encode_keychange
executablemacOS133.1 KBx86_64, arm64
Hardware communication utility — manages direct driver and device interactions
Communicates directly with hardware drivers and devices through low-level interfaces. Contacts multiple network endpoints for operations or telemetry purposes. Accesses five file paths during execution and references bundle identifiers for inter-process communication. Uses eight standard macOS frameworks to support its hardware operations. Runs with capabilities that bypass normal sandboxing restrictions to interface with drivers and hardware directly.AI
Fingerprint
- Platform
- macOS
- Type
- executable
- Arch
- x86_64, arm64
- Min OS
- 26.1.0
- SDK
- 26.1.0
- File Size
- 133.1 KB
- UUID
- FEE5AF0C-30BD-3698-AF07-45700558AD45
- Analyzed
- 2026-04-07T05:21:12Z
- CDHash
- c39bd79a53c480b84168c6efb0781485eb20009a11e6193c83601116815e00fa
Capabilities
HardwareDirect hardware/driver communication
/System/Library/Frameworks/IOKit.framework/Versions/A/IOKitFrameworks8
Interesting Strings
Bundle IDs(1)
File Paths(5)
/System/Library/Frameworks/ApplicationServices.framework/Versions/A/ApplicationServices/System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation/System/Library/Frameworks/CoreServices.framework/Versions/A/CoreServices/System/Library/Frameworks/DiskArbitration.framework/Versions/A/DiskArbitration/System/Library/Frameworks/IOKit.framework/Versions/A/IOKit
Network Surface
Networking Frameworks
DNA Capability Vector
Location
0
Keychain
0
Network
0
Storage
0
Hardware
1
IPC
0
Analytics
0
Security
0
System
0
Behavioral Profile
URL Endpoints
4
Telemetry Strings
0
File Paths
5
Bundle IDs
1
IOKit Constants
0
Library Functions
0
Structural HashesSHA-256
Static Libraries0 / 7 functions identified
Functions(7)
0x1000008c8sub_1000008c8
0x100001688sub_100001688
0x100001714sub_100001714
0x100001748sub_100001748
0x100001bd8sub_100001bd8
0x100001be8sub_100001be8
0x100001d4csub_100001d4c
Imports44 symbols from 2 dylibs
Exports1
_mh_execute_header0x0