Source: unknown | TCP traffic detected without corresponding DNS query: 89.34.111.113 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.34.111.113 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.34.111.113 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.34.111.113 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.34.111.113 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.34.111.113 |
Source: unknown | TCP traffic detected without corresponding DNS query: 17.57.146.20 |
Source: unknown | TCP traffic detected without corresponding DNS query: 17.57.146.20 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.34.111.113 |
Source: unknown | TCP traffic detected without corresponding DNS query: 17.188.166.11 |
Source: unknown | TCP traffic detected without corresponding DNS query: 17.188.166.11 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.34.111.113 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.34.111.113 |
Source: unknown | TCP traffic detected without corresponding DNS query: 17.253.57.212 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.20.214.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.20.214.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 17.253.57.212 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.34.111.113 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.34.111.113 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.34.111.113 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.34.111.113 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.34.111.113 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.34.111.113 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.34.111.113 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.34.111.113 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.34.111.113 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.34.111.113 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.34.111.113 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.34.111.113 |
Source: symbol | Static MACH information: _CFNetworkCopyProxiesForURL |
Source: symbol | Static MACH information: _CFNetworkExecuteProxyAutoConfigurationURL |
Source: symbol | Static MACH information: _kCFProxyAutoConfigurationURLKey |
Source: symbol | Static MACH information: _kCFProxyHostNameKey |
Source: symbol | Static MACH information: _kCFProxyPortNumberKey |
Source: symbol | Static MACH information: _kCFProxyTypeAutoConfigurationURL |
Source: symbol | Static MACH information: _kCFProxyTypeHTTP |
Source: symbol | Static MACH information: _kCFProxyTypeKey |
Source: symbol | Static MACH information: _kCFProxyTypeSOCKS |
Source: M4BfJpvkrT | String found in binary or memory: http://www.apple.com/DTDs/PropertyList-1.0.dtd |
Source: M4BfJpvkrT | String found in binary or memory: http://www.google.com |
Source: M4BfJpvkrT | String found in binary or memory: http://www.google.com%USER%Unknown% |
Source: unknown | Network traffic detected: HTTP traffic on port 49318 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49314 -> 443 |
Source: symbol | Static MACH information: _CGEventCreateKeyboardEvent |
Source: symbol | Static MACH information: _CGEventCreateMouseEvent |
Source: M4BfJpvkrT, type: SAMPLE | Matched rule: Detects OSX Netwire A |
Source: /Users/henry/.defaults/Finder.app/Contents/MacOS/Finder, type: DROPPED | Matched rule: Detects OSX Netwire A |
Source: classification engine | Classification label: mal68.troj.evad.mac@0/4@0/0 |
Source: symbol | Static MACH information: _CGSConnectionGetPID |
Source: symbol | Static MACH information: __CFCopyServerVersionDictionary |
Source: symbol | Static MACH information: __CGSDefaultConnection |
Source: symbol | Static MACH information: _connect$UNIX2003 |
Source: symbol | Static MACH information: _gethostbyname |
Source: symbol | Static MACH information: _kCFProxyPortNumberKey |
Source: symbol | Static MACH information: _kCFProxyTypeHTTP |
Source: symbol | Static MACH information: _kCFProxyTypeSOCKS |
Source: symbol | Static MACH information: _send$UNIX2003 |
Source: symbol | Static MACH information: _setsockopt |
Source: symbol | Static MACH information: _socket |
Source: symbol | Static MACH information: _CGSConnectionGetPID |
Source: symbol | Static MACH information: __CFCopyServerVersionDictionary |
Source: symbol | Static MACH information: __CGSDefaultConnection |
Source: symbol | Static MACH information: _connect$UNIX2003 |
Source: symbol | Static MACH information: _gethostbyname |
Source: symbol | Static MACH information: _kCFProxyPortNumberKey |
Source: symbol | Static MACH information: _kCFProxyTypeHTTP |
Source: symbol | Static MACH information: _kCFProxyTypeSOCKS |
Source: symbol | Static MACH information: _send$UNIX2003 |
Source: symbol | Static MACH information: _setsockopt |
Source: symbol | Static MACH information: _socket |
Source: initial sample | Static MACH information: dylib_command -> /System/Library/Frameworks/IOKit.framework/Versions/A/IOKit |
Source: initial sample | Static MACH information: dylib_command -> /System/Library/Frameworks/IOKit.framework/Versions/A/IOKit |
Source: /Users/henry/Desktop/M4BfJpvkrT (PID: 606) | File in hidden directory executed: /Users/henry/.defaults/Finder.app/Contents/MacOS/Finder - | Jump to behavior |
Source: /Users/henry/Desktop/M4BfJpvkrT (PID: 605) | 32-bit Mach-O written to hidden directory: /Users/henry/.defaults/Finder.app/Contents/MacOS/Finder | Jump to dropped file |
Source: /Users/henry/Desktop/M4BfJpvkrT (PID: 605) | Permissions modified for written 32-bit Mach-O /Users/henry/.defaults/Finder.app/Contents/MacOS/Finder: bits: - usr: rwx grp: rwx all: rwx | Jump to dropped file |
Source: symbol | Static MACH information: _LSSharedFileListCopySnapshot |
Source: symbol | Static MACH information: _LSSharedFileListCreate |
Source: symbol | Static MACH information: _LSSharedFileListInsertItemURL |
Source: symbol | Static MACH information: _LSSharedFileListItemRemove |
Source: symbol | Static MACH information: _LSSharedFileListItemResolve |
Source: symbol | Static MACH information: _kLSSharedFileListItemLast |
Source: symbol | Static MACH information: _kLSSharedFileListSessionLoginItems |
Source: symbol | Static MACH information: _KillProcess |
Source: /Users/henry/Desktop/M4BfJpvkrT (PID: 605) | Bundle Info.plist file created: /Users/henry/.defaults/Finder.app/Contents/Info.plist | Jump to behavior |
Source: /Users/henry/Desktop/M4BfJpvkrT (PID: 605) | Hidden Directory created: /Users/henry/.defaults -> /Users/henry/.defaults | Jump to behavior |
Source: /Users/henry/.defaults/Finder.app/Contents/MacOS/Finder (PID: 606) | Hidden file created: /Users/henry/.defaults/Finder.app/Contents/MacOS/.settings.conf | Jump to behavior |
Source: /Users/henry/.defaults/Finder.app/Contents/MacOS/Finder (PID: 606) | Launchservices plist file read: /System/Library/Preferences/Logging/Subsystems/com.apple.launchservices.plist | Jump to behavior |
Source: /Users/henry/Desktop/M4BfJpvkrT (PID: 605) | File written: /Users/henry/.defaults/Finder.app/Contents/MacOS/Finder | Jump to dropped file |
Source: /Users/henry/Desktop/M4BfJpvkrT (PID: 605) | XML plist file created: /Users/henry/.defaults/Finder.app/Contents/Info.plist | Jump to dropped file |
Source: /Users/henry/.defaults/Finder.app/Contents/MacOS/Finder (PID: 606) | Launch agent created file created: /Users/henry/Library/LaunchAgents/com.mac.host.plist | Jump to behavior |
Source: /Users/henry/Desktop/M4BfJpvkrT (PID: 605) | IOC file dropped: /Users/henry/.defaults/Finder.app/Contents/MacOS/Finder | Jump to dropped file |
Source: /Users/henry/.defaults/Finder.app/Contents/MacOS/Finder (PID: 606) | IOC file dropped: /Users/henry/Library/LaunchAgents/com.mac.host.plist | Jump to dropped file |
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.