Daisukixci
07/07/2021, 12:05 PMallister
07/07/2021, 12:06 PMDaisukixci
07/07/2021, 12:06 PMallister
07/07/2021, 12:06 PMURLDownloader
{'Input': {'filename': 'osquery.pkg',
'url': '<https://osquery-packages.s3.amazonaws.com/darwin/osquery.pkg'}}>
URLDownloader: No value supplied for prefetch_filename, setting default value of: False
URLDownloader: No value supplied for CHECK_FILESIZE_ONLY, setting default value of: False
URLDownloader: Storing new Last-Modified header: Tue, 22 Jun 2021 19:04:54 GMT
URLDownloader: Storing new ETag header: "9180d84001b51fd92f85e8d5ba418db8"
URLDownloader: Downloaded /Users/allister/Library/AutoPkg/Cache/com.github.keeleysam.recipes.osquery.download/downloads/osquery.pkg
{'Output': {'download_changed': True,
'etag': '"9180d84001b51fd92f85e8d5ba418db8"',
'last_modified': 'Tue, 22 Jun 2021 19:04:54 GMT',
'pathname': '/Users/allister/Library/AutoPkg/Cache/com.github.keeleysam.recipes.osquery.download/downloads/osquery.pkg',
'url_downloader_summary_result': {'data': {'download_path': '/Users/allister/Library/AutoPkg/Cache/com.github.keeleysam.recipes.osquery.download/downloads/osquery.pkg'},
'summary_text': 'The following '
'new items were '
'downloaded:'}}}
EndOfCheckPhase
{'Input': {}}
{'Output': {}}
CodeSignatureVerifier
{'Input': {'expected_authority_names': ['Developer ID Installer: Theodore Reed '
'(B89LNTUADM)',
'Developer ID Certification Authority',
'Apple Root CA'],
'input_path': '/Users/allister/Library/AutoPkg/Cache/com.github.keeleysam.recipes.osquery.download/downloads/osquery.pkg'}}
Daisukixci
07/07/2021, 12:07 PMallister
07/07/2021, 12:07 PMDaisukixci
07/07/2021, 12:07 PMallister
07/07/2021, 12:07 PM3f9ab772596f4da69687a2d7db9a382535b5eabf2346abd452b24666b8f25102
Daisukixci
07/07/2021, 12:07 PMallister
07/07/2021, 12:08 PM% santactl fileinfo /Users/allister/Library/AutoPkg/Cache/com.github.keeleysam.recipes.osquery.download/downloads/osquery.pkg
Path : /Users/allister/Library/AutoPkg/Cache/com.github.keeleysam.recipes.osquery.download/downloads/osquery.pkg
SHA-256 : 3f9ab772596f4da69687a2d7db9a382535b5eabf2346abd452b24666b8f25102
Daisukixci
07/07/2021, 12:08 PMallister
07/07/2021, 12:08 PMDaisukixci
07/07/2021, 12:18 PMallister
07/07/2021, 12:19 PMStefano Bonicatti
07/07/2021, 12:34 PMallister
07/07/2021, 12:44 PMpkgutil --expand autopkgpath /tmp/s3
then used archive utility to expand the payload and diff'd them which pointed to osqueryd (and the pkginfo, since it looks at exact size in bytes of the payload, and bom as per the content you see converted by lsbom) being differentStefano Bonicatti
07/07/2021, 12:56 PMallister
07/07/2021, 1:11 PMStefano Bonicatti
07/07/2021, 1:11 PMallister
07/07/2021, 1:11 PMStefano Bonicatti
07/07/2021, 1:11 PMcodesign --verbose=4 -dv ../website/osquery/Payload/usr/local/bin/osqueryd
Executable=/private/tmp/osquery/website/osquery/Payload/usr/local/bin/osqueryd
Identifier=osqueryd
Format=Mach-O thin (x86_64)
CodeDirectory v=20500 size=311636 flags=0x10000(runtime) hashes=9733+2 location=embedded
VersionPlatform=1
VersionMin=658432
VersionSDK=721152
Hash type=sha256 size=32
CandidateCDHash sha256=4010e5a75de2c29387cdfd76ed20ddaa9c0f438e
CandidateCDHashFull sha256=4010e5a75de2c29387cdfd76ed20ddaa9c0f438e4bb851c486de2b46e0476cd0
Hash choices=sha256
CMSDigest=4010e5a75de2c29387cdfd76ed20ddaa9c0f438e4bb851c486de2b46e0476cd0
CMSDigestType=2
Page size=4096
-2=695ae83a2af26948741ec57ed0f661fa69ffece7e4fc6e7c81b3550cde5492a7
CDHash=4010e5a75de2c29387cdfd76ed20ddaa9c0f438e
Signature size=8996
Authority=Developer ID Application: Theodore Reed (B89LNTUADM)
Authority=Developer ID Certification Authority
Authority=Apple Root CA
Timestamp=22 Jun 2021 at 21:04:40
Info.plist=not bound
TeamIdentifier=B89LNTUADM
Runtime Version=11.1.0
Sealed Resources=none
Internal requirements count=1 size=168
codesign --verbose=4 -dv osquery/Payload/usr/local/bin/osqueryd
Executable=/private/tmp/osquery/github/osquery/Payload/usr/local/bin/osqueryd
Identifier=osqueryd
Format=Mach-O thin (x86_64)
CodeDirectory v=20500 size=311732 flags=0x10000(runtime) hashes=9733+5 location=embedded
VersionPlatform=1
VersionMin=658432
VersionSDK=721152
Hash type=sha256 size=32
CandidateCDHash sha256=70e03c536569ef97594a762c8f428a69752acf40
CandidateCDHashFull sha256=70e03c536569ef97594a762c8f428a69752acf40220b6ae74cd22c4cb96fcbec
Hash choices=sha256
CMSDigest=70e03c536569ef97594a762c8f428a69752acf40220b6ae74cd22c4cb96fcbec
CMSDigestType=2
Page size=4096
-5=cf468074bceac0fbab1058e86626b0357adf297c18c7a4fc22929f6644b4f6e0
-4=0000000000000000000000000000000000000000000000000000000000000000
-3=0000000000000000000000000000000000000000000000000000000000000000
-2=eedc00297f1acf7b04a82fa071552093e345ee06d62595e66c766aeeef05665a
CDHash=70e03c536569ef97594a762c8f428a69752acf40
Signature size=9022
Authority=Developer ID Application: OSQUERY A Series of LF Projects, LLC (3522FA9PXF)
Authority=Developer ID Certification Authority
Authority=Apple Root CA
Timestamp=15 Jun 2021 at 03:38:09
Info.plist=not bound
TeamIdentifier=3522FA9PXF
Runtime Version=11.1.0
Sealed Resources=none
Internal requirements count=1 size=168
allister
07/07/2021, 1:14 PMStefano Bonicatti
07/07/2021, 1:14 PMseph
07/07/2021, 1:45 PMDaisukixci
07/07/2021, 1:46 PMseph
07/07/2021, 1:56 PMallister
07/07/2021, 2:16 PMDaisukixci
07/07/2021, 3:24 PM