|
|
|
|
|
by johnisgood
234 days ago
|
|
So I downloaded this file... Apparently it is: $ file -b grecaptcha
Mach-O universal binary with 2 architectures: [x86_64:\012- Mach-O 64-bit x86_64 executable, flags:<NOUNDEFS|DYLDLINK|TWOLEVEL|PIE>] [\012- arm64:\012- Mach-O 64-bit arm64 executable, flags:<NOUNDEFS|DYLDLINK|TWOLEVEL|PIE>]
I cannot perform a dynamic analysis as I do not have macOS. :(May anyone do it for me? Use "otool", "dtruss", and "tcpdump" or something. :D Be careful! The executable is available here: https://www.amanagencies.com/assets/js/grecaptcha as per decoded base64. |
|
> AMOS is designed for broad data theft, capable of stealing credentials, browser data, cryptocurrency wallets, Telegram chats, VPN profiles, keychain items, Apple Notes, and files from common folders.
[0] https://www.trendmicro.com/en_us/research/25/i/an-mdr-analys...