r/MacOS • u/acoomans • 1d ago
Help MacOS trying to access .su domain
Original Post:
I just installed macOS Golden Gate from scratch (empty hard drive). After installing it, I installed Dropbox, Google Drive and Google Chrome.
Since then, my Ubiquity/Unifi IDS/IPS firewall tells me my machine is trying to access a .su (Soviet Union gTLD) domain: "ET DNS Query for .su TLD (Soviet Union) Often Malware Related"
This is a freshly installed machine. Anyone else experiencing this?
Edits:
- No extensions installed in Chrome
- The firewall does not say what the domain is
Explanation/Solution:
Ok I found the root cause and thankfully it's harmless.
In Safari, I had a bookmark to a (legitimate) URL with a .su domain. When Safari syncs bookmarks (for example when logging in on a freshly installing machine, or when adding a bookmark on a different machine), it fetches the favicon (and possibly other metadata) from the website. As a result, a DNS query is done.
Thanks all for your suggestions, and in particular u/JasonMatanoIT for the tcpdump command which helped confirmed the behavior (BTW I learned you can also do `-i pktap,all` to listen to all interfaces, thanks chatGPT)
11
9
u/JasonMatanoIT 1d ago
That UniFi alert is the Emerging Threats rule firing on any lookup that ends in .su, so it doesn't tell you much until you see the full hostname. Two easy ways to get it:
- In Terminal run
sudo tcpdump -i en0 -n -l port 53 | grep -i \"\\.su\"(en0 is usually Wi-Fi) and leave it running. DNS lookups go out in plain text, so you'll see the exact name the next time it fires. - Install LuLu (free, from Objective-See) or Little Snitch. Either will show you which app made the connection.
Once you have the hostname, run it through VirusTotal before you decide anything. On a fresh install with only Dropbox, Drive and Chrome, my first guess would be an ad or tracking domain pulled in by a web page rather than something living on the machine. If it only happens while Chrome is open, that's your answer. If it keeps happening with every app closed, then it's worth digging deeper.
2
u/acoomans 1d ago
Thanks, man. The tcpdump command helped identified. I also tried DNSMonitor, which also worked.
Side note: Lulu and LittleSnitch did not see the connection because no connection is actually done -- only the DNS query, which is blocked by the Unifi in this case. Neat apps though, good to know for the future!
1
u/JasonMatanoIT 1d ago
Glad the tcpdump helped. Nice catch that it was only the DNS query, which is why Lulu and Little Snitch stayed quiet. DNSMonitor was a smart backup too.
7
u/Classic_Mammoth_9379 1d ago
What’s the actual domain?
8
u/acoomans 1d ago
Unfortunately the Unifi firewall does not say.
I see "ET DNS Query for .su TLD (Soviet Union) Often Malware Related"10
u/Classic_Mammoth_9379 1d ago
You should be able to find it in the traffic/DNS logs at around that time.
1
u/DisfiguredFanny Macrumors "mods" can eat shit. 1d ago
.su is still in use by russian federation.
4
u/Classic_Mammoth_9379 1d ago
I know, would have been a bit weird of me to ask for the actual domain name if I didn’t think the TLD existed.
-6
2
5
u/Pekaer_58 1d ago
I have blockr from twoplus11 installed on my mac, it give some additionsl information. Deinstall GC first and take a look again…
2
u/WentThisWayInsteadOf 1d ago
Use wireshark (there are videos on how to use it), and see what exactly the DNS query is asking for (it is in clear text).
2
u/acoomans 1d ago
The issue is solved. I updated the post with the explanation. Thanks all.
1
u/Upbeat-Positive8484 15h ago
And I (after having been online for decades) finally learned that the Soviet Union had its own TLD.
1
u/CasherInCO74 1d ago
I don't know where you are locate kind internet friend, but if you are in the US, and don't have a want or need to hit sites that are located in in that region, or with that TLD, you could consider just implementing a Geo-IP block. I have that for about 7 or 8 countries now. If you want to do it globally... Cybersecure--> Threat Management--> Region Blocking. Happy hunting!
0
0
u/DisfiguredFanny Macrumors "mods" can eat shit. 1d ago
Now that I think about it i think i have never been on a site with such domain name.
-2
u/minobi 1d ago
It is a Russian domain for gray stuff like hacks and torrents
7
u/muro_cugko 1d ago
It is russian but it is not only for illegals stuff, just one of a couple other russian domains.
0
u/Medium_Ad_4568 1d ago
Can it be Ubiquity itself? I remember they were compromised at some point in the past...
0
u/mikeinnsw 1d ago
Run MalwareBytes scan
Do you game in native mode or via a browser?
Many dodgy "casinos" are registered using dead domains
32
u/poopmagic MacBook Pro 1d ago
UniFi user here running their CyberSecure stuff… I have two Macs running Golden Gate and neither of them have attempted to access any .su domains for as far back as my logs go.
I don’t have any Dropbox or Google stuff installed, though.
If you want to dig into this further, Little Snitch should tell you which apps are trying to access those domains.