macOS Analysis Report
CapCut_7376205375613272081_installer.dmg

Overview

General Information

Sample name: CapCut_7376205375613272081_installer.dmg
Analysis ID: 1466526
MD5: 1fce5d25462b93618fc8fabee0349021
SHA1: 26895b70fa6911ce088f93c9bb15e3a84f8a77e2
SHA256: f3569a8226b3ec687da41ed5710fae7043f824f29ad1c9cde58a36190c25e541
Infos:

Detection

Score: 52
Range: 0 - 100
Whitelisted: false

Signatures

Searches for passwords in macOS's keychain
Executes the "security" command used to access the keychain
Contains symbols with paths
Contains symbols with suspicious names likely related to networking
Queries for attached disk images with shell command 'hdiutil'
Reads hardware related sysctl values
Reads the sysctl safe boot value (probably to check if the system is in safe boot mode)
Reads the systems OS release and/or type
Reads the systems hostname
Uses Security framework containing interfaces for system-level user authentication and authorization

Classification

Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: __ZN15ShellDownloader27ReportClickLanguageSpecificEP8NSStringl
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: __ZN15ShellDownloader24ReportPopInstalledWindowE24PopInstalledWindowAction
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: __ZN15ShellDownloader27ReportClickLanguageSpecificEP8NSStringl
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: __ZN15ShellDownloader24ReportPopInstalledWindowE24PopInstalledWindowAction
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: __ZN15ShellDownloader21ReportPopCancelWindowE23PopuCancelWindowpActionii
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: __ZN15ShellDownloader21ReportPopCancelWindowE23PopuCancelWindowpActionii
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: __ZN15ShellDownloader20ReportInstallsStatusE16DownloaderStatusiiP8NSString
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: __ZN15ShellDownloader20ReportInstallsStatusE16DownloaderStatusiiP8NSString
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: __ZN15ShellDownloader17ReportInstallTimeEi
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: __ZN15ShellDownloader17ReportInstallTimeEi
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: __ZN12_GLOBAL__N_135g_destory_shell_event_reporter_funcE
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: __ZN12_GLOBAL__N_135g_destory_shell_event_reporter_funcE
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: __ZN12_GLOBAL__N_119g_reporter_test_urlE
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: __ZN12_GLOBAL__N_119g_reporter_test_urlE
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: __ZN12_GLOBAL__N_114g_reporter_urlE
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: __ZN12_GLOBAL__N_114g_reporter_urlE
Source: /Volumes/CapCut Downloader/CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader (PID: 631) Reads from socket in process: data
Source: CapCut-Downloader String found in binary or memory: http://certs.apple.com/devidg2.der02
Source: CapCut_7376205375613272081_installer.dmg String found in binary or memory: http://crl.apple.com/applerootcag3.crl0
Source: CapCut-Downloader, 00000631.00000278.1.00000001112fa000.0000000111323000.r--.sdmp, CapCut-Downloader, 00000631.00000278.1.00000001063ec000.00000001063ef000.r--.sdmp String found in binary or memory: http://crl.apple.com/codesigning.crl0
Source: CapCut-Downloader String found in binary or memory: http://crl.apple.com/root.crl0
Source: CapCut-Downloader String found in binary or memory: http://crl.apple.com/timestamp.crl0
Source: CapCut-Downloader String found in binary or memory: http://ocsp.apple.com/ocsp03-applerootca0.
Source: CapCut_7376205375613272081_installer.dmg String found in binary or memory: http://ocsp.apple.com/ocsp03-applerootcag307
Source: CapCut_7376205375613272081_installer.dmg String found in binary or memory: http://ocsp.apple.com/ocsp03-asica4020
Source: CapCut-Downloader String found in binary or memory: http://ocsp.apple.com/ocsp03-devidg2010
Source: CapCut-Downloader, CodeResources String found in binary or memory: http://www.apple.com/DTDs/PropertyList-1.0.dtd
Source: CapCut-Downloader, 00000631.00000278.1.00000001112fa000.0000000111323000.r--.sdmp, CapCut-Downloader, 00000631.00000278.1.00000001063ec000.00000001063ef000.r--.sdmp String found in binary or memory: http://www.apple.com/appleca/root.crl0
Source: CapCut-Downloader String found in binary or memory: http://www.apple.com/appleca0
Source: CapCut-Downloader, 00000631.00000278.1.00000001112fa000.0000000111323000.r--.sdmp, CapCut-Downloader, 00000631.00000278.1.00000001063ec000.00000001063ef000.r--.sdmp String found in binary or memory: http://www.apple.com/certificateauthority0
Source: CapCut-Downloader, 00000631.00000278.1.00000001045e0000.0000000104797000.r--.sdmp String found in binary or memory: http://www.apple.com/http://www.apple.com/Copyright
Source: CapCut-Downloader, 00000631.00000278.1.00000001027f3000.0000000102a1d000.r-x.sdmp String found in binary or memory: https://curl.se/docs/alt-svc.html
Source: CapCut-Downloader, 00000631.00000278.1.00000001027f3000.0000000102a1d000.r-x.sdmp String found in binary or memory: https://curl.se/docs/hsts.html
Source: CapCut-Downloader, 00000631.00000278.1.00000001027f3000.0000000102a1d000.r-x.sdmp String found in binary or memory: https://curl.se/docs/http-cookies.html
Source: CapCut-Downloader, 00000631.00000278.1.00000001027f3000.0000000102a1d000.r-x.sdmp String found in binary or memory: https://editor-api-sg.capcut.com
Source: CapCut-Downloader, 00000631.00000278.1.00000001027f3000.0000000102a1d000.r-x.sdmp String found in binary or memory: https://editor-api-sg.capcut.com/service/2/app_alert_check/
Source: CapCut-Downloader, 00000631.00000278.1.00000001027f3000.0000000102a1d000.r-x.sdmp String found in binary or memory: https://editor-api-sg.capcut.com/service/2/desktop/device_register/
Source: CapCut-Downloader String found in binary or memory: https://editor-api.capcutapi.com/service/2/app_alert_check/
Source: CapCut-Downloader String found in binary or memory: https://editor-api.capcutapi.com/service/2/desktop/device_register/
Source: CapCut-Downloader String found in binary or memory: https://editor-api.capcutapi.com/service/2/desktop/device_register/https://editor-api.capcutapi.com/
Source: CapCut-Downloader String found in binary or memory: https://lf16-capcut.faceulv.com/obj/capcutpc-packages-us/packages/CapCut_2_6_0_834_capcutpc_0_creato
Source: CapCut-Downloader, 00000631.00000278.1.00000001027f3000.0000000102a1d000.r-x.sdmp String found in binary or memory: https://maliva-mcs.byteoversea.com
Source: CapCut-Downloader String found in binary or memory: https://mcs.byteoversea.net/v1/json_test
Source: CapCut-Downloader, 00000631.00000278.1.00000001027f3000.0000000102a1d000.r-x.sdmp String found in binary or memory: https://sgali-mcs.byteoversea.com
Source: CapCut-Downloader String found in binary or memory: https://sgali-mcs.byteoversea.com/v1/json
Source: CapCut-Downloader String found in binary or memory: https://www.apple.com/appleca/0
Source: CapCut-Downloader String found in binary or memory: https://www.apple.com/certificateauthority/0
Source: /Volumes/CapCut Downloader/CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader (PID: 631) Writes from socket in process: data
Source: classification engine Classification label: mal52.spyw.macDMG@0/16@0/0
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/appdownloader/MainWindow/MainWindowPages/
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/appdownloader/
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/appdownloader/Downloader/
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/appdownloader/FlatButton/
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/appdownloader/MainWindow/
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/appdownloader/MainWindow/
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/appdownloader/MainWindow/
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/appdownloader/MainWindow/MainWindowPages/
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/appdownloader/MainWindow/MainWindowPages/
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/appdownloader/
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/appdownloader/MessageBox/
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/appdownloader/RFOverlayScrollView/
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/appdownloader/RFOverlayScrollView/
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/appdownloader/MessageBox/
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/appdownloader/MessageBox/
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/appdownloader/MessageBox/
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/appdownloader/MessageBox/
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/appdownloader/MessageBox/
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/appdownloader/MessageBox/
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/appdownloader/MessageBox/
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/build/Build/Intermediates.noindex/appdownloader.build/Release/appdownloader.build/Objects-normal/x86_64/AppDelegate.o
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/build/Build/Intermediates.noindex/appdownloader.build/Release/appdownloader.build/Objects-normal/x86_64/BorderlessWindow.o
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/appdownloader/TTBanner/
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/appdownloader/TTBanner/
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/appdownloader/TTBanner/
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/appdownloader/TTBanner/
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/appdownloader/TTBanner/
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/appdownloader/TTBanner/
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/appdownloader/TTBanner/
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/appdownloader/TTProgressBar/
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/build/Build/Intermediates.noindex/appdownloader.build/Release/appdownloader.build/Objects-normal/x86_64/MultiLangViewController.o
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/build/Build/Intermediates.noindex/appdownloader.build/Release/appdownloader.build/Objects-normal/x86_64/InitPageViewController.o
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/build/Build/Intermediates.noindex/appdownloader.build/Release/appdownloader.build/Objects-normal/x86_64/InstallPageViewController.o
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/build/Build/Intermediates.noindex/appdownloader.build/Release/appdownloader.build/Objects-normal/x86_64/MainWindowController.o
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/build/Build/Intermediates.noindex/appdownloader.build/Release/appdownloader.build/Objects-normal/x86_64/MainWindowViewController.o
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/build/Build/Intermediates.noindex/appdownloader.build/Release/appdownloader.build/Objects-normal/x86_64/MsgBoxController.o
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/build/Build/Intermediates.noindex/appdownloader.build/Release/appdownloader.build/Objects-normal/x86_64/MsgBoxViewController.o
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/build/Build/Intermediates.noindex/appdownloader.build/Release/appdownloader.build/Objects-normal/x86_64/MultiLangBoxController.o
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/build/Build/Intermediates.noindex/appdownloader.build/Release/appdownloader.build/Objects-normal/x86_64/MultiLangItemView.o
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/build/Build/Intermediates.noindex/appdownloader.build/Release/appdownloader.build/Objects-normal/x86_64/DownloadPageViewController.o
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/build/Build/Intermediates.noindex/appdownloader.build/Release/appdownloader.build/Objects-normal/x86_64/PageIndicatorView.o
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/build/Build/Intermediates.noindex/appdownloader.build/Release/appdownloader.build/Objects-normal/x86_64/RFOverlayScrollView.o
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/build/Build/Intermediates.noindex/appdownloader.build/Release/appdownloader.build/Objects-normal/x86_64/RFOverlayScroller.o
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/build/Build/Intermediates.noindex/appdownloader.build/Release/appdownloader.build/Objects-normal/x86_64/ShellDownloader.o
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/build/Build/Intermediates.noindex/appdownloader.build/Release/appdownloader.build/Objects-normal/x86_64/TTBanner.o
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/build/Build/Intermediates.noindex/appdownloader.build/Release/appdownloader.build/Objects-normal/x86_64/TTBannerItem.o
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/build/Build/Intermediates.noindex/appdownloader.build/Release/appdownloader.build/Objects-normal/x86_64/TTBannerItemView.o
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/build/Build/Intermediates.noindex/appdownloader.build/Release/appdownloader.build/Objects-normal/x86_64/TTButton.o
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/build/Build/Intermediates.noindex/appdownloader.build/Release/appdownloader.build/Objects-normal/x86_64/MutiLangListItem.o
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/build/Build/Intermediates.noindex/appdownloader.build/Release/appdownloader.build/Objects-normal/x86_64/PageIndicatorController.o
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/build/Build/Intermediates.noindex/appdownloader.build/Release/appdownloader.build/Objects-normal/x86_64/TTNoScrollBannerItem.o
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/build/Build/Intermediates.noindex/appdownloader.build/Release/appdownloader.build/Objects-normal/x86_64/TTProgressBar.o
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/build/Build/Intermediates.noindex/appdownloader.build/Release/appdownloader.build/Objects-normal/x86_64/main.o
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/build/Build/Intermediates.noindex/appdownloader.build/Release/appdownloader.build/Objects-normal/x86_64/TTFakeNSAlertController.o
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/build/Build/Intermediates.noindex/appdownloader.build/Release/appdownloader.build/Objects-normal/x86_64/TTFakeNSAlertViewController.o
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O symbol: /Users/iOS_2_6_hyva_bbcrj_qnqka/38814/mac_installer_downlaoder/build/Build/Intermediates.noindex/appdownloader.build/Release/appdownloader.build/Objects-normal/x86_64/TTNoScrollBanner.o
Source: /Volumes/CapCut Downloader/CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader (PID: 631) Hdiutil command executed: /usr/bin/hdiutil info
Source: /usr/bin/security (PID: 634) Security framework info plist opened: /System/Library/Frameworks/Security.framework/Resources/Info.plist
Source: extracted file from DMG submission CodeResources XML file: CapCut-Downloader.app/Contents/_CodeSignature/CodeResources
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O header: load_dylib -> /System/Library/Frameworks/AVFoundation.framework/Versions/A/AVFoundation
Source: extracted file from submission: CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader Mach-O header: load_dylib -> /System/Library/Frameworks/AppKit.framework/Versions/C/AppKit
Source: /Volumes/CapCut Downloader/CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader (PID: 631) AppleKeyboardLayouts info plist opened: /System/Library/Keyboard Layouts/AppleKeyboardLayouts.bundle/Contents/Info.plist Jump to behavior
Source: CapCut-Downloader, 00000631.00000278.1.0000000102aa4000.0000000102aaa000.r--.sdmp Binary or memory string: framework.vmnet
Source: app_package_447fdc9fc7.zip.278.dr Binary or memory string: PhgFs
Source: CapCut-Downloader, 00000631.00000278.1.0000000102aa4000.0000000102aaa000.r--.sdmp Binary or memory string: framework.vmnet$
Source: app_package_447fdc9fc7.zip.278.dr Binary or memory string: 7tQeMU
Source: app_package_447fdc9fc7.zip.278.dr Binary or memory string: y0FhGfS
Source: /Volumes/CapCut Downloader/CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader (PID: 631) Sysctl read request: kern.safeboot (1.66)
Source: /Volumes/CapCut Downloader/CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader (PID: 631) Sysctl read request: hw.ncpu (6.3)
Source: /Volumes/CapCut Downloader/CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader (PID: 631) Sysctl read request: hw.availcpu (6.25)
Source: /Volumes/CapCut Downloader/CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader (PID: 631) Sysctl requested: kern.ostype (1.1)
Source: /Volumes/CapCut Downloader/CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader (PID: 631) Sysctl requested: kern.osrelease (1.2)
Source: /Volumes/CapCut Downloader/CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader (PID: 631) Sysctl requested: kern.hostname (1.10)
Source: /usr/bin/open (PID: 630) System or server version plist file read: /System/Library/CoreServices/SystemVersion.plist Jump to behavior
Source: /Volumes/CapCut Downloader/CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader (PID: 631) System or server version plist file read: /System/Library/CoreServices/SystemVersion.plist Jump to behavior

Stealing of Sensitive Information

barindex
Source: /Volumes/CapCut Downloader/CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader (PID: 631) Security executable: /usr/bin/security /usr/bin/security find-generic-password -s CapCutWebInfoId -a WebInfoId
Source: /Volumes/CapCut Downloader/CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader (PID: 631) Security executable: /usr/bin/security /usr/bin/security find-generic-password -s CapCutWebInfoId -a WebInfoId
Source: /Volumes/CapCut Downloader/CapCut-Downloader.app/Contents/MacOS/CapCut-Downloader (PID: 631) Security executable: /usr/bin/security /usr/bin/security add-generic-password -a WebInfoId -s CapCutWebInfoId -w CapCut_7376205375613272081_installer -U -T /usr/bin/security
No contacted IP infos