🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 188.166.83.118:80.

Database Entry


IOC ID:1906300
IOC: 188.166.83.118:80
IOC Type :ip:port
Threat Type :botnet_cc
Malware: AMOS
Malware alias:Atomic macOS Stealer
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS14061 DIGITALOCEAN-ASN
Country:- US
First seen:2026-09-09 15:58:26 UTC
Last seen:never
UUID:902d13ba-ac65-11f1-b569-42010aa4000a
Reporter Anonymous
Reward 5 credits from ThreatFox
Tags:Amos ClickFix macOS
Reference: https://bazaar.abuse.ch/sample/8f12396cfb1ac4d52b3c0fad997b2cf83839bc464cfa43e43959239a3016d287/

Avatar
Anonymous
Hardcoded telemetry C2 in the AMOS ClickFix stage 5 AppleScript (DigitalOcean). Beacons are POSTed to /api/metrics/run as JSON at each collection stage, starting with a boot event before any collection. Contacted by raw IP with no DNS lookup, so DNS-based network reviews will not see it.