ThreatFox IOC Database

You are viewing the ThreatFox database entry for url https://ferncurrent14.com/curl/a7ec41c89a3dc6bf3de47264b4a3013134c7273dd1aa379859c2149b7517f0b2.

Database Entry


IOC ID:1868345
IOC: https://ferncurrent14.com/curl/a7ec41c89a3dc6bf3de47264b4a3013134c7273dd1aa379859c2149b7517f0b2
IOC Type :url
Threat Type :payload_delivery
Malware: Unknown malware
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS13335 CLOUDFLARENET
Country:- US
First seen:2026-08-04 16:28:12 UTC
Last seen:never
UUID:ada20a2f-9019-11f1-8325-42010aa4000a
Reporter novumanalytica
Reward 5 credits from ThreatFox
Tags:ClickFix Cloudflare FakeCaptcha macOS
Reference: https://gist.github.com/raimurokko/951c27b9b5af7ca91445bcbf0490f874

Avatar
novumanalytica
Stage 2 loader URL from a macOS ClickFix chain, 2026-08-04. Fetched via curl -s and piped directly into zsh — fileless, nothing written to disk. Reached only after the stage-1 gate returns "ok" for a valid per-victim token. Payload not retrieved, hence malware: unknown. The stage-1 URL is not submitted: its path component is session-scoped and already burned.