Ocsp.pki.goog and associated malware
The below urls and constituent serving ip’s come up a fair amount in company iPhones. The UTF-8 hashes correspond to “some” application or octet stream, but, while the URL’s themselves scan somewhat clean, apart from invalid certificates and lousy Whois info, the serving up addresses are loaded with malicious communicating files, many of which reference these same url/filehash/ GET requests.
if anyone has any pertinent info, it would be welcomed, many of the files I’ve found are communicating directly with 17. Addresses.
Reference: https://www.virustotal.com/gui/ip-address/23.64.114.214/summary
Link to file hosting
Arcsight flags this url as suspicious.
Reference: https://www.virustotal.com/gui/ip-address/173.194.196.94/summary
Link to file hosting
scans clean, but then… the ip address….
Reference: https://www.virustotal.com/gui/ip-address/72.21.91.29/summary
Link to file hosting
Xictium and one other vendor flag this url as malicious and the serving IP is trash.
So, malicious GET requests, coming in on seemingly legitimate domains, are passing the censor, so to speak. How to keep this evil at bay? About 6 apps are regularly communicating with these addresses, and since Apple, in all their wisdom, (geniuses…..) has seen fit to obfusticate time and dates that apps are contacting these domains, it makes it nearly impossible for the end user to actually solve. So, what do?
vpn? No good, tried several, this exploit seems to evade due to the legitimacy of the initial domain.
blacklist? No good, file hashes change regularly to the tune of over 100 in the last few months.
Reference: https://otx.alienvault.com/pulse/650b22b488fd536495791218
scanning apps? Not detecting these requests as malicious, avast, avg, Norton, cannot block all these requests and “some” Ocsp.pki.goog requests are actually necessary for app and iPhone function. Though nearly all of the ones I’m seeing in the above pulse are pure evil.
I’m out of answers and my crystal ball is in the witch-store getting a new djinn.
[Edited by Moderator]
iPhone 11