Edit tour

macOS Analysis Report
OmniFocus-4.5.3.dmg

Overview

General Information

Sample name:OmniFocus-4.5.3.dmg
Analysis ID:1670533
MD5:6cc2b8f9b609a7a59539682ac85440c3
SHA1:d9129ade88e8ca4293567f3a415f8a90ebe50adc
SHA256:24ec296dcecf7323575055612ee6cead4a2309fb17bcd5366691c64a580afb47
Infos:
Errors
  • Tool error: Failed to mount DMG, hdiutil command return code = 1 - error: hdiutil: attach failed - corrupt image
  • Corrupt sample or wrongly selected analyzer. Details: No application bundle or package found in archive file that can be executed.

Detection

Score:0
Range:0 - 100

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1670533
Start date and time:2025-04-21 20:38:58 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 3m 52s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultmacfilecookbook.jbs
Analysis system description:Virtual Machine, Mojave (Office 16 16.27, Java 11.0.2+9, Adobe Reader 2019.010.20099)
macOS major version:10.14
CPU architecture:x86_64
Analysis Mode:default
Sample name:OmniFocus-4.5.3.dmg
Detection:CLEAN
Classification:clean0.macDMG@0/0@0/0
  • Tool error: Failed to mount DMG, hdiutil command return code = 1 - error: hdiutil: attach failed - corrupt image
  • Corrupt sample or wrongly selected analyzer. Details: No application bundle or package found in archive file that can be executed.
  • Excluded IPs from analysis (whitelisted): 172.64.149.23, 23.222.201.219, 17.253.97.204, 17.36.200.79, 17.253.3.135, 17.253.3.140, 104.86.96.30, 17.253.3.131
  • Excluded domains from analysis (whitelisted): e11408.d.akamaiedge.net, lcdn-locator-usuqo.apple.com.akadns.net, updates.cdn-apple.com.akadns.net, e673.dsce9.akamaiedge.net, help-ar.apple.com.edgekey.net, crl.apple.com, ocsp.comodoca.com, lcdn-locator.apple.com.akadns.net, help.origin-apple.com.akadns.net, lcdn-locator.apple.com, updates.g.aaplimg.com, itunes.apple.com.edgekey.net, help.apple.com, init.itunes.apple.com, mesu.apple.com, updates.cdn-apple.com, init-cdn.itunes-apple.com.akadns.net
  • System is macvm-mojave
  • nsurlstoraged (MD5: 321b0a40e24b45f0af49ba42742b3f64) Arguments: /usr/libexec/nsurlstoraged --privileged
  • eficheck (MD5: 328beb81a2263449258057506bb4987f) Arguments: /usr/libexec/firmwarecheckers/eficheck/eficheck --integrity-check-daemon
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 151.101.47.6:443 -> 192.168.11.12:49390 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.47.6:443 -> 192.168.11.12:49391 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.47.6:443 -> 192.168.11.12:49396 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.47.6:443 -> 192.168.11.12:49397 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.47.6:443 -> 192.168.11.12:49398 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.47.6:443 -> 192.168.11.12:49399 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.47.6:443 -> 192.168.11.12:49400 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 17.248.199.12
Source: unknownTCP traffic detected without corresponding DNS query: 17.248.199.12
Source: unknownTCP traffic detected without corresponding DNS query: 17.248.199.12
Source: unknownTCP traffic detected without corresponding DNS query: 17.248.199.12
Source: unknownTCP traffic detected without corresponding DNS query: 17.248.199.12
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: unknownTCP traffic detected without corresponding DNS query: 151.101.47.6
Source: OmniFocus-4.5.3.dmgString found in binary or memory: http://crl.apple.com/applerootcag3.crl0
Source: OmniFocus-4.5.3.dmgString found in binary or memory: http://crl.apple.com/root.crl0
Source: OmniFocus-4.5.3.dmgString found in binary or memory: http://crl.apple.com/timestamp.crl0
Source: OmniFocus-4.5.3.dmgString found in binary or memory: http://ocsp.apple.com/ocsp03-applerootcag307
Source: OmniFocus-4.5.3.dmgString found in binary or memory: http://ocsp.apple.com/ocsp03-asica4020
Source: OmniFocus-4.5.3.dmgString found in binary or memory: http://ocsp.apple.com/ocsp03-devid060
Source: OmniFocus-4.5.3.dmgString found in binary or memory: http://www.apple.com/DTDs/PropertyList-1.0.dtd
Source: OmniFocus-4.5.3.dmgString found in binary or memory: http://www.apple.com/appleca0
Source: OmniFocus-4.5.3.dmgString found in binary or memory: http://www.apple.com/certificateauthority/0
Source: OmniFocus-4.5.3.dmgString found in binary or memory: https://www.apple.com/appleca/0
Source: unknownNetwork traffic detected: HTTP traffic on port 49399 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49347
Source: unknownNetwork traffic detected: HTTP traffic on port 49398 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49397 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49400
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49399
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49398
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49397
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49396
Source: unknownNetwork traffic detected: HTTP traffic on port 49391 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49391
Source: unknownNetwork traffic detected: HTTP traffic on port 49396 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49390
Source: unknownNetwork traffic detected: HTTP traffic on port 49390 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49400 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49347 -> 443
Source: unknownHTTPS traffic detected: 151.101.47.6:443 -> 192.168.11.12:49390 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.47.6:443 -> 192.168.11.12:49391 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.47.6:443 -> 192.168.11.12:49396 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.47.6:443 -> 192.168.11.12:49397 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.47.6:443 -> 192.168.11.12:49398 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.47.6:443 -> 192.168.11.12:49399 version: TLS 1.2
Source: unknownHTTPS traffic detected: 151.101.47.6:443 -> 192.168.11.12:49400 version: TLS 1.2
Source: classification engineClassification label: clean0.macDMG@0/0@0/0
Source: /usr/libexec/firmwarecheckers/eficheck/eficheck (PID: 640)Random device file read: /dev/randomJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Shell
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1670533 Sample: OmniFocus-4.5.3.dmg Startdate: 21/04/2025 Architecture: MAC Score: 0 9 151.101.47.6, 443, 49390, 49391 FASTLYUS United States 2->9 11 104.86.97.28, 49344, 80 CMCSUS United States 2->11 5 xpcproxy nsurlstoraged 2->5         started        7 xpcproxy eficheck 2->7         started        process3

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


cam-macmac-stand
SourceDetectionScannerLabelLink
OmniFocus-4.5.3.dmg0%VirustotalBrowse
OmniFocus-4.5.3.dmg0%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
104.86.97.28
unknownUnited States
33652CMCSUSfalse
151.101.47.6
unknownUnited States
54113FASTLYUSfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
151.101.47.6https://garglingably.comGet hashmaliciousUnknownBrowse
    d8SJC8BaVe.dmgGet hashmaliciousBanshee StealerBrowse
      Eqx3KrV3ru.dmgGet hashmaliciousBanshee StealerBrowse
        log.jsonGet hashmaliciousUnknownBrowse
          No context
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          CMCSUSSecuriteInfo.com.Trojan.Siggen31.9411.1178.4099.exeGet hashmaliciousAveMaria, Blank Grabber, DCRat, Destiny Stealer, KeyLogger, PureLog Stealer, StormKittyBrowse
          • 45.133.251.174
          xd.sh4.elfGet hashmaliciousMiraiBrowse
          • 50.238.120.149
          https://pub-63cd7f5e8c77471cafc82a3a928746a7.r2.dev/linknew.html#david.hopper@martinmlp.comGet hashmaliciousHTMLPhisherBrowse
          • 104.67.201.252
          https://easymails.baruzotech.com/api/mail-track/link/eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpbSI6dHJ1ZSwibGluayI6ImxpbmtJZDphSFIwY0hNNkx5OXRZWE4wY21WemMybGpiMmRzWVhOekxtMTVMdz09IiwiZW1haWxUcmFja2luZ0NvZGUiOiJQNm0wTXBzNGdDTkpQZ1RJVWJBT1RVRVVXbk1oblpwOGhPTmZGZUtmVTUxaTBXVW1NZiIsImlhdCI6MTc0NDgwNzAxMX0.HvmzGMksOuf7aEIF1gztpOH_rJgcZxPtSdAR0r0UjRgGet hashmaliciousHTMLPhisherBrowse
          • 23.48.162.214
          https://www.kleinmetall.de/productFinder/resetFinder?redirectUrl=https://webtech-services.com/document/Get hashmaliciousHTMLPhisher, Invisible JS, Tycoon2FABrowse
          • 104.67.201.252
          x32.elfGet hashmaliciousMiraiBrowse
          • 193.168.198.150
          https://www.brex.com/?q_mailing_7U7ZspCH65Ry71KT5PT32Mp4Mh84KauTF5Mkz=RooaWAQ9YWz35a3to3iyt5oDoyC5ayTktbwbH3nq8AC8gd2QT5z4MXiLzGet hashmaliciousUnknownBrowse
          • 104.67.201.252
          https://campaign-statistics.com/link_click/e5ZL3B-mqJWmNn-4hlSKn/9246f534af647a666dc7b3a5d3e64604Get hashmaliciousHTMLPhisherBrowse
          • 104.67.201.252
          https://myidverify.s3.us-east-1.amazonaws.com/redirect.htmlGet hashmaliciousAsyncRAT, DcRatBrowse
          • 104.67.201.252
          http://re-livraison-mondialrelay.comGet hashmaliciousUnknownBrowse
          • 45.139.104.24
          FASTLYUSSTATEMENT COMPLETED_DOCUMENT.rtfGet hashmaliciousUnknownBrowse
          • 151.101.1.229
          STATEMENT COMPLETED_DOCUMENT.rtfGet hashmaliciousUnknownBrowse
          • 151.101.1.140
          SAMPLE_PICTURES.vbsGet hashmaliciousLodaRATBrowse
          • 185.199.111.133
          phish_alert_iocp_v1.4.48 (67).emlGet hashmaliciousUnknownBrowse
          • 199.232.210.172
          http://vertequipment.comGet hashmaliciousUnknownBrowse
          • 151.101.193.229
          Signature Required(3 pages).pdfGet hashmaliciousGabagoolBrowse
          • 151.101.66.137
          Signature Required(3 pages).pdfGet hashmaliciousGabagoolBrowse
          • 151.101.2.137
          https://keap.app/contact-us/1168682290035553Get hashmaliciousInvisible JS, Tycoon2FABrowse
          • 151.101.65.195
          https://keap.app/contact-us/1957585279746512Get hashmaliciousInvisible JSBrowse
          • 151.101.65.195
          https://keap.app/contact-us/1957585279746512Get hashmaliciousInvisible JS, Tycoon2FABrowse
          • 151.101.130.137
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          5c118da645babe52f060d0754256a73chttps://garglingably.comGet hashmaliciousUnknownBrowse
          • 151.101.47.6
          LygVsV8I5u.dmgGet hashmaliciousBanshee StealerBrowse
          • 151.101.47.6
          d8SJC8BaVe.dmgGet hashmaliciousBanshee StealerBrowse
          • 151.101.47.6
          imtjW1Rf7L.dmgGet hashmaliciousBanshee StealerBrowse
          • 151.101.47.6
          Eqx3KrV3ru.dmgGet hashmaliciousBanshee StealerBrowse
          • 151.101.47.6
          log.jsonGet hashmaliciousUnknownBrowse
          • 151.101.47.6
          ConstateGet hashmaliciousUnknownBrowse
          • 151.101.47.6
          https://amhcouk.org/membership-proforma1Get hashmaliciousUnknownBrowse
          • 151.101.47.6
          minaUSBGet hashmaliciousUnknownBrowse
          • 151.101.47.6
          .BC.T_nlroYH.278.drGet hashmaliciousUnknownBrowse
          • 151.101.47.6
          No context
          No created / dropped files found
          File type:XZ compressed data, checksum NONE
          Entropy (8bit):7.998729126235879
          TrID:
          • XZ container (without checksum) (6008/2) 85.72%
          • QuickBasic BSAVE binary data (1001/1) 14.28%
          File name:OmniFocus-4.5.3.dmg
          File size:32'685'305 bytes
          MD5:6cc2b8f9b609a7a59539682ac85440c3
          SHA1:d9129ade88e8ca4293567f3a415f8a90ebe50adc
          SHA256:24ec296dcecf7323575055612ee6cead4a2309fb17bcd5366691c64a580afb47
          SHA512:60375599ac45dd36c9ebdb539f6542a0540ceecda4bba459fe317a5d6463c9d73320cf727d1477565ffcadf7dbea4e27938f622491ebd6c50c2170fb0286422e
          SSDEEP:786432:A0tWzZ6JIPTSXgOJefC7/ef4OJpPmBcU/savybL1gE12aJ:A0eZ6JogIfC7/e5kcUUOoL1gE12A
          TLSH:D46733F46F2C75A8FC368EB00932B882AC4F7747B6125B578E8D464024F5A11FD94A6F
          File Content Preview:.7zXZ......A...y..@!....-.l,...<.]..o......|X..{..%k....?...!5H..M.s...6...i..3..!qYf.H..TZ.....:.......g.9.6...AV3k...5.8..Q7W...e.i.h..*...+o&...:.9<..H......=1.........c".......[.......A.YN2.....@r..J|` .zK..].Zc.#...^...l<z...a?@..X...........3.......

          Download Network PCAP: filteredfull

          • Total Packets: 63
          • 443 (HTTPS)
          • 80 (HTTP)
          TimestampSource PortDest PortSource IPDest IP
          Apr 21, 2025 20:40:00.591944933 CEST49347443192.168.11.1217.248.199.12
          Apr 21, 2025 20:40:01.082561970 CEST49347443192.168.11.1217.248.199.12
          Apr 21, 2025 20:40:01.621995926 CEST49347443192.168.11.1217.248.199.12
          Apr 21, 2025 20:40:01.624624014 CEST49347443192.168.11.1217.248.199.12
          Apr 21, 2025 20:40:01.725677013 CEST4434934717.248.199.12192.168.11.12
          Apr 21, 2025 20:40:01.726331949 CEST49347443192.168.11.1217.248.199.12
          Apr 21, 2025 20:40:01.728132010 CEST4434934717.248.199.12192.168.11.12
          Apr 21, 2025 20:40:36.480134964 CEST49390443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:36.480248928 CEST44349390151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:36.480837107 CEST49390443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:36.481841087 CEST49390443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:36.481898069 CEST44349390151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:36.705188036 CEST44349390151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:36.707118034 CEST49390443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:36.707253933 CEST49390443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:36.747123003 CEST49390443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:36.747283936 CEST44349390151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:36.747510910 CEST44349390151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:36.748367071 CEST49390443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:36.748392105 CEST49390443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:36.788877964 CEST49391443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:36.788933039 CEST44349391151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:36.789540052 CEST49391443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:36.790323019 CEST49391443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:36.790349007 CEST44349391151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:37.014522076 CEST44349391151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:37.015647888 CEST49391443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:37.015717030 CEST49391443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:37.031153917 CEST49391443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:37.031332970 CEST44349391151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:37.031709909 CEST44349391151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:37.031924009 CEST49391443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:37.032286882 CEST49391443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:38.101667881 CEST49396443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:38.101753950 CEST44349396151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:38.102684021 CEST49396443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:38.103295088 CEST49396443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:38.103349924 CEST44349396151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:38.346410036 CEST44349396151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:38.347801924 CEST49396443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:38.347862005 CEST49396443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:38.367933035 CEST49396443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:38.368174076 CEST44349396151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:38.368659973 CEST44349396151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:38.368947983 CEST49396443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:38.369227886 CEST49396443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:38.472167969 CEST49397443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:38.472250938 CEST44349397151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:38.473017931 CEST49397443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:38.474270105 CEST49397443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:38.474324942 CEST44349397151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:38.693994999 CEST44349397151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:38.694683075 CEST49397443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:38.694801092 CEST49397443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:38.703615904 CEST49397443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:38.703809023 CEST44349397151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:38.704222918 CEST44349397151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:38.704397917 CEST49397443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:38.704628944 CEST49397443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:38.737711906 CEST49398443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:38.737792015 CEST44349398151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:38.738363981 CEST49398443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:38.766616106 CEST49398443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:38.766666889 CEST44349398151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:38.990284920 CEST44349398151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:38.991089106 CEST49398443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:38.991138935 CEST49398443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:39.028480053 CEST49398443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:39.028718948 CEST44349398151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:39.029211044 CEST44349398151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:39.029306889 CEST49398443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:39.029928923 CEST49398443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:39.079941034 CEST49399443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:39.080019951 CEST44349399151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:39.080579996 CEST49399443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:39.083816051 CEST49399443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:39.083867073 CEST44349399151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:39.960367918 CEST44349399151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:39.961333990 CEST49399443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:39.961560011 CEST49399443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:39.971318007 CEST49399443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:39.971496105 CEST44349399151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:39.971914053 CEST44349399151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:39.972366095 CEST49399443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:39.972616911 CEST49399443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:39.995165110 CEST49400443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:39.995275974 CEST44349400151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:39.996051073 CEST49400443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:39.997046947 CEST49400443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:39.997101068 CEST44349400151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:40.221539021 CEST44349400151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:40.222347975 CEST49400443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:40.222400904 CEST49400443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:40.230551004 CEST49400443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:40.230720997 CEST44349400151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:40.231139898 CEST44349400151.101.47.6192.168.11.12
          Apr 21, 2025 20:40:40.231319904 CEST49400443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:40.231656075 CEST49400443192.168.11.12151.101.47.6
          Apr 21, 2025 20:40:59.401957035 CEST4934480192.168.11.12104.86.97.28
          Apr 21, 2025 20:40:59.509018898 CEST8049344104.86.97.28192.168.11.12
          Apr 21, 2025 20:40:59.509701014 CEST4934480192.168.11.12104.86.97.28
          TimestampSource PortDest PortSource IPDest IP
          Apr 21, 2025 20:40:51.644185066 CEST137137192.168.11.12192.168.11.255
          Apr 21, 2025 20:40:51.644185066 CEST137137192.168.11.12192.168.11.255

          System Behavior

          Start time (UTC):18:39:58
          Start date (UTC):21/04/2025
          Path:/usr/libexec/xpcproxy
          Arguments:-
          File size:44048 bytes
          MD5 hash:4764d9eafe6b7dac23253a9f8b7f73d6
          Start time (UTC):18:39:58
          Start date (UTC):21/04/2025
          Path:/usr/libexec/nsurlstoraged
          Arguments:/usr/libexec/nsurlstoraged --privileged
          File size:246624 bytes
          MD5 hash:321b0a40e24b45f0af49ba42742b3f64
          Start time (UTC):18:40:37
          Start date (UTC):21/04/2025
          Path:/usr/libexec/xpcproxy
          Arguments:-
          File size:44048 bytes
          MD5 hash:4764d9eafe6b7dac23253a9f8b7f73d6
          Start time (UTC):18:40:37
          Start date (UTC):21/04/2025
          Path:/usr/libexec/firmwarecheckers/eficheck/eficheck
          Arguments:/usr/libexec/firmwarecheckers/eficheck/eficheck --integrity-check-daemon
          File size:74048 bytes
          MD5 hash:328beb81a2263449258057506bb4987f