IOC Report
https://www.youtube.com/channel/UCAuerig2N-RZWJT8x75V9yw

loading gif

Files

File Path
Type
Category
Malicious
/Users/berri/Library/Safari/.dat.nosync036f.TyISu0
Apple binary property list
dropped
/Users/berri/Library/Safari/Favicon Cache/favicons/.dat.nosync036f.pdcdlR
MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
dropped
/Users/berri/Library/WebKit/com.apple.Safari/WebsiteData/ResourceLoadStatistics/full_browsing_session_resourceLog.plist
Apple binary property list
dropped
/dev/null
ASCII text
dropped
/private/var/folders/ql/8wfqxrtx52n95h35b6cz4nyw0000gn/0/SafariFamily/Safari/.dat.nosync036f.Pk6yS5
Apple binary property list
dropped
/private/var/folders/ql/8wfqxrtx52n95h35b6cz4nyw0000gn/C/mds/mdsDirectory.db_
Mac OS X Keychain File
dropped
/private/var/folders/ql/8wfqxrtx52n95h35b6cz4nyw0000gn/C/mds/mdsObject.db_
Mac OS X Keychain File
dropped
/private/var/tmp/NSCreateObjectFileImageFromMemory-GLnGst
Mach-O 64-bit x86_64 bundle, flags:<NOUNDEFS|DYLDLINK|TWOLEVEL>
dropped
/private/var/tmp/NSCreateObjectFileImageFromMemory-TphzPP
Mach-O 64-bit x86_64 bundle, flags:<NOUNDEFS|DYLDLINK|TWOLEVEL>
dropped
/private/var/tmp/NSCreateObjectFileImageFromMemory-cKdWhB
Mach-O 64-bit x86_64 bundle, flags:<NOUNDEFS|DYLDLINK|TWOLEVEL>
dropped

Processes

Path
Cmdline
Malicious
/Library/Frameworks/Mono.framework/Versions/4.4.2/bin/mono-sgen32
n/a
/usr/bin/open
/usr/libexec/xpcproxy
n/a
/Applications/Safari.app/Contents/MacOS/Safari
/Applications/Safari.app/Contents/MacOS/Safari

URLs

Name
IP
Malicious
https://www.youtube.com/channel/UCAuerig2N-RZWJT8x75V9yw
https://www.youtube.com/channel/UCAuerig2N-RZWJT8x75V9yw
142.250.185.174
https://play.google.com/log?format=json&hasfast=true
172.217.16.142
https://consent.youtube.com/_/ConsentUi/browserinfo?f.sid=6542961051346440918&bl=boq_identityfrontenduiserver_20230314.06_p1&hl=en&gl=GB&_reqid=30759&rt=j
172.217.16.206
https://play.google.com/log?format=json&hasfast=true&authuser=0
172.217.16.142
https://consent.youtube.com/m?continue=https%3A%2F%2Fwww.youtube.com%2Fchannel%2FUCAuerig2N-RZWJT8x75V9yw%3Fcbrd%3D1&gl=GB&m=0&pc=yt&cm=2&hl=en&src=1
172.217.16.206
https://www.google.com/favicon.ico
142.250.186.164
https://consent.youtube.com/_/ConsentUi/browserinfo?f.sid=6542961051346440918&bl=boq_identityfrontenduiserver_20230314.06_p1&hl=en&gl=GB&_reqid=130759&rt=j
172.217.16.206
https://consent.youtube.com/m?continue=https%3A%2F%2Fwww.youtube.com%2Fchannel%2FUCAuerig2N-RZWJT8x7
unknown

Domains

Name
IP
Malicious
youtube-ui.l.google.com
142.250.185.174
play.google.com
172.217.16.142
gateway.fe.apple-dns.net
17.248.248.15
consent.youtube.com
172.217.16.206
www.google.com
142.250.186.164
www.youtube.com
unknown

IPs

IP
Domain
Country
Malicious
142.250.185.174
youtube-ui.l.google.com
United States
172.217.16.206
consent.youtube.com
United States
142.250.186.164
www.google.com
United States
172.217.16.142
play.google.com
United States