Loading Joe Sandbox Report ...

Edit tour

macOS Analysis Report
Pipidae.app

Overview

General Information

Sample Name:Pipidae.app
Analysis ID:1294523
MD5:8881338c77f4285d197fb52229575d64
SHA1:23eea6ab534cf7aa5e9356660cfa974c3e610bbd
SHA256:7a1f844ec0aa595b09d4044e99690cf3d3095a3faae5656a7f5b78cc593563f5
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Denies being traced/debugged (via ptrace PT_DENY_ATTACH)
Process executable has a file extension which is uncommon (probably to disguise the executable)
Contains symbols with suspicious names likely related to encryption
Contains symbols with suspicious names likely related to networking
Uses CFNetwork bundle containing interfaces for network communication (HTTP, sockets, and Bonjour)
Reads the systems OS release and/or type

Classification

Joe Sandbox Version:38.0.0 Beryl
Analysis ID:1294523
Start date and time:2023-08-21 15:42:38 +02:00
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 4m 21s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultmacfilecookbook.jbs
Analysis system description:Virtual Machine, High Sierra (Office 2016 16.16, Java 11.0.2+9, Adobe Reader 2019.010.20099)
macOS major version:10.13
CPU architecture:x86_64
Analysis Mode:default
Sample file name:Pipidae.app
Detection:MAL
Classification:mal56.evad.macAPP@0/0@1/0
Command:/Users/berri/Desktop/Pipidae.app
PID:895
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • System is macvm-highsierra
  • Pipidae.app (MD5: 8881338c77f4285d197fb52229575d64) Arguments: /Users/berri/Desktop/Pipidae.app
  • cleanup
No yara matches
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Pipidae.appReversingLabs: Detection: 13%
Source: Pipidae.appVirustotal: Detection: 38%Perma Link
Source: submission: Pipidae.appMach-O symbol: _CCCryptorRelease
Source: submission: Pipidae.appMach-O symbol: _CCCryptorUpdate
Source: submission: Pipidae.appMach-O symbol: _CCCryptorFinal
Source: submission: Pipidae.appMach-O symbol: _CCCryptorGetOutputLength
Source: submission: Pipidae.appMach-O symbol: _CCCryptorCreate
Source: unknownHTTPS traffic detected: 54.70.175.13:443 -> 192.168.11.11:49304 version: TLS 1.2
Source: submission: Pipidae.appMach-O symbol: _kIOMasterPortDefault
Source: unknownDNS traffic detected: queries for: www.ipahufm.icu
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49304
Source: unknownNetwork traffic detected: HTTP traffic on port 49304 -> 443
Source: unknownTCP traffic detected without corresponding DNS query: 17.253.15.208
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.196.201
Source: unknownTCP traffic detected without corresponding DNS query: 17.253.15.208
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.196.201
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: Pipidae.app, 00000895.00000282.9.000000011188f000.00000001118aa000.r--.sdmpString found in binary or memory: http://crl.apple.com/codesigning.crl0
Source: Pipidae.app, 00000895.00000282.9.000000011188f000.00000001118aa000.r--.sdmpString found in binary or memory: http://www.apple.com/DTDs/PropertyList-1.0.dtd
Source: Pipidae.app, 00000895.00000282.9.000000011188f000.00000001118aa000.r--.sdmpString found in binary or memory: http://www.apple.com/appleca/root.crl0
Source: Pipidae.app, 00000895.00000282.9.000000011188f000.00000001118aa000.r--.sdmpString found in binary or memory: http://www.apple.com/certificateauthority0
Source: Pipidae.app, 00000895.00000282.9.000000011188f000.00000001118aa000.r--.sdmpString found in binary or memory: https://www.apple.com/appleca/0
Source: unknownHTTP traffic detected: POST /se/cu HTTP/1.1Host: www.ipahufm.icuContent-Type: application/jsonConnection: keep-aliveAccept: */*User-Agent: Pipidae.app (unknown version) CFNetwork/893.13.1 Darwin/17.3.0 (x86_64)Content-Length: 42Accept-Language: en-usAccept-Encoding: br, gzip, deflate
Source: unknownHTTPS traffic detected: 54.70.175.13:443 -> 192.168.11.11:49304 version: TLS 1.2
Source: classification engineClassification label: mal56.evad.macAPP@0/0@1/0
Source: /Users/berri/Desktop/Pipidae.app (PID: 895)CFNetwork info plist opened: /System/Library/Frameworks/CFNetwork.framework/Resources/Info.plistJump to behavior
Source: submission: Pipidae.appMach-O header: dylib_command -> /System/Library/Frameworks/AppKit.framework/Versions/C/AppKit
Source: submission: Pipidae.appMach-O header: dylib_command -> /System/Library/Frameworks/SystemConfiguration.framework/Versions/A/SystemConfiguration
Source: submission: Pipidae.appMach-O header: dylib_command -> /System/Library/Frameworks/IOKit.framework/Versions/A/IOKit

Hooking and other Techniques for Hiding and Protection

barindex
Source: /Users/berri/Desktop/Pipidae.app (PID: 895)PTRACE system call (PT_DENY_ATTACH): PID 895 denies future tracesJump to behavior
Source: /Library/Frameworks/Mono.framework/Versions/4.4.2/bin/mono-sgen32 (PID: 895)Process executable with extension: /Users/berri/Desktop/Pipidae.appJump to behavior
Source: Pipidae.app, 00000895.00000282.9.000000010ae47000.000000010ae5b000.rw-.sdmpBinary or memory string: VMware
Source: /Users/berri/Desktop/Pipidae.app (PID: 895)Sysctl requested: kern.ostype (1.1)Jump to behavior
Source: /Users/berri/Desktop/Pipidae.app (PID: 895)Sysctl requested: kern.osrelease (1.2)Jump to behavior
Source: /Users/berri/Desktop/Pipidae.app (PID: 895)System or server version plist file read: /System/Library/CoreServices/SystemVersion.plistJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Masquerading
1
GUI Input Capture
1
Security Software Discovery
Remote Services1
GUI Input Capture
Exfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Disable or Modify Tools
LSASS Memory11
System Information Discovery
Remote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth2
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account Manager1
System Network Configuration Discovery
SMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration3
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


cam-macmac-stand
SourceDetectionScannerLabelLink
Pipidae.app13%ReversingLabsMacOS.Adware.Generic
Pipidae.app38%VirustotalBrowse
No Antivirus matches
SourceDetectionScannerLabelLink
www.ipahufm.icu0%VirustotalBrowse
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
searchlb-3b453017ec33bbb9.elb.us-west-2.amazonaws.com
54.70.175.13
truefalse
    high
    www.ipahufm.icu
    unknown
    unknownfalseunknown
    NameMaliciousAntivirus DetectionReputation
    https://www.ipahufm.icu/se/cufalse
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      54.70.175.13
      searchlb-3b453017ec33bbb9.elb.us-west-2.amazonaws.comUnited States
      16509AMAZON-02USfalse
      2.23.196.201
      unknownEuropean Union
      1273CWVodafoneGroupPLCEUfalse
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      54.70.175.13RavenwiseGet hashmaliciousUnknownBrowse
        RavenwiseGet hashmaliciousUnknownBrowse
          bfeGet hashmaliciousUnknownBrowse
            ctapp_230720_b1nt12.zipGet hashmaliciousUnknownBrowse
              Kx1A2vl0kcGet hashmaliciousUnknownBrowse
                ctapp_230720_b1nt12.zipGet hashmaliciousUnknownBrowse
                  2.23.196.201https://pub-1658c2dd66434dd7b5f48ce167884c7e.r2.dev/index.html#support@ashleymadison.comGet hashmaliciousUnknownBrowse
                    http://daubinvestments.comGet hashmaliciousUnknownBrowse
                      https://clothingmemorialadorable.com/xfk47a7yg?key=02661d03f8c3bed95f6dd5fe5d58f347Get hashmaliciousUnknownBrowse
                        SetupGet hashmaliciousUnknownBrowse
                          https://trk.klclick3.com/ls/click?upn=ODUWvrrWUUEee10FYhP2wZyPL1bLpxmK7tCWb4Xj1Noy-2F-2Bu0ZUvzWzy588C54QNl6EPf-2FtlYqzO-2FJkqf-2FjkkjhJXLWf5Q-2Bh3bAFwhgyoBKZRylURgGbO-2Fl-2FhbyBLIcM6kcBGS3VJC0dCH8iqTpiv-2BA-3D-3DC_TS_BdoE-2BqcBt692Zq6TFVs-2BIYMNWNao2bfciBVD4n-2F5m-2FzBQafN-2F7-2Bb30sW9-2BzFZMaW-2FLJeG6XW598f6wa-2Fo11l-2BHQQC5ig3nbpcHiAiLC4qo8M7BJH-2F03cOZNeyWMYx0sU6lI0DVg-2B-2BNK9mEASj1W3RH6HbZ9xgEE-2FV3ByC-2FjRioxk8-2FwBZ-2F867xPaQnbyASSD67hoK3iQXHJ3Jh-2F7VIbGFcx6Zr-2BEDbt1-2FQNWkxAShvSmZiu3FbvM8NrUGz63EdoSph70Bw3S915mU18T7xAa8FAnmS7G1NDJnJLYcw9Hiuc6zL4gJ6nwznB2cBoMoKt9fNH-2BGzhiVYtPk3qcCu-2BP8scoYS0uRT5d-2Flgt-2BUGYNIKc9NeNdHghkoytvotQ8p35TvSzKDt0nLjjlQUYFcKRWB6OB5D-2FMLRGYA9ZoGxrLTg-3D#cl/488482_md/10/419673/6491/60323/1797583Get hashmaliciousUnknownBrowse
                            https://1drv.ms/b/s!AuDWrgYDuxytbac78BbaB6ykfT8Get hashmaliciousUnknownBrowse
                              https://o3g46bxs.page.link/dmCnGet hashmaliciousUnknownBrowse
                                https://clothingmemorialadorable.com/xfk47a7yg?key=02661d03f8c3bed95f6dd5fe5d58f347Get hashmaliciousUnknownBrowse
                                  https://clothingmemorialadorable.com/xfk47a7yg?Get hashmaliciousUnknownBrowse
                                    mainGet hashmaliciousUnknownBrowse
                                      http://t.co/C3j7hxRH1i?go1Get hashmaliciousUnknownBrowse
                                        https://tax.taxmatch.pw/index.php?fname=Sonia&Iname=Zamora&address=Dexter%20ct%20woodbridge&city=Harrisburg&state=PA&zip=17101&email=no@email.com&phone=7175747162Get hashmaliciousUnknownBrowse
                                          9FajbP2iUgGet hashmaliciousCloudMensisBrowse
                                            qSyn3wYEjYGet hashmaliciousCalistoBrowse
                                              12mu8VHN8kGet hashmaliciousUnknownBrowse
                                                https://rum.edgio.netGet hashmaliciousUnknownBrowse
                                                  https://workdrive.zohoexternal.com/file/cy5wr6f6bb22f7def4ca5a9c1783a9c058602Get hashmaliciousUnknownBrowse
                                                    Payment_receipt #june_ 4139.htmGet hashmaliciousHTMLPhisherBrowse
                                                      il9Qwo3sVfGet hashmaliciousUnknownBrowse
                                                        https://pub-094517efd3704d3cb6704b960e13b773.r2.dev/indexxe.html#credit-control@itv.comGet hashmaliciousUnknownBrowse
                                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                          searchlb-3b453017ec33bbb9.elb.us-west-2.amazonaws.comRavenwiseGet hashmaliciousUnknownBrowse
                                                          • 54.70.175.13
                                                          RavenwiseGet hashmaliciousUnknownBrowse
                                                          • 54.70.175.13
                                                          bfeGet hashmaliciousUnknownBrowse
                                                          • 54.70.175.13
                                                          ctapp_230720_b1nt12.zipGet hashmaliciousUnknownBrowse
                                                          • 54.70.175.13
                                                          Kx1A2vl0kcGet hashmaliciousUnknownBrowse
                                                          • 54.70.175.13
                                                          ctapp_230720_b1nt12.zipGet hashmaliciousUnknownBrowse
                                                          • 54.70.175.13
                                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                          AMAZON-02UShttps://skilltrackers.com/product/chatgpt-for-accountants-understand-fiduciary-accounting-principles/?utm_source=EQ2&utm_medium=180823&utm_campaign=HR&utm_id=email&c=E,1,UCYU-yIXtYLMpHGZXEkkKAg_BAlLBjF_g0yJxCpN032LNtX1J7DTpr3TON8zIWLbNLgWzgAwj7cF9IJtU2bZ7BKtzYQnLge0asG_jk6HQSHs-w,,&typo=1Get hashmaliciousUnknownBrowse
                                                          • 54.186.23.98
                                                          http://documen.site/download/bosch-kts-200-keygen-213l_pdfGet hashmaliciousUnknownBrowse
                                                          • 35.181.29.184
                                                          https://red0zv3n.page.link/nYJzGet hashmaliciousUnknownBrowse
                                                          • 3.75.62.37
                                                          RFQ20230821_Commercial_list.exeGet hashmaliciousFormBook, GuLoaderBrowse
                                                          • 3.19.30.28
                                                          http://ecv.microsoft.com/yes23p1SdDGet hashmaliciousCaptcha PhishBrowse
                                                          • 13.32.110.126
                                                          KCyJ0EWBsw.elfGet hashmaliciousMiraiBrowse
                                                          • 184.78.140.227
                                                          https://qvrcu28l.page.link/jdF1Get hashmaliciousUnknownBrowse
                                                          • 3.75.62.37
                                                          ungziped_file.exeGet hashmaliciousFormBook, GuLoaderBrowse
                                                          • 54.179.30.8
                                                          RFQ-Material_List0816023.exeGet hashmaliciousFormBookBrowse
                                                          • 44.227.76.166
                                                          https://runningonrice.com/auth3/cap/turnstile?userid=tbarris@estrellagaliciausa.comGet hashmaliciousUnknownBrowse
                                                          • 108.138.34.115
                                                          https://www.surveymonkey.com/r/xrm2tsxGet hashmaliciousUnknownBrowse
                                                          • 108.138.36.106
                                                          8 Hhtm.htmlGet hashmaliciousHTMLPhisherBrowse
                                                          • 52.218.118.41
                                                          Vm4U4HAc98.elfGet hashmaliciousMiraiBrowse
                                                          • 18.238.106.150
                                                          uuCAncltoX.elfGet hashmaliciousMiraiBrowse
                                                          • 54.104.26.113
                                                          427YPKJWie.elfGet hashmaliciousMiraiBrowse
                                                          • 65.3.242.62
                                                          pDtHFbnrHT.elfGet hashmaliciousMiraiBrowse
                                                          • 34.211.14.94
                                                          https://www.svatma.in/Get hashmaliciousUnknownBrowse
                                                          • 35.158.84.222
                                                          http://tink69.com/Get hashmaliciousUnknownBrowse
                                                          • 13.232.151.197
                                                          cutie.arm7.elfGet hashmaliciousMiraiBrowse
                                                          • 54.255.24.89
                                                          MHm4xSPZnZ.elfGet hashmaliciousMiraiBrowse
                                                          • 108.152.25.13
                                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                          3e4e87dda5a3162306609b7e330441d2https://finvestcapital.ca/Get hashmaliciousUnknownBrowse
                                                          • 54.70.175.13
                                                          https://pub-1658c2dd66434dd7b5f48ce167884c7e.r2.dev/index.html#support@ashleymadison.comGet hashmaliciousUnknownBrowse
                                                          • 54.70.175.13
                                                          https://sharedfiles132456-665542.s3.us-east-005.backblazeb2.com/grace.htmlGet hashmaliciousUnknownBrowse
                                                          • 54.70.175.13
                                                          https://ncv.microsoft.com/LB68CYHnI7Get hashmaliciousUnknownBrowse
                                                          • 54.70.175.13
                                                          http://daubinvestments.comGet hashmaliciousUnknownBrowse
                                                          • 54.70.175.13
                                                          https://mtbsign-onlineshelp6232.duckdns.org/Get hashmaliciousUnknownBrowse
                                                          • 54.70.175.13
                                                          https://clothingmemorialadorable.com/xfk47a7yg?key=02661d03f8c3bed95f6dd5fe5d58f347Get hashmaliciousUnknownBrowse
                                                          • 54.70.175.13
                                                          https://trk.klclick3.com/ls/click?upn=ODUWvrrWUUEee10FYhP2wZyPL1bLpxmK7tCWb4Xj1Noy-2F-2Bu0ZUvzWzy588C54QNl6EPf-2FtlYqzO-2FJkqf-2FjkkjhJXLWf5Q-2Bh3bAFwhgyoBKZRylURgGbO-2Fl-2FhbyBLIcM6kcBGS3VJC0dCH8iqTpiv-2BA-3D-3DC_TS_BdoE-2BqcBt692Zq6TFVs-2BIYMNWNao2bfciBVD4n-2F5m-2FzBQafN-2F7-2Bb30sW9-2BzFZMaW-2FLJeG6XW598f6wa-2Fo11l-2BHQQC5ig3nbpcHiAiLC4qo8M7BJH-2F03cOZNeyWMYx0sU6lI0DVg-2B-2BNK9mEASj1W3RH6HbZ9xgEE-2FV3ByC-2FjRioxk8-2FwBZ-2F867xPaQnbyASSD67hoK3iQXHJ3Jh-2F7VIbGFcx6Zr-2BEDbt1-2FQNWkxAShvSmZiu3FbvM8NrUGz63EdoSph70Bw3S915mU18T7xAa8FAnmS7G1NDJnJLYcw9Hiuc6zL4gJ6nwznB2cBoMoKt9fNH-2BGzhiVYtPk3qcCu-2BP8scoYS0uRT5d-2Flgt-2BUGYNIKc9NeNdHghkoytvotQ8p35TvSzKDt0nLjjlQUYFcKRWB6OB5D-2FMLRGYA9ZoGxrLTg-3D#cl/488482_md/10/419673/6491/60323/1797583Get hashmaliciousUnknownBrowse
                                                          • 54.70.175.13
                                                          https://1drv.ms/b/s!AuDWrgYDuxytbac78BbaB6ykfT8Get hashmaliciousUnknownBrowse
                                                          • 54.70.175.13
                                                          https://59zt7n39kiyr6n1exiq2.bxn6.ru/p6R3a9/Get hashmaliciousUnknownBrowse
                                                          • 54.70.175.13
                                                          https://clothingmemorialadorable.com/xfk47a7yg?key=02661d03f8c3bed95f6dd5fe5d58f347Get hashmaliciousUnknownBrowse
                                                          • 54.70.175.13
                                                          https://clothingmemorialadorable.com/xfk47a7yg?Get hashmaliciousUnknownBrowse
                                                          • 54.70.175.13
                                                          http://t.co/C3j7hxRH1i?go1Get hashmaliciousUnknownBrowse
                                                          • 54.70.175.13
                                                          https://tax.taxmatch.pw/index.php?fname=Sonia&Iname=Zamora&address=Dexter%20ct%20woodbridge&city=Harrisburg&state=PA&zip=17101&email=no@email.com&phone=7175747162Get hashmaliciousUnknownBrowse
                                                          • 54.70.175.13
                                                          9FajbP2iUgGet hashmaliciousCloudMensisBrowse
                                                          • 54.70.175.13
                                                          https://rum.edgio.netGet hashmaliciousUnknownBrowse
                                                          • 54.70.175.13
                                                          https://workdrive.zohoexternal.com/file/cy5wr6f6bb22f7def4ca5a9c1783a9c058602Get hashmaliciousUnknownBrowse
                                                          • 54.70.175.13
                                                          Payment_receipt #june_ 4139.htmGet hashmaliciousHTMLPhisherBrowse
                                                          • 54.70.175.13
                                                          https://pub-094517efd3704d3cb6704b960e13b773.r2.dev/indexxe.html#credit-control@itv.comGet hashmaliciousUnknownBrowse
                                                          • 54.70.175.13
                                                          https://autoingress.com.au/lq/?0463582Get hashmaliciousUnknownBrowse
                                                          • 54.70.175.13
                                                          No context
                                                          No created / dropped files found
                                                          File type:Mach-O 64-bit x86_64 executable, flags:<NOUNDEFS|DYLDLINK|TWOLEVEL|PIE>
                                                          Entropy (8bit):6.185759414823282
                                                          TrID:
                                                          • Mac OS X Mach-O 64-bit Intel executable (4008/2) 50.02%
                                                          • Mac OS X Mach-O 64-bit executable (little-endian) (4004/1) 49.98%
                                                          File name:Pipidae.app
                                                          File size:436'592 bytes
                                                          MD5:8881338c77f4285d197fb52229575d64
                                                          SHA1:23eea6ab534cf7aa5e9356660cfa974c3e610bbd
                                                          SHA256:7a1f844ec0aa595b09d4044e99690cf3d3095a3faae5656a7f5b78cc593563f5
                                                          SHA512:93f16cf160b864bb6e98fe029043a0e404901986b22c91afc2a23557071d8807fcbb2be15941f2e9b136fc9dea8a2a81ea0dbcc426c1e5e7e033ba203d3e4115
                                                          SSDEEP:6144:n7V6t+FfwK6yOWq81k3ekY3U2qV4jcxHu72XTqJpqj7+Bdcm:nwcKJtrs64jcxvTOpaNm
                                                          TLSH:F294E7075367D4C1D430DAF80BF94BA10B60DA495597BE8A3091B1347C4BE2BAFF1B6A
                                                          File Content Preview:.......................... .........H...__PAGEZERO..............................................................__TEXT...................@...............@......................__text..........__TEXT..........H...............H..............................
                                                          General Information for header 1
                                                          Endian:little-endian
                                                          Size:64-bit
                                                          Architecture:x86_64
                                                          Filetype:execute
                                                          Nbr. of load commands:22
                                                          Entry point:0x7F7E
                                                          NameValue
                                                          segname__PAGEZERO
                                                          vmaddr0x0
                                                          vmsize0x100000000
                                                          fileoff0x0
                                                          filesize0x0
                                                          maxprot0x0
                                                          initprot0x0
                                                          nsects0
                                                          flags0x0
                                                          NameValue
                                                          segname__TEXT
                                                          vmaddr0x100000000
                                                          vmsize0x54000
                                                          fileoff0x0
                                                          filesize0x54000
                                                          maxprot0x5
                                                          initprot0x5
                                                          nsects9
                                                          flags0x0
                                                          Datas
                                                          sectnamesegnameaddrsizeoffsetentropyalignreloffnrelocflags
                                                          __text__TEXT0x1000018480x500F50x18486.42370x20x000x80000400
                                                          __stubs__TEXT0x10005193E0x22E0x5193E3.45910x10x000x80000408
                                                          __stub_helper__TEXT0x100051B6C0x3B20x51B6C4.45830x20x000x80000400
                                                          __const__TEXT0x100051F200x10680x51F201.82080x40x000x0
                                                          __objc_methname__TEXT0x100052F880xA7C0x52F884.82490x00x000x2
                                                          __cstring__TEXT0x100053A040x3D80x53A045.04090x00x000x2
                                                          __objc_classname__TEXT0x100053DDC0x490x53DDC4.18350x00x000x2
                                                          __objc_methtype__TEXT0x100053E250x360x53E253.43010x00x000x2
                                                          __unwind_info__TEXT0x100053E5C0x19C0x53E5C5.07440x20x000x0
                                                          NameValue
                                                          segname__DATA
                                                          vmaddr0x100054000
                                                          vmsize0x14000
                                                          fileoff0x54000
                                                          filesize0x14000
                                                          maxprot0x3
                                                          initprot0x3
                                                          nsects14
                                                          flags0x0
                                                          Datas
                                                          sectnamesegnameaddrsizeoffsetentropyalignreloffnrelocflags
                                                          __nl_symbol_ptr__DATA0x1000540000x80x54000-0.00000x30x000x6
                                                          __got__DATA0x1000540080xB80x54008-0.00000x30x000x6
                                                          __la_symbol_ptr__DATA0x1000540C00x2E80x540C03.05880x30x000x7
                                                          __const__DATA0x1000543A80x2000x543A81.82080x30x000x0
                                                          __objc_nlclslist__DATA0x1000545A80x80x545A82.00000x30x000x10000000
                                                          __objc_protolist__DATA0x1000545B00x100x545B02.12500x30x000x0
                                                          __objc_imageinfo__DATA0x1000545C00x80x545C00.54360x20x000x0
                                                          __objc_const__DATA0x1000545C80x1400x545C81.81190x30x000x0
                                                          __objc_selrefs__DATA0x1000547080x4780x547083.23170x30x000x10000005
                                                          __objc_protorefs__DATA0x100054B800x100x54B802.12500x30x000x0
                                                          __objc_classrefs__DATA0x100054B900xD00x54B90-0.00000x30x000x10000000
                                                          __objc_data__DATA0x100054C600x500x54C601.51710x30x000x0
                                                          __data__DATA0x100054CB00x107680x54CB05.08500x40x000x0
                                                          __bss__DATA0x1000654200x3600x00.00000x40x000x1
                                                          NameValue
                                                          segname__LINKEDIT
                                                          vmaddr0x100068000
                                                          vmsize0x2970
                                                          fileoff0x68000
                                                          filesize0x2970
                                                          maxprot0x1
                                                          initprot0x1
                                                          nsects0
                                                          flags0x0
                                                          NameValue
                                                          rebase_off425984
                                                          rebase_size256
                                                          bind_off426240
                                                          bind_size1672
                                                          weak_bind_off0
                                                          weak_bind_size0
                                                          lazy_bind_off427912
                                                          lazy_bind_size2400
                                                          export_off430312
                                                          export_size32
                                                          NameValue
                                                          symoff430576
                                                          nsyms142
                                                          stroff433688
                                                          strsize2904
                                                          NameValue
                                                          ilocalsym0
                                                          nlocalsym1
                                                          iextdefsym1
                                                          nextdefsym1
                                                          iundefsym2
                                                          nundefsym140
                                                          tocoff0
                                                          ntoc0
                                                          modtaboff0
                                                          nmodtab0
                                                          extrefsymoff0
                                                          nextrefsyms0
                                                          indirectsymoff432848
                                                          nindirectsyms210
                                                          extreloff0
                                                          nextrel0
                                                          locreloff0
                                                          nlocrel0
                                                          NameValue
                                                          name12
                                                          Datas/usr/lib/dyld
                                                          NameValue
                                                          uuidb'k\xa4>\xe4\xc3\x19=z\xacC{b\xf6\x83Mw'
                                                          NameValue
                                                          version657920
                                                          sdk852224
                                                          NameValue
                                                          version0
                                                          NameValue
                                                          entryoff32638
                                                          stacksize0
                                                          NameValue
                                                          name24
                                                          timestampThu Jan 1 01:00:02 1970
                                                          current_version1953.255.0
                                                          compatibility_version300.0.0
                                                          Datas/System/Library/Frameworks/Foundation.framework/Versions/C/Foundation
                                                          NameValue
                                                          name24
                                                          timestampThu Jan 1 01:00:02 1970
                                                          current_version228.0.0
                                                          compatibility_version1.0.0
                                                          Datas/usr/lib/libobjc.A.dylib
                                                          NameValue
                                                          name24
                                                          timestampThu Jan 1 01:00:02 1970
                                                          current_version1319.0.0
                                                          compatibility_version1.0.0
                                                          Datas/usr/lib/libSystem.B.dylib
                                                          NameValue
                                                          name24
                                                          timestampThu Jan 1 01:00:02 1970
                                                          current_version2299.30.112
                                                          compatibility_version45.0.0
                                                          Datas/System/Library/Frameworks/AppKit.framework/Versions/C/AppKit
                                                          NameValue
                                                          name24
                                                          timestampThu Jan 1 01:00:02 1970
                                                          current_version1953.255.0
                                                          compatibility_version150.0.0
                                                          Datas/System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation
                                                          NameValue
                                                          name24
                                                          timestampThu Jan 1 01:00:02 1970
                                                          current_version275.0.0
                                                          compatibility_version1.0.0
                                                          Datas/System/Library/Frameworks/IOKit.framework/Versions/A/IOKit
                                                          NameValue
                                                          name24
                                                          timestampThu Jan 1 01:00:02 1970
                                                          current_version1241.60.3
                                                          compatibility_version1.0.0
                                                          Datas/System/Library/Frameworks/SystemConfiguration.framework/Versions/A/SystemConfiguration
                                                          NameValue
                                                          path12
                                                          Datas@executable_path/../Frameworks
                                                          NameValue
                                                          dataoff430344
                                                          datasize224
                                                          NameValue
                                                          dataoff430568
                                                          datasize8
                                                          _CCCryptorCreate
                                                          _CCCryptorFinal
                                                          _CCCryptorGetOutputLength
                                                          _CCCryptorRelease
                                                          _CCCryptorUpdate
                                                          _CCHmacFinal
                                                          _CCHmacInit
                                                          _CCHmacUpdate
                                                          _CCKeyDerivationPBKDF
                                                          _CC_MD5
                                                          _CFDataGetTypeID
                                                          _CFDictionaryGetCount
                                                          _CFDictionaryGetKeysAndValues
                                                          _CFGetTypeID
                                                          _CFRelease
                                                          _CFStringGetCStringPtr
                                                          _CFStringGetTypeID
                                                          _IOIteratorNext
                                                          _IOObjectRelease
                                                          _IORegistryEntryCreateCFProperties
                                                          _IORegistryEntryCreateCFProperty
                                                          _IORegistryEntryGetChildIterator
                                                          _IORegistryGetRootEntry
                                                          _IOServiceGetMatchingService
                                                          _IOServiceMatching
                                                          _NSSetUncaughtExceptionHandler
                                                          _NSTemporaryDirectory
                                                          _OBJC_CLASS_$_NSArray
                                                          _OBJC_CLASS_$_NSBundle
                                                          _OBJC_CLASS_$_NSCharacterSet
                                                          _OBJC_CLASS_$_NSData
                                                          _OBJC_CLASS_$_NSDictionary
                                                          _OBJC_CLASS_$_NSFileHandle
                                                          _OBJC_CLASS_$_NSFileManager
                                                          _OBJC_CLASS_$_NSJSONSerialization
                                                          _OBJC_CLASS_$_NSMutableArray
                                                          _OBJC_CLASS_$_NSMutableData
                                                          _OBJC_CLASS_$_NSMutableString
                                                          _OBJC_CLASS_$_NSMutableURLRequest
                                                          _OBJC_CLASS_$_NSNumber
                                                          _OBJC_CLASS_$_NSPipe
                                                          _OBJC_CLASS_$_NSPredicate
                                                          _OBJC_CLASS_$_NSProcessInfo
                                                          _OBJC_CLASS_$_NSRunLoop
                                                          _OBJC_CLASS_$_NSString
                                                          _OBJC_CLASS_$_NSTask
                                                          _OBJC_CLASS_$_NSThread
                                                          _OBJC_CLASS_$_NSURL
                                                          _OBJC_CLASS_$_NSURLComponents
                                                          _OBJC_CLASS_$_NSURLQueryItem
                                                          _OBJC_CLASS_$_NSURLSession
                                                          _OBJC_CLASS_$_NSUUID
                                                          _OBJC_CLASS_$_NSWorkspace
                                                          __Block_copy
                                                          __Block_object_assign
                                                          __DefaultRuneLocale
                                                          __NSConcreteGlobalBlock
                                                          __NSConcreteStackBlock
                                                          ___CFConstantStringClassReference
                                                          ___bzero
                                                          ___stack_chk_fail
                                                          ___stack_chk_guard
                                                          __dyld_register_func_for_add_image
                                                          __mh_execute_header
                                                          __objc_empty_cache
                                                          __objc_empty_vtable
                                                          _abort
                                                          _asprintf
                                                          _bzero
                                                          _calloc
                                                          _class_addMethod
                                                          _class_addProperty
                                                          _class_addProtocol
                                                          _class_getInstanceMethod
                                                          _class_getInstanceSize
                                                          _class_getInstanceVariable
                                                          _class_getIvarLayout
                                                          _class_getName
                                                          _class_getSuperclass
                                                          _class_isMetaClass
                                                          _class_replaceMethod
                                                          _class_respondsToSelector
                                                          _dispatch_async
                                                          _dispatch_get_global_queue
                                                          _dlopen
                                                          _dlsym
                                                          _exit
                                                          _free
                                                          _hash_create
                                                          _hash_search
                                                          _ivar_getName
                                                          _ivar_getOffset
                                                          _kCFAllocatorDefault
                                                          _kCFCoreFoundationVersionNumber
                                                          _kIOMasterPortDefault
                                                          _malloc
                                                          _memcpy
                                                          _method_setImplementation
                                                          _objc_alloc
                                                          _objc_allocateClassPair
                                                          _objc_autorelease
                                                          _objc_autoreleasePoolPop
                                                          _objc_autoreleasePoolPush
                                                          _objc_autoreleaseReturnValue
                                                          _objc_constructInstance
                                                          _objc_copyClassNamesForImage
                                                          _objc_enumerationMutation
                                                          _objc_getClass
                                                          _objc_getMetaClass
                                                          _objc_getProtocol
                                                          _objc_getRequiredClass
                                                          _objc_initializeClassPair
                                                          _objc_loadClassref
                                                          _objc_lookUpClass
                                                          _objc_msgSend
                                                          _objc_msgSend_stret
                                                          _objc_readClassPair
                                                          _objc_registerClassPair
                                                          _objc_release
                                                          _objc_retain
                                                          _objc_retainAutorelease
                                                          _objc_retainAutoreleaseReturnValue
                                                          _objc_retainAutoreleasedReturnValue
                                                          _objc_retainBlock
                                                          _object_getClass
                                                          _object_getIndexedIvars
                                                          _object_getIvar
                                                          _object_setIvar
                                                          _property_copyAttributeList
                                                          _protocol_getMethodDescription
                                                          _protocol_getName
                                                          _pthread_mutex_lock
                                                          _pthread_mutex_unlock
                                                          _sel_getUid
                                                          _signal
                                                          _strcmp
                                                          _strlen
                                                          _strncmp
                                                          _sysctl
                                                          _sysctlbyname
                                                          dyld_stub_binder
                                                          radr://5614542
                                                          _CCCryptorCreate
                                                          _CCCryptorFinal
                                                          _CCCryptorGetOutputLength
                                                          _CCCryptorRelease
                                                          _CCCryptorUpdate
                                                          _CCHmacFinal
                                                          _CCHmacInit
                                                          _CCHmacUpdate
                                                          _CCKeyDerivationPBKDF
                                                          _CC_MD5
                                                          _CFDataGetTypeID
                                                          _CFDictionaryGetCount
                                                          _CFDictionaryGetKeysAndValues
                                                          _CFGetTypeID
                                                          _CFRelease
                                                          _CFStringGetCStringPtr
                                                          _CFStringGetTypeID
                                                          _IOIteratorNext
                                                          _IOObjectRelease
                                                          _IORegistryEntryCreateCFProperties
                                                          _IORegistryEntryCreateCFProperty
                                                          _IORegistryEntryGetChildIterator
                                                          _IORegistryGetRootEntry
                                                          _IOServiceGetMatchingService
                                                          _IOServiceMatching
                                                          _NSSetUncaughtExceptionHandler
                                                          _NSTemporaryDirectory
                                                          __Block_copy
                                                          __Block_object_assign
                                                          ___bzero
                                                          ___stack_chk_fail
                                                          __dyld_register_func_for_add_image
                                                          _abort
                                                          _asprintf
                                                          _bzero
                                                          _calloc
                                                          _class_addMethod
                                                          _class_addProperty
                                                          _class_addProtocol
                                                          _class_getInstanceMethod
                                                          _class_getInstanceSize
                                                          _class_getInstanceVariable
                                                          _class_getIvarLayout
                                                          _class_getSuperclass
                                                          _class_isMetaClass
                                                          _class_replaceMethod
                                                          _class_respondsToSelector
                                                          _dispatch_async
                                                          _dispatch_get_global_queue
                                                          _dlopen
                                                          _dlsym
                                                          _exit
                                                          _free
                                                          _hash_create
                                                          _hash_search
                                                          _ivar_getName
                                                          _ivar_getOffset
                                                          _malloc
                                                          _memcpy
                                                          _method_setImplementation
                                                          _objc_alloc
                                                          _objc_autorelease
                                                          _objc_autoreleasePoolPop
                                                          _objc_autoreleasePoolPush
                                                          _objc_autoreleaseReturnValue
                                                          _objc_constructInstance
                                                          _objc_enumerationMutation
                                                          _objc_getClass
                                                          _objc_getMetaClass
                                                          _objc_getProtocol
                                                          _objc_getRequiredClass
                                                          _objc_initializeClassPair
                                                          _objc_lookUpClass
                                                          _objc_msgSend_stret
                                                          _objc_registerClassPair
                                                          _objc_retainAutorelease
                                                          _objc_retainAutoreleaseReturnValue
                                                          _objc_retainAutoreleasedReturnValue
                                                          _objc_retainBlock
                                                          _object_getClass
                                                          _object_getIvar
                                                          _object_setIvar
                                                          _property_copyAttributeList
                                                          _protocol_getMethodDescription
                                                          _pthread_mutex_lock
                                                          _pthread_mutex_unlock
                                                          _sel_getUid
                                                          _signal
                                                          _strcmp
                                                          _strlen
                                                          _strncmp
                                                          _sysctl
                                                          _sysctlbyname
                                                          TimestampSource PortDest PortSource IPDest IP
                                                          Aug 21, 2023 15:43:51.275496960 CEST49304443192.168.11.1154.70.175.13
                                                          Aug 21, 2023 15:43:51.275573015 CEST4434930454.70.175.13192.168.11.11
                                                          Aug 21, 2023 15:43:51.276235104 CEST49304443192.168.11.1154.70.175.13
                                                          Aug 21, 2023 15:43:51.276993036 CEST49304443192.168.11.1154.70.175.13
                                                          Aug 21, 2023 15:43:51.277030945 CEST4434930454.70.175.13192.168.11.11
                                                          Aug 21, 2023 15:43:51.868381023 CEST4434930454.70.175.13192.168.11.11
                                                          Aug 21, 2023 15:43:51.869110107 CEST49304443192.168.11.1154.70.175.13
                                                          Aug 21, 2023 15:43:51.869235992 CEST49304443192.168.11.1154.70.175.13
                                                          Aug 21, 2023 15:43:51.911729097 CEST49304443192.168.11.1154.70.175.13
                                                          Aug 21, 2023 15:43:51.911818981 CEST4434930454.70.175.13192.168.11.11
                                                          Aug 21, 2023 15:43:51.913033009 CEST4434930454.70.175.13192.168.11.11
                                                          Aug 21, 2023 15:43:51.913559914 CEST49304443192.168.11.1154.70.175.13
                                                          Aug 21, 2023 15:43:51.917047977 CEST49304443192.168.11.1154.70.175.13
                                                          Aug 21, 2023 15:43:51.920885086 CEST49304443192.168.11.1154.70.175.13
                                                          Aug 21, 2023 15:43:51.921049118 CEST4434930454.70.175.13192.168.11.11
                                                          Aug 21, 2023 15:43:52.321096897 CEST4434930454.70.175.13192.168.11.11
                                                          Aug 21, 2023 15:43:52.321501970 CEST4434930454.70.175.13192.168.11.11
                                                          Aug 21, 2023 15:43:52.322710037 CEST49304443192.168.11.1154.70.175.13
                                                          Aug 21, 2023 15:43:52.322990894 CEST49304443192.168.11.1154.70.175.13
                                                          Aug 21, 2023 15:43:52.324465036 CEST49304443192.168.11.1154.70.175.13
                                                          Aug 21, 2023 15:43:52.324526072 CEST4434930454.70.175.13192.168.11.11
                                                          Aug 21, 2023 15:44:12.088114977 CEST4929580192.168.11.1117.253.15.208
                                                          Aug 21, 2023 15:44:12.088501930 CEST4929680192.168.11.112.23.196.201
                                                          Aug 21, 2023 15:44:12.096960068 CEST804929517.253.15.208192.168.11.11
                                                          Aug 21, 2023 15:44:12.097316027 CEST80492962.23.196.201192.168.11.11
                                                          Aug 21, 2023 15:44:12.098865032 CEST4929580192.168.11.1117.253.15.208
                                                          Aug 21, 2023 15:44:12.099056959 CEST4929680192.168.11.112.23.196.201
                                                          TimestampSource PortDest PortSource IPDest IP
                                                          Aug 21, 2023 15:43:51.231131077 CEST5580453192.168.11.111.1.1.1
                                                          Aug 21, 2023 15:43:51.270880938 CEST53558041.1.1.1192.168.11.11
                                                          Aug 21, 2023 15:44:02.316143990 CEST137137192.168.11.11192.168.11.255
                                                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                          Aug 21, 2023 15:43:51.231131077 CEST192.168.11.111.1.1.10x8724Standard query (0)www.ipahufm.icuA (IP address)IN (0x0001)false
                                                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                          Aug 21, 2023 15:43:51.270880938 CEST1.1.1.1192.168.11.110x8724No error (0)www.ipahufm.icusearchlb-3b453017ec33bbb9.elb.us-west-2.amazonaws.comCNAME (Canonical name)IN (0x0001)false
                                                          Aug 21, 2023 15:43:51.270880938 CEST1.1.1.1192.168.11.110x8724No error (0)searchlb-3b453017ec33bbb9.elb.us-west-2.amazonaws.com54.70.175.13A (IP address)IN (0x0001)false
                                                          • www.ipahufm.icu
                                                          Session IDSource IPSource PortDestination IPDestination Port
                                                          0192.168.11.114930454.70.175.13443
                                                          TimestampkBytes transferredDirectionData
                                                          2023-08-21 13:43:51 UTC0OUTPOST /se/cu HTTP/1.1
                                                          Host: www.ipahufm.icu
                                                          Content-Type: application/json
                                                          Connection: keep-alive
                                                          Accept: */*
                                                          User-Agent: Pipidae.app (unknown version) CFNetwork/893.13.1 Darwin/17.3.0 (x86_64)
                                                          Content-Length: 42
                                                          Accept-Language: en-us
                                                          Accept-Encoding: br, gzip, deflate
                                                          2023-08-21 13:43:51 UTC0OUTData Raw: 7b 22 6d 69 64 22 3a 22 31 36 64 33 30 36 39 63 62 36 37 64 36 64 38 32 31 64 30 30 32 64 64 66 62 66 30 36 36 39 32 32 22 7d
                                                          Data Ascii: {"mid":"16d3069cb67d6d821d002ddfbf066922"}
                                                          2023-08-21 13:43:52 UTC0INHTTP/1.1 200 OK
                                                          Server: nginx/1.10.3 (Ubuntu)
                                                          Date: Mon, 21 Aug 2023 13:43:52 GMT
                                                          Content-Type: text/html; charset=utf-8
                                                          Content-Length: 1
                                                          Connection: close
                                                          2023-08-21 13:43:52 UTC0INData Raw: 30
                                                          Data Ascii: 0


                                                          System Behavior

                                                          Start time:15:43:50
                                                          Start date:21/08/2023
                                                          Path:/Library/Frameworks/Mono.framework/Versions/4.4.2/bin/mono-sgen32
                                                          Arguments:-
                                                          File size:3722408 bytes
                                                          MD5 hash:8910349f44a940d8d79318367855b236
                                                          Start time:15:43:50
                                                          Start date:21/08/2023
                                                          Path:/Users/berri/Desktop/Pipidae.app
                                                          Arguments:/Users/berri/Desktop/Pipidae.app
                                                          File size:436592 bytes
                                                          MD5 hash:8881338c77f4285d197fb52229575d64