macOS
Analysis Report
http://www.liveupdt.com/ext/rd.php
Overview
Detection
Score: | 56 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Writes 64-bit Mach-O files to disk
Opens the Safari browser app
Classification
Joe Sandbox Version: | 34.0.0 Boulder Opal |
Analysis ID: | 577098 |
Start date: | 23.02.2022 |
Start time: | 11:20:44 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 3m 25s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | http://www.liveupdt.com/ext/rd.php |
Analysis system description: | Virtual Machine, High Sierra (Office 2016 16.16, Java 11.0.2+9, Adobe Reader 2019.010.20099) |
Analysis Mode: | default |
Detection: | MAL |
Classification: | mal56.mac@0/10@2/0 |
- Excluded IPs from analysis (whitelisted): 18.156.205.85, 18.156.44.202, 104.92.88.65, 93.184.220.29, 23.37.43.27, 142.250.203.106, 104.92.88.33, 142.250.203.99, 17.253.55.204, 17.253.55.208, 2.22.33.179, 104.90.178.254
- Excluded domains from analysis (whitelisted): e11408.d.akamaiedge.net, cs9.wac.phicdn.net, ocsp-a.g.aaplimg.com, e8652.dscx.akamaiedge.net, gateway.icloud.com, g.symcd.com, api-glb-euc1b.smoot.apple.com, ocsp.digicert.com, safebrowsing.googleapis.com, help.apple.com, smoot-searchv2-euc1b.v.aaplimg.com, crl.root-x1.letsencrypt.org.edgekey.net, cds-cdn.v.aaplimg.com, cds.apple.com.akadns.net, e673.dsce9.akamaiedge.net, e8218.dscb1.akamaiedge.net, cds.apple.com, ocsp.pki.goog, help-ar.apple.com.edgekey.net, api.smoot.apple.com, bag-smoot.v.aaplimg.com, ocsp-ds.ws.symantec.com.edgekey.net, lb._dns-sd._udp.0.11.168.192.in-addr.arpa, configuration.apple.com, cds.apple.com.edgekey.net, ocsp.apple.com, help.origin-apple.com.akadns.net, configuration.apple.com.akadns.net, configuration.apple.com.edgekey.net, e14768.dscb.akamaiedge.net
- Report size getting too big, too many PREAD calls found.
- VT rate limit hit for: https://www.liveupdt.com/ext/rd.php
⊘No yara matches
- • AV Detection
- • Compliance
- • Networking
- • System Summary
- • Persistence and Installation Behavior
- • Language, Device and Operating System Detection
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira URL Cloud: |
Source: | Virustotal: | Perma Link |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | File written: | Jump to dropped file | ||
Source: | File written: | Jump to dropped file | ||
Source: | File written: | Jump to dropped file |
Source: | Safari app opened: | Jump to behavior |
Source: | AppleKeyboardLayouts info plist opened: | Jump to behavior |
Source: | Random device file read: | Jump to behavior |
Source: | XML plist file created: | Jump to dropped file | ||
Source: | Binary plist file created: | Jump to dropped file | ||
Source: | Binary plist file created: | Jump to dropped file |
Source: | System or server version plist file read: | Jump to behavior |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Windows Management Instrumentation | 1 Plist Modification | 1 Plist Modification | Direct Volume Access | OS Credential Dumping | 1 System Information Discovery | Remote Services | Data from Local System | Exfiltration Over Other Network Medium | 1 Encrypted Channel | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | 2 Non-Application Layer Protocol | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | 3 Application Layer Protocol | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | At (Windows) | Logon Script (Mac) | Logon Script (Mac) | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Scheduled Transfer | 1 Ingress Tool Transfer | SIM Card Swap | Carrier Billing Fraud |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
8% | Virustotal | Browse | ||
100% | Avira URL Cloud | phishing |
⊘No Antivirus matches
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Virustotal | Browse | ||
6% | Virustotal | Browse | ||
0% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | phishing |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
gateway.fe.apple-dns.net | 17.248.145.104 | true | false |
| unknown |
www.liveupdt.com | 67.205.63.212 | true | true |
| unknown |
pki-goog.l.google.com | 142.250.203.99 | true | false | high | |
x1.c.lencr.org | unknown | unknown | false |
| unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
true |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
23.211.5.115 | unknown | United States | 16625 | AKAMAI-ASUS | false | |
67.205.63.212 | www.liveupdt.com | United States | 26347 | DREAMHOST-ASUS | true |
⊘No context
⊘No context
⊘No context
⊘No context
⊘No context
Process: | /Applications/Safari.app/Contents/MacOS/Safari |
File Type: | |
Category: | dropped |
Size (bytes): | 1513 |
Entropy (8bit): | 7.251278254979247 |
Encrypted: | false |
SSDEEP: | 24:/MVp+dVGmEH3oFqBSIebHoTAqg97kwzxlXogfdOK67P3zteFRsSQFnCEt:E3NmrA8oTlg9wwXXf1OPrztADQFCg |
MD5: | F19D87317A248BACB51E5AC6D55216CF |
SHA1: | CEDD26DC5BCFADCD390B3208B91FAC265C368BDC |
SHA-256: | 73734077A324573A536527DC24999ABA0DE7D11462D37A5CBC873DE5C196DB1D |
SHA-512: | 44A3306990CE4E1D6E835BD51835AE7F82BCD26A7F65DFAC727DADED5F2D38FFDCDE5523C7E6085C1DA2C2183D56D8BA1217CF9FE59BCD04CA1D496E5B36A616 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | /Applications/Safari.app/Contents/MacOS/Safari |
File Type: | |
Category: | dropped |
Size (bytes): | 1012 |
Entropy (8bit): | 5.286991847916908 |
Encrypted: | false |
SSDEEP: | 24:2dfyiwHuG5Ku3hu65juqVrTrmuGoTxR1F1xW:cfyP5Z/5PrUon1F1xW |
MD5: | 0C29425555C7FF0CA114B1FD0DC39C50 |
SHA1: | D7D808E8BE92462F4C3CEBA66734F0E9BB26ACDD |
SHA-256: | 52826AFEEC974BB7BACB85BDC01DC4F23BF917D65E04773D7CAD393F7866F3FD |
SHA-512: | D9C8364A85F4B4A96CAAC1409F32F9D6B2F8AE19201E0ABD2D449A3EEDADD471E99E44BC92DEB5D8FB60287DA64A88E61B45F759E7B9A383A9BBE5F5FD242F95 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | /Applications/Safari.app/Contents/MacOS/Safari |
File Type: | |
Category: | dropped |
Size (bytes): | 803 |
Entropy (8bit): | 7.6982156720665404 |
Encrypted: | false |
SSDEEP: | 12:6v/7KkBgFkdUZhfQ3VXRjK+fw3jIT4DAtmm80JJu1cMInH+1GbGFyM5SW8R4P7:7sUZtQlhmbPDSmdrYeYb0yvW8e |
MD5: | 01574C9C36BE716E31B885A2EC4D4EB9 |
SHA1: | 4DBF323B0023ECBC9A7A6786A863C89ACFB4B26F |
SHA-256: | 40A8F24C22200FE18D0FE1910781B3489E51594C13958E93BCEEF0F54B8503C4 |
SHA-512: | 1A65824CCE6C8CB2E2CD987AB754EAA410972CD5207ED79AC7D9927E1E3A0E5FF1154BF9B77BDF98282EB0AB7E6153F19497FD74902A90CCC96DFA4CDF0273D7 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | /Applications/Safari.app/Contents/MacOS/Safari |
File Type: | |
Category: | dropped |
Size (bytes): | 61 |
Entropy (8bit): | 4.668121763650529 |
Encrypted: | false |
SSDEEP: | 3:tXyuPXUfWPWdF2/lZGA1WOv:dM+PWmZiA |
MD5: | C4B4F458F8C923434FC7BF3E885B8020 |
SHA1: | 0BCDC4C51F385BD2400F0ECE4B8707C5B4D36389 |
SHA-256: | 707C2C14219E2E3DE40BBC8FDF2F650138EC8C24B7562726ACF32E6303D0894E |
SHA-512: | E43F238AEAE64E656D43BD8313BB45D17713319CB0E78ED53997B573A493215E1EF04A737EE69AC01C8242EEBC663D45F855E8685A34CF53B5E7705E1D967BDD |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | /Applications/Safari.app/Contents/MacOS/Safari |
File Type: | |
Category: | dropped |
Size (bytes): | 76 |
Entropy (8bit): | 3.9370658315190226 |
Encrypted: | false |
SSDEEP: | 3:N1n6qMvRGNMTAnd/t1tH:N1nleRaMTAltH |
MD5: | CDC65B5F112547EAFAE0F16F9C149426 |
SHA1: | AEAF9908A5B6FF3E2F7B738ABF5FE9E79108BA01 |
SHA-256: | 1C6D085D871A855CE4A3902BAB4B9B92631B8EE8F0B7F6536768A2AAF427B45C |
SHA-512: | E8B0E4CE6A760A718A19976D3CFE9063F04FB4BF179947AECA84E94C83F21459FB9DC0FFABEA8F633BD2D0BA94FE1E15D8C97E9604FDE8BD0DEA961EB83BDDB7 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | /Applications/Safari.app/Contents/MacOS/Safari |
File Type: | |
Category: | dropped |
Size (bytes): | 48908 |
Entropy (8bit): | 3.533948990143748 |
Encrypted: | false |
SSDEEP: | 384:xSMdGleGkIG7FF3theSMVXBD0tgcNrGBOmBfbouR6/chQOnGqwc2U+v+h/:8MdGleOGmBouRwchQOnGqwc2U+v+h/ |
MD5: | 09070E01FA6ED1973D94FAD50C35E3ED |
SHA1: | 7546663E66F9889EE3365A7A0BE372300C6022CA |
SHA-256: | 2E6EC437A97DD88F9067B2E99AC64789670D9B9C1FC50B2856E392E66163211F |
SHA-512: | 621399FF832F1A8352E5E9A54984B878C7D3432156D9CF9986A1A5B75662E92D9A00FA1BA6714D679286BB49E71916F72655AADA2B99880A2806FAFC6F86E7F3 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | /Applications/Safari.app/Contents/MacOS/Safari |
File Type: | |
Category: | dropped |
Size (bytes): | 4404 |
Entropy (8bit): | 3.5113078915037033 |
Encrypted: | false |
SSDEEP: | 48:m6Xsh+CLjL3Pe3T5FFKfEuyu+iYxGv4sS:3X6LjLfe3wEuyu9YxGQX |
MD5: | D487F899A14AE98519B46D51BC810F1B |
SHA1: | 64877ECFBE47ED66EED545B2449BBE8B22B775D0 |
SHA-256: | 4835899C464487946E281D535381D4CAB8BC90EC08CD00A6A0ECB97854E9321D |
SHA-512: | EB4FABD61B4FD2B9EF3C9E93793CA5F11353A1F81EA4DA22E0F79ED45D89180B77469B9E5DCD5350AE650B31DE9018743DA7716EFA7B5CDDFC3FA7A13C476F40 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | /Applications/Safari.app/Contents/MacOS/Safari |
File Type: | |
Category: | dropped |
Size (bytes): | 4752 |
Entropy (8bit): | 5.761647040683616 |
Encrypted: | false |
SSDEEP: | 96:xKvjeoJ2eQIMA1EVQvOsD1cbY2vF/jllllllllKflNJz5w6w:0dJ2eQpMtxmvrllllllllKfly |
MD5: | 1D6F449D22D11E760495CE85C933ADF8 |
SHA1: | D77F5B05549E51310D0C96347482178EBD23C476 |
SHA-256: | BEF505FE1329E19B4AF2FFFD868C753A0824B96FB4531BD106C810D96EFB1D94 |
SHA-512: | 4A9F4BD053BC5069625D60DDD3E1225E01FCE6B31824C35A12D7CAFAC2AD9BF79EE7785A6860E5549836970D8A4C7968355EC715C652EE1C771EDD9D9D1616A6 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | /Applications/Safari.app/Contents/MacOS/Safari |
File Type: | |
Category: | dropped |
Size (bytes): | 4780 |
Entropy (8bit): | 5.78784933687558 |
Encrypted: | false |
SSDEEP: | 96:xav2J2yfQoIeVyCxVaBHlZF/jllllllllKflPz5w65:keJ2OQYTTarllllllllKflT |
MD5: | 6903FFA70C6EF8F2493E3E49101C694D |
SHA1: | B70A5F8C3F48BB2251B114500DFFF1CCCE72D966 |
SHA-256: | 633CEE31BFBF56590F6B62891CD0CB55264FD0F01E183036D8E3556B9EFF72D5 |
SHA-512: | 2A8A297AEE0F285EAA494BA5B731D023BF6438E207B83495FF490EB67BE3D9B4E887F91680761E759973D9FEC782B9E0CEC7E1957C4E794739A0DF90E2346D87 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | /Applications/Safari.app/Contents/MacOS/Safari |
File Type: | |
Category: | dropped |
Size (bytes): | 17444 |
Entropy (8bit): | 4.344757944263916 |
Encrypted: | false |
SSDEEP: | 384:wwjJcXgiRVP7J3AMqLllllllKfllJlROW:wga13AMqAOW |
MD5: | 737239EDB5D8B7977A5A8D928A1A8A26 |
SHA1: | 0175F7B768051D8EEC31BEF07EA3C41E2A59290B |
SHA-256: | 545E972B5FD592C3607C71402888F87C07E18F1B8394001AE7352BCE6B362918 |
SHA-512: | E164F22FAA86FDD62FB075E8B22917A78C5B9CD9731D7C04C45A8A5CF6EDC1647EF7985F0360D60F299D6CE8B947DD04BA0366B7C6C2FFCDC9F2AC9309FC82F1 |
Malicious: | false |
Reputation: | low |
Preview: |
⊘No static file info
Download Network PCAP: filtered – full
- Total Packets: 89
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Feb 23, 2022 11:21:38.127042055 CET | 49293 | 443 | 192.168.11.11 | 17.248.145.104 |
Feb 23, 2022 11:21:38.135236979 CET | 443 | 49293 | 17.248.145.104 | 192.168.11.11 |
Feb 23, 2022 11:21:38.135869980 CET | 49293 | 443 | 192.168.11.11 | 17.248.145.104 |
Feb 23, 2022 11:21:38.136168003 CET | 49293 | 443 | 192.168.11.11 | 17.248.145.104 |
Feb 23, 2022 11:21:38.144287109 CET | 443 | 49293 | 17.248.145.104 | 192.168.11.11 |
Feb 23, 2022 11:21:38.144404888 CET | 443 | 49293 | 17.248.145.104 | 192.168.11.11 |
Feb 23, 2022 11:21:38.144474030 CET | 443 | 49293 | 17.248.145.104 | 192.168.11.11 |
Feb 23, 2022 11:21:38.144536018 CET | 443 | 49293 | 17.248.145.104 | 192.168.11.11 |
Feb 23, 2022 11:21:38.144581079 CET | 443 | 49293 | 17.248.145.104 | 192.168.11.11 |
Feb 23, 2022 11:21:38.144643068 CET | 443 | 49293 | 17.248.145.104 | 192.168.11.11 |
Feb 23, 2022 11:21:38.144694090 CET | 443 | 49293 | 17.248.145.104 | 192.168.11.11 |
Feb 23, 2022 11:21:38.145108938 CET | 49293 | 443 | 192.168.11.11 | 17.248.145.104 |
Feb 23, 2022 11:21:38.145210981 CET | 49293 | 443 | 192.168.11.11 | 17.248.145.104 |
Feb 23, 2022 11:21:38.145226955 CET | 49293 | 443 | 192.168.11.11 | 17.248.145.104 |
Feb 23, 2022 11:21:38.145239115 CET | 49293 | 443 | 192.168.11.11 | 17.248.145.104 |
Feb 23, 2022 11:21:38.145251036 CET | 49293 | 443 | 192.168.11.11 | 17.248.145.104 |
Feb 23, 2022 11:21:38.253391027 CET | 49293 | 443 | 192.168.11.11 | 17.248.145.104 |
Feb 23, 2022 11:21:38.261603117 CET | 443 | 49293 | 17.248.145.104 | 192.168.11.11 |
Feb 23, 2022 11:21:38.261672974 CET | 443 | 49293 | 17.248.145.104 | 192.168.11.11 |
Feb 23, 2022 11:21:38.261718035 CET | 443 | 49293 | 17.248.145.104 | 192.168.11.11 |
Feb 23, 2022 11:21:38.262345076 CET | 49293 | 443 | 192.168.11.11 | 17.248.145.104 |
Feb 23, 2022 11:21:38.262445927 CET | 49293 | 443 | 192.168.11.11 | 17.248.145.104 |
Feb 23, 2022 11:21:38.315386057 CET | 49293 | 443 | 192.168.11.11 | 17.248.145.104 |
Feb 23, 2022 11:21:38.315457106 CET | 49293 | 443 | 192.168.11.11 | 17.248.145.104 |
Feb 23, 2022 11:21:38.315833092 CET | 49293 | 443 | 192.168.11.11 | 17.248.145.104 |
Feb 23, 2022 11:21:38.315911055 CET | 49293 | 443 | 192.168.11.11 | 17.248.145.104 |
Feb 23, 2022 11:21:38.316677094 CET | 49295 | 80 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:38.316951990 CET | 49293 | 443 | 192.168.11.11 | 17.248.145.104 |
Feb 23, 2022 11:21:38.323538065 CET | 443 | 49293 | 17.248.145.104 | 192.168.11.11 |
Feb 23, 2022 11:21:38.323628902 CET | 443 | 49293 | 17.248.145.104 | 192.168.11.11 |
Feb 23, 2022 11:21:38.323669910 CET | 443 | 49293 | 17.248.145.104 | 192.168.11.11 |
Feb 23, 2022 11:21:38.323709965 CET | 443 | 49293 | 17.248.145.104 | 192.168.11.11 |
Feb 23, 2022 11:21:38.323764086 CET | 443 | 49293 | 17.248.145.104 | 192.168.11.11 |
Feb 23, 2022 11:21:38.324018002 CET | 49293 | 443 | 192.168.11.11 | 17.248.145.104 |
Feb 23, 2022 11:21:38.324980974 CET | 443 | 49293 | 17.248.145.104 | 192.168.11.11 |
Feb 23, 2022 11:21:38.326001883 CET | 443 | 49293 | 17.248.145.104 | 192.168.11.11 |
Feb 23, 2022 11:21:38.326107979 CET | 443 | 49293 | 17.248.145.104 | 192.168.11.11 |
Feb 23, 2022 11:21:38.326199055 CET | 443 | 49293 | 17.248.145.104 | 192.168.11.11 |
Feb 23, 2022 11:21:38.326256037 CET | 443 | 49293 | 17.248.145.104 | 192.168.11.11 |
Feb 23, 2022 11:21:38.326309919 CET | 443 | 49293 | 17.248.145.104 | 192.168.11.11 |
Feb 23, 2022 11:21:38.326364040 CET | 443 | 49293 | 17.248.145.104 | 192.168.11.11 |
Feb 23, 2022 11:21:38.326458931 CET | 49293 | 443 | 192.168.11.11 | 17.248.145.104 |
Feb 23, 2022 11:21:38.326519966 CET | 49293 | 443 | 192.168.11.11 | 17.248.145.104 |
Feb 23, 2022 11:21:38.326775074 CET | 49293 | 443 | 192.168.11.11 | 17.248.145.104 |
Feb 23, 2022 11:21:38.326813936 CET | 49293 | 443 | 192.168.11.11 | 17.248.145.104 |
Feb 23, 2022 11:21:38.326932907 CET | 49293 | 443 | 192.168.11.11 | 17.248.145.104 |
Feb 23, 2022 11:21:38.326952934 CET | 49293 | 443 | 192.168.11.11 | 17.248.145.104 |
Feb 23, 2022 11:21:38.327095985 CET | 443 | 49293 | 17.248.145.104 | 192.168.11.11 |
Feb 23, 2022 11:21:38.327172041 CET | 443 | 49293 | 17.248.145.104 | 192.168.11.11 |
Feb 23, 2022 11:21:38.327224970 CET | 443 | 49293 | 17.248.145.104 | 192.168.11.11 |
Feb 23, 2022 11:21:38.327708006 CET | 49293 | 443 | 192.168.11.11 | 17.248.145.104 |
Feb 23, 2022 11:21:38.327800989 CET | 49293 | 443 | 192.168.11.11 | 17.248.145.104 |
Feb 23, 2022 11:21:38.327815056 CET | 49293 | 443 | 192.168.11.11 | 17.248.145.104 |
Feb 23, 2022 11:21:38.392680883 CET | 49293 | 443 | 192.168.11.11 | 17.248.145.104 |
Feb 23, 2022 11:21:38.400644064 CET | 443 | 49293 | 17.248.145.104 | 192.168.11.11 |
Feb 23, 2022 11:21:38.415904045 CET | 80 | 49295 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:38.416388035 CET | 49295 | 80 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:38.417150021 CET | 49295 | 80 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:38.516392946 CET | 80 | 49295 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:38.777218103 CET | 80 | 49295 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:38.777622938 CET | 49295 | 80 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:38.789688110 CET | 49297 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:39.353552103 CET | 80 | 49295 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:39.354655981 CET | 49295 | 80 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:39.354839087 CET | 49295 | 80 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:39.454129934 CET | 80 | 49295 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:39.623286963 CET | 49293 | 443 | 192.168.11.11 | 17.248.145.104 |
Feb 23, 2022 11:21:39.623388052 CET | 49293 | 443 | 192.168.11.11 | 17.248.145.104 |
Feb 23, 2022 11:21:39.623656034 CET | 49293 | 443 | 192.168.11.11 | 17.248.145.104 |
Feb 23, 2022 11:21:39.631757021 CET | 443 | 49293 | 17.248.145.104 | 192.168.11.11 |
Feb 23, 2022 11:21:39.631825924 CET | 443 | 49293 | 17.248.145.104 | 192.168.11.11 |
Feb 23, 2022 11:21:39.631870031 CET | 443 | 49293 | 17.248.145.104 | 192.168.11.11 |
Feb 23, 2022 11:21:39.632363081 CET | 49293 | 443 | 192.168.11.11 | 17.248.145.104 |
Feb 23, 2022 11:21:39.805162907 CET | 49297 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:39.905467987 CET | 443 | 49297 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:39.906178951 CET | 49297 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:39.906419039 CET | 49297 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:40.006531000 CET | 443 | 49297 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:41.978424072 CET | 443 | 49297 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:41.978511095 CET | 443 | 49297 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:41.978559017 CET | 443 | 49297 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:41.978593111 CET | 443 | 49297 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:41.979070902 CET | 49297 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:41.979105949 CET | 49297 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:41.979185104 CET | 49297 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:41.979428053 CET | 443 | 49297 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:41.979892015 CET | 49297 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:42.120003939 CET | 49297 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:42.219810009 CET | 443 | 49297 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:42.220156908 CET | 443 | 49297 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:42.220190048 CET | 443 | 49297 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:42.220551968 CET | 49297 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:42.220632076 CET | 49297 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:42.223906994 CET | 49297 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:42.223984957 CET | 49297 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:42.224131107 CET | 49297 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:42.224164009 CET | 49297 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:42.224229097 CET | 49297 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:42.323878050 CET | 443 | 49297 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:42.323925018 CET | 443 | 49297 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:42.324273109 CET | 49297 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:42.324385881 CET | 443 | 49297 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:42.325944901 CET | 443 | 49297 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:42.326451063 CET | 49297 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:42.367310047 CET | 49310 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:42.466187000 CET | 443 | 49310 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:42.466600895 CET | 49310 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:42.466999054 CET | 49310 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:42.566158056 CET | 443 | 49310 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:43.548182964 CET | 443 | 49310 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:43.548295975 CET | 443 | 49310 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:43.548306942 CET | 443 | 49310 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:43.548315048 CET | 443 | 49310 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:43.548727036 CET | 49310 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:43.548819065 CET | 49310 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:43.548969984 CET | 49310 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:43.549253941 CET | 443 | 49310 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:43.549635887 CET | 49310 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:43.557528019 CET | 49310 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:43.636044025 CET | 443 | 49297 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:43.636101961 CET | 443 | 49297 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:43.636142969 CET | 443 | 49297 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:43.636497021 CET | 49297 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:43.636534929 CET | 49297 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:43.636550903 CET | 49297 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:43.637851000 CET | 49297 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:43.637896061 CET | 49297 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:43.638477087 CET | 49297 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:43.656672001 CET | 443 | 49310 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:43.656703949 CET | 443 | 49310 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:43.656800985 CET | 443 | 49310 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:43.657149076 CET | 49310 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:43.657208920 CET | 49310 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:43.658016920 CET | 49310 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:43.658080101 CET | 49310 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:43.658103943 CET | 49310 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:43.658118963 CET | 49310 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:43.658133030 CET | 49310 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:43.737781048 CET | 443 | 49297 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:43.738301039 CET | 443 | 49297 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:43.757344007 CET | 443 | 49310 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:43.757421970 CET | 443 | 49310 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:43.757749081 CET | 49310 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:43.758619070 CET | 443 | 49310 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:43.758955956 CET | 49310 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:45.516078949 CET | 443 | 49310 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:45.516163111 CET | 443 | 49310 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:45.516875982 CET | 49310 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:45.516985893 CET | 49310 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:45.517004967 CET | 49310 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:45.517103910 CET | 49310 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:45.517330885 CET | 49310 | 443 | 192.168.11.11 | 67.205.63.212 |
Feb 23, 2022 11:21:45.616678953 CET | 443 | 49310 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:21:45.616744995 CET | 443 | 49310 | 67.205.63.212 | 192.168.11.11 |
Feb 23, 2022 11:22:03.861161947 CET | 49285 | 80 | 192.168.11.11 | 17.253.17.205 |
Feb 23, 2022 11:22:04.016201973 CET | 80 | 49285 | 17.253.17.205 | 192.168.11.11 |
Feb 23, 2022 11:22:04.016796112 CET | 49285 | 80 | 192.168.11.11 | 17.253.17.205 |
Feb 23, 2022 11:22:34.242413998 CET | 49287 | 80 | 192.168.11.11 | 23.211.5.115 |
Feb 23, 2022 11:22:34.251344919 CET | 80 | 49287 | 23.211.5.115 | 192.168.11.11 |
Feb 23, 2022 11:22:34.252055883 CET | 49287 | 80 | 192.168.11.11 | 23.211.5.115 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Feb 23, 2022 11:21:38.304719925 CET | 50965 | 53 | 192.168.11.11 | 1.1.1.1 |
Feb 23, 2022 11:21:38.315015078 CET | 53 | 50965 | 1.1.1.1 | 192.168.11.11 |
Feb 23, 2022 11:21:42.019087076 CET | 51585 | 53 | 192.168.11.11 | 1.1.1.1 |
Feb 23, 2022 11:22:05.614177942 CET | 53 | 51399 | 1.1.1.1 | 192.168.11.11 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class |
---|---|---|---|---|---|---|---|
Feb 23, 2022 11:21:38.304719925 CET | 192.168.11.11 | 1.1.1.1 | 0xf07c | Standard query (0) | A (IP address) | IN (0x0001) | |
Feb 23, 2022 11:21:42.019087076 CET | 192.168.11.11 | 1.1.1.1 | 0xb843 | Standard query (0) | A (IP address) | IN (0x0001) |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class |
---|---|---|---|---|---|---|---|---|---|
Feb 23, 2022 11:21:38.124434948 CET | 1.1.1.1 | 192.168.11.11 | 0xf89e | No error (0) | 17.248.145.104 | A (IP address) | IN (0x0001) | ||
Feb 23, 2022 11:21:38.124434948 CET | 1.1.1.1 | 192.168.11.11 | 0xf89e | No error (0) | 17.248.145.83 | A (IP address) | IN (0x0001) | ||
Feb 23, 2022 11:21:38.124434948 CET | 1.1.1.1 | 192.168.11.11 | 0xf89e | No error (0) | 17.248.145.145 | A (IP address) | IN (0x0001) | ||
Feb 23, 2022 11:21:38.124434948 CET | 1.1.1.1 | 192.168.11.11 | 0xf89e | No error (0) | 17.248.248.74 | A (IP address) | IN (0x0001) | ||
Feb 23, 2022 11:21:38.124434948 CET | 1.1.1.1 | 192.168.11.11 | 0xf89e | No error (0) | 17.248.145.239 | A (IP address) | IN (0x0001) | ||
Feb 23, 2022 11:21:38.124434948 CET | 1.1.1.1 | 192.168.11.11 | 0xf89e | No error (0) | 17.248.145.78 | A (IP address) | IN (0x0001) | ||
Feb 23, 2022 11:21:38.124434948 CET | 1.1.1.1 | 192.168.11.11 | 0xf89e | No error (0) | 17.248.145.167 | A (IP address) | IN (0x0001) | ||
Feb 23, 2022 11:21:38.124434948 CET | 1.1.1.1 | 192.168.11.11 | 0xf89e | No error (0) | 17.248.248.42 | A (IP address) | IN (0x0001) | ||
Feb 23, 2022 11:21:38.315015078 CET | 1.1.1.1 | 192.168.11.11 | 0xf07c | No error (0) | 67.205.63.212 | A (IP address) | IN (0x0001) | ||
Feb 23, 2022 11:21:40.146079063 CET | 1.1.1.1 | 192.168.11.11 | 0x292b | No error (0) | 142.250.203.99 | A (IP address) | IN (0x0001) | ||
Feb 23, 2022 11:21:42.027430058 CET | 1.1.1.1 | 192.168.11.11 | 0xb843 | No error (0) | crl.root-x1.letsencrypt.org.edgekey.net | CNAME (Canonical name) | IN (0x0001) |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.11.11 | 49295 | 67.205.63.212 | 80 |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Feb 23, 2022 11:21:38.417150021 CET | 89 | OUT | |
Feb 23, 2022 11:21:38.777218103 CET | 89 | IN |
Timestamp | Source IP | Source Port | Dest IP | Dest Port | Subject | Issuer | Not Before | Not After | JA3 SSL Client Fingerprint | JA3 SSL Client Digest |
---|---|---|---|---|---|---|---|---|---|---|
Feb 23, 2022 11:21:38.144643068 CET | 17.248.145.104 | 443 | 192.168.11.11 | 49293 | C=US, ST=California, O=Apple Inc., CN=gateway.icloud.com C=US, O=Apple Inc., OU=Certification Authority, CN=Apple IST CA 2 - G1 C=US, O=Apple Inc., OU=Certification Authority, CN=Apple IST CA 2 - G1 | C=US, O=Apple Inc., OU=Certification Authority, CN=Apple IST CA 2 - G1 CN=Baltimore CyberTrust Root, OU=CyberTrust, O=Baltimore, C=IE CN=GeoTrust Global CA, O=GeoTrust Inc., C=US | Tue Jun 22 13:54:06 CEST 2021 Wed Dec 12 13:00:00 CET 2018 Mon Jun 16 17:42:02 CEST 2014 | Fri Jul 22 13:54:05 CEST 2022 Wed May 07 14:00:00 CEST 2025 Fri May 20 17:42:02 CEST 2022 | 771,49196-49195-49188-49187-49162-49161-52393-49200-49199-49192-49191-49172-49171-52392-157-156-61-60-53-47,65281-0-23-13-5-13172-18-16-11-10,29-23-24,0 | 3e4e87dda5a3162306609b7e330441d2 |
C=US, O=Apple Inc., OU=Certification Authority, CN=Apple IST CA 2 - G1 | CN=Baltimore CyberTrust Root, OU=CyberTrust, O=Baltimore, C=IE | Wed Dec 12 13:00:00 CET 2018 | Wed May 07 14:00:00 CEST 2025 | |||||||
C=US, O=Apple Inc., OU=Certification Authority, CN=Apple IST CA 2 - G1 | CN=GeoTrust Global CA, O=GeoTrust Inc., C=US | Mon Jun 16 17:42:02 CEST 2014 | Fri May 20 17:42:02 CEST 2022 | |||||||
Feb 23, 2022 11:21:41.979428053 CET | 67.205.63.212 | 443 | 192.168.11.11 | 49297 | CN=www.liveupdt.com CN=R3, O=Let's Encrypt, C=US CN=ISRG Root X1, O=Internet Security Research Group, C=US | CN=R3, O=Let's Encrypt, C=US CN=ISRG Root X1, O=Internet Security Research Group, C=US CN=DST Root CA X3, O=Digital Signature Trust Co. | Mon Jan 24 07:33:10 CET 2022 Fri Sep 04 02:00:00 CEST 2020 Wed Jan 20 20:14:03 CET 2021 | Sun Apr 24 08:33:09 CEST 2022 Mon Sep 15 18:00:00 CEST 2025 Mon Sep 30 20:14:03 CEST 2024 | 771,49196-49195-49188-49187-49162-49161-52393-49200-49199-49192-49191-49172-49171-52392-157-156-61-60-53-47,65281-0-23-13-5-13172-18-16-11-10,29-23-24,0 | 3e4e87dda5a3162306609b7e330441d2 |
CN=R3, O=Let's Encrypt, C=US | CN=ISRG Root X1, O=Internet Security Research Group, C=US | Fri Sep 04 02:00:00 CEST 2020 | Mon Sep 15 18:00:00 CEST 2025 | |||||||
CN=ISRG Root X1, O=Internet Security Research Group, C=US | CN=DST Root CA X3, O=Digital Signature Trust Co. | Wed Jan 20 20:14:03 CET 2021 | Mon Sep 30 20:14:03 CEST 2024 | |||||||
Feb 23, 2022 11:21:43.549253941 CET | 67.205.63.212 | 443 | 192.168.11.11 | 49310 | CN=www.liveupdt.com CN=R3, O=Let's Encrypt, C=US CN=ISRG Root X1, O=Internet Security Research Group, C=US | CN=R3, O=Let's Encrypt, C=US CN=ISRG Root X1, O=Internet Security Research Group, C=US CN=DST Root CA X3, O=Digital Signature Trust Co. | Mon Jan 24 07:33:10 CET 2022 Fri Sep 04 02:00:00 CEST 2020 Wed Jan 20 20:14:03 CET 2021 | Sun Apr 24 08:33:09 CEST 2022 Mon Sep 15 18:00:00 CEST 2025 Mon Sep 30 20:14:03 CEST 2024 | 771,49196-49195-49188-49187-49162-49161-52393-49200-49199-49192-49191-49172-49171-52392-157-156-61-60-53-47,65281-0-23-13-5-13172-18-16-11-10,29-23-24,0 | 3e4e87dda5a3162306609b7e330441d2 |
CN=R3, O=Let's Encrypt, C=US | CN=ISRG Root X1, O=Internet Security Research Group, C=US | Fri Sep 04 02:00:00 CEST 2020 | Mon Sep 15 18:00:00 CEST 2025 | |||||||
CN=ISRG Root X1, O=Internet Security Research Group, C=US | CN=DST Root CA X3, O=Digital Signature Trust Co. | Wed Jan 20 20:14:03 CET 2021 | Mon Sep 30 20:14:03 CEST 2024 |
System Behavior
Start time: | 11:21:35 |
Start date: | 23/02/2022 |
Path: | /usr/libexec/xpcproxy |
Arguments: | n/a |
File size: | 43488 bytes |
MD5 hash: | d1bb9a4899f0af921e8188218b20d744 |
Start time: | 11:21:35 |
Start date: | 23/02/2022 |
Path: | /Applications/Safari.app/Contents/MacOS/Safari |
Arguments: | /Applications/Safari.app/Contents/MacOS/Safari |
File size: | 20896 bytes |
MD5 hash: | 8e18be737fe87f19fe7a97b4821e2005 |