🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for domain wsecurite.com.

Database Entry


IOC ID:1924028
IOC: wsecurite.com
IOC Type :domain
Threat Type :botnet_cc
Malware: MacSync
Confidence Level : Confidence level is high (90%)
Is compromised? : False
First seen:2026-09-18 17:23:40 UTC
Last seen:never
UUID:944ecedb-b381-11f1-abee-42010aa4000a
Reporter c4ffeine
Reward 5 credits from ThreatFox
Tags:backdoor macOS MacSync reverse-tunnel
Reference: https://www.virustotal.com/gui/file/6e4b84389afb4683e19f921ce3f54703fb6bb146fbdbffac3e398894074c0fa0

Avatar
c4ffeine
MacSync loader_agent reverse-tunnel backdoor C2, recovered 2026-09-18 from the XOR-0xAA string table of the genovaw.com 'safeguard' build loader_agent Mach-O (sha256 6e4b84389afb4683e19f921ce3f54703fb6bb146fbdbffac3e398894074c0fa0). Only non-Apple, C2-shaped hostname in the table; misses the Seedhook_LoaderAgent_realtux YARA rule because this build's baked C2 is not realtux.com. Registered UnstoppableUS2 LLC 2026-07-09, NS aisha+kyree (new Cloudflare account pair). No A/AAAA record as of 2026-09-18 16:3x UTC (NOERROR+SOA only, DoH over Tor) — the C2 is staged/compiled-in but not yet resolving; RDAP last-change 2026-09-10T07:12:01Z, 26 minutes from genovaw.com's own last-change (07:38:46Z), consistent with the two hosts being provisioned together. Not seen live, hence confidence 90 rather than 100. Recovered offline in badbrew-scpt --network none; nothing executed, no traffic sent to the host.