Does some MacOS service attempt to check SSH links?

The past few days I'm experiencing a repeated issue with the firewall of my web site host provider blocking my IP due to repeated failed SSH attempts. The only change I can think of that correlates is upgrading my Macs to High Sierra.


I've installed antivirus and run scans of all my machines, removed all web browser extensions, and looked for (and failed to find) any sort of networking software running in the background that I can recognize.


Can some kind soul point me to potential known culprits, or what sort of logs I should be looking at to see what is doing this?


Many thanks in advance.


Mark

Posted on Nov 6, 2017 6:25 AM

Reply
4 replies

Nov 6, 2017 7:06 AM in response to Spinland

Antivirus are no help. I realize you installed in order to look for causes of the problem, but not only they are useless, they tend to cause other problems themselves.


You could try installing Little Snitch, which can monitor network access, but I personally find it a nuisance.


You can run Etrecheck and post its report here, so we can have a chance to see if there is something suspicious.

Nov 6, 2017 7:06 AM in response to Luis Sequeira1

Yeah, I have no faith in them either, but my host provider raised that issue and I needed to be able to tell them I had eliminated that as a possibility. I used a trial period license and will be uninstalling the software asap.


I have Little Snitch on my laptop because I take that to client sites, and it's not raising any red flags. I really have little faith in the idea of some sort of malware being behind this. Sigh.


Thanks for the Etrecheck idea, I'll pursue that. I have five Macs on site so that'll take a little while.


Thanks again!

Nov 6, 2017 7:38 AM in response to Luis Sequeira1

Here's the check of the Mac Pro. I presume pasting the full text is the right protocol? If not I'll be happy to supply the others via the preferred method.


EtreCheck version: 3.4.6 (460)

Report generated 2017-11-06 10:36:16

Download EtreCheck from https://etrecheck.com

Runtime: 2:30

Performance: Excellent


Click the [Lookup] links for more information from Apple Support Communities.

Click the [Details] links for more information about that line.

Click the [Clean up] link to delete unused files.


Problem: Other problem

Description:

Possibility of unknown app trying to reach my web site server via SSH


Hardware Information:

Mac Pro (Late 2013)

[Technical Specifications] - [User Guide] - [Warranty & Service]

Mac Pro - model: MacPro6,1

1 3.5 GHz 6-Core Intel Xeon E5 (Xeon(R)) CPU: 6-core

32 GB RAM Upgradeable - [Instructions]

DIMM1

8 GB DDR3 ECC 1866 MHz ok

DIMM2

8 GB DDR3 ECC 1866 MHz ok

DIMM3

8 GB DDR3 ECC 1866 MHz ecc_errors

DIMM4

8 GB DDR3 ECC 1866 MHz ok

Handoff/Airdrop2: supported

Wireless: en2: 802.11 a/b/g/n/ac

iCloud Quota: 155.01 GB available


Video Information:

AMD FirePro D500 - VRAM: 3 GB

AMD FirePro D500 - VRAM: 3 GB

DELL U3415W 3440 x 1440 @ 50 Hz

LED Cinema Display 2560 x 1440


Disk Information:

OWC Aura SSD disk0: (959.89 GB) (Rotational)

EFI (disk0s1 - MS-DOS FAT32) <not mounted> [EFI]: 210 MB

MacintoshHD (disk0s2 - Journaled HFS+) / [Startup]: 959.03 GB (475.34 GB free)

Recovery HD (disk0s3 - Journaled HFS+) <not mounted> [Recovery]: 650 MB


MARVELL VIRTUALL ()


USB Information:

USB20Bus

hub_device

Apple Inc. BRCM20702 Hub

Apple Inc. Bluetooth USB Host Controller

USB30Bus

VIA Labs, Inc. USB3.0 Hub

VIA Labs, Inc. USB3.0 Hub

GenesysLogic USB3.0 Hub

Inateck ASM1153E

ASM1153E disk1: (4 TB)

EFI (disk1s1 - MS-DOS FAT32) <not mounted> [EFI]: 210 MB

External (disk1s2 - Journaled HFS+) /Volumes/External : 2.00 TB (166.85 GB free)

TimeMachine (disk1s3 - Journaled HFS+) /Volumes/TimeMachine : 2.00 TB (447.52 GB free)

VIA Labs, Inc. USB3.0 Hub

VIA Labs, Inc. USB3.0 Hub

VIA Labs, Inc. USB3.0 Hub

Seagate BUP Slim BK

BUP Slim BK disk3: (2 TB)

(disk3s1) <not mounted> [partition_map]: 32 KB

Work Mobile (disk3s3 - Journaled HFS+) /Volumes/Work Mobile : 2.00 TB (544.40 GB free)

VIA Labs, Inc. USB2.0 Hub

HD Pro Webcam C920

VIA Labs, Inc. USB2.0 Hub

GenesysLogic USB2.0 Hub

Focusrite Scarlett 2i4 USB

Audiofront MIDI Expression BLACK

VIA Labs, Inc. USB2.0 Hub

VIA Labs, Inc. USB2.0 Hub

VIA Labs, Inc. USB2.0 Hub

Apple Inc. Apple Watch Magnetic Charging Cable

Apple Inc. iPod

Tablet PTK-640

Apple, Inc. Keyboard Hub

Logitech USB Receiver

Apple, Inc Apple Keyboard

Sony DRX-800UL

Syncrosoft eLicenser

USB30Bus

hub_device

Apple Inc. iPad

Apple Inc. iPhone

Apple Inc. iPod

Apple Inc. Apple LED Cinema Display

Apple Inc. Display iSight

Apple Inc. Display Audio


Thunderbolt Information:

Apple Inc. thunderbolt_bus_2

Sonnet Technologies, Inc. USB 3.0 & Gigabit Ethernet Thunderbolt Adapter

Apple Inc. thunderbolt_bus_1

Apple Inc. thunderbolt_bus_0


System Software:

macOS High Sierra 10.13 (17A405) - Time since boot: about 2 days


Gatekeeper:

Mac App Store and identified developers


Clean up:

/Library/LaunchDaemons/com.logmein.raupdate.plist

/Library/Application Support/LogMeIn/update/raupdate /s

Executable not found!

One orphan file found. [Clean up]


Kernel Extensions:

/Applications/iTube Studio.app

[not loaded] com.Perfect.Driver.SystemAudioRecorder (1.1.0 - SDK 10.6) [Lookup]


/Library/Application Support/LogMeIn/drivers

[loaded] com.logmein.driver.LogMeInSoundDriver (4.1.8517) [Lookup]


/Library/Extensions

[not loaded] com.FTDI.driver.D2XXHelper (1.0 - SDK 10.12) [Lookup]

[loaded] com.Logitech.Control Center.HID Driver (3.9.5 - SDK 10.8) [Lookup]

[loaded] com.Logitech.Unifying.HID Driver (1.3.5 - SDK 10.8) [Lookup]

[loaded] com.malwarebytes.mbam.rtprotection (3.1 - SDK 10.12) [Lookup]

[loaded] com.techsmith.TACC (1.0.3 - SDK 10.10) [Lookup]

[not loaded] com.wacom.kext.wacomtablet (Wacom Tablet 6.3.22-1 - SDK 10.12) [Lookup]

[not loaded] jp.co.roland.RDUSB0178Dev (1.0.2 - SDK 10.9) [Lookup]


System Launch Agents:

[not loaded] 8 Apple tasks

[loaded] 160 Apple tasks

[running] 120 Apple tasks


System Launch Daemons:

[not loaded] 33 Apple tasks

[loaded] 173 Apple tasks

[running] 122 Apple tasks


Launch Agents:

[running] com.Logitech.Control Center.Daemon.plist (Logitech Inc. - installed 2017-04-05) [Lookup]

[not loaded] com.adobe.AAM.Updater-1.0.plist (Adobe Systems, Inc. - installed 2017-08-11) [Lookup]

[failed] com.adobe.ARMDCHelper.cc24aef4a1b90ed56a725c38014c95072f92651fb65e1bf9c8e43c37a2 3d420d.plist (Adobe Systems, Inc. - installed 2017-04-04) [Lookup]

[running] com.adobe.AdobeCreativeCloud.plist (Adobe Systems, Inc. - installed 2017-09-26) [Lookup]

[running] com.brother.LOGINserver.plist (? a1772de2 41ad4933 - installed 2017-07-21) [Lookup]

[loaded] com.google.keystone.agent.plist (Google, Inc. - installed 2017-09-27) [Lookup]

[running] com.logmein.logmeingui.plist (LogMeIn, Inc. - installed 2017-09-23) [Lookup]

[running] com.logmein.logmeinguiagent.plist (LogMeIn, Inc. - installed 2017-09-23) [Lookup]

[not loaded] com.logmein.logmeinguiagentatlogin.plist (LogMeIn, Inc. - installed 2017-09-23) [Lookup]

[running] com.malwarebytes.mbam.frontend.agent.plist (Malwarebytes Corporation - installed 2017-11-04) [Lookup]

[loaded] com.oracle.java.Java-Updater.plist (? 1fb332c8 72ac4dde - installed 2017-10-25) [Lookup]

[running] com.wacom.wacomtablet.plist (Wacom Technology Corp. - installed 2017-06-13) [Lookup]


Launch Daemons:

[loaded] com.adobe.ARMDC.Communicator.plist (Adobe Systems, Inc. - installed 2017-04-04) [Lookup]

[loaded] com.adobe.ARMDC.SMJobBlessHelper.plist (Adobe Systems, Inc. - installed 2017-04-04) [Lookup]

[loaded] com.adobe.acc.installer.plist (Adobe Systems, Inc. - installed 2017-09-26) [Lookup]

[running] com.adobe.agsservice.plist (Adobe Systems, Inc. - installed 2017-09-26) [Lookup]

[loaded] com.adobe.fpsaud.plist (? 2afb3af7 564efddb - installed 2017-10-20) [Lookup]

[not loaded] com.apple.installer.cleanupinstaller.plist (? 1963bf56 0 - installed 2017-10-13)

[running] com.autodesk.backburner_manager.plist (? 1d85fe3b 3242b24d - installed 2010-03-03) [Lookup]

[running] com.autodesk.backburner_server.plist (Shell Script 686ee575 - installed 2010-03-03) [Lookup]

[loaded] com.autodesk.backburner_start.plist (Shell Script d833ca96 - installed 2010-03-03) [Lookup]

[running] com.bombich.ccchelper.plist (Bombich Software, Inc. - installed 2017-11-06) [Lookup]

[loaded] com.google.keystone.daemon.plist (Google, Inc. - installed 2017-10-13) [Lookup]

[running] com.logmein.logmeinserver.plist (LogMeIn, Inc. - installed 2017-09-23) [Lookup]

[loaded] com.logmein.raupdate.plist (? c8be1d3f 0 - installed 2017-04-11) [Lookup] - /Library/Application Support/LogMeIn/update/raupdate: Executable not found!

[running] com.malwarebytes.mbam.rtprotection.daemon.plist (Malwarebytes Corporation - installed 2017-11-04) [Lookup]

[running] com.malwarebytes.mbam.settings.daemon.plist (Malwarebytes Corporation - installed 2017-11-04) [Lookup]

[running] com.microsoft.autoupdate.helper.plist (Microsoft Corporation - installed 2017-10-12) [Lookup]

[loaded] com.microsoft.office.licensingV2.helper.plist (Microsoft Corporation - installed 2017-03-09) [Lookup]

[loaded] com.native-instruments.NativeAccess.Helper.plist (Native Instruments GmbH - installed 2017-05-08) [Lookup]

[loaded] com.oracle.java.Helper-Tool.plist (Shell Script e3fefdd2 - installed 2017-09-05) [Lookup]

[running] com.paceap.eden.licensed.plist (PACE Anti-Piracy, Inc. - installed 2017-10-24) [Lookup]

[loaded] com.redgiant.LinkUpdateChecker.plist (? 7f740f41 f596d6e8 - installed 2017-10-12) [Lookup]

[loaded] com.rogueamoeba.instanton-agent.plist (Rogue Amoeba Software, LLC - installed 2017-07-24) [Lookup]

[running] com.wacom.TabletHelper.plist (Wacom Technology Corp. - installed 2017-06-13) [Lookup]

[loaded] com.wacom.displayhelper.plist (Apple, Inc. - installed 2017-10-03)

[running] jp.co.roland.RDUSB0178Setupd.plist (Roland Corporation - installed 2017-05-01) [Lookup]


User Launch Agents:

[loaded] com.adobe.AAM.Updater-1.0.plist (Adobe Systems, Inc. - installed 2017-08-11) [Lookup]

[loaded] com.dropbox.DropboxMacUpdate.agent.plist (Dropbox, Inc. - installed 2017-08-10) [Lookup]

[loaded] com.redgiantsoftware.updater.plist (? de9e3665 0 - installed 2017-10-25) [Lookup]

[loaded] com.skype.skype.shareagent.plist (Skype Communications S.a.r.l - installed 2017-10-26) [Lookup]


User Login Items:

Aimersoft Helper Compact Application

(~/Library/Application Support/Helper/Aimersoft Helper Compact.app)

SpyderUtility Application

(/Applications/Datacolor/Spyder5Elite/Support/SpyderUtility.app)

Dropbox Application

(/Applications/Dropbox.app)

WunderlistHelper SMLoginItem - Hidden (Apple, Inc. - installed 2017-06-20)

(/Applications/Wunderlist.app/Contents/Library/LoginItems/WunderlistHelper.app)

EvernoteHelper SMLoginItem - Hidden (Apple, Inc. - installed 2017-11-03)

(/Applications/Evernote.app/Contents/Library/LoginItems/EvernoteHelper.app)


Internet Plug-ins:

AdobeAAMDetect: 3.0.0.0 (installed 2017-09-26) [Lookup]

FlashPlayer-10.6: 27.0.0.183 (installed 2017-10-25) [Lookup]

QuickTime Plugin: 7.7.3 (installed 2017-10-03)

AdobePDFViewerNPAPI: 17.012.20098 (installed 2017-08-29) [Lookup]

AdobePDFViewer: 17.012.20098 (installed 2017-08-29) [Lookup]

Flash Player: 27.0.0.183 (installed 2017-10-25) [Lookup]

o1dbrowserplugin: 5.41.3.0 (installed 2017-04-05) [Lookup]

googletalkbrowserplugin: 5.41.3.0 (installed 2015-12-11) [Lookup]

WacomTabletPlugin: WacomTabletPlugin 2.1.0.6 (installed 2017-05-12) [Lookup]

JavaAppletPlugin: Java 8 Update 151 build 12 (installed 2017-10-25) Check version


Safari Extensions:

[disabled] Evernote Web Clipper - Evernote Corp. - http://evernote.com (installed 2017-10-05)

[disabled] Adblock Plus - Eyeo GmbH - https://adblockplus.org/ (installed 2017-04-04)

[disabled] Amazon Assistant for Safari - Amazon - https://www.amazon.com?tag=amz-mkt-saf-us-20 (installed 2017-10-22)

[enabled] iTube Studio - iTube Studio - http://itube.aimersoft.com (installed 2017-06-14)

[disabled] Tampermonkey - Jan Biniok - http://tampermonkey.net (installed 2017-10-05)


3rd Party Preference Panes:

Flash Player (installed 2017-10-20) [Lookup]

Java (installed 2017-10-25) [Lookup]

Logitech Control Center (installed 2017-04-05) [Lookup]

ME-80 (installed 2016-09-16) [Lookup]

WacomTablet (installed 2017-05-12) [Lookup]


Time Machine:

Skip System Files: NO

Mobile backups: OFF

Auto backup: YES

Volumes being backed up:

MacintoshHD: Disk size: 959.03 GB Disk used: 483.70 GB

Destinations:

TimeMachine [Local]

Total size: 2.00 TB

Total number of backups: 54

Oldest backup: 9/18/17, 2:13 PM

Last backup: 11/6/17, 9:14 AM

Size of backup disk: Adequate

Backup size 2.00 TB > (Disk used 483.70 GB X 3)


Top Processes by CPU:

13% kernel_task

6% Mail

5% WindowServer

4% Terminal

2% RTProtectionDaemon


Top Processes by Memory:

2.04 GB kernel_task

526 MB mds_stores

308 MB Dropbox

284 MB iTunes

243 MB Mail


Top Processes by Network Use:

Input Output Process name

889 MB 351.81 GB kernel_task

66 MB 116 MB Mail

69 MB 4 MB mDNSResponder

48 MB 9 MB Dropbox

36 MB 6 MB smbd


Top Processes by Energy Use:

11.28 Terminal

6.88 WindowServer

3.74 Mail

2.20 ditto


Virtual Memory Information:

22.12 GB Available RAM

7.12 GB Free RAM

9.88 GB Used RAM

14.99 GB Cached files

251 MB Swap Used


Software installs (last 30 days):

Adobe Flash Player: (installed 2017-10-10)

Microsoft AutoUpdate: (installed 2017-10-12)

Microsoft OneNote for Mac: (installed 2017-10-12)

Microsoft Excel for Mac: (installed 2017-10-12)

Microsoft PowerPoint for Mac: (installed 2017-10-12)

Microsoft Outlook for Mac: (installed 2017-10-12)

Microsoft Word for Mac: (installed 2017-10-12)

1Password: 6.8.3 (installed 2017-10-13)

Adobe Flash Player: (installed 2017-10-16)

Miroslav Philharmonik 2: (installed 2017-10-23)

Miroslav Philharmonik 2: (installed 2017-10-23)

Authorization Manager (Ver. 1.0.18): (installed 2017-10-23)

SampleTank 3 CS: (installed 2017-10-24)

SampleTank 3 CS: (installed 2017-10-24)

MODO BASS: (installed 2017-10-24)

Miroslav Philharmonik 2: (installed 2017-10-24)

AmpliTube 4: (installed 2017-10-24)

Toontrack Product Manager: (installed 2017-10-24)

EW Installation Center: (installed 2017-10-24)

PLAY: (installed 2017-10-24)

Slack: 2.8.2 (installed 2017-10-24)

Java 8 Update 151: (installed 2017-10-25)

Adobe Flash Player: (installed 2017-10-25)

nanoKONTROL2 Control Surface plug-in for GarageBand/Logic: (installed 2017-10-26)

nanoKONTROL2 Control Surface plug-in for GarageBand/Logic: (installed 2017-10-26)

nanoKONTROL2 Control Surface plug-in for GarageBand/Logic: (installed 2017-10-26)

MIDI Expression Control: (installed 2017-10-27)

Poser 11 Update: 11.0.6 (installed 2017-10-30)

Evernote: 6.13 (installed 2017-11-03)

Malwarebytes for Mac: (installed 2017-11-04)

Deliveries: 3.0.6 (installed 2017-11-04)

1Password: 6.8.4 (installed 2017-11-06)


Install information may not be complete.


Diagnostics Events (last 3 days for minor events):

2017-11-05 21:09:27 com.apple.WebKit.WebContent Crash [Open]

Cause: Pure virtual function called!

abort() called

Bundle controller class:

BrowserBundleController

2017-11-04 08:39:12 Last shutdown cause: 3 - Hard shutdown

2017-11-04 00:51:20 mds_stores High CPU use [Open] [Details]

2017-11-03 23:59:02 Kernel Panic [Open] [Details]

3rd Party Kernel Extensions:

com.techsmith.TACC 1.0.3

com.Logitech.Control Center.HID Driver 3.9.5

com.Logitech.Unifying.HID Driver 1.3.5

2017-11-03 23:44:58 Adobe CEF Helper.app Crash [Open]

2017-11-03 23:07:21 SpyderUtility.app Crash [Open]

2017-11-03 16:13:38 Adobe Premiere Pro CC 2018.app High CPU use [Open] [Details]

2017-11-03 13:11:20 Adobe After Effects CC 2018.app High CPU use [Open] [Details]

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Does some MacOS service attempt to check SSH links?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.