Analysis

  • max time kernel
    77s
  • max time network
    125s
  • platform
    macos-10.15_amd64
  • resource
    macos-20240611-en
  • resource tags

    arch:amd64arch:i386image:macos-20240611-enkernel:19b77alocale:en-usos:macos-10.15-amd64system
  • submitted
    04-07-2024 14:03

General

  • Target

    $PLUGINSDIR/PrimoRedist/pxhelp20.sys

  • Size

    44KB

  • MD5

    e42e3433dbb4cffe8fdd91eab29aea8e

  • SHA1

    6f764c5e20eecd6f3d4154d9d89d2420dd783470

  • SHA256

    20abd8372b242fd356ac143e7eb56f93cfea4988ed1b0c4434cb64c387d7f66c

  • SHA512

    260a2104aef64fd5a276e289e1cbe37502583e94039af41a3803f1c464d78c72def4e911f14312b94c63b28b1f6792a7bd10f23db837daf5a1a9ffd478c40810

  • SSDEEP

    768:UD8M77TDwgA0BdpVVIC8X4tzQq2edfEVxAyDiypP+TsZ0I8V8/L+HbmpmF:Ux73E0/iQz12asV5VUsWI8o0mIF

Score
1/10

Malware Config

Signatures

Processes

  • /bin/sh
    sh -c "sudo /bin/zsh -c \"/Users/run/\$PLUGINSDIR/PrimoRedist/pxhelp20.sys\""
    1⤵
      PID:535
    • /bin/bash
      sh -c "sudo /bin/zsh -c \"/Users/run/\$PLUGINSDIR/PrimoRedist/pxhelp20.sys\""
      1⤵
        PID:535
      • /usr/bin/sudo
        sudo /bin/zsh -c /Users/run//PrimoRedist/pxhelp20.sys
        1⤵
          PID:535
          • /bin/zsh
            /bin/zsh -c /Users/run//PrimoRedist/pxhelp20.sys
            2⤵
              PID:536
            • /Users/run//PrimoRedist/pxhelp20.sys
              /Users/run//PrimoRedist/pxhelp20.sys
              2⤵
                PID:536
            • /usr/bin/pluginkit
              /usr/bin/pluginkit -e ignore -i com.microsoft.OneDrive.FinderSync
              1⤵
                PID:605
              • /usr/sbin/spctl
                /usr/sbin/spctl --assess --type execute /var/folders/pq/yy2b5ptn4cz739jgclj4m1wm0000gp/T/OneDriveUpdaterBCBF2C69/OneDrive.app
                1⤵
                  PID:606

                Network

                MITRE ATT&CK Matrix

                Replay Monitor

                Loading Replay Monitor...

                Downloads