THE diary entry written by Brad Duncan details an infection caused by the Atomic MacOS (AMOS) stealer malware, which was propagated through a deceptive web page. The page instructed users to paste text into the macOS Terminal, falsely claiming to be a 'macOS toolkit.' The author executed the command to study its effects, resulting in repeated infection traffic and persistent malware on the infected device.
The report includes images of the malicious instructions, compromised files from the system, and indicators of compromise such as URLs and SHA-256 hashes of associated malicious files. Key indicators include communications with a command-and-control (C2) server and various HTTP requests involved in the malware's operation.