2023-05-11 14:32:17 +00:00
|
|
|
-- Find unexpected regular files in /var/run
|
|
|
|
--
|
|
|
|
-- false positives:
|
|
|
|
-- * none known
|
|
|
|
--
|
|
|
|
-- references:
|
|
|
|
-- * https://sandflysecurity.com/blog/bpfdoor-an-evasive-linux-backdoor-technical-analysis/
|
|
|
|
--
|
2023-05-11 14:33:51 +00:00
|
|
|
-- tags: persistent
|
2023-05-11 14:32:17 +00:00
|
|
|
-- platform: darwin
|
2023-05-11 14:33:51 +00:00
|
|
|
SELECT
|
|
|
|
file.filename,
|
|
|
|
uid,
|
|
|
|
gid,
|
|
|
|
mode,
|
|
|
|
file.ctime,
|
|
|
|
file.atime,
|
|
|
|
file.mtime,
|
|
|
|
file.size,
|
|
|
|
hash.sha256,
|
|
|
|
magic.data
|
|
|
|
FROM
|
|
|
|
file
|
|
|
|
LEFT JOIN hash on file.path = hash.path
|
|
|
|
LEFT JOIN magic ON file.path = magic.path
|
|
|
|
WHERE
|
|
|
|
file.directory = "/var/run"
|
|
|
|
AND file.type = "regular"
|
|
|
|
AND file.filename NOT IN (
|
2023-10-02 15:35:11 +00:00
|
|
|
'.DidRunFLO',
|
2023-08-15 22:13:06 +00:00
|
|
|
'.autoBackup',
|
2023-10-02 15:35:11 +00:00
|
|
|
'.fctcompsupdate',
|
2024-02-16 22:14:11 +00:00
|
|
|
'VMware Fusion Services.lock',
|
2023-08-15 22:13:06 +00:00
|
|
|
'FirstBootAfterUpdate',
|
|
|
|
'FirstBootCleanupHandled',
|
2023-05-11 14:33:51 +00:00
|
|
|
'appfwd.pid',
|
2024-09-23 15:07:53 +00:00
|
|
|
'MobileAssetStartupActivation.doneThisBoot',
|
2023-05-11 14:33:51 +00:00
|
|
|
'auditd.pid',
|
|
|
|
'automount.initialized',
|
2023-05-23 15:31:37 +00:00
|
|
|
'bootpd.pid',
|
2023-05-11 14:33:51 +00:00
|
|
|
'com.apple.DumpPanic.finishedPMUFaultHandling',
|
|
|
|
'com.apple.DumpPanic.finishedThisBoot',
|
2023-08-15 22:13:06 +00:00
|
|
|
'com.apple.WindowServer.didRunThisBoot',
|
2023-05-11 14:33:51 +00:00
|
|
|
'com.apple.logind.didRunThisBoot',
|
|
|
|
'com.apple.loginwindow.didRunThisBoot',
|
|
|
|
'com.apple.mdmclient.daemon.didRunThisBoot',
|
|
|
|
'com.apple.mobileassetd-MobileAssetBrain',
|
|
|
|
'com.apple.parentalcontrols.webfilterctl.mutex',
|
|
|
|
'com.apple.softwareupdate.availableupdatesupdated',
|
|
|
|
'diskarbitrationd.pid',
|
2023-08-15 22:13:06 +00:00
|
|
|
'fctc.s',
|
2023-05-11 14:33:51 +00:00
|
|
|
'hdiejectd.pid',
|
2023-06-07 13:55:17 +00:00
|
|
|
'installd.commit.pid',
|
2023-05-11 15:29:55 +00:00
|
|
|
'kdc.pid',
|
2023-05-11 14:33:51 +00:00
|
|
|
'prl_disp_service.pid',
|
|
|
|
'prl_naptd.pid',
|
|
|
|
'prl_watchdog-ebdba5702a20.pid',
|
|
|
|
'resolv.conf',
|
|
|
|
'rtadvd.pid',
|
2023-05-23 15:31:37 +00:00
|
|
|
'signpost_reporter_running',
|
2023-05-11 14:33:51 +00:00
|
|
|
'socketfilterfw.launchd',
|
|
|
|
'syslog.pid',
|
|
|
|
'systemkeychaincheck.done',
|
|
|
|
'utmpx',
|
|
|
|
'wifi'
|
|
|
|
)
|
2024-01-09 00:07:57 +00:00
|
|
|
AND NOT file.filename LIKE '%.pid'
|
2023-05-11 14:33:51 +00:00
|
|
|
GROUP BY
|
|
|
|
file.path;
|