Edit tour

macOS Analysis Report
palera1n-macos-universal

Overview

General Information

Sample Name:palera1n-macos-universal
Analysis ID:1335883
MD5:1ea859eba583e6eab3d377dbb6bc61d7
SHA1:661aa3fab1be48677244be0e53ec7b91066a8c17
SHA256:596dedefc9b3771c6e9f7b9a256bfb44330ebdff77936b48cfa8c891825296ed
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Mach-O contains sections with high entropy indicating compressed/encrypted content
Contains symbols with suspicious names likely related to networking
Sample is a FAT Mach-O sample containing binaries for multiple architectures

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox Version:38.0.0 Ammolite
Analysis ID:1335883
Start date and time:2023-11-02 09:40:34 +01:00
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 4m 40s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultmacfilecookbook.jbs
Analysis system description:Virtual Machine, High Sierra (Office 2016 16.16, Java 11.0.2+9, Adobe Reader 2019.010.20099)
macOS major version:10.13
CPU architecture:x86_64
Analysis Mode:default
Sample file name:palera1n-macos-universal
Detection:MAL
Classification:mal48.mac@0/0@0/0
  • Excluded IPs from analysis (whitelisted): 17.253.13.204, 17.253.13.203, 23.213.225.112, 17.253.13.202, 17.253.13.201, 17.253.13.205, 17.253.12.253, 17.253.6.253, 17.253.12.125, 23.45.33.79
  • Excluded domains from analysis (whitelisted): cds-cdn.v.aaplimg.com, e11408.d.akamaiedge.net, cds.apple.com.akadns.net, time-macos.apple.com, ocsp-a.g.aaplimg.com, fbs.smoot.apple.com, cds.apple.com, help-ar.apple.com.edgekey.net, valid.apple.com, lb._dns-sd._udp.0.11.168.192.in-addr.arpa, ocsp-lb.apple.com.akadns.net, ocsp.apple.com, glb-fbs.v.aaplimg.com, valid.origin-apple.com.akadns.net, help.origin-apple.com.akadns.net, valid-apple.g.aaplimg.com, time.g.aaplimg.com, help.apple.com, world-gen.g.aaplimg.com
Command:/Users/berri/Desktop/palera1n-macos-universal
PID:899
Exit Code:
Exit Code Info:
Killed:True
Standard Output:
- [0m[[0;90m11/02/23 09:41:35[0m] [1;36m<Info>[0m: [0;36mWaiting for devices[0m
Standard Error:# == palera1n-c ==
#
# Made by: Nick Chan, Ploosh, Samara, Nebula, staturnz, kok3shidoll
#
# Thanks to: pythonplayer123, llsc12, Mineek, tihmstar, nikias
# (libimobiledevice), checkra1n team (Siguza, axi0mx, littlelailo
# et al.), Procursus Team (Hayden Seay, Cameron Katri, Keto et.al)
  • System is macvm-highsierra
  • palera1n-macos-universal (MD5: 1ea859eba583e6eab3d377dbb6bc61d7) Arguments: /Users/berri/Desktop/palera1n-macos-universal
  • cleanup
No yara matches
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: palera1n-macos-universalVirustotal: Detection: 9%Perma Link
Source: unknownHTTPS traffic detected: 100.22.10.168:443 -> 192.168.11.11:49400 version: TLS 1.2
Source: submission: palera1n-macos-universalMach-O symbol: _socket
Source: submission: palera1n-macos-universalMach-O symbol: _send
Source: submission: palera1n-macos-universalMach-O symbol: _setsockopt
Source: submission: palera1n-macos-universalMach-O symbol: _connect
Source: submission: palera1n-macos-universalMach-O symbol: _getsockopt
Source: submission: palera1n-macos-universalMach-O symbol: _kIOMasterPortDefault
Source: submission: palera1n-macos-universalMach-O symbol: _IONotificationPortGetRunLoopSource
Source: submission: palera1n-macos-universalMach-O symbol: _IONotificationPortCreate
Source: submission: palera1n-macos-universalMach-O symbol: _send
Source: submission: palera1n-macos-universalMach-O symbol: _setsockopt
Source: submission: palera1n-macos-universalMach-O symbol: _connect
Source: submission: palera1n-macos-universalMach-O symbol: _socket
Source: submission: palera1n-macos-universalMach-O symbol: _getsockopt
Source: submission: palera1n-macos-universalMach-O symbol: _kIOMasterPortDefault
Source: submission: palera1n-macos-universalMach-O symbol: _IONotificationPortGetRunLoopSource
Source: submission: palera1n-macos-universalMach-O symbol: _IONotificationPortCreate
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49400
Source: unknownNetwork traffic detected: HTTP traffic on port 49400 -> 443
Source: palera1n-macos-universalString found in binary or memory: http://www.apple.com/DTDs/PropertyList-1.0.dtd
Source: palera1n-macos-universalString found in binary or memory: https://checkra.in
Source: palera1n-macos-universalString found in binary or memory: https://checkra.in#====
Source: palera1n-macos-universalString found in binary or memory: https://checkra.infirmware-versionBooted
Source: palera1n-macos-universalString found in binary or memory: https://ellekit.space/
Source: palera1n-macos-universalString found in binary or memory: https://repo.palera.in/
Source: palera1n-macos-universalString found in binary or memory: https://strap.palera.in/
Source: unknownTCP traffic detected without corresponding DNS query: 17.253.13.207
Source: unknownTCP traffic detected without corresponding DNS query: 23.213.224.212
Source: unknownTCP traffic detected without corresponding DNS query: 17.253.13.207
Source: unknownTCP traffic detected without corresponding DNS query: 23.213.224.212
Source: unknownHTTPS traffic detected: 100.22.10.168:443 -> 192.168.11.11:49400 version: TLS 1.2
Source: classification engineClassification label: mal48.mac@0/0@0/0
Source: submissionFile header: Mach-O universal binary with 2 architectures: [x86_64:Mach-O 64-bit x86_64 executable, flags:<NOUNDEFS|DYLDLINK|TWOLEVEL|PIE>] [arm64]
Source: submissionMach-O header: Mach-O universal binary with 2 architectures: [x86_64:Mach-O 64-bit x86_64 executable, flags:<NOUNDEFS|DYLDLINK|TWOLEVEL|PIE>] [arm64]
Source: submission: palera1n-macos-universalMach-O header: dylib_command -> /System/Library/Frameworks/IOKit.framework/Versions/A/IOKit
Source: submission: palera1n-macos-universalMach-O header: dylib_command -> /System/Library/Frameworks/IOKit.framework/Versions/A/IOKit
Source: submissionCodeSign Info: Executable=/Users/berri/Desktop/palera1n-macos-universal
Source: palera1n-macos-universalSubmission file: section __data with 7.2629 entropy (max. 8.0)
Source: palera1n-macos-universalSubmission file: section __data with 7.2381 entropy (max. 8.0)
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Invalid Code Signature
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Code Signing
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)1
Obfuscated Files or Information
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Shell
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1335883 Sample: palera1n-macos-universal Startdate: 02/11/2023 Architecture: MAC Score: 48 8 23.213.224.212, 49376, 80 PROXIMUS-ISP-ASBE United States 2->8 10 pubingress-feedback-1a6fe9caff1148fe.elb.us-west-2.amazonaws.com 100.22.10.168, 443, 49400 AMAZON-02US United States 2->10 12 Multi AV Scanner detection for submitted file 2->12 6 mono-sgen32 palera1n-macos-universal 2->6         started        signatures3 process4

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


cam-macmac-stand
SourceDetectionScannerLabelLink
palera1n-macos-universal8%ReversingLabsBinary.PUA.Jailbreak
palera1n-macos-universal10%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
pubingress-feedback-1a6fe9caff1148fe.elb.us-west-2.amazonaws.com
100.22.10.168
truefalse
    high
    NameSourceMaliciousAntivirus DetectionReputation
    https://checkra.inpalera1n-macos-universalfalse
      unknown
      https://checkra.in#====palera1n-macos-universalfalse
        unknown
        https://repo.palera.in/palera1n-macos-universalfalse
          unknown
          https://strap.palera.in/palera1n-macos-universalfalse
            unknown
            https://ellekit.space/palera1n-macos-universalfalse
              unknown
              https://checkra.infirmware-versionBootedpalera1n-macos-universalfalse
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                100.22.10.168
                pubingress-feedback-1a6fe9caff1148fe.elb.us-west-2.amazonaws.comUnited States
                16509AMAZON-02USfalse
                23.213.224.212
                unknownUnited States
                5432PROXIMUS-ISP-ASBEfalse
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                100.22.10.1681rNsYj4HBTGet hashmaliciousUnknownBrowse
                  Zotero-6.0.26.dmgGet hashmaliciousUnknownBrowse
                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                    pubingress-feedback-1a6fe9caff1148fe.elb.us-west-2.amazonaws.com1rNsYj4HBTGet hashmaliciousUnknownBrowse
                    • 100.22.10.168
                    Zotero-6.0.26.dmgGet hashmaliciousUnknownBrowse
                    • 100.22.10.168
                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                    AMAZON-02US5R9V8icHfz.elfGet hashmaliciousMirai, MoobotBrowse
                    • 54.110.214.160
                    skid.arm7.elfGet hashmaliciousMirai, MoobotBrowse
                    • 13.254.33.0
                    skid.x86.elfGet hashmaliciousMirai, MoobotBrowse
                    • 63.35.95.131
                    skid.x86_64.elfGet hashmaliciousMirai, MoobotBrowse
                    • 54.228.23.110
                    skid.mpsl.elfGet hashmaliciousMirai, MoobotBrowse
                    • 13.242.39.200
                    skid.mips.elfGet hashmaliciousMirai, MoobotBrowse
                    • 35.167.195.214
                    skid.arm.elfGet hashmaliciousMirai, MoobotBrowse
                    • 108.156.54.172
                    https://protect-eu.mimecast.com/s/UIJ2C2xAMCRxBZAUneUgR?domain=1cl3j.trk.elasticemail.comGet hashmaliciousUnknownBrowse
                    • 52.85.132.118
                    kwEwXhZSx3.elfGet hashmaliciousUnknownBrowse
                    • 34.249.145.219
                    https://www.canva.com/design/DAFy6E4uIKY/LBBY1MAy4r-_eLnQrrdsGw/view?utm_content=DAFy6E4uIKY&utm_campaign=designshare&utm_medium=link&utm_source=editorGet hashmaliciousHTMLPhisherBrowse
                    • 18.218.176.238
                    https://url12.mailanyone.net/scanner?m=1qyQGX-000631-3i&d=4%7Cmail%2F90%2F1698902400%2F1qyQGX-000631-3i%7Cin12l%7C57e1b682%7C21208867%7C12850088%7C654333A97E0E3847F1DBE1AD2A2490A8&o=%2Fphtd%3A%2Fetsfp.atinop-ten.v&s=xaxQsEUId4te_eq5C82Cn2GILosGet hashmaliciousHTMLPhisherBrowse
                    • 108.138.85.58
                    https://r20.rs6.netGet hashmaliciousUnknownBrowse
                    • 108.138.64.117
                    Signal-Android-website-prod-universal-release-6.37.2 (2).apkGet hashmaliciousUnknownBrowse
                    • 54.230.31.53
                    bHFZDHNHZw.elfGet hashmaliciousMiraiBrowse
                    • 99.80.182.198
                    tW89v9x9F4.elfGet hashmaliciousMiraiBrowse
                    • 44.241.44.177
                    oKToHgW7tv.elfGet hashmaliciousMiraiBrowse
                    • 130.177.62.212
                    https://www.ocregister.com/2023/09/07/what-exodus-california-has-4th-stickiest-population-in-us/Get hashmaliciousUnknownBrowse
                    • 13.249.39.19
                    http://www.wildcatfiretrucks.comGet hashmaliciousUnknownBrowse
                    • 44.228.215.240
                    https://ship.directx.ca/#?sso_token=7d76786f-14c7-4f83-af25-5cefc6d3cbb1Get hashmaliciousUnknownBrowse
                    • 34.252.35.255
                    https://t.ly/mV-Qq#M=SmFuLVBldGVyLkhlaXNlQG5vcnRvbnJvc2VmdWxicmlnaHQuY29tGet hashmaliciousHTMLPhisherBrowse
                    • 18.188.137.210
                    PROXIMUS-ISP-ASBEskid.mips.elfGet hashmaliciousMirai, MoobotBrowse
                    • 109.133.41.252
                    7N7Lo1caw1.elfGet hashmaliciousMiraiBrowse
                    • 83.134.237.27
                    ODfOto3gt3.elfGet hashmaliciousUnknownBrowse
                    • 193.75.185.6
                    kJ7wgYp6Mw.elfGet hashmaliciousMiraiBrowse
                    • 46.179.86.106
                    T2b74gKWzG.elfGet hashmaliciousMiraiBrowse
                    • 178.144.247.182
                    7SyP6X5mqJ.elfGet hashmaliciousMiraiBrowse
                    • 109.138.31.16
                    mnv41CRAfH.elfGet hashmaliciousMiraiBrowse
                    • 91.178.161.162
                    sora.x86.elfGet hashmaliciousMiraiBrowse
                    • 109.131.127.178
                    sora.arm7.elfGet hashmaliciousMiraiBrowse
                    • 91.182.121.121
                    sora.mpsl.elfGet hashmaliciousMiraiBrowse
                    • 91.178.246.94
                    zHZxBxq6je.elfGet hashmaliciousMiraiBrowse
                    • 91.178.113.229
                    dwA3Y86oKf.elfGet hashmaliciousUnknownBrowse
                    • 91.181.85.149
                    rvOM61u4nZ.elfGet hashmaliciousMiraiBrowse
                    • 91.176.245.102
                    IO6T5PKtWK.elfGet hashmaliciousMiraiBrowse
                    • 109.128.109.174
                    7ry2TkWdG5.elfGet hashmaliciousUnknownBrowse
                    • 87.66.87.94
                    1gHZusf2qN.elfGet hashmaliciousUnknownBrowse
                    • 87.65.111.82
                    sora.arm.elfGet hashmaliciousMiraiBrowse
                    • 91.181.37.231
                    Aqua.arm4-20231022-0333.elfGet hashmaliciousMiraiBrowse
                    • 87.66.17.141
                    x86.elfGet hashmaliciousUnknownBrowse
                    • 91.179.103.148
                    sora.arm.elfGet hashmaliciousMiraiBrowse
                    • 109.128.53.131
                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                    3e4e87dda5a3162306609b7e330441d2anytrans-ios-official-en-mac.dmgGet hashmaliciousUnknownBrowse
                    • 100.22.10.168
                    https://theagency786.com/qomo/?32188931Get hashmaliciousUnknownBrowse
                    • 100.22.10.168
                    http://hill-family.usGet hashmaliciousUnknownBrowse
                    • 100.22.10.168
                    https://aussieshutters.com/ed/?71517431Get hashmaliciousUnknownBrowse
                    • 100.22.10.168
                    https://tlctrlstate.com/Mpetra.de.graaf@ict.nlGet hashmaliciousUnknownBrowse
                    • 100.22.10.168
                    https://re-captha-version-3-39.top/ms/1410_desc_1_B/?c=2e52e252-0e12-419b-8389-405438cdfa40&a=l143904Get hashmaliciousUnknownBrowse
                    • 100.22.10.168
                    https://urluso.com/2tvRvpGet hashmaliciousUnknownBrowse
                    • 100.22.10.168
                    1rNsYj4HBTGet hashmaliciousUnknownBrowse
                    • 100.22.10.168
                    http://zx.paymentsmusic.comGet hashmaliciousUnknownBrowse
                    • 100.22.10.168
                    http://zx.paymentsmusic.comGet hashmaliciousUnknownBrowse
                    • 100.22.10.168
                    http://zx.paymentsmusic.comGet hashmaliciousUnknownBrowse
                    • 100.22.10.168
                    http://zx.paymentsmusic.comGet hashmaliciousUnknownBrowse
                    • 100.22.10.168
                    http://zx.paymentsmusic.comGet hashmaliciousUnknownBrowse
                    • 100.22.10.168
                    http://zx.paymentsmusic.comGet hashmaliciousUnknownBrowse
                    • 100.22.10.168
                    http://zx.paymentsmusic.comGet hashmaliciousUnknownBrowse
                    • 100.22.10.168
                    http://zx.paymentsmusic.comGet hashmaliciousUnknownBrowse
                    • 100.22.10.168
                    http://zx.paymentsmusic.comGet hashmaliciousUnknownBrowse
                    • 100.22.10.168
                    http://zx.paymentsmusic.comGet hashmaliciousUnknownBrowse
                    • 100.22.10.168
                    http://zx.paymentsmusic.comGet hashmaliciousUnknownBrowse
                    • 100.22.10.168
                    http://zx.paymentsmusic.comGet hashmaliciousUnknownBrowse
                    • 100.22.10.168
                    No context
                    No created / dropped files found
                    File type:Mach-O universal binary with 2 architectures: [x86_64:Mach-O 64-bit x86_64 executable, flags:<NOUNDEFS|DYLDLINK|TWOLEVEL|PIE>] [arm64]
                    Entropy (8bit):7.2118151974024745
                    TrID:
                    • Mac OS X Universal Binary executable (4004/1) 75.96%
                    • HSC music composer song (1267/141) 24.04%
                    File name:palera1n-macos-universal
                    File size:9'822'128 bytes
                    MD5:1ea859eba583e6eab3d377dbb6bc61d7
                    SHA1:661aa3fab1be48677244be0e53ec7b91066a8c17
                    SHA256:596dedefc9b3771c6e9f7b9a256bfb44330ebdff77936b48cfa8c891825296ed
                    SHA512:ac28c41a18b706f2f531b87b89deb97abb01fa03d756ec60d860c9a26a195318afab195491f93734ed38e152daf433ebf7d122f07463c7b70323460c04eddf81
                    SSDEEP:196608:ydfylkmw6+y5s2F+vKO3dfylkmw6+y5s2F+vK:WfW4655NEvHfW4655NEv
                    TLSH:32A61262EE1C6C24D1C5D1BD994A4B91563BF8718352D3AA3691B33CEFCA6E03179323
                    File Content Preview:..................@..J. .............K@..J.....................................................................................................................................................................................................................
                    [
                        "Executable=/Users/berri/Desktop/palera1n-macos-universal",
                        "Identifier=palera1n-macosx-x86_64",
                        "Format=Mach-O universal (x86_64 arm64)",
                        "CodeDirectory v=20400 size=38031 flags=0x0(none) hashes=1183+2 location=embedded",
                        "OSPlatform=36",
                        "OSSDKVersion=852224",
                        "OSVersionMin=657408",
                        "Hash type=sha256 size=32",
                        "CandidateCDHash sha1=88aacc099de283fdec746618d160e990b324d732",
                        "CandidateCDHash sha256=926aebac1990ff66aec0f981b98493a17d3f421e",
                        "Hash choices=sha1,sha256",
                        "Executable Segment base=0",
                        "Executable Segment limit=524288",
                        "Executable Segment flags=0x1",
                        "Page size=4096",
                        "CDHash=926aebac1990ff66aec0f981b98493a17d3f421e",
                        "/Users/berri/Desktop/palera1n-macos-universal: no signature",
                        "Info.plist=not bound",
                        "TeamIdentifier=not set",
                        "Sealed Resources=none",
                        "Internal requirements count=1 size=140"
                    ]
                    General Information for header 1
                    Endian:little-endian
                    Size:64-bit
                    Architecture:x86_64
                    Filetype:execute
                    Nbr. of load commands:18
                    Entry point:0xBCC
                    NameValue
                    segname__PAGEZERO
                    vmaddr0x0
                    vmsize0x100000000
                    fileoff0x0
                    filesize0x0
                    maxprot0x0
                    initprot0x0
                    nsects0
                    flags0x0
                    NameValue
                    segname__TEXT
                    vmaddr0x100000000
                    vmsize0x80000
                    fileoff0x0
                    filesize0x80000
                    maxprot0x5
                    initprot0x5
                    nsects8
                    flags0x0
                    Datas
                    sectnamesegnameaddrsizeoffsetentropyalignreloffnrelocflags
                    __text__TEXT0x100000BC00x663950xBC06.40510x40x000x80000400
                    __stubs__TEXT0x100066F560x34E0x66F563.86100x10x000x80000408
                    __stub_helper__TEXT0x1000672A40x5920x672A44.59800x20x000x80000400
                    __const__TEXT0x1000678400x89680x678402.36770x40x000x0
                    __cstring__TEXT0x1000701B00xA4610x701B05.63700x40x000x2
                    __ustring__TEXT0x10007A6120x1E0x7A6123.35590x10x000x0
                    __unwind_info__TEXT0x10007A6300x4EC0x7A6305.57880x20x000x0
                    __eh_frame__TEXT0x10007AB200x54E00x7AB204.36960x30x000x0
                    NameValue
                    segname__DATA
                    vmaddr0x100080000
                    vmsize0x41C000
                    fileoff0x80000
                    filesize0x41C000
                    maxprot0x3
                    initprot0x3
                    nsects8
                    flags0x0
                    Datas
                    sectnamesegnameaddrsizeoffsetentropyalignreloffnrelocflags
                    __nl_symbol_ptr__DATA0x1000800000x80x80000-0.00000x30x000x6
                    __got__DATA0x1000800080x800x80008-0.00000x30x000x6
                    __la_symbol_ptr__DATA0x1000800880x4680x800883.16410x30x000x7
                    __mod_init_func__DATA0x1000804F00x300x804F02.43140x30x000x9
                    __const__DATA0x1000805200x85980x805202.36770x40x000x0
                    __cfstring__DATA0x100088AB80xE00x88AB81.54590x30x000x0
                    __data__DATA0x100088BA00x410AC80x88BA07.26290x40x000x0
                    __bss__DATA0x1004996700x28700x00.00000x40x000x1
                    NameValue
                    segname__LINKEDIT
                    vmaddr0x10049C000
                    vmsize0x13000
                    fileoff0x49C000
                    filesize0x12220
                    maxprot0x1
                    initprot0x1
                    nsects0
                    flags0x0
                    NameValue
                    rebase_off4833280
                    rebase_size1800
                    bind_off4835080
                    bind_size416
                    weak_bind_off0
                    weak_bind_size0
                    lazy_bind_off4835496
                    lazy_bind_size2832
                    export_off4838328
                    export_size48
                    NameValue
                    symoff4839616
                    nsyms158
                    stroff4843344
                    strsize2176
                    NameValue
                    ilocalsym0
                    nlocalsym1
                    iextdefsym1
                    nextdefsym1
                    iundefsym2
                    nundefsym156
                    tocoff0
                    ntoc0
                    modtaboff0
                    nmodtab0
                    extrefsymoff0
                    nextrefsyms0
                    indirectsymoff4842144
                    nindirectsyms299
                    extreloff0
                    nextrel0
                    locreloff0
                    nlocrel0
                    NameValue
                    name12
                    Datas/usr/lib/dyld
                    NameValue
                    uuidb'y\xbd\xd7%q\x9a:z\xa0\xae\x1a\x0e:\xca\x1d\x0c'
                    NameValue
                    version657408
                    sdk852224
                    NameValue
                    version0
                    NameValue
                    entryoff3020
                    stacksize0
                    NameValue
                    name24
                    timestampThu Jan 1 01:00:02 1970
                    current_version1319.0.0
                    compatibility_version1.0.0
                    Datas/usr/lib/libSystem.B.dylib
                    NameValue
                    name24
                    timestampThu Jan 1 01:00:02 1970
                    current_version1953.255.0
                    compatibility_version150.0.0
                    Datas/System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation
                    NameValue
                    name24
                    timestampThu Jan 1 01:00:02 1970
                    current_version275.0.0
                    compatibility_version1.0.0
                    Datas/System/Library/Frameworks/IOKit.framework/Versions/A/IOKit
                    NameValue
                    dataoff4838376
                    datasize848
                    NameValue
                    dataoff4839224
                    datasize392
                    NameValue
                    dataoff4845520
                    datasize62032
                    _CFDictionaryCreate
                    _CFDictionarySetValue
                    _CFNumberCreate
                    _CFNumberGetValue
                    _CFRelease
                    _CFRetain
                    _CFRunLoopAddSource
                    _CFRunLoopGetCurrent
                    _CFRunLoopRun
                    _CFRunLoopStop
                    _CFStringCreateWithFormat
                    _CFStringFind
                    _CFStringGetCString
                    _CFUUIDGetConstantUUIDWithBytes
                    _CFUUIDGetUUIDBytes
                    _IOCreatePlugInInterfaceForService
                    _IODestroyPlugInInterface
                    _IOIteratorNext
                    _IONotificationPortCreate
                    _IONotificationPortGetRunLoopSource
                    _IOObjectRelease
                    _IORegistryEntryCreateCFProperty
                    _IORegistryEntryGetRegistryEntryID
                    _IOServiceAddMatchingNotification
                    _IOServiceGetMatchingServices
                    _IOServiceMatching
                    __DefaultRuneLocale
                    __NSGetExecutablePath
                    ___CFConstantStringClassReference
                    ___assert_rtn
                    ___bzero
                    ___cxa_atexit
                    ___darwin_check_fd_set_overflow
                    ___error
                    ___memcpy_chk
                    ___memset_chk
                    ___sprintf_chk
                    ___stack_chk_fail
                    ___stack_chk_guard
                    ___stderrp
                    ___stdoutp
                    ___strncat_chk
                    ___strncpy_chk
                    ___udivti3
                    __mh_execute_header
                    _access
                    _asprintf
                    _atof
                    _calloc
                    _chmod
                    _close
                    _connect
                    _environ
                    _exit
                    _fclose
                    _fcntl
                    _fflush
                    _fopen
                    _fprintf
                    _fputc
                    _fread
                    _free
                    _freeaddrinfo
                    _freeifaddrs
                    _fstat$INODE64
                    _fwrite
                    _gai_strerror
                    _getaddrinfo
                    _getchar
                    _getenv
                    _getifaddrs
                    _getopt_long
                    _getprogname
                    _getsockopt
                    _gmtime
                    _gmtime_r
                    _inet_ntop
                    _kCFAllocatorDefault
                    _kCFAllocatorSystemDefault
                    _kCFRunLoopDefaultMode
                    _kCFTypeDictionaryKeyCallBacks
                    _kCFTypeDictionaryValueCallBacks
                    _kIOMasterPortDefault
                    _localtime
                    _mach_error_string
                    _malloc
                    _memchr
                    _memcmp
                    _memcpy
                    _memmove
                    _memset
                    _mkstemp
                    _mmap
                    _munmap
                    _open
                    _optarg
                    _optind
                    _perror
                    _posix_spawn
                    _pow
                    _printf
                    _pthread_cancel
                    _pthread_cond_destroy
                    _pthread_cond_init
                    _pthread_cond_signal
                    _pthread_cond_wait
                    _pthread_create
                    _pthread_exit
                    _pthread_join
                    _pthread_kill
                    _pthread_mutex_destroy
                    _pthread_mutex_init
                    _pthread_mutex_lock
                    _pthread_mutex_unlock
                    _pthread_once
                    _pthread_self
                    _putchar
                    _puts
                    _rand
                    _realloc
                    _recv
                    _select$1050
                    _send
                    _setbuf
                    _setenv
                    _setsockopt
                    _shutdown
                    _sleep
                    _snprintf
                    _socket
                    _srand
                    _sscanf
                    _stat$INODE64
                    _stpncpy
                    _strcasecmp
                    _strchr
                    _strcmp
                    _strcpy
                    _strdup
                    _strerror
                    _strftime
                    _strlen
                    _strncmp
                    _strncpy
                    _strndup
                    _strptime
                    _strrchr
                    _strstr
                    _strtol
                    _strtoull
                    _time
                    _unlink
                    _vasprintf
                    _vprintf
                    _waitpid
                    _write
                    dyld_stub_binder
                    radr://5614542
                    _CFDictionaryCreate
                    _CFDictionarySetValue
                    _CFNumberCreate
                    _CFNumberGetValue
                    _CFRelease
                    _CFRetain
                    _CFRunLoopAddSource
                    _CFRunLoopGetCurrent
                    _CFRunLoopRun
                    _CFRunLoopStop
                    _CFStringCreateWithFormat
                    _CFStringFind
                    _CFStringGetCString
                    _CFUUIDGetConstantUUIDWithBytes
                    _CFUUIDGetUUIDBytes
                    _IOCreatePlugInInterfaceForService
                    _IODestroyPlugInInterface
                    _IOIteratorNext
                    _IONotificationPortCreate
                    _IONotificationPortGetRunLoopSource
                    _IOObjectRelease
                    _IORegistryEntryCreateCFProperty
                    _IORegistryEntryGetRegistryEntryID
                    _IOServiceAddMatchingNotification
                    _IOServiceGetMatchingServices
                    _IOServiceMatching
                    __NSGetExecutablePath
                    ___assert_rtn
                    ___bzero
                    ___cxa_atexit
                    ___darwin_check_fd_set_overflow
                    ___error
                    ___memcpy_chk
                    ___memset_chk
                    ___sprintf_chk
                    ___stack_chk_fail
                    ___strncat_chk
                    ___strncpy_chk
                    ___udivti3
                    _access
                    _asprintf
                    _atof
                    _calloc
                    _chmod
                    _close
                    _connect
                    _exit
                    _fclose
                    _fcntl
                    _fflush
                    _fopen
                    _fprintf
                    _fputc
                    _fread
                    _free
                    _freeaddrinfo
                    _freeifaddrs
                    _fstat$INODE64
                    _fwrite
                    _gai_strerror
                    _getaddrinfo
                    _getchar
                    _getenv
                    _getifaddrs
                    _getopt_long
                    _getprogname
                    _getsockopt
                    _gmtime
                    _gmtime_r
                    _inet_ntop
                    _localtime
                    _mach_error_string
                    _malloc
                    _memchr
                    _memcmp
                    _memcpy
                    _memmove
                    _memset
                    _mkstemp
                    _mmap
                    _munmap
                    _open
                    _perror
                    _posix_spawn
                    _pow
                    _printf
                    _pthread_cancel
                    _pthread_cond_destroy
                    _pthread_cond_init
                    _pthread_cond_signal
                    _pthread_cond_wait
                    _pthread_create
                    _pthread_exit
                    _pthread_join
                    _pthread_kill
                    _pthread_mutex_destroy
                    _pthread_mutex_init
                    _pthread_mutex_lock
                    _pthread_mutex_unlock
                    _pthread_once
                    _pthread_self
                    _putchar
                    _puts
                    _rand
                    _realloc
                    _recv
                    _select$1050
                    _send
                    _setbuf
                    _setenv
                    _setsockopt
                    _shutdown
                    _sleep
                    _snprintf
                    _socket
                    _srand
                    _sscanf
                    _stat$INODE64
                    _stpncpy
                    _strcasecmp
                    _strchr
                    _strcmp
                    _strcpy
                    _strdup
                    _strerror
                    _strftime
                    _strlen
                    _strncmp
                    _strncpy
                    _strndup
                    _strptime
                    _strrchr
                    _strstr
                    _strtol
                    _strtoull
                    _time
                    _unlink
                    _vasprintf
                    _vprintf
                    _waitpid
                    _write

                    General Information for header 2
                    Endian:little-endian
                    Size:64-bit
                    Architecture:arm64
                    Filetype:execute
                    Nbr. of load commands:19
                    Entry point:0x353C
                    NameValue
                    segname__PAGEZERO
                    vmaddr0x0
                    vmsize0x100000000
                    fileoff0x0
                    filesize0x0
                    maxprot0x0
                    initprot0x0
                    nsects0
                    flags0x0
                    NameValue
                    segname__TEXT
                    vmaddr0x100000000
                    vmsize0x74000
                    fileoff0x0
                    filesize0x74000
                    maxprot0x5
                    initprot0x5
                    nsects7
                    flags0x0
                    Datas
                    sectnamesegnameaddrsizeoffsetentropyalignreloffnrelocflags
                    __text__TEXT0x1000035340x5CCEC0x35346.78030x20x000x80000400
                    __stubs__TEXT0x1000602200x69C0x602204.01520x20x000x80000408
                    __stub_helper__TEXT0x1000608BC0x6B40x608BC4.19610x20x000x80000400
                    __const__TEXT0x100060F700x86000x60F702.37410x40x000x0
                    __cstring__TEXT0x1000695700xA40D0x695705.63990x00x000x2
                    __ustring__TEXT0x10007397E0x1E0x7397E3.35590x10x000x0
                    __unwind_info__TEXT0x10007399C0x6580x7399C5.79930x20x000x0
                    NameValue
                    segname__DATA_CONST
                    vmaddr0x100074000
                    vmsize0xC000
                    fileoff0x74000
                    filesize0xC000
                    maxprot0x3
                    initprot0x3
                    nsects4
                    flags0x10
                    Datas
                    sectnamesegnameaddrsizeoffsetentropyalignreloffnrelocflags
                    __got__DATA_CONST0x1000740000x800x74000-0.00000x30x000x6
                    __mod_init_func__DATA_CONST0x1000740800x300x740802.37520x30x000x9
                    __const__DATA_CONST0x1000740B00x85800x740B02.37410x30x000x0
                    __cfstring__DATA_CONST0x10007C6300xE00x7C6301.59270x30x000x0
                    NameValue
                    segname__DATA
                    vmaddr0x100080000
                    vmsize0x418000
                    fileoff0x80000
                    filesize0x418000
                    maxprot0x3
                    initprot0x3
                    nsects3
                    flags0x0
                    Datas
                    sectnamesegnameaddrsizeoffsetentropyalignreloffnrelocflags
                    __la_symbol_ptr__DATA0x1000800000x4680x800003.07570x30x000x7
                    __data__DATA0x1000804680x414B580x804687.23810x30x000x0
                    __bss__DATA0x100494FC00x7300x00.00000x40x000x1
                    NameValue
                    segname__LINKEDIT
                    vmaddr0x100498000
                    vmsize0x14000
                    fileoff0x498000
                    filesize0x11FB0
                    maxprot0x1
                    initprot0x1
                    nsects0
                    flags0x0
                    NameValue
                    rebase_off4816896
                    rebase_size1800
                    bind_off4818696
                    bind_size400
                    weak_bind_off0
                    weak_bind_size0
                    lazy_bind_off4819096
                    lazy_bind_size2800
                    export_off4821896
                    export_size48
                    NameValue
                    symoff4822800
                    nsyms159
                    stroff4826536
                    strsize2176
                    NameValue
                    ilocalsym0
                    nlocalsym1
                    iextdefsym1
                    nextdefsym1
                    iundefsym2
                    nundefsym157
                    tocoff0
                    ntoc0
                    modtaboff0
                    nmodtab0
                    extrefsymoff0
                    nextrefsyms0
                    indirectsymoff4825344
                    nindirectsyms298
                    extreloff0
                    nextrel0
                    locreloff0
                    nlocrel0
                    NameValue
                    name12
                    Datas/usr/lib/dyld
                    NameValue
                    uuidb'9\xe7UQ\xfe\xc95\xfd\x80\xa8;\xdd\x1c\xa3\xfe\x03'
                    NameValue
                    platform1
                    minos720896
                    sdk852224
                    ntools1
                    Datas.
                    NameValue
                    version0
                    NameValue
                    entryoff13628
                    stacksize0
                    NameValue
                    name24
                    timestampThu Jan 1 01:00:02 1970
                    current_version1319.0.0
                    compatibility_version1.0.0
                    Datas/usr/lib/libSystem.B.dylib
                    NameValue
                    name24
                    timestampThu Jan 1 01:00:02 1970
                    current_version1953.255.0
                    compatibility_version150.0.0
                    Datas/System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation
                    NameValue
                    name24
                    timestampThu Jan 1 01:00:02 1970
                    current_version275.0.0
                    compatibility_version1.0.0
                    Datas/System/Library/Frameworks/IOKit.framework/Versions/A/IOKit
                    NameValue
                    dataoff4821944
                    datasize856
                    NameValue
                    dataoff4822800
                    datasize0
                    NameValue
                    dataoff4828720
                    datasize61824
                    _CFDictionaryCreate
                    _CFDictionarySetValue
                    _CFNumberCreate
                    _CFNumberGetValue
                    _CFRelease
                    _CFRetain
                    _CFRunLoopAddSource
                    _CFRunLoopGetCurrent
                    _CFRunLoopRun
                    _CFRunLoopStop
                    _CFStringCreateWithFormat
                    _CFStringFind
                    _CFStringGetCString
                    _CFUUIDGetConstantUUIDWithBytes
                    _CFUUIDGetUUIDBytes
                    _IOCreatePlugInInterfaceForService
                    _IODestroyPlugInInterface
                    _IOIteratorNext
                    _IONotificationPortCreate
                    _IONotificationPortGetRunLoopSource
                    _IOObjectRelease
                    _IORegistryEntryCreateCFProperty
                    _IORegistryEntryGetRegistryEntryID
                    _IOServiceAddMatchingNotification
                    _IOServiceGetMatchingServices
                    _IOServiceMatching
                    __DefaultRuneLocale
                    __NSGetExecutablePath
                    ___CFConstantStringClassReference
                    ___assert_rtn
                    ___chkstk_darwin
                    ___cxa_atexit
                    ___darwin_check_fd_set_overflow
                    ___error
                    ___exp10
                    ___memcpy_chk
                    ___memset_chk
                    ___sprintf_chk
                    ___stack_chk_fail
                    ___stack_chk_guard
                    ___stderrp
                    ___stdoutp
                    ___strncat_chk
                    ___strncpy_chk
                    ___udivti3
                    __mh_execute_header
                    _access
                    _asprintf
                    _atof
                    _bzero
                    _calloc
                    _chmod
                    _close
                    _connect
                    _environ
                    _exit
                    _fclose
                    _fcntl
                    _fflush
                    _fopen
                    _fprintf
                    _fputc
                    _fread
                    _free
                    _freeaddrinfo
                    _freeifaddrs
                    _fstat
                    _fwrite
                    _gai_strerror
                    _getaddrinfo
                    _getchar
                    _getenv
                    _getifaddrs
                    _getopt_long
                    _getprogname
                    _getsockopt
                    _gmtime
                    _gmtime_r
                    _inet_ntop
                    _kCFAllocatorDefault
                    _kCFAllocatorSystemDefault
                    _kCFRunLoopDefaultMode
                    _kCFTypeDictionaryKeyCallBacks
                    _kCFTypeDictionaryValueCallBacks
                    _kIOMasterPortDefault
                    _localtime
                    _mach_error_string
                    _malloc
                    _memchr
                    _memcmp
                    _memcpy
                    _memmove
                    _memset
                    _mkstemp
                    _mmap
                    _munmap
                    _open
                    _optarg
                    _optind
                    _perror
                    _posix_spawn
                    _printf
                    _pthread_cancel
                    _pthread_cond_destroy
                    _pthread_cond_init
                    _pthread_cond_signal
                    _pthread_cond_wait
                    _pthread_create
                    _pthread_exit
                    _pthread_join
                    _pthread_kill
                    _pthread_mutex_destroy
                    _pthread_mutex_init
                    _pthread_mutex_lock
                    _pthread_mutex_unlock
                    _pthread_once
                    _pthread_self
                    _putchar
                    _puts
                    _rand
                    _realloc
                    _recv
                    _select
                    _send
                    _setbuf
                    _setenv
                    _setsockopt
                    _shutdown
                    _sleep
                    _snprintf
                    _socket
                    _srand
                    _sscanf
                    _stat
                    _stpncpy
                    _strcasecmp
                    _strchr
                    _strcmp
                    _strcpy
                    _strdup
                    _strerror
                    _strftime
                    _strlen
                    _strncmp
                    _strncpy
                    _strndup
                    _strptime
                    _strrchr
                    _strstr
                    _strtol
                    _strtoull
                    _time
                    _unlink
                    _vasprintf
                    _vprintf
                    _waitpid
                    _write
                    dyld_stub_binder
                    radr://5614542
                    _CFDictionaryCreate
                    _CFDictionarySetValue
                    _CFNumberCreate
                    _CFNumberGetValue
                    _CFRelease
                    _CFRetain
                    _CFRunLoopAddSource
                    _CFRunLoopGetCurrent
                    _CFRunLoopRun
                    _CFRunLoopStop
                    _CFStringCreateWithFormat
                    _CFStringFind
                    _CFStringGetCString
                    _CFUUIDGetConstantUUIDWithBytes
                    _CFUUIDGetUUIDBytes
                    _IOCreatePlugInInterfaceForService
                    _IODestroyPlugInInterface
                    _IOIteratorNext
                    _IONotificationPortCreate
                    _IONotificationPortGetRunLoopSource
                    _IOObjectRelease
                    _IORegistryEntryCreateCFProperty
                    _IORegistryEntryGetRegistryEntryID
                    _IOServiceAddMatchingNotification
                    _IOServiceGetMatchingServices
                    _IOServiceMatching
                    __NSGetExecutablePath
                    ___assert_rtn
                    ___cxa_atexit
                    ___darwin_check_fd_set_overflow
                    ___error
                    ___exp10
                    ___memcpy_chk
                    ___memset_chk
                    ___sprintf_chk
                    ___stack_chk_fail
                    ___strncat_chk
                    ___strncpy_chk
                    ___udivti3
                    _access
                    _asprintf
                    _atof
                    _bzero
                    _calloc
                    _chmod
                    _close
                    _connect
                    _exit
                    _fclose
                    _fcntl
                    _fflush
                    _fopen
                    _fprintf
                    _fputc
                    _fread
                    _free
                    _freeaddrinfo
                    _freeifaddrs
                    _fstat
                    _fwrite
                    _gai_strerror
                    _getaddrinfo
                    _getchar
                    _getenv
                    _getifaddrs
                    _getopt_long
                    _getprogname
                    _getsockopt
                    _gmtime
                    _gmtime_r
                    _inet_ntop
                    _localtime
                    _mach_error_string
                    _malloc
                    _memchr
                    _memcmp
                    _memcpy
                    _memmove
                    _memset
                    _mkstemp
                    _mmap
                    _munmap
                    _open
                    _perror
                    _posix_spawn
                    _printf
                    _pthread_cancel
                    _pthread_cond_destroy
                    _pthread_cond_init
                    _pthread_cond_signal
                    _pthread_cond_wait
                    _pthread_create
                    _pthread_exit
                    _pthread_join
                    _pthread_kill
                    _pthread_mutex_destroy
                    _pthread_mutex_init
                    _pthread_mutex_lock
                    _pthread_mutex_unlock
                    _pthread_once
                    _pthread_self
                    _putchar
                    _puts
                    _rand
                    _realloc
                    _recv
                    _select
                    _send
                    _setbuf
                    _setenv
                    _setsockopt
                    _shutdown
                    _sleep
                    _snprintf
                    _socket
                    _srand
                    _sscanf
                    _stat
                    _stpncpy
                    _strcasecmp
                    _strchr
                    _strcmp
                    _strcpy
                    _strdup
                    _strerror
                    _strftime
                    _strlen
                    _strncmp
                    _strncpy
                    _strndup
                    _strptime
                    _strrchr
                    _strstr
                    _strtol
                    _strtoull
                    _time
                    _unlink
                    _vasprintf
                    _vprintf
                    _waitpid
                    _write

                    Download Network PCAP: filteredfull

                    • Total Packets: 12
                    • 443 (HTTPS)
                    • 80 (HTTP)
                    TimestampSource PortDest PortSource IPDest IP
                    Nov 2, 2023 09:41:58.778693914 CET4937580192.168.11.1117.253.13.207
                    Nov 2, 2023 09:41:58.778956890 CET4937680192.168.11.1123.213.224.212
                    Nov 2, 2023 09:41:58.907910109 CET804937517.253.13.207192.168.11.11
                    Nov 2, 2023 09:41:58.907988071 CET804937623.213.224.212192.168.11.11
                    Nov 2, 2023 09:41:58.909487963 CET4937580192.168.11.1117.253.13.207
                    Nov 2, 2023 09:41:58.909547091 CET4937680192.168.11.1123.213.224.212
                    Nov 2, 2023 09:44:17.397432089 CET49400443192.168.11.11100.22.10.168
                    Nov 2, 2023 09:44:17.397733927 CET44349400100.22.10.168192.168.11.11
                    Nov 2, 2023 09:44:17.399641037 CET49400443192.168.11.11100.22.10.168
                    Nov 2, 2023 09:44:17.400513887 CET49400443192.168.11.11100.22.10.168
                    Nov 2, 2023 09:44:17.400773048 CET44349400100.22.10.168192.168.11.11
                    Nov 2, 2023 09:44:17.858114004 CET44349400100.22.10.168192.168.11.11
                    Nov 2, 2023 09:44:17.860759020 CET49400443192.168.11.11100.22.10.168
                    Nov 2, 2023 09:44:17.860938072 CET49400443192.168.11.11100.22.10.168
                    Nov 2, 2023 09:44:17.893022060 CET49400443192.168.11.11100.22.10.168
                    Nov 2, 2023 09:44:17.893093109 CET44349400100.22.10.168192.168.11.11
                    Nov 2, 2023 09:44:17.893307924 CET44349400100.22.10.168192.168.11.11
                    Nov 2, 2023 09:44:17.893672943 CET49400443192.168.11.11100.22.10.168
                    Nov 2, 2023 09:44:17.893965960 CET49400443192.168.11.11100.22.10.168
                    TimestampSource PortDest PortSource IPDest IP
                    Nov 2, 2023 09:41:55.789163113 CET53525661.1.1.1192.168.11.11
                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                    Nov 2, 2023 09:44:17.393728018 CET1.1.1.1192.168.11.110xfd1fNo error (0)pubingress-feedback-1a6fe9caff1148fe.elb.us-west-2.amazonaws.com100.22.10.168A (IP address)IN (0x0001)false
                    Nov 2, 2023 09:44:17.393728018 CET1.1.1.1192.168.11.110xfd1fNo error (0)pubingress-feedback-1a6fe9caff1148fe.elb.us-west-2.amazonaws.com44.235.78.64A (IP address)IN (0x0001)false
                    Nov 2, 2023 09:44:17.393728018 CET1.1.1.1192.168.11.110xfd1fNo error (0)pubingress-feedback-1a6fe9caff1148fe.elb.us-west-2.amazonaws.com44.232.224.125A (IP address)IN (0x0001)false

                    System Behavior

                    Start time (UTC):08:41:35
                    Start date (UTC):02/11/2023
                    Path:/Library/Frameworks/Mono.framework/Versions/4.4.2/bin/mono-sgen32
                    Arguments:-
                    File size:3722408 bytes
                    MD5 hash:8910349f44a940d8d79318367855b236
                    Start time (UTC):08:41:35
                    Start date (UTC):02/11/2023
                    Path:/Users/berri/Desktop/palera1n-macos-universal
                    Arguments:/Users/berri/Desktop/palera1n-macos-universal
                    File size:9822128 bytes
                    MD5 hash:1ea859eba583e6eab3d377dbb6bc61d7