |
General |
|---|
| Start time: | 10:03:37 |
| Start date: | 25/09/2014 |
| Path: | /bin/sh |
| File size: | 1228304 bytes |
| MD5 hash: | 5e013647982463a5cde1143b88519a0b |
General |
|---|
| Start time: | 10:03:37 |
| Start date: | 25/09/2014 |
| Path: | /bin/chmod |
| File size: | 26080 bytes |
| MD5 hash: | 751c097604656513c3f35bdc6315e603 |
General |
|---|
| Start time: | 10:03:37 |
| Start date: | 25/09/2014 |
| Path: | /bin/sh |
| File size: | 1228304 bytes |
| MD5 hash: | 5e013647982463a5cde1143b88519a0b |
General |
|---|
| Start time: | 10:03:37 |
| Start date: | 25/09/2014 |
| Path: | /usr/bin/killall |
| File size: | 19984 bytes |
| MD5 hash: | abf593d7fc091c4a91c552439b3cccb2 |
General |
|---|
| Start time: | 10:03:37 |
| Start date: | 25/09/2014 |
| Path: | /bin/sh |
| File size: | 1228304 bytes |
| MD5 hash: | 5e013647982463a5cde1143b88519a0b |
General |
|---|
| Start time: | 10:03:37 |
| Start date: | 25/09/2014 |
| Path: | /usr/bin/killall |
| File size: | 19984 bytes |
| MD5 hash: | abf593d7fc091c4a91c552439b3cccb2 |
General |
|---|
| Start time: | 10:03:47 |
| Start date: | 25/09/2014 |
| Path: | /bin/sh |
| File size: | 1228304 bytes |
| MD5 hash: | 5e013647982463a5cde1143b88519a0b |
General |
|---|
| Start time: | 10:03:47 |
| Start date: | 25/09/2014 |
| Path: | /Library/.local/updated |
| File size: | 33168 bytes |
| MD5 hash: | ceeceb4585780228660ebc17300540ea |
General |
|---|
| Start time: | 10:03:48 |
| Start date: | 25/09/2014 |
| Path: | /bin/sh |
| File size: | 1228304 bytes |
| MD5 hash: | 5e013647982463a5cde1143b88519a0b |
General |
|---|
| Start time: | 10:03:48 |
| Start date: | 25/09/2014 |
| Path: | /usr/bin/killall |
| File size: | 19984 bytes |
| MD5 hash: | abf593d7fc091c4a91c552439b3cccb2 |
General |
|---|
| Start time: | 10:03:49 |
| Start date: | 25/09/2014 |
| Path: | /bin/sh |
| File size: | 1228304 bytes |
| MD5 hash: | 5e013647982463a5cde1143b88519a0b |
General |
|---|
| Start time: | 10:03:49 |
| Start date: | 25/09/2014 |
| Path: | /bin/sh |
| File size: | 1228304 bytes |
| MD5 hash: | 5e013647982463a5cde1143b88519a0b |
General |
|---|
| Start time: | 10:03:49 |
| Start date: | 25/09/2014 |
| Path: | /Library/.local/EventMonitor |
| File size: | 26832 bytes |
| MD5 hash: | 88a7221e4928ae90ef6506604fe58e06 |
General |
|---|
| Start time: | 10:04:34 |
| Start date: | 25/09/2014 |
| Path: | /bin/sh |
| File size: | 1228304 bytes |
| MD5 hash: | 5e013647982463a5cde1143b88519a0b |
General |
|---|
| Start time: | 10:04:34 |
| Start date: | 25/09/2014 |
| Path: | /Library/.local/update |
| File size: | 63652 bytes |
| MD5 hash: | 80e7dc419bafa8bf59d2bda6bcde885d |
General |
|---|
| Start time: | 10:05:19 |
| Start date: | 25/09/2014 |
| Path: | /bin/sh |
| File size: | 1228304 bytes |
| MD5 hash: | 5e013647982463a5cde1143b88519a0b |
General |
|---|
| Start time: | 10:05:19 |
| Start date: | 25/09/2014 |
| Path: | /Library/.local/update |
| File size: | 63652 bytes |
| MD5 hash: | 80e7dc419bafa8bf59d2bda6bcde885d |
General |
|---|
| Start time: | 10:06:04 |
| Start date: | 25/09/2014 |
| Path: | /bin/sh |
| File size: | 1228304 bytes |
| MD5 hash: | 5e013647982463a5cde1143b88519a0b |
General |
|---|
| Start time: | 10:06:04 |
| Start date: | 25/09/2014 |
| Path: | /Library/.local/update |
| File size: | 63652 bytes |
| MD5 hash: | 80e7dc419bafa8bf59d2bda6bcde885d |
General |
|---|
| Start time: | 10:06:49 |
| Start date: | 25/09/2014 |
| Path: | /bin/sh |
| File size: | 1228304 bytes |
| MD5 hash: | 5e013647982463a5cde1143b88519a0b |
General |
|---|
| Start time: | 10:06:49 |
| Start date: | 25/09/2014 |
| Path: | /Library/.local/update |
| File size: | 63652 bytes |
| MD5 hash: | 80e7dc419bafa8bf59d2bda6bcde885d |
General |
|---|
| Start time: | 10:04:48 |
| Start date: | 25/09/2014 |
| Path: | /sbin/launchd |
| File size: | 194160 bytes |
| MD5 hash: | ba25b3aa91447246a1d2abf0be919078 |
General |
|---|
| Start time: | 10:04:49 |
| Start date: | 25/09/2014 |
| Path: | /Applications/TextEdit.app/Contents/MacOS/TextEdit |
| File size: | 166576 bytes |
| MD5 hash: | c4108c7bbaebd2a2fad1bd35616a5b5d |