Edit tour

macOS Analysis Report
palera1n-macos-arm64

Overview

General Information

Sample Name:palera1n-macos-arm64
Analysis ID:1335881
MD5:0ae3f4d1ea920ae68d9dde33afed3d96
SHA1:9ea6b47044857ab4a15baa85fa33cd25bef165ef
SHA256:55101f72fe65d0d7707ed4b1b8340ad2e7bedf061cd46feff05361308422e02b
Infos:
Errors
  • No process behavior to analyse as no analysis process or sample was found

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Mach-O contains sections with high entropy indicating compressed/encrypted content
Contains symbols with suspicious names likely related to networking

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious

Analysis Advice

Exit code suggests that the sample could not be started, try to look at standard streams or writes to anonymous pipes for possible reason.
Mach-O sample file can only execute on ARM64 Apple Silicon.
Non-zero exit code suggests an error during the execution. Lookup the error code for hints.
Joe Sandbox Version:38.0.0 Ammolite
Analysis ID:1335881
Start date and time:2023-11-02 09:36:10 +01:00
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 3m 44s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultmacfilecookbook.jbs
Analysis system description:Virtual Machine, High Sierra (Office 2016 16.16, Java 11.0.2+9, Adobe Reader 2019.010.20099)
macOS major version:10.13
CPU architecture:x86_64
Analysis Mode:default
Sample file name:palera1n-macos-arm64
Detection:MAL
Classification:mal48.mac@0/0@0/0
  • No process behavior to analyse as no analysis process or sample was found
  • Excluded IPs from analysis (whitelisted): 17.253.13.204, 17.253.13.201, 23.213.225.112, 17.253.13.205, 17.253.13.207, 17.253.13.206
  • Excluded domains from analysis (whitelisted): cds-cdn.v.aaplimg.com, e11408.d.akamaiedge.net, cds.apple.com.akadns.net, ocsp-a.g.aaplimg.com, cds.apple.com, help-ar.apple.com.edgekey.net, valid.apple.com, lb._dns-sd._udp.0.11.168.192.in-addr.arpa, ocsp-lb.apple.com.akadns.net, ocsp.apple.com, valid.origin-apple.com.akadns.net, help.origin-apple.com.akadns.net, valid-apple.g.aaplimg.com, help.apple.com, world-gen.g.aaplimg.com
Command:/Users/berri/Desktop/palera1n-macos-arm64
PID:897
Exit Code:255
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
No yara matches
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: palera1n-macos-arm64Virustotal: Detection: 8%Perma Link
Source: submission: palera1n-macos-arm64Mach-O symbol: _send
Source: submission: palera1n-macos-arm64Mach-O symbol: _setsockopt
Source: submission: palera1n-macos-arm64Mach-O symbol: _connect
Source: submission: palera1n-macos-arm64Mach-O symbol: _socket
Source: submission: palera1n-macos-arm64Mach-O symbol: _getsockopt
Source: submission: palera1n-macos-arm64Mach-O symbol: _kIOMasterPortDefault
Source: submission: palera1n-macos-arm64Mach-O symbol: _IONotificationPortGetRunLoopSource
Source: submission: palera1n-macos-arm64Mach-O symbol: _IONotificationPortCreate
Source: palera1n-macos-arm64String found in binary or memory: http://www.apple.com/DTDs/PropertyList-1.0.dtd
Source: palera1n-macos-arm64String found in binary or memory: https://checkra.in
Source: palera1n-macos-arm64String found in binary or memory: https://checkra.in#====
Source: palera1n-macos-arm64String found in binary or memory: https://checkra.infirmware-versionBooted
Source: palera1n-macos-arm64String found in binary or memory: https://ellekit.space/
Source: palera1n-macos-arm64String found in binary or memory: https://repo.palera.in/
Source: palera1n-macos-arm64String found in binary or memory: https://strap.palera.in/
Source: unknownTCP traffic detected without corresponding DNS query: 17.253.13.202
Source: unknownTCP traffic detected without corresponding DNS query: 23.45.32.198
Source: unknownTCP traffic detected without corresponding DNS query: 17.253.13.202
Source: unknownTCP traffic detected without corresponding DNS query: 23.45.32.198
Source: classification engineClassification label: mal48.mac@0/0@0/0
Source: submissionMach-O header: Mach-O 64-bit arm64 executable, flags:<NOUNDEFS|DYLDLINK|TWOLEVEL|PIE>
Source: submission: palera1n-macos-arm64Mach-O header: dylib_command -> /System/Library/Frameworks/IOKit.framework/Versions/A/IOKit
Source: submissionCodeSign Info: Executable=/Users/berri/Desktop/palera1n-macos-arm64
Source: palera1n-macos-arm64Submission file: section __data with 7.2381 entropy (max. 8.0)
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Invalid Code Signature
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network MediumData ObfuscationEavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Code Signing
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothJunk DataExploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)1
Obfuscated Files or Information
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Shell
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1335881 Sample: palera1n-macos-arm64 Startdate: 02/11/2023 Architecture: MAC Score: 48 6 23.45.32.198, 49376, 80 AKAMAI-ASUS United States 2->6 8 Multi AV Scanner detection for submitted file 2->8 signatures3

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


cam-macmac-stand
SourceDetectionScannerLabelLink
palera1n-macos-arm648%VirustotalBrowse
palera1n-macos-arm648%ReversingLabsMacOS.PUA.Jailbreak
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
https://checkra.inpalera1n-macos-arm64false
    unknown
    https://checkra.in#====palera1n-macos-arm64false
      unknown
      https://repo.palera.in/palera1n-macos-arm64false
        unknown
        https://strap.palera.in/palera1n-macos-arm64false
          unknown
          https://ellekit.space/palera1n-macos-arm64false
            unknown
            https://checkra.infirmware-versionBootedpalera1n-macos-arm64false
              unknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              23.45.32.198
              unknownUnited States
              16625AKAMAI-ASUSfalse
              No context
              No context
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              AKAMAI-ASUSskid.x86_64.elfGet hashmaliciousMirai, MoobotBrowse
              • 96.7.64.170
              file.exeGet hashmaliciousGlupteba, SmokeLoader, Vidar, zgRATBrowse
              • 23.36.118.84
              file.exeGet hashmaliciousAmadey, Glupteba, SmokeLoaderBrowse
              • 2.17.5.164
              tW89v9x9F4.elfGet hashmaliciousMiraiBrowse
              • 104.92.20.179
              https://t.ly/mV-Qq#M=SmFuLVBldGVyLkhlaXNlQG5vcnRvbnJvc2VmdWxicmlnaHQuY29tGet hashmaliciousHTMLPhisherBrowse
              • 104.106.162.18
              https://acrobat.adobe.com/id/urn:aaid:sc:US:b1c915de-7158-4dd9-aa63-db461c226178Get hashmaliciousHTMLPhisherBrowse
              • 23.212.249.86
              file.exeGet hashmaliciousAmadey, Babadeda, Mystic Stealer, Raccoon Stealer v2, RedLine, SmokeLoader, zgRATBrowse
              • 23.50.124.114
              db0fa4b8db0333367e9bda3ab68b8042.x86.elfGet hashmaliciousMiraiBrowse
              • 184.50.149.118
              eOIFF58KfU.elfGet hashmaliciousUnknownBrowse
              • 104.76.15.38
              https://indd.adobe.com/view/73bb3547-7519-45db-b904-9b659611f483Get hashmaliciousHTMLPhisherBrowse
              • 23.52.160.23
              file.exeGet hashmaliciousAmadey, Babadeda, Mystic Stealer, Raccoon Stealer v2, RedLine, SmokeLoader, zgRATBrowse
              • 23.55.204.114
              file.exeGet hashmaliciousAmadey, Babadeda, Mystic Stealer, Raccoon Stealer v2, RedLine, SmokeLoader, XmrigBrowse
              • 23.50.124.114
              file.exeGet hashmaliciousAmadey, Babadeda, Mystic Stealer, Raccoon Stealer v2, RedLine, SmokeLoader, zgRATBrowse
              • 23.55.204.114
              sDZf1h3xl6.elfGet hashmaliciousMiraiBrowse
              • 23.65.239.76
              ePqNFTeLyU.exeGet hashmaliciousAmadey, Babadeda, Mystic Stealer, RedLine, SmokeLoader, zgRATBrowse
              • 23.50.124.114
              24zU4pepXX.exeGet hashmaliciousAmadey, Babadeda, Glupteba, Mystic Stealer, Raccoon Stealer v2, RedLine, SmokeLoaderBrowse
              • 23.220.124.106
              BL.xlsGet hashmaliciousUnknownBrowse
              • 23.50.124.134
              file.exeGet hashmaliciousAmadey, Babadeda, Mystic Stealer, Raccoon Stealer v2, RedLine, SmokeLoader, XmrigBrowse
              • 23.50.124.114
              7CS0Vo57.exeGet hashmaliciousBabadedaBrowse
              • 23.50.124.114
              file.exeGet hashmaliciousGlupteba, SmokeLoader, VidarBrowse
              • 23.40.18.82
              No context
              No context
              No created / dropped files found
              File type:Mach-O 64-bit arm64 executable, flags:<NOUNDEFS|DYLDLINK|TWOLEVEL|PIE>
              Entropy (8bit):7.197670595515602
              TrID:
              • Mac OS X Mach-O 64-bit ARM executable (little-endian) (4008/2) 50.02%
              • Mac OS X Mach-O 64-bit executable (little-endian) (4004/1) 49.98%
              File name:palera1n-macos-arm64
              File size:4'890'544 bytes
              MD5:0ae3f4d1ea920ae68d9dde33afed3d96
              SHA1:9ea6b47044857ab4a15baa85fa33cd25bef165ef
              SHA256:55101f72fe65d0d7707ed4b1b8340ad2e7bedf061cd46feff05361308422e02b
              SHA512:9cc612ae9347ea5b4d080a95f4176c7e4b08fa43119660e4f4ce68193a99579fa36f570a57a3c289e4c7561bfc91b2b6ced2e97fdb14a5c38c18c4591eab0a10
              SSDEEP:98304:Ng6mTdfylkLXLjy+Iq6+pCF5s2Pd+CifyBFmSx:u3dfylkmw6+y5s2F+vK
              TLSH:05360291EE1C2D11D2C2E1BEC9054B90523FF4B18766C3A97561A23DEECA7E0317A763
              File Content Preview:.......................... .........H...__PAGEZERO..........................................................x...__TEXT...................@...............@......................__text..........__TEXT..........45..............45.............................
              [
                  "Executable=/Users/berri/Desktop/palera1n-macos-arm64",
                  "Identifier=palera1n-macosx-arm64",
                  "Format=Mach-O thin (arm64)",
                  "CodeDirectory v=20400 size=37902 flags=0x0(none) hashes=1179+2 location=embedded",
                  "Hash type=sha256 size=32",
                  "CandidateCDHash sha1=0d9c7e67a13cf0d493cd8ac8c44649b755b73025",
                  "CandidateCDHash sha256=d402f1fe583a994e53e6470004257d463bb4fde1",
                  "Hash choices=sha1,sha256",
                  "Executable Segment base=0",
                  "Executable Segment limit=475136",
                  "Executable Segment flags=0x1",
                  "Page size=4096",
                  "CDHash=d402f1fe583a994e53e6470004257d463bb4fde1",
                  "/Users/berri/Desktop/palera1n-macos-arm64: no signature",
                  "Info.plist=not bound",
                  "TeamIdentifier=not set",
                  "Sealed Resources=none",
                  "Internal requirements count=1 size=140"
              ]
              General Information for header 1
              Endian:little-endian
              Size:64-bit
              Architecture:arm64
              Filetype:execute
              Nbr. of load commands:19
              Entry point:0x353C
              NameValue
              segname__PAGEZERO
              vmaddr0x0
              vmsize0x100000000
              fileoff0x0
              filesize0x0
              maxprot0x0
              initprot0x0
              nsects0
              flags0x0
              NameValue
              segname__TEXT
              vmaddr0x100000000
              vmsize0x74000
              fileoff0x0
              filesize0x74000
              maxprot0x5
              initprot0x5
              nsects7
              flags0x0
              Datas
              sectnamesegnameaddrsizeoffsetentropyalignreloffnrelocflags
              __text__TEXT0x1000035340x5CCEC0x35346.78030x20x000x80000400
              __stubs__TEXT0x1000602200x69C0x602204.01520x20x000x80000408
              __stub_helper__TEXT0x1000608BC0x6B40x608BC4.19610x20x000x80000400
              __const__TEXT0x100060F700x86000x60F702.37410x40x000x0
              __cstring__TEXT0x1000695700xA40D0x695705.63990x00x000x2
              __ustring__TEXT0x10007397E0x1E0x7397E3.35590x10x000x0
              __unwind_info__TEXT0x10007399C0x6580x7399C5.79930x20x000x0
              NameValue
              segname__DATA_CONST
              vmaddr0x100074000
              vmsize0xC000
              fileoff0x74000
              filesize0xC000
              maxprot0x3
              initprot0x3
              nsects4
              flags0x10
              Datas
              sectnamesegnameaddrsizeoffsetentropyalignreloffnrelocflags
              __got__DATA_CONST0x1000740000x800x74000-0.00000x30x000x6
              __mod_init_func__DATA_CONST0x1000740800x300x740802.37520x30x000x9
              __const__DATA_CONST0x1000740B00x85800x740B02.37410x30x000x0
              __cfstring__DATA_CONST0x10007C6300xE00x7C6301.59270x30x000x0
              NameValue
              segname__DATA
              vmaddr0x100080000
              vmsize0x418000
              fileoff0x80000
              filesize0x418000
              maxprot0x3
              initprot0x3
              nsects3
              flags0x0
              Datas
              sectnamesegnameaddrsizeoffsetentropyalignreloffnrelocflags
              __la_symbol_ptr__DATA0x1000800000x4680x800003.07570x30x000x7
              __data__DATA0x1000804680x414B580x804687.23810x30x000x0
              __bss__DATA0x100494FC00x7300x00.00000x40x000x1
              NameValue
              segname__LINKEDIT
              vmaddr0x100498000
              vmsize0x14000
              fileoff0x498000
              filesize0x11FB0
              maxprot0x1
              initprot0x1
              nsects0
              flags0x0
              NameValue
              rebase_off4816896
              rebase_size1800
              bind_off4818696
              bind_size400
              weak_bind_off0
              weak_bind_size0
              lazy_bind_off4819096
              lazy_bind_size2800
              export_off4821896
              export_size48
              NameValue
              symoff4822800
              nsyms159
              stroff4826536
              strsize2176
              NameValue
              ilocalsym0
              nlocalsym1
              iextdefsym1
              nextdefsym1
              iundefsym2
              nundefsym157
              tocoff0
              ntoc0
              modtaboff0
              nmodtab0
              extrefsymoff0
              nextrefsyms0
              indirectsymoff4825344
              nindirectsyms298
              extreloff0
              nextrel0
              locreloff0
              nlocrel0
              NameValue
              name12
              Datas/usr/lib/dyld
              NameValue
              uuidb'9\xe7UQ\xfe\xc95\xfd\x80\xa8;\xdd\x1c\xa3\xfe\x03'
              NameValue
              platform1
              minos720896
              sdk852224
              ntools1
              Datas.
              NameValue
              version0
              NameValue
              entryoff13628
              stacksize0
              NameValue
              name24
              timestampThu Jan 1 01:00:02 1970
              current_version1319.0.0
              compatibility_version1.0.0
              Datas/usr/lib/libSystem.B.dylib
              NameValue
              name24
              timestampThu Jan 1 01:00:02 1970
              current_version1953.255.0
              compatibility_version150.0.0
              Datas/System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation
              NameValue
              name24
              timestampThu Jan 1 01:00:02 1970
              current_version275.0.0
              compatibility_version1.0.0
              Datas/System/Library/Frameworks/IOKit.framework/Versions/A/IOKit
              NameValue
              dataoff4821944
              datasize856
              NameValue
              dataoff4822800
              datasize0
              NameValue
              dataoff4828720
              datasize61824
              _CFDictionaryCreate
              _CFDictionarySetValue
              _CFNumberCreate
              _CFNumberGetValue
              _CFRelease
              _CFRetain
              _CFRunLoopAddSource
              _CFRunLoopGetCurrent
              _CFRunLoopRun
              _CFRunLoopStop
              _CFStringCreateWithFormat
              _CFStringFind
              _CFStringGetCString
              _CFUUIDGetConstantUUIDWithBytes
              _CFUUIDGetUUIDBytes
              _IOCreatePlugInInterfaceForService
              _IODestroyPlugInInterface
              _IOIteratorNext
              _IONotificationPortCreate
              _IONotificationPortGetRunLoopSource
              _IOObjectRelease
              _IORegistryEntryCreateCFProperty
              _IORegistryEntryGetRegistryEntryID
              _IOServiceAddMatchingNotification
              _IOServiceGetMatchingServices
              _IOServiceMatching
              __DefaultRuneLocale
              __NSGetExecutablePath
              ___CFConstantStringClassReference
              ___assert_rtn
              ___chkstk_darwin
              ___cxa_atexit
              ___darwin_check_fd_set_overflow
              ___error
              ___exp10
              ___memcpy_chk
              ___memset_chk
              ___sprintf_chk
              ___stack_chk_fail
              ___stack_chk_guard
              ___stderrp
              ___stdoutp
              ___strncat_chk
              ___strncpy_chk
              ___udivti3
              __mh_execute_header
              _access
              _asprintf
              _atof
              _bzero
              _calloc
              _chmod
              _close
              _connect
              _environ
              _exit
              _fclose
              _fcntl
              _fflush
              _fopen
              _fprintf
              _fputc
              _fread
              _free
              _freeaddrinfo
              _freeifaddrs
              _fstat
              _fwrite
              _gai_strerror
              _getaddrinfo
              _getchar
              _getenv
              _getifaddrs
              _getopt_long
              _getprogname
              _getsockopt
              _gmtime
              _gmtime_r
              _inet_ntop
              _kCFAllocatorDefault
              _kCFAllocatorSystemDefault
              _kCFRunLoopDefaultMode
              _kCFTypeDictionaryKeyCallBacks
              _kCFTypeDictionaryValueCallBacks
              _kIOMasterPortDefault
              _localtime
              _mach_error_string
              _malloc
              _memchr
              _memcmp
              _memcpy
              _memmove
              _memset
              _mkstemp
              _mmap
              _munmap
              _open
              _optarg
              _optind
              _perror
              _posix_spawn
              _printf
              _pthread_cancel
              _pthread_cond_destroy
              _pthread_cond_init
              _pthread_cond_signal
              _pthread_cond_wait
              _pthread_create
              _pthread_exit
              _pthread_join
              _pthread_kill
              _pthread_mutex_destroy
              _pthread_mutex_init
              _pthread_mutex_lock
              _pthread_mutex_unlock
              _pthread_once
              _pthread_self
              _putchar
              _puts
              _rand
              _realloc
              _recv
              _select
              _send
              _setbuf
              _setenv
              _setsockopt
              _shutdown
              _sleep
              _snprintf
              _socket
              _srand
              _sscanf
              _stat
              _stpncpy
              _strcasecmp
              _strchr
              _strcmp
              _strcpy
              _strdup
              _strerror
              _strftime
              _strlen
              _strncmp
              _strncpy
              _strndup
              _strptime
              _strrchr
              _strstr
              _strtol
              _strtoull
              _time
              _unlink
              _vasprintf
              _vprintf
              _waitpid
              _write
              dyld_stub_binder
              radr://5614542
              _CFDictionaryCreate
              _CFDictionarySetValue
              _CFNumberCreate
              _CFNumberGetValue
              _CFRelease
              _CFRetain
              _CFRunLoopAddSource
              _CFRunLoopGetCurrent
              _CFRunLoopRun
              _CFRunLoopStop
              _CFStringCreateWithFormat
              _CFStringFind
              _CFStringGetCString
              _CFUUIDGetConstantUUIDWithBytes
              _CFUUIDGetUUIDBytes
              _IOCreatePlugInInterfaceForService
              _IODestroyPlugInInterface
              _IOIteratorNext
              _IONotificationPortCreate
              _IONotificationPortGetRunLoopSource
              _IOObjectRelease
              _IORegistryEntryCreateCFProperty
              _IORegistryEntryGetRegistryEntryID
              _IOServiceAddMatchingNotification
              _IOServiceGetMatchingServices
              _IOServiceMatching
              __NSGetExecutablePath
              ___assert_rtn
              ___cxa_atexit
              ___darwin_check_fd_set_overflow
              ___error
              ___exp10
              ___memcpy_chk
              ___memset_chk
              ___sprintf_chk
              ___stack_chk_fail
              ___strncat_chk
              ___strncpy_chk
              ___udivti3
              _access
              _asprintf
              _atof
              _bzero
              _calloc
              _chmod
              _close
              _connect
              _exit
              _fclose
              _fcntl
              _fflush
              _fopen
              _fprintf
              _fputc
              _fread
              _free
              _freeaddrinfo
              _freeifaddrs
              _fstat
              _fwrite
              _gai_strerror
              _getaddrinfo
              _getchar
              _getenv
              _getifaddrs
              _getopt_long
              _getprogname
              _getsockopt
              _gmtime
              _gmtime_r
              _inet_ntop
              _localtime
              _mach_error_string
              _malloc
              _memchr
              _memcmp
              _memcpy
              _memmove
              _memset
              _mkstemp
              _mmap
              _munmap
              _open
              _perror
              _posix_spawn
              _printf
              _pthread_cancel
              _pthread_cond_destroy
              _pthread_cond_init
              _pthread_cond_signal
              _pthread_cond_wait
              _pthread_create
              _pthread_exit
              _pthread_join
              _pthread_kill
              _pthread_mutex_destroy
              _pthread_mutex_init
              _pthread_mutex_lock
              _pthread_mutex_unlock
              _pthread_once
              _pthread_self
              _putchar
              _puts
              _rand
              _realloc
              _recv
              _select
              _send
              _setbuf
              _setenv
              _setsockopt
              _shutdown
              _sleep
              _snprintf
              _socket
              _srand
              _sscanf
              _stat
              _stpncpy
              _strcasecmp
              _strchr
              _strcmp
              _strcpy
              _strdup
              _strerror
              _strftime
              _strlen
              _strncmp
              _strncpy
              _strndup
              _strptime
              _strrchr
              _strstr
              _strtol
              _strtoull
              _time
              _unlink
              _vasprintf
              _vprintf
              _waitpid
              _write

              Download Network PCAP: filteredfull

              TimestampSource PortDest PortSource IPDest IP
              Nov 2, 2023 09:37:35.652091980 CET4937580192.168.11.1117.253.13.202
              Nov 2, 2023 09:37:35.652333975 CET4937680192.168.11.1123.45.32.198
              Nov 2, 2023 09:37:35.781440020 CET804937517.253.13.202192.168.11.11
              Nov 2, 2023 09:37:35.783050060 CET4937580192.168.11.1117.253.13.202
              Nov 2, 2023 09:37:35.797913074 CET804937623.45.32.198192.168.11.11
              Nov 2, 2023 09:37:35.799566031 CET4937680192.168.11.1123.45.32.198
              TimestampSource PortDest PortSource IPDest IP
              Nov 2, 2023 09:37:32.608099937 CET53503931.1.1.1192.168.11.11

              System Behavior