Edit tour
macOS
Analysis Report
V6QED2Q1WBYVOPE
Overview
General Information
Detection
Score: | 56 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Mach-O contains sections with high entropy indicating compressed/encrypted content
Sample or dropped file has a small TEXT segment size indicating that the actual code is not in this segment hampering debugging
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1558654 |
Start date and time: | 2024-11-19 17:03:04 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 6s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultmacfilecookbook.jbs |
Analysis system description: | Virtual Machine, Mojave (Office 16 16.27, Java 11.0.2+9, Adobe Reader 2019.010.20099) |
macOS major version: | 10.14 |
CPU architecture: | x86_64 |
Analysis Mode: | default |
Sample name: | V6QED2Q1WBYVOPE |
Detection: | MAL |
Classification: | mal56.mac@0/0@1/0 |
- Excluded IPs from analysis (whitelisted): 17.253.97.205, 17.253.97.201, 17.36.200.79, 17.253.27.196, 17.253.27.204, 17.253.3.198, 23.58.90.40
- Excluded domains from analysis (whitelisted): lcdn-locator-usuqo.apple.com.akadns.net, updates.cdn-apple.com.akadns.net, e673.dsce9.akamaiedge.net, crl.apple.com, lb._dns-sd._udp.0.11.168.192.in-addr.arpa, lcdn-locator.apple.com.akadns.net, lcdn-locator.apple.com, mesu.g.aaplimg.com, updates.g.aaplimg.com, itunes.apple.com.edgekey.net, init.itunes.apple.com, updates.cdn-apple.com, init-cdn.itunes-apple.com.akadns.net
- VT rate limit hit for: V6QED2Q1WBYVOPE
Command: | /Users/bernard/Desktop/V6QED2Q1WBYVOPE |
PID: | 620 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | |
Standard Error: |
- System is macvm-mojave
- mono-sgen32 New Fork (PID: 620, Parent: 537)
- xpcproxy New Fork (PID: 639, Parent: 1)
- cleanup
⊘No yara matches
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | Random device file read: | Jump to behavior |
Source: | Submission file: |
Source: | Mach-O __TEXT segment size: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | 1 Obfuscated Files or Information | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 2 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | OSX/GM.Agent.MB | ||
50% | ReversingLabs | MacOS.Dropper.SAgnt |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
h3.apis.apple.map.fastly.net | 151.101.131.6 | true | false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
151.101.131.6 | h3.apis.apple.map.fastly.net | United States | 54113 | FASTLYUS | false | |
23.48.144.29 | unknown | United States | 20940 | AKAMAI-ASN1EU | false | |
23.195.93.152 | unknown | United States | 16625 | AKAMAI-ASUS | false | |
151.101.67.6 | unknown | United States | 54113 | FASTLYUS | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
151.101.131.6 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
23.48.144.29 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
151.101.67.6 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | CTHULHU STEALER | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
h3.apis.apple.map.fastly.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | CTHULHU STEALER | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
AKAMAI-ASUS | Get hash | malicious | HTMLPhisher | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC, Amadey, Credential Flusher, LummaC Stealer, Stealc, Vidar | Browse |
| ||
Get hash | malicious | PureCrypter, LummaC, Amadey, Credential Flusher, LummaC Stealer, Stealc, Vidar | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
FASTLYUS | Get hash | malicious | Credential Flusher | Browse |
| |
Get hash | malicious | Credential Flusher | Browse |
| ||
Get hash | malicious | Credential Flusher | Browse |
| ||
Get hash | malicious | Credential Flusher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Credential Flusher | Browse |
| ||
Get hash | malicious | Credential Flusher | Browse |
| ||
Get hash | malicious | Credential Flusher | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Credential Flusher | Browse |
| ||
FASTLYUS | Get hash | malicious | Credential Flusher | Browse |
| |
Get hash | malicious | Credential Flusher | Browse |
| ||
Get hash | malicious | Credential Flusher | Browse |
| ||
Get hash | malicious | Credential Flusher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Credential Flusher | Browse |
| ||
Get hash | malicious | Credential Flusher | Browse |
| ||
Get hash | malicious | Credential Flusher | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Credential Flusher | Browse |
| ||
AKAMAI-ASN1EU | Get hash | malicious | Amadey, Cryptbot, Stealc, Vidar | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AsyncRAT | Browse |
| ||
Get hash | malicious | LummaC, Amadey, LummaC Stealer, Stealc, Vidar | Browse |
| ||
Get hash | malicious | PureCrypter, LummaC, Amadey, Credential Flusher, LummaC Stealer, Stealc, Vidar | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
5c118da645babe52f060d0754256a73c | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | CTHULHU STEALER | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 7.999550458092694 |
TrID: |
|
File name: | V6QED2Q1WBYVOPE |
File size: | 9'507'924 bytes |
MD5: | 6dee3bbd2bb0b9de6423700a8e1fe1e8 |
SHA1: | 88537c509c075956ba5d4e1d9fbdd18eaa357e53 |
SHA256: | 1001c1ed209abec59d96e0f27007561c3036c585dd0113ed3cc074bf6a11c105 |
SHA512: | 0f6c7ebb1ae128eba6d1350058f00c026ad58f8d6a4c580fa73cf9eb9b8147581fca957894d4a1c4b1a6f5eb6c2d3264ad155f08551e895f405d5952839b8be7 |
SSDEEP: | 196608:n5v0ZL3vCmgUTRDB397K0AHJuOML1SinMHc85tSygFHQy9VRnQI:nR09sUTb97plOMLTMHc4tPQFPRQI |
TLSH: | 18A6334DE6B32C36F6656274B07E789CB848671E65A1B2E9B0C4F7CD2C40D62C7782C6 |
File Content Preview: | .......................... .........H...__PAGEZERO..........................................................(...__TEXT..........................................................__text..........__TEXT..................*...................................... |
General Information for header 1 | |
Endian: | |
Size: | |
Architecture: | |
Filetype: | |
Nbr. of load commands: | 16 |
Entry point: |
Name | Value |
---|---|
segname | __PAGEZERO |
vmaddr | 0x0 |
vmsize | 0x100000000 |
fileoff | 0x0 |
filesize | 0x0 |
maxprot | 0x0 |
initprot | 0x0 |
nsects | 0 |
flags | 0x0 |
Name | Value | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
segname | __TEXT | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
vmaddr | 0x100000000 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
vmsize | 0x1000 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
fileoff | 0x0 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
filesize | 0x1000 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
maxprot | 0x7 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
initprot | 0x5 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
nsects | 6 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
flags | 0x0 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Datas |
|
Name | Value | ||||||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
segname | __DATA | ||||||||||||||||||||||||||||||||||||||||||||||||||
vmaddr | 0x100001000 | ||||||||||||||||||||||||||||||||||||||||||||||||||
vmsize | 0x910000 | ||||||||||||||||||||||||||||||||||||||||||||||||||
fileoff | 0x1000 | ||||||||||||||||||||||||||||||||||||||||||||||||||
filesize | 0x910000 | ||||||||||||||||||||||||||||||||||||||||||||||||||
maxprot | 0x7 | ||||||||||||||||||||||||||||||||||||||||||||||||||
initprot | 0x3 | ||||||||||||||||||||||||||||||||||||||||||||||||||
nsects | 4 | ||||||||||||||||||||||||||||||||||||||||||||||||||
flags | 0x0 | ||||||||||||||||||||||||||||||||||||||||||||||||||
Datas |
|
Name | Value |
---|---|
segname | __LINKEDIT |
vmaddr | 0x100911000 |
vmsize | 0x1000 |
fileoff | 0x911000 |
filesize | 0x454 |
maxprot | 0x7 |
initprot | 0x1 |
nsects | 0 |
flags | 0x0 |
Name | Value |
---|---|
rebase_off | 9506816 |
rebase_size | 8 |
bind_off | 9506824 |
bind_size | 56 |
weak_bind_off | 0 |
weak_bind_size | 0 |
lazy_bind_off | 9506880 |
lazy_bind_size | 224 |
export_off | 9507104 |
export_size | 80 |
Name | Value |
---|---|
symoff | 9507256 |
nsyms | 20 |
stroff | 9507692 |
strsize | 232 |
Name | Value |
---|---|
ilocalsym | 0 |
nlocalsym | 0 |
iextdefsym | 0 |
nextdefsym | 5 |
iundefsym | 5 |
nundefsym | 15 |
tocoff | 0 |
ntoc | 0 |
modtaboff | 0 |
nmodtab | 0 |
extrefsymoff | 0 |
nextrefsyms | 0 |
indirectsymoff | 9507576 |
nindirectsyms | 29 |
extreloff | 0 |
nextrel | 0 |
locreloff | 0 |
nlocrel | 0 |
Name | Value |
---|
Name | Value |
---|---|
uuid | 331b5ea8-e511-3977-b94a-1f7cc89c9c13 |
Name | Value |
---|---|
version | 10.9.0 |
sdk | 10.9.0 |
Name | Value |
---|---|
path | 0.0.0.0.0 |
Name | Value |
---|
Name | Value |
---|---|
compatibility_version | 1.0.0 |
current_version | 1197.1.1 |
timestamp | 1970-01-01 |
Datas |
Name | Value |
---|---|
dataoff | 9507184 |
datasize | 8 |
Name | Value |
---|---|
dataoff | 9507192 |
datasize | 0 |
Name | Value |
---|---|
dataoff | 9507192 |
datasize | 9507192 |
Name | Category | Origin | Segment Name | Bind Address | Library Name |
---|---|---|---|---|---|
__mh_execute_header | EXTERNAL | LC_SYMTAB | |||
_bytes | EXTERNAL | LC_SYMTAB | |||
_key | EXTERNAL | LC_SYMTAB | |||
_main | EXTERNAL | LC_SYMTAB | |||
_strpos | EXTERNAL | LC_SYMTAB | |||
__NSGetExecutablePath | UNDEFINED | LC_SYMTAB | __DATA | 0x100001018 | /usr/lib/libSystem.B.dylib |
___memset_chk | UNDEFINED | LC_SYMTAB | __DATA | 0x100001020 | /usr/lib/libSystem.B.dylib |
___sprintf_chk | UNDEFINED | LC_SYMTAB | __DATA | 0x100001028 | /usr/lib/libSystem.B.dylib |
___stack_chk_fail | UNDEFINED | LC_SYMTAB | __DATA | 0x100001030 | /usr/lib/libSystem.B.dylib |
___stack_chk_guard | UNDEFINED | LC_SYMTAB | __DATA | 0x100001010 | /usr/lib/libSystem.B.dylib |
___strcat_chk | UNDEFINED | LC_SYMTAB | __DATA | 0x100001038 | /usr/lib/libSystem.B.dylib |
_fclose | UNDEFINED | LC_SYMTAB | __DATA | 0x100001040 | /usr/lib/libSystem.B.dylib |
_fopen | UNDEFINED | LC_SYMTAB | __DATA | 0x100001048 | /usr/lib/libSystem.B.dylib |
_fwrite | UNDEFINED | LC_SYMTAB | __DATA | 0x100001050 | /usr/lib/libSystem.B.dylib |
_malloc | UNDEFINED | LC_SYMTAB | __DATA | 0x100001058 | /usr/lib/libSystem.B.dylib |
_memset | UNDEFINED | LC_SYMTAB | __DATA | 0x100001060 | /usr/lib/libSystem.B.dylib |
_strlen | UNDEFINED | LC_SYMTAB | __DATA | 0x100001068 | /usr/lib/libSystem.B.dylib |
_strstr | UNDEFINED | LC_SYMTAB | __DATA | 0x100001070 | /usr/lib/libSystem.B.dylib |
_system | UNDEFINED | LC_SYMTAB | __DATA | 0x100001078 | /usr/lib/libSystem.B.dylib |
dyld_stub_binder | UNDEFINED | LC_SYMTAB | __DATA | 0x100001000 | /usr/lib/libSystem.B.dylib |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 19, 2024 17:04:39.983302116 CET | 49381 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:39.983345985 CET | 443 | 49381 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:39.983994007 CET | 49381 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:39.984745026 CET | 49381 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:39.984759092 CET | 443 | 49381 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:40.181462049 CET | 443 | 49381 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:40.182219028 CET | 49381 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:40.182586908 CET | 49381 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:40.207413912 CET | 49381 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:40.207528114 CET | 443 | 49381 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:40.207669020 CET | 443 | 49381 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:40.208230972 CET | 49381 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:40.208230972 CET | 49381 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:40.239852905 CET | 49382 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:40.239900112 CET | 443 | 49382 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:40.240586042 CET | 49382 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:40.241601944 CET | 49382 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:40.241616011 CET | 443 | 49382 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:40.437441111 CET | 443 | 49382 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:40.439269066 CET | 49382 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:40.439269066 CET | 49382 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:40.446038961 CET | 49382 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:40.446100950 CET | 443 | 49382 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:40.446192026 CET | 443 | 49382 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:40.446794987 CET | 49382 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:40.446794987 CET | 49382 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:40.463907003 CET | 49383 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:40.463952065 CET | 443 | 49383 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:40.464611053 CET | 49383 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:40.465437889 CET | 49383 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:40.465471983 CET | 443 | 49383 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:40.659374952 CET | 443 | 49383 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:40.661350965 CET | 49383 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:40.661350965 CET | 49383 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:40.667638063 CET | 49383 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:40.667746067 CET | 443 | 49383 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:40.667886019 CET | 443 | 49383 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:40.668436050 CET | 49383 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:40.668654919 CET | 49383 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:40.679480076 CET | 49384 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:40.679523945 CET | 443 | 49384 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:40.680120945 CET | 49384 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:40.681075096 CET | 49384 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:40.681109905 CET | 443 | 49384 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:40.881270885 CET | 443 | 49384 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:40.882145882 CET | 49384 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:40.882145882 CET | 49384 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:40.887540102 CET | 49384 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:40.887768984 CET | 443 | 49384 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:40.888248920 CET | 443 | 49384 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:40.888402939 CET | 49384 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:40.888695002 CET | 49384 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:41.526765108 CET | 49385 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:41.526876926 CET | 443 | 49385 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:41.527611971 CET | 49385 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:41.528840065 CET | 49385 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:41.528901100 CET | 443 | 49385 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:41.731548071 CET | 443 | 49385 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:41.732285976 CET | 49385 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:41.732445955 CET | 49385 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:41.764358997 CET | 49385 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:41.764611959 CET | 443 | 49385 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:41.765049934 CET | 443 | 49385 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:41.765208006 CET | 49385 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:41.765505075 CET | 49385 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:41.824763060 CET | 49386 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:41.824879885 CET | 443 | 49386 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:41.825484037 CET | 49386 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:41.826282978 CET | 49386 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:41.826343060 CET | 443 | 49386 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:42.029242992 CET | 443 | 49386 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:42.030265093 CET | 49386 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:42.030325890 CET | 49386 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:42.039565086 CET | 49386 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:42.039820910 CET | 443 | 49386 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:42.040277958 CET | 443 | 49386 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:42.040381908 CET | 49386 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:42.040849924 CET | 49386 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:42.894253016 CET | 49390 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:42.894376040 CET | 443 | 49390 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:42.895073891 CET | 49390 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:42.895869017 CET | 49390 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:42.895931005 CET | 443 | 49390 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:43.090893030 CET | 443 | 49390 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:43.091991901 CET | 49390 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:43.092138052 CET | 49390 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:43.133562088 CET | 49390 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:43.133666992 CET | 443 | 49390 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:43.133805037 CET | 443 | 49390 | 151.101.67.6 | 192.168.11.12 |
Nov 19, 2024 17:04:43.134464025 CET | 49390 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:04:43.134485006 CET | 49390 | 443 | 192.168.11.12 | 151.101.67.6 |
Nov 19, 2024 17:05:04.818169117 CET | 49347 | 80 | 192.168.11.12 | 23.48.144.29 |
Nov 19, 2024 17:05:04.953430891 CET | 80 | 49347 | 23.48.144.29 | 192.168.11.12 |
Nov 19, 2024 17:05:04.975131989 CET | 80 | 49347 | 23.48.144.29 | 192.168.11.12 |
Nov 19, 2024 17:05:04.975723982 CET | 49347 | 80 | 192.168.11.12 | 23.48.144.29 |
Nov 19, 2024 17:05:09.134529114 CET | 49353 | 443 | 192.168.11.12 | 23.195.93.152 |
Nov 19, 2024 17:05:09.136161089 CET | 49353 | 443 | 192.168.11.12 | 23.195.93.152 |
Nov 19, 2024 17:05:09.250516891 CET | 443 | 49353 | 23.195.93.152 | 192.168.11.12 |
Nov 19, 2024 17:05:09.250530958 CET | 443 | 49353 | 23.195.93.152 | 192.168.11.12 |
Nov 19, 2024 17:05:09.252394915 CET | 49353 | 443 | 192.168.11.12 | 23.195.93.152 |
Nov 19, 2024 17:05:09.252394915 CET | 49353 | 443 | 192.168.11.12 | 23.195.93.152 |
Nov 19, 2024 17:06:10.590363979 CET | 49394 | 443 | 192.168.11.12 | 151.101.131.6 |
Nov 19, 2024 17:06:10.590418100 CET | 443 | 49394 | 151.101.131.6 | 192.168.11.12 |
Nov 19, 2024 17:06:10.591047049 CET | 49394 | 443 | 192.168.11.12 | 151.101.131.6 |
Nov 19, 2024 17:06:10.591871977 CET | 49394 | 443 | 192.168.11.12 | 151.101.131.6 |
Nov 19, 2024 17:06:10.591897964 CET | 443 | 49394 | 151.101.131.6 | 192.168.11.12 |
Nov 19, 2024 17:06:10.786360979 CET | 443 | 49394 | 151.101.131.6 | 192.168.11.12 |
Nov 19, 2024 17:06:10.787170887 CET | 49394 | 443 | 192.168.11.12 | 151.101.131.6 |
Nov 19, 2024 17:06:10.787193060 CET | 49394 | 443 | 192.168.11.12 | 151.101.131.6 |
Nov 19, 2024 17:06:10.794425011 CET | 49394 | 443 | 192.168.11.12 | 151.101.131.6 |
Nov 19, 2024 17:06:10.794500113 CET | 443 | 49394 | 151.101.131.6 | 192.168.11.12 |
Nov 19, 2024 17:06:10.794631004 CET | 443 | 49394 | 151.101.131.6 | 192.168.11.12 |
Nov 19, 2024 17:06:10.795140982 CET | 49394 | 443 | 192.168.11.12 | 151.101.131.6 |
Nov 19, 2024 17:06:10.795165062 CET | 49394 | 443 | 192.168.11.12 | 151.101.131.6 |
Nov 19, 2024 17:06:10.811619043 CET | 49395 | 443 | 192.168.11.12 | 151.101.131.6 |
Nov 19, 2024 17:06:10.811674118 CET | 443 | 49395 | 151.101.131.6 | 192.168.11.12 |
Nov 19, 2024 17:06:10.812325954 CET | 49395 | 443 | 192.168.11.12 | 151.101.131.6 |
Nov 19, 2024 17:06:10.813126087 CET | 49395 | 443 | 192.168.11.12 | 151.101.131.6 |
Nov 19, 2024 17:06:10.813146114 CET | 443 | 49395 | 151.101.131.6 | 192.168.11.12 |
Nov 19, 2024 17:06:11.007011890 CET | 443 | 49395 | 151.101.131.6 | 192.168.11.12 |
Nov 19, 2024 17:06:11.007785082 CET | 49395 | 443 | 192.168.11.12 | 151.101.131.6 |
Nov 19, 2024 17:06:11.007931948 CET | 49395 | 443 | 192.168.11.12 | 151.101.131.6 |
Nov 19, 2024 17:06:11.012516022 CET | 49395 | 443 | 192.168.11.12 | 151.101.131.6 |
Nov 19, 2024 17:06:11.012590885 CET | 443 | 49395 | 151.101.131.6 | 192.168.11.12 |
Nov 19, 2024 17:06:11.012723923 CET | 443 | 49395 | 151.101.131.6 | 192.168.11.12 |
Nov 19, 2024 17:06:11.013242006 CET | 49395 | 443 | 192.168.11.12 | 151.101.131.6 |
Nov 19, 2024 17:06:11.013326883 CET | 49395 | 443 | 192.168.11.12 | 151.101.131.6 |
Nov 19, 2024 17:06:11.040772915 CET | 49396 | 443 | 192.168.11.12 | 151.101.131.6 |
Nov 19, 2024 17:06:11.040828943 CET | 443 | 49396 | 151.101.131.6 | 192.168.11.12 |
Nov 19, 2024 17:06:11.041523933 CET | 49396 | 443 | 192.168.11.12 | 151.101.131.6 |
Nov 19, 2024 17:06:11.042443037 CET | 49396 | 443 | 192.168.11.12 | 151.101.131.6 |
Nov 19, 2024 17:06:11.042486906 CET | 443 | 49396 | 151.101.131.6 | 192.168.11.12 |
Nov 19, 2024 17:06:11.237250090 CET | 443 | 49396 | 151.101.131.6 | 192.168.11.12 |
Nov 19, 2024 17:06:11.237991095 CET | 49396 | 443 | 192.168.11.12 | 151.101.131.6 |
Nov 19, 2024 17:06:11.238013983 CET | 49396 | 443 | 192.168.11.12 | 151.101.131.6 |
Nov 19, 2024 17:06:11.243618965 CET | 49396 | 443 | 192.168.11.12 | 151.101.131.6 |
Nov 19, 2024 17:06:11.243695021 CET | 443 | 49396 | 151.101.131.6 | 192.168.11.12 |
Nov 19, 2024 17:06:11.243828058 CET | 443 | 49396 | 151.101.131.6 | 192.168.11.12 |
Nov 19, 2024 17:06:11.244362116 CET | 49396 | 443 | 192.168.11.12 | 151.101.131.6 |
Nov 19, 2024 17:06:11.244389057 CET | 49396 | 443 | 192.168.11.12 | 151.101.131.6 |
Nov 19, 2024 17:06:11.258131981 CET | 49397 | 443 | 192.168.11.12 | 151.101.131.6 |
Nov 19, 2024 17:06:11.258192062 CET | 443 | 49397 | 151.101.131.6 | 192.168.11.12 |
Nov 19, 2024 17:06:11.259218931 CET | 49397 | 443 | 192.168.11.12 | 151.101.131.6 |
Nov 19, 2024 17:06:11.260046005 CET | 49397 | 443 | 192.168.11.12 | 151.101.131.6 |
Nov 19, 2024 17:06:11.260071993 CET | 443 | 49397 | 151.101.131.6 | 192.168.11.12 |
Nov 19, 2024 17:06:11.453663111 CET | 443 | 49397 | 151.101.131.6 | 192.168.11.12 |
Nov 19, 2024 17:06:11.454425097 CET | 49397 | 443 | 192.168.11.12 | 151.101.131.6 |
Nov 19, 2024 17:06:11.454514027 CET | 49397 | 443 | 192.168.11.12 | 151.101.131.6 |
Nov 19, 2024 17:06:11.460832119 CET | 49397 | 443 | 192.168.11.12 | 151.101.131.6 |
Nov 19, 2024 17:06:11.460903883 CET | 443 | 49397 | 151.101.131.6 | 192.168.11.12 |
Nov 19, 2024 17:06:11.461041927 CET | 443 | 49397 | 151.101.131.6 | 192.168.11.12 |
Nov 19, 2024 17:06:11.461571932 CET | 49397 | 443 | 192.168.11.12 | 151.101.131.6 |
Nov 19, 2024 17:06:11.461663961 CET | 49397 | 443 | 192.168.11.12 | 151.101.131.6 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 19, 2024 17:04:28.405605078 CET | 53 | 52458 | 1.1.1.1 | 192.168.11.12 |
Nov 19, 2024 17:06:10.492904902 CET | 63909 | 53 | 192.168.11.12 | 1.1.1.1 |
Nov 19, 2024 17:06:10.588174105 CET | 53 | 63909 | 1.1.1.1 | 192.168.11.12 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 19, 2024 17:06:10.492904902 CET | 192.168.11.12 | 1.1.1.1 | 0x362e | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 19, 2024 17:06:10.588174105 CET | 1.1.1.1 | 192.168.11.12 | 0x362e | No error (0) | 151.101.131.6 | A (IP address) | IN (0x0001) | false | ||
Nov 19, 2024 17:06:10.588174105 CET | 1.1.1.1 | 192.168.11.12 | 0x362e | No error (0) | 151.101.67.6 | A (IP address) | IN (0x0001) | false | ||
Nov 19, 2024 17:06:10.588174105 CET | 1.1.1.1 | 192.168.11.12 | 0x362e | No error (0) | 151.101.3.6 | A (IP address) | IN (0x0001) | false | ||
Nov 19, 2024 17:06:10.588174105 CET | 1.1.1.1 | 192.168.11.12 | 0x362e | No error (0) | 151.101.195.6 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 16:04:17 |
Start date (UTC): | 19/11/2024 |
Path: | /Library/Frameworks/Mono.framework/Versions/4.4.2/bin/mono-sgen32 |
Arguments: | - |
File size: | 3722408 bytes |
MD5 hash: | 8910349f44a940d8d79318367855b236 |
Start time (UTC): | 16:04:17 |
Start date (UTC): | 19/11/2024 |
Path: | /Users/bernard/Desktop/V6QED2Q1WBYVOPE |
Arguments: | /Users/bernard/Desktop/V6QED2Q1WBYVOPE |
File size: | 9507924 bytes |
MD5 hash: | 6dee3bbd2bb0b9de6423700a8e1fe1e8 |
Start time (UTC): | 16:04:48 |
Start date (UTC): | 19/11/2024 |
Path: | /usr/libexec/xpcproxy |
Arguments: | - |
File size: | 44048 bytes |
MD5 hash: | 4764d9eafe6b7dac23253a9f8b7f73d6 |
Start time (UTC): | 16:04:48 |
Start date (UTC): | 19/11/2024 |
Path: | /usr/libexec/firmwarecheckers/eficheck/eficheck |
Arguments: | /usr/libexec/firmwarecheckers/eficheck/eficheck --integrity-check-daemon |
File size: | 74048 bytes |
MD5 hash: | 328beb81a2263449258057506bb4987f |