ThreatFox IOC Database

You are viewing the ThreatFox database entry for url https://sheltercirrus.com/2kqYRM0DCrnyJgoS4gVLl_FHJRRdTUhGCbjyuYwpZ6c/oo9/update.

Database Entry


IOC ID:1883176
IOC: https://sheltercirrus.com/2kqYRM0DCrnyJgoS4gVLl_FHJRRdTUhGCbjyuYwpZ6c/oo9/update
IOC Type :url
Threat Type :payload_delivery
Malware: IClickFix
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS13335 CLOUDFLARENET
Country:- US
First seen:2026-08-20 15:10:56 UTC
Last seen:never
UUID:51fdee99-9ca9-11f1-a7c1-42010aa4000a
Reporter Efren
Reward 5 credits from ThreatFox
Reference: https://www.microsoft.com/en-us/security/blog/2026/05/06/clickfix-campaign-uses-fake-macos-utilities-lures-deliver-infostealers/

Avatar
Efren
Active ClickFix campaign, the final site to arrive is filevegatech.com which impersonates Github and asks to execute a command that downloads malware. Then this malware is provided at the sheltercirrus.com site, which provides the malware that uses grove-satin.com as a C2