Loading Joe Sandbox Report ...

Edit tour

macOS Analysis Report
CGESrv

Overview

General Information

Sample name:CGESrv
Analysis ID:1578045
MD5:f0d721e663f6e3a2fafd2a27ef95cee0
SHA1:1ddefc194d322e23e480f6143b958dffe6bae21f
SHA256:c8df7fb1bed859df3932704053bf581482b33bed6effc5ef1f2a2efebdfd2396
Infos:

Detection

CobaltStrike
Score:56
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Yara detected CobaltStrike
Contains symbols with suspicious names likely related to anti-analysis
Contains symbols with suspicious names likely related to networking

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1578045
Start date and time:2024-12-19 08:04:43 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 2s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultmacfilecookbook.jbs
Analysis system description:Virtual Machine, Mojave (Office 16 16.27, Java 11.0.2+9, Adobe Reader 2019.010.20099)
macOS major version:10.14
CPU architecture:x86_64
Analysis Mode:default
Sample name:CGESrv
Detection:MAL
Classification:mal56.troj.mac@0/0@1/0
  • Excluded IPs from analysis (whitelisted): 17.253.7.131, 17.253.49.201, 17.253.1.204, 17.253.127.134, 17.253.5.203, 17.253.83.198, 17.253.21.205, 17.253.85.202, 17.253.54.197, 17.253.7.134, 17.253.7.145, 17.36.200.79, 17.253.7.135, 17.253.7.142, 23.202.144.19, 17.253.7.136
  • Excluded domains from analysis (whitelisted): lcdn-locator-usuqo.apple.com.akadns.net, updates.cdn-apple.com.akadns.net, e673.dsce9.akamaiedge.net, crl.apple.com, lb._dns-sd._udp.0.11.168.192.in-addr.arpa, lcdn-locator.apple.com.akadns.net, lcdn-locator.apple.com, mesu.g.aaplimg.com, updates.g.aaplimg.com, itunes.apple.com.edgekey.net, init.itunes.apple.com, mesu.apple.com, updates.cdn-apple.com, init-cdn.itunes-apple.com.akadns.net
  • VT rate limit hit for: https://api.jieyafei.comtracecheckstackownershiphash
Command:/Users/bernard/Desktop/CGESrv
PID:620
Exit Code:134
Exit Code Info:SIGABRT (6) Abort signal from abort
Killed:False
Standard Output:

Standard Error:dyld: cannot load 'CGESrv' (load command 0x80000034 is unknown)
  • System is macvm-mojave
  • CGESrv (MD5: f0d721e663f6e3a2fafd2a27ef95cee0) Arguments: /Users/bernard/Desktop/CGESrv
  • eficheck (MD5: 328beb81a2263449258057506bb4987f) Arguments: /usr/libexec/firmwarecheckers/eficheck/eficheck --integrity-check-daemon
  • cleanup
SourceRuleDescriptionAuthorStrings
CGESrvJoeSecurity_CobaltStrike_6Yara detected CobaltStrikeJoe Security
    No Suricata rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: CGESrvVirustotal: Detection: 36%Perma Link
    Source: CGESrvReversingLabs: Detection: 18%
    Source: unknownHTTPS traffic detected: 151.101.131.6:443 -> 192.168.11.12:49385 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 151.101.131.6:443 -> 192.168.11.12:49386 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 151.101.131.6:443 -> 192.168.11.12:49390 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 151.101.131.6:443 -> 192.168.11.12:49391 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 151.101.131.6:443 -> 192.168.11.12:49392 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 151.101.131.6:443 -> 192.168.11.12:49393 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 151.101.131.6:443 -> 192.168.11.12:49394 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 151.101.67.6:443 -> 192.168.11.12:49395 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 151.101.67.6:443 -> 192.168.11.12:49396 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 151.101.67.6:443 -> 192.168.11.12:49397 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 151.101.67.6:443 -> 192.168.11.12:49398 version: TLS 1.2
    Source: submission: CGESrvMach-O symbol: _connect
    Source: submission: CGESrvMach-O symbol: _sendfile
    Source: submission: CGESrvMach-O symbol: _socket
    Source: submission: CGESrvMach-O symbol: _setsockopt
    Source: submission: CGESrvMach-O symbol: _getsockopt
    Source: submission: CGESrvMach-O symbol: _getsockname
    Source: unknownTCP traffic detected without corresponding DNS query: 23.202.144.197
    Source: unknownTCP traffic detected without corresponding DNS query: 23.202.144.197
    Source: unknownTCP traffic detected without corresponding DNS query: 23.207.53.102
    Source: unknownTCP traffic detected without corresponding DNS query: 23.207.53.102
    Source: unknownTCP traffic detected without corresponding DNS query: 23.207.53.102
    Source: unknownTCP traffic detected without corresponding DNS query: 23.207.53.102
    Source: unknownTCP traffic detected without corresponding DNS query: 23.207.53.102
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: global trafficDNS traffic detected: DNS query: h3.apis.apple.map.fastly.net
    Source: CGESrvString found in binary or memory: https://api.jieyafei.comtracecheckstackownershiphash
    Source: CGESrvString found in binary or memory: https://www.baidu.com/integer
    Source: unknownNetwork traffic detected: HTTP traffic on port 49397 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49386
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49385
    Source: unknownNetwork traffic detected: HTTP traffic on port 49393 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49395 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49391 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49386 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49398 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49354
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49398
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49397
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49396
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49395
    Source: unknownNetwork traffic detected: HTTP traffic on port 49394 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49394
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49393
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49392
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49391
    Source: unknownNetwork traffic detected: HTTP traffic on port 49354 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49396 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49390
    Source: unknownNetwork traffic detected: HTTP traffic on port 49392 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49390 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49385 -> 443
    Source: unknownHTTPS traffic detected: 151.101.131.6:443 -> 192.168.11.12:49385 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 151.101.131.6:443 -> 192.168.11.12:49386 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 151.101.131.6:443 -> 192.168.11.12:49390 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 151.101.131.6:443 -> 192.168.11.12:49391 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 151.101.131.6:443 -> 192.168.11.12:49392 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 151.101.131.6:443 -> 192.168.11.12:49393 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 151.101.131.6:443 -> 192.168.11.12:49394 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 151.101.67.6:443 -> 192.168.11.12:49395 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 151.101.67.6:443 -> 192.168.11.12:49396 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 151.101.67.6:443 -> 192.168.11.12:49397 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 151.101.67.6:443 -> 192.168.11.12:49398 version: TLS 1.2

    E-Banking Fraud

    barindex
    Source: Yara matchFile source: CGESrv, type: SAMPLE
    Source: classification engineClassification label: mal56.troj.mac@0/0@1/0
    Source: submission: CGESrvMach-O header: load_dylib -> /System/Library/Frameworks/Security.framework/Versions/A/Security
    Source: /usr/libexec/firmwarecheckers/eficheck/eficheck (PID: 640)Random device file read: /dev/randomJump to behavior
    Source: submission: CGESrvMach-O symbol: _ptrace
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
    Virtualization/Sandbox Evasion
    OS Credential Dumping1
    Virtualization/Sandbox Evasion
    Remote ServicesData from Local System2
    Encrypted Channel
    Exfiltration Over Other Network MediumAbuse Accessibility Features
    CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
    Non-Application Layer Protocol
    Exfiltration Over BluetoothNetwork Denial of Service
    Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
    Application Layer Protocol
    Automated ExfiltrationData Encrypted for Impact
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Shell
    • Is malicious
    • Internet

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.


    cam-macmac-stand
    SourceDetectionScannerLabelLink
    CGESrv37%VirustotalBrowse
    CGESrv18%ReversingLabsMacOS.Trojan.CobaltStrike
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    NameIPActiveMaliciousAntivirus DetectionReputation
    h3.apis.apple.map.fastly.net
    151.101.3.6
    truefalse
      high
      NameSourceMaliciousAntivirus DetectionReputation
      https://www.baidu.com/integerCGESrvfalse
        high
        https://api.jieyafei.comtracecheckstackownershiphashCGESrvfalse
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          23.202.144.197
          unknownUnited States
          1273CWVodafoneGroupPLCEUfalse
          23.207.53.102
          unknownUnited States
          16625AKAMAI-ASUSfalse
          151.101.131.6
          unknownUnited States
          54113FASTLYUSfalse
          151.101.67.6
          unknownUnited States
          54113FASTLYUSfalse
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          151.101.131.6https://ivsmn.kidsavancados.com/Get hashmaliciousUnknownBrowse
            https://fastbposolutions.com/language/overrides/message.alibaba.com/login.alibaba-com/saexy7ktc4fw1k7zk9xpnx19.phpGet hashmaliciousUnknownBrowse
              http://eocf.jyjwohl.ru/KIOJOJMAIEJFLVSF280212193270471103367JIGUHOIIAX4RQ0SVD?beunjabnkfaakr796013636449016227029WA5LIQI5PMNQO0EETORGet hashmaliciousUnknownBrowse
                https://commandes.maisonetstyles.com/Short/?Verification=aalborz_02@yahoo.comGet hashmaliciousUnknownBrowse
                  aJU0obOiEeGet hashmaliciousUnknownBrowse
                    V6QED2Q1WBYVOPEGet hashmaliciousUnknownBrowse
                      https://henrybodmerabeggco.wordpress.com/abegg-co-ag-proposal/Get hashmaliciousUnknownBrowse
                        V6QED2Q1WBYVOPEGet hashmaliciousUnknownBrowse
                          CalendlyAppGet hashmaliciousUnknownBrowse
                            https://burlingtonenqlish.com/vm%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20/Get hashmaliciousUnknownBrowse
                              151.101.67.618037.docGet hashmaliciousUnknownBrowse
                                https://docs.google.com/presentation/d/e/2PACX-1vTBMx4bSFDj_B_GCJTdTqUpVgpLXyQPR3uFGYP9j81KKHswOSbzMWDM5ZByYtVAwpACe-iOzHmzehje/pub?start=false&loop=false&delayms=3000Get hashmaliciousUnknownBrowse
                                  TelegramGet hashmaliciousUnknownBrowse
                                    http://eocf.jyjwohl.ru/KIOJOJMAIEJFLVSF280212193270471103367JIGUHOIIAX4RQ0SVD?beunjabnkfaakr796013636449016227029WA5LIQI5PMNQO0EETORGet hashmaliciousUnknownBrowse
                                      https://commandes.maisonetstyles.com/Short/?Verification=aalborz_02@yahoo.comGet hashmaliciousUnknownBrowse
                                        V6QED2Q1WBYVOPEGet hashmaliciousUnknownBrowse
                                          V6QED2Q1WBYVOPEGet hashmaliciousUnknownBrowse
                                            CalendlyAppGet hashmaliciousUnknownBrowse
                                              ConstateGet hashmaliciousUnknownBrowse
                                                iB8UZgdjgkGet hashmaliciousCTHULHU STEALERBrowse
                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                  h3.apis.apple.map.fastly.net18037.docGet hashmaliciousUnknownBrowse
                                                  • 151.101.3.6
                                                  TelegramGet hashmaliciousUnknownBrowse
                                                  • 151.101.3.6
                                                  http://eocf.jyjwohl.ru/KIOJOJMAIEJFLVSF280212193270471103367JIGUHOIIAX4RQ0SVD?beunjabnkfaakr796013636449016227029WA5LIQI5PMNQO0EETORGet hashmaliciousUnknownBrowse
                                                  • 151.101.131.6
                                                  https://commandes.maisonetstyles.com/Short/?Verification=aalborz_02@yahoo.comGet hashmaliciousUnknownBrowse
                                                  • 151.101.3.6
                                                  V6QED2Q1WBYVOPEGet hashmaliciousUnknownBrowse
                                                  • 151.101.131.6
                                                  https://henrybodmerabeggco.wordpress.com/abegg-co-ag-proposal/Get hashmaliciousUnknownBrowse
                                                  • 151.101.195.6
                                                  https://my.toruftuiov.com/a43a39c3-796e-468c-aae4-b83c862e0918Get hashmaliciousUnknownBrowse
                                                  • 151.101.3.6
                                                  V6QED2Q1WBYVOPEGet hashmaliciousUnknownBrowse
                                                  • 151.101.131.6
                                                  CalendlyAppGet hashmaliciousUnknownBrowse
                                                  • 151.101.131.6
                                                  CalendlyAppGet hashmaliciousUnknownBrowse
                                                  • 151.101.195.6
                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                  AKAMAI-ASUS1.elfGet hashmaliciousUnknownBrowse
                                                  • 23.57.220.59
                                                  la.bot.mips.elfGet hashmaliciousMiraiBrowse
                                                  • 23.211.7.47
                                                  la.bot.sparc.elfGet hashmaliciousMiraiBrowse
                                                  • 23.199.141.119
                                                  la.bot.arm.elfGet hashmaliciousMiraiBrowse
                                                  • 23.13.44.108
                                                  la.bot.sh4.elfGet hashmaliciousMiraiBrowse
                                                  • 23.50.132.247
                                                  http://files.playanext.com/v8/avast_secure_browser_setup.exeGet hashmaliciousUnknownBrowse
                                                  • 23.50.252.137
                                                  la.bot.mipsel.elfGet hashmaliciousMiraiBrowse
                                                  • 104.98.7.134
                                                  loligang.sh4.elfGet hashmaliciousMiraiBrowse
                                                  • 23.60.108.117
                                                  loligang.mips.elfGet hashmaliciousMiraiBrowse
                                                  • 23.209.249.233
                                                  loligang.x86.elfGet hashmaliciousMiraiBrowse
                                                  • 172.230.179.94
                                                  FASTLYUSfile.exeGet hashmaliciousAmadey, LummaC Stealer, PureLog Stealer, RHADAMANTHYSBrowse
                                                  • 185.199.111.133
                                                  https://pdf.ac/4lLzbtGet hashmaliciousUnknownBrowse
                                                  • 151.101.129.44
                                                  file.exeGet hashmaliciousLummaC, Amadey, LummaC Stealer, RHADAMANTHYS, XmrigBrowse
                                                  • 185.199.110.133
                                                  https://www.bing.com/ck/a?!&&p=24da94b1cbc4e30be5abd9acb5737b3bdb775a56c39aac0141dd9c17c937dea1JmltdHM9MTczMzI3MDQwMA&ptn=3&ver=2&hsh=4&fclid=1bf8b81c-3b95-652f-24ec-ad573a81643b&u=a1aHR0cHM6Ly93d3cueXV4aW5na2V0YW5nLmNvbS9jb2xsZWN0aW9ucy90aHJvdy1ibGFua2V0cw#aHR0cHM6Ly9Uby5lZW1qaGl1bHoucnUvek83UkZORy8=Get hashmaliciousUnknownBrowse
                                                  • 151.101.2.137
                                                  https://www.bing.com/ck/a?!&&p=24da94b1cbc4e30be5abd9acb5737b3bdb775a56c39aac0141dd9c17c937dea1JmltdHM9MTczMzI3MDQwMA&ptn=3&ver=2&hsh=4&fclid=1bf8b81c-3b95-652f-24ec-ad573a81643b&u=a1aHR0cHM6Ly93d3cueXV4aW5na2V0YW5nLmNvbS9jb2xsZWN0aW9ucy90aHJvdy1ibGFua2V0cw#aHR0cHM6Ly9Uby5lZW1qaGl1bHoucnUvek83UkZORy8=Get hashmaliciousUnknownBrowse
                                                  • 151.101.194.137
                                                  vRecord__0064secs__warriorsheart.com.htmlGet hashmaliciousUnknownBrowse
                                                  • 151.101.194.137
                                                  https://fm.blebsions.com/R7tS/Get hashmaliciousUnknownBrowse
                                                  • 151.101.194.137
                                                  file.exeGet hashmaliciousLummaC, Amadey, LummaC Stealer, XmrigBrowse
                                                  • 185.199.111.133
                                                  https://www.asda.com@hnvs.xyz/asda-christmas-prizesGet hashmaliciousUnknownBrowse
                                                  • 199.232.196.193
                                                  https://vCyA.warmickmak.ru/PrEvJj/Get hashmaliciousUnknownBrowse
                                                  • 151.101.66.137
                                                  CWVodafoneGroupPLCEUla.bot.m68k.elfGet hashmaliciousMiraiBrowse
                                                  • 217.135.227.46
                                                  jew.sh4.elfGet hashmaliciousUnknownBrowse
                                                  • 62.208.195.84
                                                  https://dot.itsecuritymessages.com/45sf4657dvz4hn/afc6c7/00179cbf-581d-4c00-98d3-bf1104b204adGet hashmaliciousUnknownBrowse
                                                  • 2.16.149.71
                                                  Tbconsulting Company Guidelines Employee Handbook.docxGet hashmaliciousUnknownBrowse
                                                  • 92.122.101.59
                                                  mips.elfGet hashmaliciousUnknownBrowse
                                                  • 159.197.33.131
                                                  ppc.elfGet hashmaliciousUnknownBrowse
                                                  • 62.208.171.35
                                                  IGz.mips.elfGet hashmaliciousMiraiBrowse
                                                  • 195.44.6.179
                                                  arm5.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                  • 141.1.87.10
                                                  mipsel.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                  • 194.177.185.230
                                                  sh4.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                  • 217.135.102.136
                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                  5c118da645babe52f060d0754256a73chttps://ivsmn.kidsavancados.com/Get hashmaliciousUnknownBrowse
                                                  • 151.101.131.6
                                                  • 151.101.67.6
                                                  18037.docGet hashmaliciousUnknownBrowse
                                                  • 151.101.131.6
                                                  • 151.101.67.6
                                                  https://docs.google.com/presentation/d/e/2PACX-1vTBMx4bSFDj_B_GCJTdTqUpVgpLXyQPR3uFGYP9j81KKHswOSbzMWDM5ZByYtVAwpACe-iOzHmzehje/pub?start=false&loop=false&delayms=3000Get hashmaliciousUnknownBrowse
                                                  • 151.101.131.6
                                                  • 151.101.67.6
                                                  TelegramGet hashmaliciousUnknownBrowse
                                                  • 151.101.131.6
                                                  • 151.101.67.6
                                                  https://fastbposolutions.com/language/overrides/message.alibaba.com/login.alibaba-com/saexy7ktc4fw1k7zk9xpnx19.phpGet hashmaliciousUnknownBrowse
                                                  • 151.101.131.6
                                                  • 151.101.67.6
                                                  http://eocf.jyjwohl.ru/KIOJOJMAIEJFLVSF280212193270471103367JIGUHOIIAX4RQ0SVD?beunjabnkfaakr796013636449016227029WA5LIQI5PMNQO0EETORGet hashmaliciousUnknownBrowse
                                                  • 151.101.131.6
                                                  • 151.101.67.6
                                                  https://commandes.maisonetstyles.com/Short/?Verification=aalborz_02@yahoo.comGet hashmaliciousUnknownBrowse
                                                  • 151.101.131.6
                                                  • 151.101.67.6
                                                  aJU0obOiEeGet hashmaliciousUnknownBrowse
                                                  • 151.101.131.6
                                                  • 151.101.67.6
                                                  V6QED2Q1WBYVOPEGet hashmaliciousUnknownBrowse
                                                  • 151.101.131.6
                                                  • 151.101.67.6
                                                  V6QED2Q1WBYVOPEGet hashmaliciousUnknownBrowse
                                                  • 151.101.131.6
                                                  • 151.101.67.6
                                                  No context
                                                  No created / dropped files found
                                                  File type:Mach-O 64-bit x86_64 executable, flags:<NOUNDEFS|DYLDLINK|TWOLEVEL|PIE>
                                                  Entropy (8bit):6.229387812290317
                                                  TrID:
                                                  • Mac OS X Mach-O 64-bit Intel executable (4008/2) 50.02%
                                                  • Mac OS X Mach-O 64-bit executable (little-endian) (4004/1) 49.98%
                                                  File name:CGESrv
                                                  File size:6'749'072 bytes
                                                  MD5:f0d721e663f6e3a2fafd2a27ef95cee0
                                                  SHA1:1ddefc194d322e23e480f6143b958dffe6bae21f
                                                  SHA256:c8df7fb1bed859df3932704053bf581482b33bed6effc5ef1f2a2efebdfd2396
                                                  SHA512:b98b9aa717a33b7967f3c7762543bb2c8ffe54811a8c18c8cec7cda9892aabc3d81405f059fa5008921a2575e290b7cab950c7966864f78e4656d340b3abf53d
                                                  SSDEEP:98304:LuZodBjNDcDii+1u+meFcEh7JnQ0pfxrRIM:akC2i+qcVRrV
                                                  TLSH:DA662A47EC9505F5C0AE923089B692537AB17C484B3127D36B90F7383F76BD0AAB9B50
                                                  File Content Preview:.......................... .........H...__PAGEZERO..........................................................(...__TEXT....................9...............9.....................__text..........__TEXT..................%.0....................................
                                                  General Information for header 1
                                                  Endian:little-endian
                                                  Size:64-bit
                                                  Architecture:x86_64
                                                  Filetype:execute
                                                  Nbr. of load commands:20
                                                  Entry point:0x100071D20
                                                  NameValue
                                                  segname__PAGEZERO
                                                  vmaddr0x0
                                                  vmsize0x100000000
                                                  fileoff0x0
                                                  filesize0x0
                                                  maxprot0x0
                                                  initprot0x0
                                                  nsects0
                                                  flags0x0
                                                  NameValue
                                                  segname__TEXT
                                                  vmaddr0x100000000
                                                  vmsize0x39E000
                                                  fileoff0x0
                                                  filesize0x39E000
                                                  maxprot0x5
                                                  initprot0x5
                                                  nsects6
                                                  flags0x0
                                                  Datas
                                                  sectnamesegnameaddrsizeoffsetentropyalignreloffnrelocflags
                                                  __text__TEXT0x1000014000x308B250x14006.1940710550x000x80000400
                                                  __stubs__TEXT0x100309F250x32A0x309F253.8023806900x000x80000400
                                                  __rodata__TEXT0x10030A2600x93C250x30A2605.3165912550x000x0
                                                  __cstring__TEXT0x10039DE850x9A0x39DE854.5300489200x000x0
                                                  __const__TEXT0x10039DF200x80x39DF20-0.0000000030x000x0
                                                  __unwind_info__TEXT0x10039DF280xC80x39DF283.7135039720x000x0
                                                  NameValue
                                                  segname__DATA_CONST
                                                  vmaddr0x10039E000
                                                  vmsize0x28A000
                                                  fileoff0x39E000
                                                  filesize0x28A000
                                                  maxprot0x3
                                                  initprot0x3
                                                  nsects5
                                                  flags0x10
                                                  Datas
                                                  sectnamesegnameaddrsizeoffsetentropyalignreloffnrelocflags
                                                  __got__DATA_CONST0x10039E0000x4400x39E0002.4069301330x000x0
                                                  __rodata__DATA_CONST0x10039E4400xAC9C00x39E4404.3311397650x000x0
                                                  __typelink__DATA_CONST0x10044AE000x1F3C0x44AE005.1092358150x000x0
                                                  __itablink__DATA_CONST0x10044CD400xCE80x44CD403.3461145850x000x0
                                                  __gopclntab__DATA_CONST0x10044DA400x1D97B00x44DA406.0655170950x000x0
                                                  NameValue
                                                  segname__DATA
                                                  vmaddr0x100628000
                                                  vmsize0x6A000
                                                  fileoff0x628000
                                                  filesize0x42000
                                                  maxprot0x3
                                                  initprot0x3
                                                  nsects6
                                                  flags0x0
                                                  Datas
                                                  sectnamesegnameaddrsizeoffsetentropyalignreloffnrelocflags
                                                  __data__DATA0x1006280000xFD200x6280002.0728519150x000x0
                                                  __go_buildinfo__DATA0x100637D200x4000x637D205.8973346340x000x0
                                                  __noptrdata__DATA0x1006381200x310E20x6381206.0115180050x000x0
                                                  __bss__DATA0x1006692200x228A00x00.0000000050x000x0
                                                  __noptrbss__DATA0x10068BAC00x61400x00.0000000050x000x0
                                                  __common__DATA0x100691C000x100x00.0000000030x000x0
                                                  NameValue
                                                  segname__LINKEDIT
                                                  vmaddr0x100692000
                                                  vmsize0x6000
                                                  fileoff0x66A000
                                                  filesize0x5B90
                                                  maxprot0x1
                                                  initprot0x1
                                                  nsects0
                                                  flags0x0
                                                  NameValue
                                                  dataoff6725632
                                                  datasize2960
                                                  NameValue
                                                  dataoff6728592
                                                  datasize1040
                                                  NameValue
                                                  symoff6742128
                                                  nsyms178
                                                  stroff6746064
                                                  strsize3008
                                                  NameValue
                                                  ilocalsym0
                                                  nlocalsym0
                                                  iextdefsym0
                                                  nextdefsym41
                                                  iundefsym41
                                                  nundefsym137
                                                  tocoff0
                                                  ntoc0
                                                  modtaboff0
                                                  nmodtab0
                                                  extrefsymoff0
                                                  nextrefsyms0
                                                  indirectsymoff6744976
                                                  nindirectsyms271
                                                  extreloff0
                                                  nextrel0
                                                  locreloff0
                                                  nlocrel0
                                                  NameValue
                                                  NameValue
                                                  uuid968fbc8d-8c6d-fd8c-f2f2-7e94f37e13dc
                                                  NameValue
                                                  NameValue
                                                  path0.0.0.0.0
                                                  NameValue
                                                  NameValue
                                                  compatibility_version1.0.0
                                                  current_version1.0.0
                                                  timestamp1970-01-01
                                                  Datas/usr/lib/libresolv.9.dylib
                                                  NameValue
                                                  compatibility_version1.0.0
                                                  current_version1345.100.2
                                                  timestamp1970-01-01
                                                  Datas/usr/lib/libSystem.B.dylib
                                                  NameValue
                                                  compatibility_version150.0.0
                                                  current_version2420.0.0
                                                  timestamp1970-01-01
                                                  Datas/System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation
                                                  NameValue
                                                  compatibility_version1.0.0
                                                  current_version61123.100.169
                                                  timestamp1970-01-01
                                                  Datas/System/Library/Frameworks/Security.framework/Versions/A/Security
                                                  NameValue
                                                  dataoff6729632
                                                  datasize12496
                                                  NameValue
                                                  dataoff6742128
                                                  datasize0
                                                  NameCategoryOriginSegment NameBind AddressLibrary Name
                                                  __cgo_534629aae644_C2func_proc_pidinfoEXTERNALLC_SYMTAB
                                                  __cgo_534629aae644_C2func_proc_pidpathEXTERNALLC_SYMTAB
                                                  __cgo_534629aae644_C2func_sysctlEXTERNALLC_SYMTAB
                                                  __cgo_534629aae644_Cfunc__CmallocEXTERNALLC_SYMTAB
                                                  __cgo_534629aae644_Cfunc_freeEXTERNALLC_SYMTAB
                                                  __cgo_534629aae644_Cfunc_mach_timebase_infoEXTERNALLC_SYMTAB
                                                  __cgo_534629aae644_Cfunc_memcpyEXTERNALLC_SYMTAB
                                                  __cgo_534629aae644_Cfunc_proc_pidinfoEXTERNALLC_SYMTAB
                                                  __cgo_534629aae644_Cfunc_proc_pidpathEXTERNALLC_SYMTAB
                                                  __cgo_534629aae644_Cfunc_sysctlEXTERNALLC_SYMTAB
                                                  __cgo_534629aae644_Cmacro_NULLEXTERNALLC_SYMTAB
                                                  __cgo_60d741e58028_Cfunc_host_processor_infoEXTERNALLC_SYMTAB
                                                  __cgo_60d741e58028_Cfunc_host_statisticsEXTERNALLC_SYMTAB
                                                  __cgo_60d741e58028_Cfunc_mach_host_selfEXTERNALLC_SYMTAB
                                                  __cgo_60d741e58028_Cfunc_vm_deallocateEXTERNALLC_SYMTAB
                                                  __cgo_f12645b68d2f_Cfunc_host_statisticsEXTERNALLC_SYMTAB
                                                  __cgo_f12645b68d2f_Cfunc_mach_host_selfEXTERNALLC_SYMTAB
                                                  __cgo_get_context_functionEXTERNALLC_SYMTAB
                                                  __cgo_panicEXTERNALLC_SYMTAB
                                                  __cgo_release_contextEXTERNALLC_SYMTAB
                                                  __cgo_set_stackloEXTERNALLC_SYMTAB
                                                  __cgo_sys_thread_startEXTERNALLC_SYMTAB
                                                  __cgo_topofstackEXTERNALLC_SYMTAB
                                                  __cgo_try_pthread_createEXTERNALLC_SYMTAB
                                                  __cgo_wait_runtime_init_doneEXTERNALLC_SYMTAB
                                                  __cgo_yieldEXTERNALLC_SYMTAB
                                                  __mh_execute_headerEXTERNALLC_SYMTAB
                                                  _crosscall1EXTERNALLC_SYMTAB
                                                  _crosscall2EXTERNALLC_SYMTAB
                                                  _x_cgo_bindmEXTERNALLC_SYMTAB
                                                  _x_cgo_callersEXTERNALLC_SYMTAB
                                                  _x_cgo_getstackboundEXTERNALLC_SYMTAB
                                                  _x_cgo_initEXTERNALLC_SYMTAB
                                                  _x_cgo_notify_runtime_init_doneEXTERNALLC_SYMTAB
                                                  _x_cgo_pthread_key_createdEXTERNALLC_SYMTAB
                                                  _x_cgo_set_context_functionEXTERNALLC_SYMTAB
                                                  _x_cgo_setenvEXTERNALLC_SYMTAB
                                                  _x_cgo_sys_thread_createEXTERNALLC_SYMTAB
                                                  _x_cgo_thread_startEXTERNALLC_SYMTAB
                                                  _x_cgo_unsetenvEXTERNALLC_SYMTAB
                                                  _x_crosscall2_ptrEXTERNALLC_SYMTAB
                                                  _CFArrayAppendValueUNDEFINEDLC_SYMTAB__DATA_CONST0x0/System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation
                                                  _CFArrayCreateMutableUNDEFINEDLC_SYMTAB__DATA_CONST0x0/System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation
                                                  _CFArrayGetCountUNDEFINEDLC_SYMTAB__DATA_CONST0x0/System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation
                                                  _CFArrayGetValueAtIndexUNDEFINEDLC_SYMTAB__DATA_CONST0x0/System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation
                                                  _CFDataCreateUNDEFINEDLC_SYMTAB__DATA_CONST0x0/System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation
                                                  _CFDataGetBytePtrUNDEFINEDLC_SYMTAB__DATA_CONST0x0/System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation
                                                  _CFDataGetLengthUNDEFINEDLC_SYMTAB__DATA_CONST0x0/System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation
                                                  _CFDateCreateUNDEFINEDLC_SYMTAB__DATA_CONST0x0/System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation
                                                  _CFErrorCopyDescriptionUNDEFINEDLC_SYMTAB__DATA_CONST0x0/System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation
                                                  _CFErrorGetCodeUNDEFINEDLC_SYMTAB__DATA_CONST0x0/System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation
                                                  _CFReleaseUNDEFINEDLC_SYMTAB__DATA_CONST0x0/System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation
                                                  _CFStringCreateExternalRepresentationUNDEFINEDLC_SYMTAB__DATA_CONST0x0/System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation
                                                  _CFStringCreateWithBytesUNDEFINEDLC_SYMTAB__DATA_CONST0x0/System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation
                                                  _SecCertificateCopyDataUNDEFINEDLC_SYMTAB__DATA_CONST0x0/System/Library/Frameworks/Security.framework/Versions/A/Security
                                                  _SecCertificateCreateWithDataUNDEFINEDLC_SYMTAB__DATA_CONST0x0/System/Library/Frameworks/Security.framework/Versions/A/Security
                                                  _SecPolicyCreateSSLUNDEFINEDLC_SYMTAB__DATA_CONST0x0/System/Library/Frameworks/Security.framework/Versions/A/Security
                                                  _SecTrustCreateWithCertificatesUNDEFINEDLC_SYMTAB__DATA_CONST0x0/System/Library/Frameworks/Security.framework/Versions/A/Security
                                                  _SecTrustEvaluateWithErrorUNDEFINEDLC_SYMTAB__DATA_CONST0x0/System/Library/Frameworks/Security.framework/Versions/A/Security
                                                  _SecTrustGetCertificateAtIndexUNDEFINEDLC_SYMTAB__DATA_CONST0x0/System/Library/Frameworks/Security.framework/Versions/A/Security
                                                  _SecTrustGetCertificateCountUNDEFINEDLC_SYMTAB__DATA_CONST0x0/System/Library/Frameworks/Security.framework/Versions/A/Security
                                                  _SecTrustSetVerifyDateUNDEFINEDLC_SYMTAB__DATA_CONST0x0/System/Library/Frameworks/Security.framework/Versions/A/Security
                                                  ___errorUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  ___stderrpUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _abortUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _acceptUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _arc4random_bufUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _bindUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _chdirUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _chmodUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _chrootUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _clock_gettimeUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _closeUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _closedirUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _connectUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _dupUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _dup2UNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _execveUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _exitUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _faccessatUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _fcntlUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _fdopendir$INODE64UNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _forkUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _fprintfUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _freeUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _freeaddrinfoUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _fstat64UNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _fwriteUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _gai_strerrorUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _getaddrinfoUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _getcwdUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _getpeernameUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _getpidUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _getpwuid_rUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _getrlimitUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _getsocknameUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _getsockoptUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _getuidUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _host_processor_infoUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _host_statisticsUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _ioctlUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _issetugidUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _keventUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _killUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _kqueueUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _listenUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _lseekUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _lstat64UNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _mach_absolute_timeUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _mach_host_selfUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _mach_task_self_UNDEFINEDLC_SYMTAB__DATA0x0/usr/lib/libSystem.B.dylib
                                                  _mach_timebase_infoUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _madviseUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _mallocUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _memcpyUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _mkdirUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _mmapUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _munmapUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _nanosleepUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _notify_is_valid_tokenUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _openUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _openatUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _pathconfUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _pipeUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _proc_pidinfoUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _proc_pidpathUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _pthread_attr_getstacksizeUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _pthread_attr_initUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _pthread_attr_setdetachstateUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _pthread_attr_setstacksizeUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _pthread_cond_broadcastUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _pthread_cond_initUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _pthread_cond_signalUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _pthread_cond_timedwait_relative_npUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _pthread_cond_waitUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _pthread_createUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _pthread_detachUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _pthread_get_stackaddr_npUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _pthread_get_stacksize_npUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _pthread_key_createUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _pthread_killUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _pthread_mutex_initUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _pthread_mutex_lockUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _pthread_mutex_unlockUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _pthread_selfUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _pthread_setspecificUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _pthread_sigmaskUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _ptraceUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _raiseUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _readUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _readdir_r$INODE64UNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _readlinkUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _renameUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _rmdirUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _sendfileUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _setenvUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _setgidUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _setgroupsUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _setpgidUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _setrlimitUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _setsidUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _setsockoptUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _setuidUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _sigactionUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _sigaltstackUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _socketUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _stat64UNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _strerrorUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _sysconfUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _sysctlUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _unlinkUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _unlinkatUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _unsetenvUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _usleepUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _vm_deallocateUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _wait4UNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _writeUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  _xpc_date_create_from_currentUNDEFINEDLC_SYMTAB__DATA_CONST0x0/usr/lib/libSystem.B.dylib
                                                  TimestampSource PortDest PortSource IPDest IP
                                                  Dec 19, 2024 08:06:20.997916937 CET49385443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:20.998023987 CET44349385151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:20.998807907 CET49385443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:21.000790119 CET49385443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:21.000842094 CET44349385151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:21.315428019 CET44349385151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:21.316226006 CET49385443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:21.316282988 CET49385443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:21.354821920 CET49385443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:21.354993105 CET44349385151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:21.355397940 CET44349385151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:21.355575085 CET49385443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:21.355799913 CET49385443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:21.422017097 CET49386443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:21.422116041 CET44349386151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:21.423284054 CET49386443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:21.425472021 CET49386443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:21.425523043 CET44349386151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:21.707232952 CET44349386151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:21.708316088 CET49386443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:21.708364964 CET49386443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:21.718014956 CET49386443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:21.718173027 CET44349386151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:21.718554974 CET44349386151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:21.718735933 CET49386443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:21.719052076 CET49386443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:22.830037117 CET49390443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:22.830112934 CET44349390151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:22.830821037 CET49390443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:22.834862947 CET49390443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:22.834873915 CET44349390151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:23.117227077 CET44349390151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:23.117973089 CET49390443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:23.118204117 CET49390443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:23.133644104 CET49390443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:23.133819103 CET44349390151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:23.134253025 CET44349390151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:23.135420084 CET49390443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:23.135540009 CET49390443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:28.993196011 CET49391443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:28.993283033 CET44349391151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:28.994098902 CET49391443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:28.994853973 CET49391443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:28.994906902 CET44349391151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:29.279747963 CET44349391151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:29.281397104 CET49391443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:29.281452894 CET49391443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:29.287825108 CET49391443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:29.288006067 CET44349391151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:29.288434982 CET44349391151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:29.288618088 CET49391443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:29.288875103 CET49391443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:29.299840927 CET49392443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:29.299928904 CET44349392151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:29.300501108 CET49392443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:29.301266909 CET49392443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:29.301318884 CET44349392151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:29.597167969 CET44349392151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:29.599245071 CET49392443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:29.599419117 CET49392443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:29.607008934 CET49392443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:29.607175112 CET44349392151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:29.607573986 CET44349392151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:29.607742071 CET49392443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:29.608072042 CET49392443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:29.667800903 CET49393443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:29.667891026 CET44349393151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:29.668535948 CET49393443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:29.669548988 CET49393443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:29.669612885 CET44349393151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:29.955296993 CET44349393151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:29.956110001 CET49393443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:29.956276894 CET49393443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:29.963466883 CET49393443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:29.963634968 CET44349393151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:29.964037895 CET44349393151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:29.964160919 CET49393443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:29.964451075 CET49393443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:29.985193968 CET49394443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:29.985271931 CET44349394151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:29.986042976 CET49394443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:29.986882925 CET49394443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:29.986936092 CET44349394151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:30.268908978 CET44349394151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:30.269790888 CET49394443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:30.269834042 CET49394443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:30.281749964 CET49394443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:30.281872988 CET44349394151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:30.282120943 CET44349394151.101.131.6192.168.11.12
                                                  Dec 19, 2024 08:06:30.282931089 CET49394443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:30.282953978 CET49394443192.168.11.12151.101.131.6
                                                  Dec 19, 2024 08:06:44.628504992 CET4934480192.168.11.1223.202.144.197
                                                  Dec 19, 2024 08:06:44.757900953 CET804934423.202.144.197192.168.11.12
                                                  Dec 19, 2024 08:06:44.758729935 CET4934480192.168.11.1223.202.144.197
                                                  Dec 19, 2024 08:06:49.874990940 CET49354443192.168.11.1223.207.53.102
                                                  Dec 19, 2024 08:06:49.876297951 CET49354443192.168.11.1223.207.53.102
                                                  Dec 19, 2024 08:06:50.016730070 CET4434935423.207.53.102192.168.11.12
                                                  Dec 19, 2024 08:06:50.016941071 CET4434935423.207.53.102192.168.11.12
                                                  Dec 19, 2024 08:06:50.016984940 CET4434935423.207.53.102192.168.11.12
                                                  Dec 19, 2024 08:06:50.017776966 CET49354443192.168.11.1223.207.53.102
                                                  Dec 19, 2024 08:06:50.017973900 CET49354443192.168.11.1223.207.53.102
                                                  Dec 19, 2024 08:06:50.017973900 CET49354443192.168.11.1223.207.53.102
                                                  Dec 19, 2024 08:07:58.566495895 CET49395443192.168.11.12151.101.67.6
                                                  Dec 19, 2024 08:07:58.566531897 CET44349395151.101.67.6192.168.11.12
                                                  Dec 19, 2024 08:07:58.567034960 CET49395443192.168.11.12151.101.67.6
                                                  Dec 19, 2024 08:07:58.567992926 CET49395443192.168.11.12151.101.67.6
                                                  Dec 19, 2024 08:07:58.568011999 CET44349395151.101.67.6192.168.11.12
                                                  Dec 19, 2024 08:07:58.843100071 CET44349395151.101.67.6192.168.11.12
                                                  Dec 19, 2024 08:07:58.843810081 CET49395443192.168.11.12151.101.67.6
                                                  Dec 19, 2024 08:07:58.843964100 CET49395443192.168.11.12151.101.67.6
                                                  Dec 19, 2024 08:07:58.849710941 CET49395443192.168.11.12151.101.67.6
                                                  Dec 19, 2024 08:07:58.849781990 CET44349395151.101.67.6192.168.11.12
                                                  Dec 19, 2024 08:07:58.849865913 CET44349395151.101.67.6192.168.11.12
                                                  Dec 19, 2024 08:07:58.850528955 CET49395443192.168.11.12151.101.67.6
                                                  Dec 19, 2024 08:07:58.850756884 CET49395443192.168.11.12151.101.67.6
                                                  Dec 19, 2024 08:07:58.864604950 CET49396443192.168.11.12151.101.67.6
                                                  Dec 19, 2024 08:07:58.864624023 CET44349396151.101.67.6192.168.11.12
                                                  Dec 19, 2024 08:07:58.865555048 CET49396443192.168.11.12151.101.67.6
                                                  Dec 19, 2024 08:07:58.866343975 CET49396443192.168.11.12151.101.67.6
                                                  Dec 19, 2024 08:07:58.866357088 CET44349396151.101.67.6192.168.11.12
                                                  Dec 19, 2024 08:07:59.154294968 CET44349396151.101.67.6192.168.11.12
                                                  Dec 19, 2024 08:07:59.155057907 CET49396443192.168.11.12151.101.67.6
                                                  Dec 19, 2024 08:07:59.155077934 CET49396443192.168.11.12151.101.67.6
                                                  Dec 19, 2024 08:07:59.161269903 CET49396443192.168.11.12151.101.67.6
                                                  Dec 19, 2024 08:07:59.161324978 CET44349396151.101.67.6192.168.11.12
                                                  Dec 19, 2024 08:07:59.161453962 CET44349396151.101.67.6192.168.11.12
                                                  Dec 19, 2024 08:07:59.162090063 CET49396443192.168.11.12151.101.67.6
                                                  Dec 19, 2024 08:07:59.162113905 CET49396443192.168.11.12151.101.67.6
                                                  Dec 19, 2024 08:07:59.183398962 CET49397443192.168.11.12151.101.67.6
                                                  Dec 19, 2024 08:07:59.183451891 CET44349397151.101.67.6192.168.11.12
                                                  Dec 19, 2024 08:07:59.184097052 CET49397443192.168.11.12151.101.67.6
                                                  Dec 19, 2024 08:07:59.185116053 CET49397443192.168.11.12151.101.67.6
                                                  Dec 19, 2024 08:07:59.185136080 CET44349397151.101.67.6192.168.11.12
                                                  Dec 19, 2024 08:07:59.472023010 CET44349397151.101.67.6192.168.11.12
                                                  Dec 19, 2024 08:07:59.472819090 CET49397443192.168.11.12151.101.67.6
                                                  Dec 19, 2024 08:07:59.472839117 CET49397443192.168.11.12151.101.67.6
                                                  Dec 19, 2024 08:07:59.478988886 CET49397443192.168.11.12151.101.67.6
                                                  Dec 19, 2024 08:07:59.479067087 CET44349397151.101.67.6192.168.11.12
                                                  Dec 19, 2024 08:07:59.479192972 CET44349397151.101.67.6192.168.11.12
                                                  Dec 19, 2024 08:07:59.479682922 CET49397443192.168.11.12151.101.67.6
                                                  Dec 19, 2024 08:07:59.479707003 CET49397443192.168.11.12151.101.67.6
                                                  Dec 19, 2024 08:07:59.493978024 CET49398443192.168.11.12151.101.67.6
                                                  Dec 19, 2024 08:07:59.494030952 CET44349398151.101.67.6192.168.11.12
                                                  Dec 19, 2024 08:07:59.494909048 CET49398443192.168.11.12151.101.67.6
                                                  Dec 19, 2024 08:07:59.495872021 CET49398443192.168.11.12151.101.67.6
                                                  Dec 19, 2024 08:07:59.495892048 CET44349398151.101.67.6192.168.11.12
                                                  Dec 19, 2024 08:07:59.773248911 CET44349398151.101.67.6192.168.11.12
                                                  Dec 19, 2024 08:07:59.775015116 CET49398443192.168.11.12151.101.67.6
                                                  Dec 19, 2024 08:07:59.775074959 CET49398443192.168.11.12151.101.67.6
                                                  Dec 19, 2024 08:07:59.781639099 CET49398443192.168.11.12151.101.67.6
                                                  Dec 19, 2024 08:07:59.781711102 CET44349398151.101.67.6192.168.11.12
                                                  Dec 19, 2024 08:07:59.781840086 CET44349398151.101.67.6192.168.11.12
                                                  Dec 19, 2024 08:07:59.782326937 CET49398443192.168.11.12151.101.67.6
                                                  Dec 19, 2024 08:07:59.782407999 CET49398443192.168.11.12151.101.67.6
                                                  TimestampSource PortDest PortSource IPDest IP
                                                  Dec 19, 2024 08:06:08.156459093 CET53524581.1.1.1192.168.11.12
                                                  Dec 19, 2024 08:07:58.422508001 CET6210453192.168.11.121.1.1.1
                                                  Dec 19, 2024 08:07:58.563860893 CET53621041.1.1.1192.168.11.12
                                                  TimestampSource IPDest IPChecksumCodeType
                                                  Dec 19, 2024 08:06:13.677428007 CET192.168.11.121.1.1.1fc1f(Port unreachable)Destination Unreachable
                                                  Dec 19, 2024 08:06:13.677489996 CET192.168.11.121.1.1.1fc1f(Port unreachable)Destination Unreachable
                                                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                  Dec 19, 2024 08:07:58.422508001 CET192.168.11.121.1.1.10xfc67Standard query (0)h3.apis.apple.map.fastly.netA (IP address)IN (0x0001)false
                                                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                  Dec 19, 2024 08:07:58.563860893 CET1.1.1.1192.168.11.120xfc67No error (0)h3.apis.apple.map.fastly.net151.101.3.6A (IP address)IN (0x0001)false
                                                  Dec 19, 2024 08:07:58.563860893 CET1.1.1.1192.168.11.120xfc67No error (0)h3.apis.apple.map.fastly.net151.101.67.6A (IP address)IN (0x0001)false
                                                  Dec 19, 2024 08:07:58.563860893 CET1.1.1.1192.168.11.120xfc67No error (0)h3.apis.apple.map.fastly.net151.101.131.6A (IP address)IN (0x0001)false
                                                  Dec 19, 2024 08:07:58.563860893 CET1.1.1.1192.168.11.120xfc67No error (0)h3.apis.apple.map.fastly.net151.101.195.6A (IP address)IN (0x0001)false

                                                  System Behavior

                                                  Start time (UTC):07:05:58
                                                  Start date (UTC):19/12/2024
                                                  Path:/Library/Frameworks/Mono.framework/Versions/4.4.2/bin/mono-sgen32
                                                  Arguments:-
                                                  File size:3722408 bytes
                                                  MD5 hash:8910349f44a940d8d79318367855b236
                                                  Start time (UTC):07:05:58
                                                  Start date (UTC):19/12/2024
                                                  Path:/Users/bernard/Desktop/CGESrv
                                                  Arguments:/Users/bernard/Desktop/CGESrv
                                                  File size:6749072 bytes
                                                  MD5 hash:f0d721e663f6e3a2fafd2a27ef95cee0
                                                  Start time (UTC):07:06:28
                                                  Start date (UTC):19/12/2024
                                                  Path:/usr/libexec/xpcproxy
                                                  Arguments:-
                                                  File size:44048 bytes
                                                  MD5 hash:4764d9eafe6b7dac23253a9f8b7f73d6
                                                  Start time (UTC):07:06:28
                                                  Start date (UTC):19/12/2024
                                                  Path:/usr/libexec/firmwarecheckers/eficheck/eficheck
                                                  Arguments:/usr/libexec/firmwarecheckers/eficheck/eficheck --integrity-check-daemon
                                                  File size:74048 bytes
                                                  MD5 hash:328beb81a2263449258057506bb4987f