IOC Report
iTerm2

loading gif

Processes

Path
Cmdline
Malicious
/usr/libexec/xpcproxy
-
/usr/libexec/nsurlstoraged
/usr/libexec/nsurlstoraged --privileged
/Library/Frameworks/Mono.framework/Versions/4.4.2/bin/mono-sgen32
-
/Users/bernard/Desktop/iTerm2
/Users/bernard/Desktop/iTerm2
/usr/libexec/xpcproxy
-
/usr/libexec/firmwarecheckers/eficheck/eficheck
/usr/libexec/firmwarecheckers/eficheck/eficheck --integrity-check-daemon

URLs

Name
IP
Malicious
https://iterm2.com/documentation-csiu.html
unknown
http://iterm2.com/captured_output.html
unknown
https://iterm2.com/bugsReport
unknown
https://google.com/search?q=%
unknown
https://iterm2.com/documentation-session-title.htmliterm2.set_title
unknown
https://iterm2.com/dynamic-profiles.html
unknown
https://iterm2.com/bugs
unknown
https://iterm2.com/automatic-profile-switching.html
unknown
https://iterm2.com/downloads/pyenv/betamanifest.json
unknown
https://iterm2.com/downloads/assets/nerd-fonts-v1.zip
unknown
http://iterm2.com/captured_output.htmlkeyclickm4av32
unknown
http://www.iterm2.com/coprocesses.html
unknown
https://iterm2.com/download.sh
unknown
https://www.iterm2.com/documentation.htmlPython
unknown
http://www.iterm2.com/smartselection.html
unknown
https://iterm2.com/downloads/pyenv/manifest.jsonScripting:
unknown
https://iterm2.com/slow_triggers
unknown
https://iterm2.com/documentation-copymode.html
unknown
https://openai.com/join/
unknown
https://iterm2.com/ai-plugin.html
unknown
https://iterm2.com/documentation-shell-integration.html
unknown
https://iterm2.com/downloads/pyenv/betamanifest.jsonScripting:
unknown
https://www.iterm2.com/documentation-triggers.html
unknown
https://iterm2.com/patrons.txt
unknown
https://iterm2.com/python-api-security-modelNew
unknown
https://iterm2.com/regex
unknown
https://whitebox.so/?utm_source=iTerm2
unknown
https://iterm2.com/documentation-csiu.html-
unknown
https://iterm2.com/search_syntax.html
unknown
https://www.iterm2.com/documentation.html
unknown
https://iterm2.com/clock-status-bar-component-help
unknown
https://iterm2.com/documentation-copymode.html-
unknown
https://iterm2.com/status-bar-layout
unknown
https://iterm2.com/3.3/documentation-status-bar.html
unknown
https://iterm2.com/downloads/pyenv/manifest.json
unknown
https://gitlab.com/gnachman/iterm2/wikis/TmuxIntegration
unknown
https://iterm2.com/troubleshoot-hostnameConnect
unknown
https://iterm2.com/why_no_content.html
unknown
https://iterm2.com/aiterm
unknown
https://iterm2.com/documentation-session-title.html
unknown
https://www.iterm2.com/colorgallery
unknown
https://www.iterm2.com/triggers.html
unknown
https://iterm2.com/captured_output.html
unknown
https://iterm2.com/python-api-security-model
unknown
https://api.openai.com/v1/completions
unknown
https://iterm2.com/Home
unknown
https://api.openai.com/v1/chat/completionsthe
unknown
https://platform.openai.com/api-keys
unknown
https://iterm2.com/shell_integration/install_shell_integration.sh
unknown
http://www.iterm2.com/coprocesses.htmlc16
unknown
https://iterm2.com/troubleshoot-hostname
unknown
https://iterm2.com//tmux22bug.html
unknown
https://iterm2.com/shell_integration/install_shell_integration_and_utilities.sh
unknown
https://iterm2.com/images.html
unknown
https://iterm2.com/shell_integration.html
unknown
https://iterm2.com/donate.html
unknown
https://iterm2.com/ai-plugin.htmlProblem
unknown
https://iterm2.com/credits
unknown
https://latch.bio/
unknown
https://api.openai.com/v1/chat/completions
unknown
https://www.iterm2.com/documentation-utilities.html
unknown
https://iterm2.com/regexkMGTPEZY%
unknown
https://iterm2.com/documentation-smart-selection.htmlCopyEnter
unknown
https://iterm2.com/lastpass-cli
unknown
https://www.iterm2.com/triggers.html-
unknown
https://www.iterm2.com/smartselection.html
unknown
http://www.iterm2.com/smartselection.html-
unknown
https://iterm2.com/downloads/assets/nerd-fonts-v1.zipv32
unknown
https://openai.com/join/https://platform.openai.com/api-keyshttps://iterm2.com/aiterm/opt/local/bin/
unknown
https://iterm2.com/python-api
unknown
https://iterm2.com/ai-prompt-helpCheckMarkWarningSignCopy
unknown
https://iterm2.com/coprocesses.html
unknown
https://iterm2.com/creditsCreditshttps://iterm2.com/patrons.txtError
unknown
https://iterm2.com/documentation-smart-selection.html
unknown
https://iterm2.com/paste_bracketing
unknown
https://iterm2.com/bugs.
unknown
https://iterm2.com/documentation-shell-integration.htmlhttps://www.iterm2.com/documentation-utilitie
unknown
https://iterm2.com/python-api-auth.html
unknown
https://iterm2.com/
unknown
https://gitlab.com/gnachman/iterm2/uploads/
unknown
https://gitlab.com/gnachman/iterm2/-/wikis/SSH-Integration
unknown
https://iterm2.com/badges.html
unknown
https://iterm2.com/ai-prompt-help
unknown
http://iterm2.com/shell_integration.html
unknown
There are 74 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
appledownload.map.fastly.net
151.101.67.8
h3.apis.apple.map.fastly.net
151.101.3.6

IPs

IP
Domain
Country
Malicious
151.101.67.8
appledownload.map.fastly.net
United States
184.50.204.201
unknown
United States
151.101.131.6
unknown
United States