Analysis showcase

Explore results for prevalent macOS malware.

  • PDF-Brain.dmg

    Apple disk image

    The PDF-Brain app executed, creating temporary Metal, GPU, Flutter-engine cache, and CFNetwork download files, and issued DNS queries for etoftheappyrince.org and atsheisdomestic.org.

    Network IOCs
    2 domains
    Captured files
    24 artifacts
    Code signing
    Unsigned
    etoftheappyrince.orgatsheisdomestic.org
    644fc49fa1006a2a2acace694e5fb83753164e2617051ece6d9dc9ea32329e70
    Open scan
  • Maccy.dmg

    Apple disk image

    The sample launched /usr/bin/osascript via /bin/zsh to run Maccy.scpt; osascript queried api.live-updates.online and modified cache and HTTP storage files under the user's Library directories.

    Process chain
    zsh → osascript
    Network IOCs
    1 domain
    Captured files
    2 artifacts
    api.live-updates.onlineMaccy.scpt
    2b512f6c393edad89a89ecafe26cd23b71cfdd271c10522f8dba98997ebf39bb
    Open scan
  • Werkbit.dmg

    Apple disk image

    The sample executed its veltod binary, resolved raw.githubusercontent.com, and attempted a TLS connection to that host over port 443 while modifying temporary and user cache database files.

    Code signing
    Revoked
    Network IOCs
    1 domain, 9 IPs
    Captured files
    4 artifacts
    raw.githubusercontent.comveltod
    3a9d703ba7f7564399365db7ab8b04238806ef7a53df0b6822f32b80bf0f5a80
    Open scan