macOS
Analysis Report
palera1n-macos-universal
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Multi AV Scanner detection for submitted file
Mach-O contains sections with high entropy indicating compressed/encrypted content
Contains symbols with suspicious names likely related to networking
Sample is a FAT Mach-O sample containing binaries for multiple architectures
Classification
Joe Sandbox Version: | 38.0.0 Ammolite |
Analysis ID: | 1335883 |
Start date and time: | 2023-11-02 09:40:34 +01:00 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 4m 40s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultmacfilecookbook.jbs |
Analysis system description: | Virtual Machine, High Sierra (Office 2016 16.16, Java 11.0.2+9, Adobe Reader 2019.010.20099) |
macOS major version: | 10.13 |
CPU architecture: | x86_64 |
Analysis Mode: | default |
Sample file name: | palera1n-macos-universal |
Detection: | MAL |
Classification: | mal48.mac@0/0@0/0 |
- Excluded IPs from analysis (whitelisted): 17.253.13.204, 17.253.13.203, 23.213.225.112, 17.253.13.202, 17.253.13.201, 17.253.13.205, 17.253.12.253, 17.253.6.253, 17.253.12.125, 23.45.33.79
- Excluded domains from analysis (whitelisted): cds-cdn.v.aaplimg.com, e11408.d.akamaiedge.net, cds.apple.com.akadns.net, time-macos.apple.com, ocsp-a.g.aaplimg.com, fbs.smoot.apple.com, cds.apple.com, help-ar.apple.com.edgekey.net, valid.apple.com, lb._dns-sd._udp.0.11.168.192.in-addr.arpa, ocsp-lb.apple.com.akadns.net, ocsp.apple.com, glb-fbs.v.aaplimg.com, valid.origin-apple.com.akadns.net, help.origin-apple.com.akadns.net, valid-apple.g.aaplimg.com, time.g.aaplimg.com, help.apple.com, world-gen.g.aaplimg.com
Command: | /Users/berri/Desktop/palera1n-macos-universal |
PID: | 899 |
Exit Code: | |
Exit Code Info: | |
Killed: | True |
Standard Output: | - [0m[[0;90m11/02/23 09:41:35[0m] [1;36m<Info>[0m: [0;36mWaiting for devices[0m |
Standard Error: | # == palera1n-c == # # Made by: Nick Chan, Ploosh, Samara, Nebula, staturnz, kok3shidoll # # Thanks to: pythonplayer123, llsc12, Mineek, tihmstar, nikias # (libimobiledevice), checkra1n team (Siguza, axi0mx, littlelailo # et al.), Procursus Team (Hayden Seay, Cameron Katri, Keto et.al) |
⊘No yara matches
⊘No Snort rule has matched
- • AV Detection
- • Compliance
- • Networking
- • System Summary
- • Persistence and Installation Behavior
- • Hooking and other Techniques for Hiding and Protection
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Virustotal: | Perma Link |
Source: | HTTPS traffic detected: |
Source: | Mach-O symbol: | ||
Source: | Mach-O symbol: | ||
Source: | Mach-O symbol: | ||
Source: | Mach-O symbol: | ||
Source: | Mach-O symbol: | ||
Source: | Mach-O symbol: | ||
Source: | Mach-O symbol: | ||
Source: | Mach-O symbol: | ||
Source: | Mach-O symbol: | ||
Source: | Mach-O symbol: | ||
Source: | Mach-O symbol: | ||
Source: | Mach-O symbol: | ||
Source: | Mach-O symbol: | ||
Source: | Mach-O symbol: | ||
Source: | Mach-O symbol: | ||
Source: | Mach-O symbol: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | File header: |
Source: | Mach-O header: |
Source: | Mach-O header: | ||
Source: | Mach-O header: |
Source: | CodeSign Info: |
Source: | Submission file: | ||
Source: | Submission file: |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | 1 Invalid Code Signature | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | Exfiltration Over Other Network Medium | 1 Encrypted Channel | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Code Signing | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | 1 Application Layer Protocol | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | Logon Script (Windows) | Logon Script (Windows) | 1 Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | Steganography | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
8% | ReversingLabs | Binary.PUA.Jailbreak | ||
10% | Virustotal | Browse |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
pubingress-feedback-1a6fe9caff1148fe.elb.us-west-2.amazonaws.com | 100.22.10.168 | true | false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
100.22.10.168 | pubingress-feedback-1a6fe9caff1148fe.elb.us-west-2.amazonaws.com | United States | 16509 | AMAZON-02US | false | |
23.213.224.212 | unknown | United States | 5432 | PROXIMUS-ISP-ASBE | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
100.22.10.168 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
pubingress-feedback-1a6fe9caff1148fe.elb.us-west-2.amazonaws.com | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
AMAZON-02US | Get hash | malicious | Mirai, Moobot | Browse |
| |
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
PROXIMUS-ISP-ASBE | Get hash | malicious | Mirai, Moobot | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
3e4e87dda5a3162306609b7e330441d2 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 7.2118151974024745 |
TrID: |
|
File name: | palera1n-macos-universal |
File size: | 9'822'128 bytes |
MD5: | 1ea859eba583e6eab3d377dbb6bc61d7 |
SHA1: | 661aa3fab1be48677244be0e53ec7b91066a8c17 |
SHA256: | 596dedefc9b3771c6e9f7b9a256bfb44330ebdff77936b48cfa8c891825296ed |
SHA512: | ac28c41a18b706f2f531b87b89deb97abb01fa03d756ec60d860c9a26a195318afab195491f93734ed38e152daf433ebf7d122f07463c7b70323460c04eddf81 |
SSDEEP: | 196608:ydfylkmw6+y5s2F+vKO3dfylkmw6+y5s2F+vK:WfW4655NEvHfW4655NEv |
TLSH: | 32A61262EE1C6C24D1C5D1BD994A4B91563BF8718352D3AA3691B33CEFCA6E03179323 |
File Content Preview: | ..................@..J. .............K@..J..................................................................................................................................................................................................................... |
|
General Information for header 1 | |
Endian: | |
Size: | |
Architecture: | |
Filetype: | |
Nbr. of load commands: | 18 |
Entry point: |
Name | Value |
---|---|
segname | __PAGEZERO |
vmaddr | 0x0 |
vmsize | 0x100000000 |
fileoff | 0x0 |
filesize | 0x0 |
maxprot | 0x0 |
initprot | 0x0 |
nsects | 0 |
flags | 0x0 |
Name | Value | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
segname | __TEXT | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
vmaddr | 0x100000000 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
vmsize | 0x80000 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
fileoff | 0x0 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
filesize | 0x80000 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
maxprot | 0x5 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
initprot | 0x5 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
nsects | 8 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
flags | 0x0 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Datas |
|
Name | Value | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
segname | __DATA | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
vmaddr | 0x100080000 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
vmsize | 0x41C000 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
fileoff | 0x80000 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
filesize | 0x41C000 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
maxprot | 0x3 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
initprot | 0x3 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
nsects | 8 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
flags | 0x0 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Datas |
|
Name | Value |
---|---|
segname | __LINKEDIT |
vmaddr | 0x10049C000 |
vmsize | 0x13000 |
fileoff | 0x49C000 |
filesize | 0x12220 |
maxprot | 0x1 |
initprot | 0x1 |
nsects | 0 |
flags | 0x0 |
Name | Value |
---|---|
rebase_off | 4833280 |
rebase_size | 1800 |
bind_off | 4835080 |
bind_size | 416 |
weak_bind_off | 0 |
weak_bind_size | 0 |
lazy_bind_off | 4835496 |
lazy_bind_size | 2832 |
export_off | 4838328 |
export_size | 48 |
Name | Value |
---|---|
symoff | 4839616 |
nsyms | 158 |
stroff | 4843344 |
strsize | 2176 |
Name | Value |
---|---|
ilocalsym | 0 |
nlocalsym | 1 |
iextdefsym | 1 |
nextdefsym | 1 |
iundefsym | 2 |
nundefsym | 156 |
tocoff | 0 |
ntoc | 0 |
modtaboff | 0 |
nmodtab | 0 |
extrefsymoff | 0 |
nextrefsyms | 0 |
indirectsymoff | 4842144 |
nindirectsyms | 299 |
extreloff | 0 |
nextrel | 0 |
locreloff | 0 |
nlocrel | 0 |
Name | Value |
---|---|
name | 12 |
Datas | /usr/lib/dyld |
Name | Value |
---|---|
uuid | b'y\xbd\xd7%q\x9a:z\xa0\xae\x1a\x0e:\xca\x1d\x0c' |
Name | Value |
---|---|
version | 657408 |
sdk | 852224 |
Name | Value |
---|---|
version | 0 |
Name | Value |
---|---|
entryoff | 3020 |
stacksize | 0 |
Name | Value |
---|---|
name | 24 |
timestamp | Thu Jan 1 01:00:02 1970 |
current_version | 1319.0.0 |
compatibility_version | 1.0.0 |
Datas | /usr/lib/libSystem.B.dylib |
Name | Value |
---|---|
name | 24 |
timestamp | Thu Jan 1 01:00:02 1970 |
current_version | 1953.255.0 |
compatibility_version | 150.0.0 |
Datas | /System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation |
Name | Value |
---|---|
name | 24 |
timestamp | Thu Jan 1 01:00:02 1970 |
current_version | 275.0.0 |
compatibility_version | 1.0.0 |
Datas | /System/Library/Frameworks/IOKit.framework/Versions/A/IOKit |
Name | Value |
---|---|
dataoff | 4838376 |
datasize | 848 |
Name | Value |
---|---|
dataoff | 4839224 |
datasize | 392 |
Name | Value |
---|---|
dataoff | 4845520 |
datasize | 62032 |
_CFDictionaryCreate |
_CFDictionarySetValue |
_CFNumberCreate |
_CFNumberGetValue |
_CFRelease |
_CFRetain |
_CFRunLoopAddSource |
_CFRunLoopGetCurrent |
_CFRunLoopRun |
_CFRunLoopStop |
_CFStringCreateWithFormat |
_CFStringFind |
_CFStringGetCString |
_CFUUIDGetConstantUUIDWithBytes |
_CFUUIDGetUUIDBytes |
_IOCreatePlugInInterfaceForService |
_IODestroyPlugInInterface |
_IOIteratorNext |
_IONotificationPortCreate |
_IONotificationPortGetRunLoopSource |
_IOObjectRelease |
_IORegistryEntryCreateCFProperty |
_IORegistryEntryGetRegistryEntryID |
_IOServiceAddMatchingNotification |
_IOServiceGetMatchingServices |
_IOServiceMatching |
__DefaultRuneLocale |
__NSGetExecutablePath |
___CFConstantStringClassReference |
___assert_rtn |
___bzero |
___cxa_atexit |
___darwin_check_fd_set_overflow |
___error |
___memcpy_chk |
___memset_chk |
___sprintf_chk |
___stack_chk_fail |
___stack_chk_guard |
___stderrp |
___stdoutp |
___strncat_chk |
___strncpy_chk |
___udivti3 |
__mh_execute_header |
_access |
_asprintf |
_atof |
_calloc |
_chmod |
_close |
_connect |
_environ |
_exit |
_fclose |
_fcntl |
_fflush |
_fopen |
_fprintf |
_fputc |
_fread |
_free |
_freeaddrinfo |
_freeifaddrs |
_fstat$INODE64 |
_fwrite |
_gai_strerror |
_getaddrinfo |
_getchar |
_getenv |
_getifaddrs |
_getopt_long |
_getprogname |
_getsockopt |
_gmtime |
_gmtime_r |
_inet_ntop |
_kCFAllocatorDefault |
_kCFAllocatorSystemDefault |
_kCFRunLoopDefaultMode |
_kCFTypeDictionaryKeyCallBacks |
_kCFTypeDictionaryValueCallBacks |
_kIOMasterPortDefault |
_localtime |
_mach_error_string |
_malloc |
_memchr |
_memcmp |
_memcpy |
_memmove |
_memset |
_mkstemp |
_mmap |
_munmap |
_open |
_optarg |
_optind |
_perror |
_posix_spawn |
_pow |
_printf |
_pthread_cancel |
_pthread_cond_destroy |
_pthread_cond_init |
_pthread_cond_signal |
_pthread_cond_wait |
_pthread_create |
_pthread_exit |
_pthread_join |
_pthread_kill |
_pthread_mutex_destroy |
_pthread_mutex_init |
_pthread_mutex_lock |
_pthread_mutex_unlock |
_pthread_once |
_pthread_self |
_putchar |
_puts |
_rand |
_realloc |
_recv |
_select$1050 |
_send |
_setbuf |
_setenv |
_setsockopt |
_shutdown |
_sleep |
_snprintf |
_socket |
_srand |
_sscanf |
_stat$INODE64 |
_stpncpy |
_strcasecmp |
_strchr |
_strcmp |
_strcpy |
_strdup |
_strerror |
_strftime |
_strlen |
_strncmp |
_strncpy |
_strndup |
_strptime |
_strrchr |
_strstr |
_strtol |
_strtoull |
_time |
_unlink |
_vasprintf |
_vprintf |
_waitpid |
_write |
dyld_stub_binder |
radr://5614542 |
_CFDictionaryCreate |
_CFDictionarySetValue |
_CFNumberCreate |
_CFNumberGetValue |
_CFRelease |
_CFRetain |
_CFRunLoopAddSource |
_CFRunLoopGetCurrent |
_CFRunLoopRun |
_CFRunLoopStop |
_CFStringCreateWithFormat |
_CFStringFind |
_CFStringGetCString |
_CFUUIDGetConstantUUIDWithBytes |
_CFUUIDGetUUIDBytes |
_IOCreatePlugInInterfaceForService |
_IODestroyPlugInInterface |
_IOIteratorNext |
_IONotificationPortCreate |
_IONotificationPortGetRunLoopSource |
_IOObjectRelease |
_IORegistryEntryCreateCFProperty |
_IORegistryEntryGetRegistryEntryID |
_IOServiceAddMatchingNotification |
_IOServiceGetMatchingServices |
_IOServiceMatching |
__NSGetExecutablePath |
___assert_rtn |
___bzero |
___cxa_atexit |
___darwin_check_fd_set_overflow |
___error |
___memcpy_chk |
___memset_chk |
___sprintf_chk |
___stack_chk_fail |
___strncat_chk |
___strncpy_chk |
___udivti3 |
_access |
_asprintf |
_atof |
_calloc |
_chmod |
_close |
_connect |
_exit |
_fclose |
_fcntl |
_fflush |
_fopen |
_fprintf |
_fputc |
_fread |
_free |
_freeaddrinfo |
_freeifaddrs |
_fstat$INODE64 |
_fwrite |
_gai_strerror |
_getaddrinfo |
_getchar |
_getenv |
_getifaddrs |
_getopt_long |
_getprogname |
_getsockopt |
_gmtime |
_gmtime_r |
_inet_ntop |
_localtime |
_mach_error_string |
_malloc |
_memchr |
_memcmp |
_memcpy |
_memmove |
_memset |
_mkstemp |
_mmap |
_munmap |
_open |
_perror |
_posix_spawn |
_pow |
_printf |
_pthread_cancel |
_pthread_cond_destroy |
_pthread_cond_init |
_pthread_cond_signal |
_pthread_cond_wait |
_pthread_create |
_pthread_exit |
_pthread_join |
_pthread_kill |
_pthread_mutex_destroy |
_pthread_mutex_init |
_pthread_mutex_lock |
_pthread_mutex_unlock |
_pthread_once |
_pthread_self |
_putchar |
_puts |
_rand |
_realloc |
_recv |
_select$1050 |
_send |
_setbuf |
_setenv |
_setsockopt |
_shutdown |
_sleep |
_snprintf |
_socket |
_srand |
_sscanf |
_stat$INODE64 |
_stpncpy |
_strcasecmp |
_strchr |
_strcmp |
_strcpy |
_strdup |
_strerror |
_strftime |
_strlen |
_strncmp |
_strncpy |
_strndup |
_strptime |
_strrchr |
_strstr |
_strtol |
_strtoull |
_time |
_unlink |
_vasprintf |
_vprintf |
_waitpid |
_write |
General Information for header 2 | |
Endian: | |
Size: | |
Architecture: | |
Filetype: | |
Nbr. of load commands: | 19 |
Entry point: |
Name | Value |
---|---|
segname | __PAGEZERO |
vmaddr | 0x0 |
vmsize | 0x100000000 |
fileoff | 0x0 |
filesize | 0x0 |
maxprot | 0x0 |
initprot | 0x0 |
nsects | 0 |
flags | 0x0 |
Name | Value | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
segname | __TEXT | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
vmaddr | 0x100000000 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
vmsize | 0x74000 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
fileoff | 0x0 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
filesize | 0x74000 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
maxprot | 0x5 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
initprot | 0x5 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
nsects | 7 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
flags | 0x0 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Datas |
|
Name | Value | ||||||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
segname | __DATA_CONST | ||||||||||||||||||||||||||||||||||||||||||||||||||
vmaddr | 0x100074000 | ||||||||||||||||||||||||||||||||||||||||||||||||||
vmsize | 0xC000 | ||||||||||||||||||||||||||||||||||||||||||||||||||
fileoff | 0x74000 | ||||||||||||||||||||||||||||||||||||||||||||||||||
filesize | 0xC000 | ||||||||||||||||||||||||||||||||||||||||||||||||||
maxprot | 0x3 | ||||||||||||||||||||||||||||||||||||||||||||||||||
initprot | 0x3 | ||||||||||||||||||||||||||||||||||||||||||||||||||
nsects | 4 | ||||||||||||||||||||||||||||||||||||||||||||||||||
flags | 0x10 | ||||||||||||||||||||||||||||||||||||||||||||||||||
Datas |
|
Name | Value | ||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
segname | __DATA | ||||||||||||||||||||||||||||||||||||||||
vmaddr | 0x100080000 | ||||||||||||||||||||||||||||||||||||||||
vmsize | 0x418000 | ||||||||||||||||||||||||||||||||||||||||
fileoff | 0x80000 | ||||||||||||||||||||||||||||||||||||||||
filesize | 0x418000 | ||||||||||||||||||||||||||||||||||||||||
maxprot | 0x3 | ||||||||||||||||||||||||||||||||||||||||
initprot | 0x3 | ||||||||||||||||||||||||||||||||||||||||
nsects | 3 | ||||||||||||||||||||||||||||||||||||||||
flags | 0x0 | ||||||||||||||||||||||||||||||||||||||||
Datas |
|
Name | Value |
---|---|
segname | __LINKEDIT |
vmaddr | 0x100498000 |
vmsize | 0x14000 |
fileoff | 0x498000 |
filesize | 0x11FB0 |
maxprot | 0x1 |
initprot | 0x1 |
nsects | 0 |
flags | 0x0 |
Name | Value |
---|---|
rebase_off | 4816896 |
rebase_size | 1800 |
bind_off | 4818696 |
bind_size | 400 |
weak_bind_off | 0 |
weak_bind_size | 0 |
lazy_bind_off | 4819096 |
lazy_bind_size | 2800 |
export_off | 4821896 |
export_size | 48 |
Name | Value |
---|---|
symoff | 4822800 |
nsyms | 159 |
stroff | 4826536 |
strsize | 2176 |
Name | Value |
---|---|
ilocalsym | 0 |
nlocalsym | 1 |
iextdefsym | 1 |
nextdefsym | 1 |
iundefsym | 2 |
nundefsym | 157 |
tocoff | 0 |
ntoc | 0 |
modtaboff | 0 |
nmodtab | 0 |
extrefsymoff | 0 |
nextrefsyms | 0 |
indirectsymoff | 4825344 |
nindirectsyms | 298 |
extreloff | 0 |
nextrel | 0 |
locreloff | 0 |
nlocrel | 0 |
Name | Value |
---|---|
name | 12 |
Datas | /usr/lib/dyld |
Name | Value |
---|---|
uuid | b'9\xe7UQ\xfe\xc95\xfd\x80\xa8;\xdd\x1c\xa3\xfe\x03' |
Name | Value |
---|---|
platform | 1 |
minos | 720896 |
sdk | 852224 |
ntools | 1 |
Datas | . |
Name | Value |
---|---|
version | 0 |
Name | Value |
---|---|
entryoff | 13628 |
stacksize | 0 |
Name | Value |
---|---|
name | 24 |
timestamp | Thu Jan 1 01:00:02 1970 |
current_version | 1319.0.0 |
compatibility_version | 1.0.0 |
Datas | /usr/lib/libSystem.B.dylib |
Name | Value |
---|---|
name | 24 |
timestamp | Thu Jan 1 01:00:02 1970 |
current_version | 1953.255.0 |
compatibility_version | 150.0.0 |
Datas | /System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation |
Name | Value |
---|---|
name | 24 |
timestamp | Thu Jan 1 01:00:02 1970 |
current_version | 275.0.0 |
compatibility_version | 1.0.0 |
Datas | /System/Library/Frameworks/IOKit.framework/Versions/A/IOKit |
Name | Value |
---|---|
dataoff | 4821944 |
datasize | 856 |
Name | Value |
---|---|
dataoff | 4822800 |
datasize | 0 |
Name | Value |
---|---|
dataoff | 4828720 |
datasize | 61824 |
_CFDictionaryCreate |
_CFDictionarySetValue |
_CFNumberCreate |
_CFNumberGetValue |
_CFRelease |
_CFRetain |
_CFRunLoopAddSource |
_CFRunLoopGetCurrent |
_CFRunLoopRun |
_CFRunLoopStop |
_CFStringCreateWithFormat |
_CFStringFind |
_CFStringGetCString |
_CFUUIDGetConstantUUIDWithBytes |
_CFUUIDGetUUIDBytes |
_IOCreatePlugInInterfaceForService |
_IODestroyPlugInInterface |
_IOIteratorNext |
_IONotificationPortCreate |
_IONotificationPortGetRunLoopSource |
_IOObjectRelease |
_IORegistryEntryCreateCFProperty |
_IORegistryEntryGetRegistryEntryID |
_IOServiceAddMatchingNotification |
_IOServiceGetMatchingServices |
_IOServiceMatching |
__DefaultRuneLocale |
__NSGetExecutablePath |
___CFConstantStringClassReference |
___assert_rtn |
___chkstk_darwin |
___cxa_atexit |
___darwin_check_fd_set_overflow |
___error |
___exp10 |
___memcpy_chk |
___memset_chk |
___sprintf_chk |
___stack_chk_fail |
___stack_chk_guard |
___stderrp |
___stdoutp |
___strncat_chk |
___strncpy_chk |
___udivti3 |
__mh_execute_header |
_access |
_asprintf |
_atof |
_bzero |
_calloc |
_chmod |
_close |
_connect |
_environ |
_exit |
_fclose |
_fcntl |
_fflush |
_fopen |
_fprintf |
_fputc |
_fread |
_free |
_freeaddrinfo |
_freeifaddrs |
_fstat |
_fwrite |
_gai_strerror |
_getaddrinfo |
_getchar |
_getenv |
_getifaddrs |
_getopt_long |
_getprogname |
_getsockopt |
_gmtime |
_gmtime_r |
_inet_ntop |
_kCFAllocatorDefault |
_kCFAllocatorSystemDefault |
_kCFRunLoopDefaultMode |
_kCFTypeDictionaryKeyCallBacks |
_kCFTypeDictionaryValueCallBacks |
_kIOMasterPortDefault |
_localtime |
_mach_error_string |
_malloc |
_memchr |
_memcmp |
_memcpy |
_memmove |
_memset |
_mkstemp |
_mmap |
_munmap |
_open |
_optarg |
_optind |
_perror |
_posix_spawn |
_printf |
_pthread_cancel |
_pthread_cond_destroy |
_pthread_cond_init |
_pthread_cond_signal |
_pthread_cond_wait |
_pthread_create |
_pthread_exit |
_pthread_join |
_pthread_kill |
_pthread_mutex_destroy |
_pthread_mutex_init |
_pthread_mutex_lock |
_pthread_mutex_unlock |
_pthread_once |
_pthread_self |
_putchar |
_puts |
_rand |
_realloc |
_recv |
_select |
_send |
_setbuf |
_setenv |
_setsockopt |
_shutdown |
_sleep |
_snprintf |
_socket |
_srand |
_sscanf |
_stat |
_stpncpy |
_strcasecmp |
_strchr |
_strcmp |
_strcpy |
_strdup |
_strerror |
_strftime |
_strlen |
_strncmp |
_strncpy |
_strndup |
_strptime |
_strrchr |
_strstr |
_strtol |
_strtoull |
_time |
_unlink |
_vasprintf |
_vprintf |
_waitpid |
_write |
dyld_stub_binder |
radr://5614542 |
_CFDictionaryCreate |
_CFDictionarySetValue |
_CFNumberCreate |
_CFNumberGetValue |
_CFRelease |
_CFRetain |
_CFRunLoopAddSource |
_CFRunLoopGetCurrent |
_CFRunLoopRun |
_CFRunLoopStop |
_CFStringCreateWithFormat |
_CFStringFind |
_CFStringGetCString |
_CFUUIDGetConstantUUIDWithBytes |
_CFUUIDGetUUIDBytes |
_IOCreatePlugInInterfaceForService |
_IODestroyPlugInInterface |
_IOIteratorNext |
_IONotificationPortCreate |
_IONotificationPortGetRunLoopSource |
_IOObjectRelease |
_IORegistryEntryCreateCFProperty |
_IORegistryEntryGetRegistryEntryID |
_IOServiceAddMatchingNotification |
_IOServiceGetMatchingServices |
_IOServiceMatching |
__NSGetExecutablePath |
___assert_rtn |
___cxa_atexit |
___darwin_check_fd_set_overflow |
___error |
___exp10 |
___memcpy_chk |
___memset_chk |
___sprintf_chk |
___stack_chk_fail |
___strncat_chk |
___strncpy_chk |
___udivti3 |
_access |
_asprintf |
_atof |
_bzero |
_calloc |
_chmod |
_close |
_connect |
_exit |
_fclose |
_fcntl |
_fflush |
_fopen |
_fprintf |
_fputc |
_fread |
_free |
_freeaddrinfo |
_freeifaddrs |
_fstat |
_fwrite |
_gai_strerror |
_getaddrinfo |
_getchar |
_getenv |
_getifaddrs |
_getopt_long |
_getprogname |
_getsockopt |
_gmtime |
_gmtime_r |
_inet_ntop |
_localtime |
_mach_error_string |
_malloc |
_memchr |
_memcmp |
_memcpy |
_memmove |
_memset |
_mkstemp |
_mmap |
_munmap |
_open |
_perror |
_posix_spawn |
_printf |
_pthread_cancel |
_pthread_cond_destroy |
_pthread_cond_init |
_pthread_cond_signal |
_pthread_cond_wait |
_pthread_create |
_pthread_exit |
_pthread_join |
_pthread_kill |
_pthread_mutex_destroy |
_pthread_mutex_init |
_pthread_mutex_lock |
_pthread_mutex_unlock |
_pthread_once |
_pthread_self |
_putchar |
_puts |
_rand |
_realloc |
_recv |
_select |
_send |
_setbuf |
_setenv |
_setsockopt |
_shutdown |
_sleep |
_snprintf |
_socket |
_srand |
_sscanf |
_stat |
_stpncpy |
_strcasecmp |
_strchr |
_strcmp |
_strcpy |
_strdup |
_strerror |
_strftime |
_strlen |
_strncmp |
_strncpy |
_strndup |
_strptime |
_strrchr |
_strstr |
_strtol |
_strtoull |
_time |
_unlink |
_vasprintf |
_vprintf |
_waitpid |
_write |
Download Network PCAP: filtered – full
- Total Packets: 12
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 2, 2023 09:41:58.778693914 CET | 49375 | 80 | 192.168.11.11 | 17.253.13.207 |
Nov 2, 2023 09:41:58.778956890 CET | 49376 | 80 | 192.168.11.11 | 23.213.224.212 |
Nov 2, 2023 09:41:58.907910109 CET | 80 | 49375 | 17.253.13.207 | 192.168.11.11 |
Nov 2, 2023 09:41:58.907988071 CET | 80 | 49376 | 23.213.224.212 | 192.168.11.11 |
Nov 2, 2023 09:41:58.909487963 CET | 49375 | 80 | 192.168.11.11 | 17.253.13.207 |
Nov 2, 2023 09:41:58.909547091 CET | 49376 | 80 | 192.168.11.11 | 23.213.224.212 |
Nov 2, 2023 09:44:17.397432089 CET | 49400 | 443 | 192.168.11.11 | 100.22.10.168 |
Nov 2, 2023 09:44:17.397733927 CET | 443 | 49400 | 100.22.10.168 | 192.168.11.11 |
Nov 2, 2023 09:44:17.399641037 CET | 49400 | 443 | 192.168.11.11 | 100.22.10.168 |
Nov 2, 2023 09:44:17.400513887 CET | 49400 | 443 | 192.168.11.11 | 100.22.10.168 |
Nov 2, 2023 09:44:17.400773048 CET | 443 | 49400 | 100.22.10.168 | 192.168.11.11 |
Nov 2, 2023 09:44:17.858114004 CET | 443 | 49400 | 100.22.10.168 | 192.168.11.11 |
Nov 2, 2023 09:44:17.860759020 CET | 49400 | 443 | 192.168.11.11 | 100.22.10.168 |
Nov 2, 2023 09:44:17.860938072 CET | 49400 | 443 | 192.168.11.11 | 100.22.10.168 |
Nov 2, 2023 09:44:17.893022060 CET | 49400 | 443 | 192.168.11.11 | 100.22.10.168 |
Nov 2, 2023 09:44:17.893093109 CET | 443 | 49400 | 100.22.10.168 | 192.168.11.11 |
Nov 2, 2023 09:44:17.893307924 CET | 443 | 49400 | 100.22.10.168 | 192.168.11.11 |
Nov 2, 2023 09:44:17.893672943 CET | 49400 | 443 | 192.168.11.11 | 100.22.10.168 |
Nov 2, 2023 09:44:17.893965960 CET | 49400 | 443 | 192.168.11.11 | 100.22.10.168 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 2, 2023 09:41:55.789163113 CET | 53 | 52566 | 1.1.1.1 | 192.168.11.11 |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 2, 2023 09:44:17.393728018 CET | 1.1.1.1 | 192.168.11.11 | 0xfd1f | No error (0) | 100.22.10.168 | A (IP address) | IN (0x0001) | false | ||
Nov 2, 2023 09:44:17.393728018 CET | 1.1.1.1 | 192.168.11.11 | 0xfd1f | No error (0) | 44.235.78.64 | A (IP address) | IN (0x0001) | false | ||
Nov 2, 2023 09:44:17.393728018 CET | 1.1.1.1 | 192.168.11.11 | 0xfd1f | No error (0) | 44.232.224.125 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 08:41:35 |
Start date (UTC): | 02/11/2023 |
Path: | /Library/Frameworks/Mono.framework/Versions/4.4.2/bin/mono-sgen32 |
Arguments: | - |
File size: | 3722408 bytes |
MD5 hash: | 8910349f44a940d8d79318367855b236 |
Start time (UTC): | 08:41:35 |
Start date (UTC): | 02/11/2023 |
Path: | /Users/berri/Desktop/palera1n-macos-universal |
Arguments: | /Users/berri/Desktop/palera1n-macos-universal |
File size: | 9822128 bytes |
MD5 hash: | 1ea859eba583e6eab3d377dbb6bc61d7 |