Source: unknown | TCP traffic detected without corresponding DNS query: 67.43.239.146 |
Source: unknown | TCP traffic detected without corresponding DNS query: 67.43.239.146 |
Source: unknown | TCP traffic detected without corresponding DNS query: 67.43.239.146 |
Source: unknown | TCP traffic detected without corresponding DNS query: 67.43.239.146 |
Source: unknown | TCP traffic detected without corresponding DNS query: 67.43.239.146 |
Source: unknown | TCP traffic detected without corresponding DNS query: 67.43.239.146 |
Source: unknown | TCP traffic detected without corresponding DNS query: 67.43.239.146 |
Source: unknown | TCP traffic detected without corresponding DNS query: 67.43.239.146 |
Source: unknown | TCP traffic detected without corresponding DNS query: 67.43.239.146 |
Source: unknown | TCP traffic detected without corresponding DNS query: 67.43.239.146 |
Source: unknown | TCP traffic detected without corresponding DNS query: 67.43.239.146 |
Source: unknown | TCP traffic detected without corresponding DNS query: 67.43.239.146 |
Source: unknown | TCP traffic detected without corresponding DNS query: 67.43.239.146 |
Source: unknown | TCP traffic detected without corresponding DNS query: 67.43.239.146 |
Source: unknown | TCP traffic detected without corresponding DNS query: 67.43.239.146 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.62.58.207 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.62.58.207 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.62.58.207 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.62.58.207 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.62.58.207 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.62.58.207 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.62.58.207 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.62.58.207 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.62.58.207 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.62.58.207 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.62.58.207 |
Source: TinkaOTP.dmg | String found in binary or memory: http://www.apple.com/DTDs/PropertyList-1.0.dtd |
Source: unknown | Network traffic detected: HTTP traffic on port 49375 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49379 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49375 |
Source: unknown | Network traffic detected: HTTP traffic on port 49379 -> 443 |
Source: classification engine | Classification label: mal60.troj.evad.macDMG@0/4@0/0 |
Source: /bin/bash (PID: 18267) | Hidden file executed: /Users/ben/Library/.mina /Users/ben/Library/.mina | Jump to behavior |
Source: /bin/cp (PID: 18265) | 64-bit Mach-O written to unusual path: /Users/ben/Library/.mina | Jump to dropped file |
Source: /bin/cp (PID: 18265) | Permissions modified for written 64-bit Mach-O /Users/ben/Library/.mina: bits: - usr: r grp: r all: rw | Jump to dropped file |
Source: /bin/cp (PID: 18265) | Hidden File created: /Users/ben/Library/.mina | Jump to behavior |
Source: /Volumes/TinkaOTP/TinkaOTP.app/Contents/MacOS/TinkaOTP (PID: 18263) | Shell command executed: /bin/bash -c cp /Volumes/TinkaOTP/TinkaOTP.app/Contents/Resources/Base.lproj/SubMenu.nib ~/Library/.mina > /dev/null 2>&1 && chmod +x ~/Library/.mina > /dev/null 2>&1 && ~/Library/.mina > /dev/null 2>&1 | Jump to behavior |
Source: /bin/bash (PID: 18266) | Chmod executable: /bin/chmod -> chmod +x /Users/ben/Library/.mina | Jump to behavior |
Source: /Volumes/TinkaOTP/TinkaOTP.app/Contents/MacOS/TinkaOTP (PID: 18263) | Launchservices plist file read: /Users/ben/Library/Preferences/com.apple.LaunchServices/com.apple.launchservices.secure.plist | Jump to behavior |
Source: /Volumes/TinkaOTP/TinkaOTP.app/Contents/MacOS/TinkaOTP (PID: 18263) | Preferences launchservices plist file read: /Users/ben/Library/Preferences/com.apple.LaunchServices/com.apple.launchservices.secure.plist | Jump to behavior |
Source: /bin/cp (PID: 18265) | File written: /Users/ben/Library/.mina | Jump to dropped file |
Source: /Users/ben/Library/.mina (PID: 18268) | Random device file read: /dev/urandom | Jump to behavior |
Source: /Volumes/TinkaOTP/TinkaOTP.app/Contents/MacOS/TinkaOTP (PID: 18263) | AppleKeyboardLayouts info plist opened: /System/Library/Keyboard Layouts/AppleKeyboardLayouts.bundle/Contents/Info.plist | Jump to behavior |
Source: /Users/ben/Library/.mina (PID: 18267) | XML plist file created: /Users/ben/Library/LaunchAgents/com.aex-loop.agent.plist | Jump to dropped file |
Source: /Users/ben/Library/.mina (PID: 18267) | Launch agent/daemon created with KeepAlive and/or RunAtLoad, file created: /Users/ben/Library/LaunchAgents/com.aex-loop.agent.plist | Jump to behavior |
Source: /Users/ben/Library/.mina (PID: 18267) | Launch agent created File created: /Users/ben/Library/LaunchAgents/com.aex-loop.agent.plist | Jump to behavior |
Source: /bin/cp (PID: 18265) | Hidden Mach-O file written: Mach-O 64 bit: /Users/ben/Library/.mina | Jump to dropped file |
Source: /Volumes/TinkaOTP/TinkaOTP.app/Contents/MacOS/TinkaOTP (PID: 18263) | Sysctl read request: kern.safeboot (1.66) | Jump to behavior |
Source: /Volumes/TinkaOTP/TinkaOTP.app/Contents/MacOS/TinkaOTP (PID: 18263) | Sysctl read request: hw.availcpu (6.25) | Jump to behavior |
Source: /bin/bash (PID: 18264) | Sysctl requested: kern.hostname (1.10) | Jump to behavior |
Source: /Volumes/TinkaOTP/TinkaOTP.app/Contents/MacOS/TinkaOTP (PID: 18263) | System or server version plist file read: /System/Library/CoreServices/SystemVersion.plist | Jump to behavior |
Source: Yara match | File source: SubMenu.nib, type: SAMPLE |
Source: Yara match | File source: /Users/ben/Library/.mina, type: DROPPED |
Source: Yara match | File source: SubMenu.nib, type: SAMPLE |
Source: Yara match | File source: /Users/ben/Library/.mina, type: DROPPED |
Sample Distance (10 = nearest)
10
9
8
7
6
5
4
3
2
1
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.