ThreatFox IOC Database

You are viewing the ThreatFox database entry for domain ferncurrent14.com.

Database Entry


IOC ID:1868342
IOC: ferncurrent14.com
IOC Type :domain
Threat Type :payload_delivery
Malware: Unknown malware
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS13335 CLOUDFLARENET
Country:- US
First seen:2026-08-04 16:28:10 UTC
Last seen:never
UUID:04a51803-9019-11f1-8325-42010aa4000a
Reporter novumanalytica
Reward 5 credits from ThreatFox
Tags:ClickFix Cloudflare FakeCaptcha macOS
Reference: https://gist.github.com/raimurokko/951c27b9b5af7ca91445bcbf0490f874

Avatar
novumanalytica
Fake Cloudflare Turnstile overlay on a compromised German school website, 2026-08-04 ~14:42 UTC. Stage 1 gates on a per-victim token and returns "ok" only once; stage 2 is piped straight into zsh. Static analysis only, payload not retrieved — hence malware: unknown. Delivery domain deliberately omitted (victim, not attacker infrastructure)