IOCReport

loading gif

Files

File Path
Type
Category
Malicious
https://sparkasse.corona-umstellungsverfahren-de.com/ALC81OPACG
URL
initial url
malicious
/Users/berri/Library/Safari/.dat.nosync0210.8kfcUv
Apple binary property list
dropped
clean
/Users/berri/Library/Safari/.dat.nosync0210.bKXvUw
XML 1.0 document, ASCII text
dropped
clean
/Users/berri/Library/Safari/Favicon Cache/favicons/.dat.nosync0210.t7NkvP
MS Windows icon resource - 6 icons, 256x256 withPNG image data, 256 x 256, 8-bit/color RGB, non-interlaced, 32 bits/pixel, 128x128, 32 bits/pixel
dropped
clean
/dev/null
ASCII text
dropped
clean
/private/var/folders/ql/8wfqxrtx52n95h35b6cz4nyw0000gn/0/SafariFamily/Safari/.dat.nosync0210.Is8mxg
Apple binary property list
dropped
clean
/private/var/folders/ql/8wfqxrtx52n95h35b6cz4nyw0000gn/C/mds/mdsDirectory.db_
Mac OS X Keychain File
dropped
clean
/private/var/folders/ql/8wfqxrtx52n95h35b6cz4nyw0000gn/C/mds/mdsObject.db_
Mac OS X Keychain File
dropped
clean

Processes

Path
Cmdline
Malicious
/usr/libexec/xpcproxy
n/a
clean
/Applications/Safari.app/Contents/MacOS/Safari
/Applications/Safari.app/Contents/MacOS/Safari
clean

URLs

Name
IP
Malicious
https://sparkasse.corona-umstellungsverfahren-de.com/ALC81OPACG
unknown
malicious

Domains

Name
IP
Malicious
sparkasse.corona-umstellungsverfahren-de.com
47.243.138.168
malicious
dart.l.doubleclick.net
172.217.16.102
clean
pagead46.l.doubleclick.net
142.250.181.226
clean
static.rheinturm.de
85.13.148.189
clean
stats.l.doubleclick.net
142.250.27.154
clean
gateway.fe.apple-dns.net
17.248.145.74
clean
a97adde81b00f2ca4.awsglobalaccelerator.com
13.248.242.197
clean
cm.g.doubleclick.net
172.217.20.2
clean
pixelglobal.sojern.com
107.178.244.119
clean
ib.anycast.adnxs.com
185.33.221.90
clean
kubernetes-loadbalancer.triptease.io
35.186.195.233
clean
static.triptease.io
unknown
clean
pixel.sojern.com
unknown
clean
ad.doubleclick.net
unknown
clean
onboard.triptease.io
unknown
clean
adservice.google.de
unknown
clean
stats.g.doubleclick.net
unknown
clean
beacon.sojern.com
unknown
clean
x1.c.lencr.org
unknown
clean
api.triptease.io
unknown
clean
ib.adnxs.com
unknown
clean
r3.o.lencr.org
unknown
clean
match.adsrvr.org
unknown
clean
There are 13 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
47.243.138.168
sparkasse.corona-umstellungsverfahren-de.com
United States
malicious
185.33.221.90
ib.anycast.adnxs.com
Netherlands
clean
107.178.244.119
pixelglobal.sojern.com
United States
clean
13.248.242.197
a97adde81b00f2ca4.awsglobalaccelerator.com
United States
clean
17.253.55.204
unknown
United States
clean
17.248.145.74
gateway.fe.apple-dns.net
United States
clean
104.76.200.212
unknown
United States
clean
85.13.148.189
static.rheinturm.de
Germany
clean
172.217.16.102
dart.l.doubleclick.net
United States
clean
142.250.27.154
stats.l.doubleclick.net
United States
clean
17.171.27.65
unknown
United States
clean
35.186.195.233
kubernetes-loadbalancer.triptease.io
United States
clean
172.217.20.2
cm.g.doubleclick.net
United States
clean
There are 3 hidden IPs, click here to show them.