Source: unknown | DNS traffic detected: queries for: www.comeinbaby.com |
Source: /Users/vreni/Desktop/com.apple.exe (PID: 390) | Writes from socket in process: |
Source: classification engine | Classification label: mal52.evad.macEXE@0/0@3/0 |
Source: initial sample | Static MACH information: dylib_command -> /System/Library/Frameworks/Security.framework/Versions/A/Security |
Source: /Users/vreni/Desktop/com.apple.exe (PID: 390) | Random device file read: /dev/urandom |
Source: /Users/vreni/Desktop/com.apple.exe (PID: 390) | Shell command executed: sh -c touch -c -t 201409100044 /usr/bin/periodicdate touch -c -t 201409100044 /usr/bin/systemkeychain-helper touch -c -t 201409100044 /usr/bin/com.apple.appstore.PluginHelper touch -c -t 201409100044 /usr/bin/com.apple.MailServiceAgentHelper touch -c -t 201409100044 /System/Library/LaunchDaemons/com.apple.periodic-dd-mm-yy.plist touch -c -t 201409100044 /System/Library/LaunchDaemons/com.apple.systemkeychain-helper.plist touch -c -t 201409100044 /System/Library/LaunchDaemons/com.apple.appstore.plughelper.plist touch -c -t 201409100044 /System/Library/LaunchDaemons/com.apple.MailServiceAgentHelper.plist touch -c -t 201409100044 /usr/bin/stty5.11.pl touch -c -t 201409100044 /etc/manpath.d/ rm -rf /var/log/system.log |
Source: /Users/vreni/Desktop/com.apple.exe (PID: 390) | Shell command executed: sh -c ps -ef|grep Xcode |grep -v grep |
Source: /Users/vreni/Desktop/com.apple.exe (PID: 390) | Shell command executed: sh -c ps -ef|grep iTunes |grep -v grep |
Source: /Users/vreni/Desktop/com.apple.exe (PID: 390) | Shell command executed: sh -c mkdir -p /System/Library/QuickTime/QuickTimeFireWireDOLBY.component |
Source: /bin/sh (PID: 405) | Grep executable: /usr/bin/grep -> grep Xcode |
Source: /bin/sh (PID: 406) | Grep executable: /usr/bin/grep -> grep -v grep |
Source: /bin/sh (PID: 409) | Grep executable: /usr/bin/grep -> grep iTunes |
Source: /bin/sh (PID: 410) | Grep executable: /usr/bin/grep -> grep -v grep |
Source: /bin/sh (PID: 411) | Mkdir executable: /bin/mkdir -> mkdir -p /System/Library/QuickTime/QuickTimeFireWireDOLBY.component |
Source: /bin/sh (PID: 404) | Ps executable: /bin/ps -> ps -ef |
Source: /bin/sh (PID: 408) | Ps executable: /bin/ps -> ps -ef |
Source: /bin/sh (PID: 392) | Touch executable: /usr/bin/touch -> touch -c -t 201409100044 /usr/bin/periodicdate |
Source: /bin/sh (PID: 393) | Touch executable: /usr/bin/touch -> touch -c -t 201409100044 /usr/bin/systemkeychain-helper |
Source: /bin/sh (PID: 394) | Touch executable: /usr/bin/touch -> touch -c -t 201409100044 /usr/bin/com.apple.appstore.PluginHelper |
Source: /bin/sh (PID: 395) | Touch executable: /usr/bin/touch -> touch -c -t 201409100044 /usr/bin/com.apple.MailServiceAgentHelper |
Source: /bin/sh (PID: 396) | Touch executable: /usr/bin/touch -> touch -c -t 201409100044 /System/Library/LaunchDaemons/com.apple.periodic-dd-mm-yy.plist |
Source: /bin/sh (PID: 397) | Touch executable: /usr/bin/touch -> touch -c -t 201409100044 /System/Library/LaunchDaemons/com.apple.systemkeychain-helper.plist |
Source: /bin/sh (PID: 398) | Touch executable: /usr/bin/touch -> touch -c -t 201409100044 /System/Library/LaunchDaemons/com.apple.appstore.plughelper.plist |
Source: /bin/sh (PID: 399) | Touch executable: /usr/bin/touch -> touch -c -t 201409100044 /System/Library/LaunchDaemons/com.apple.MailServiceAgentHelper.plist |
Source: /bin/sh (PID: 400) | Touch executable: /usr/bin/touch -> touch -c -t 201409100044 /usr/bin/stty5.11.pl |
Source: /bin/sh (PID: 401) | Touch executable: /usr/bin/touch -> touch -c -t 201409100044 /etc/manpath.d/ |
Source: /bin/sh (PID: 402) | Rm executable: /bin/rm -> rm -rf /var/log/system.log |
Source: /bin/sh (PID: 392) | Touch executable uses -c (no creation) and -t (set access/modification time) options: touch -c -t 201409100044 /usr/bin/periodicdate |
Source: /bin/sh (PID: 393) | Touch executable uses -c (no creation) and -t (set access/modification time) options: touch -c -t 201409100044 /usr/bin/systemkeychain-helper |
Source: /bin/sh (PID: 394) | Touch executable uses -c (no creation) and -t (set access/modification time) options: touch -c -t 201409100044 /usr/bin/com.apple.appstore.PluginHelper |
Source: /bin/sh (PID: 395) | Touch executable uses -c (no creation) and -t (set access/modification time) options: touch -c -t 201409100044 /usr/bin/com.apple.MailServiceAgentHelper |
Source: /bin/sh (PID: 396) | Touch executable uses -c (no creation) and -t (set access/modification time) options: touch -c -t 201409100044 /System/Library/LaunchDaemons/com.apple.periodic-dd-mm-yy.plist |
Source: /bin/sh (PID: 397) | Touch executable uses -c (no creation) and -t (set access/modification time) options: touch -c -t 201409100044 /System/Library/LaunchDaemons/com.apple.systemkeychain-helper.plist |
Source: /bin/sh (PID: 398) | Touch executable uses -c (no creation) and -t (set access/modification time) options: touch -c -t 201409100044 /System/Library/LaunchDaemons/com.apple.appstore.plughelper.plist |
Source: /bin/sh (PID: 399) | Touch executable uses -c (no creation) and -t (set access/modification time) options: touch -c -t 201409100044 /System/Library/LaunchDaemons/com.apple.MailServiceAgentHelper.plist |
Source: /bin/sh (PID: 400) | Touch executable uses -c (no creation) and -t (set access/modification time) options: touch -c -t 201409100044 /usr/bin/stty5.11.pl |
Source: /bin/sh (PID: 401) | Touch executable uses -c (no creation) and -t (set access/modification time) options: touch -c -t 201409100044 /etc/manpath.d/ |
Source: /bin/rm (PID: 402) | Log files deleted: /var/log/system.log |
Source: /Users/vreni/Desktop/com.apple.exe (PID: 390) | System or server version plist file read: /System/Library/CoreServices/SystemVersion.plist |
Source: /bin/sh (PID: 391) | Sysctl requested: kern.hostname (1.10) |
Source: /bin/sh (PID: 403) | Sysctl requested: kern.hostname (1.10) |
Source: /bin/sh (PID: 407) | Sysctl requested: kern.hostname (1.10) |
Source: /bin/sh (PID: 411) | Sysctl requested: kern.hostname (1.10) |