🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for url https://genovaw.com/loader/agent/001e07c934e19b9d10f621c6b7546b43b2fb1c7b8fce2625fc7b767dfb626336.

Database Entry


IOC ID:1924032
IOC: https://genovaw.com/loader/agent/001e07c934e19b9d10f621c6b7546b43b2fb1c7b8fce2625fc7b767dfb626336
IOC Type :url
Threat Type :payload_delivery
Malware: MacSync
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS13335 CLOUDFLARENET
Country:- US
First seen:2026-09-18 17:23:24 UTC
Last seen:never
UUID:ef0431c9-b381-11f1-abee-42010aa4000a
Reporter c4ffeine
Reward 5 credits from ThreatFox
Tags:ClickFix macOS MacSync safeguard-build
Reference: https://www.virustotal.com/gui/file/6e4b84389afb4683e19f921ce3f54703fb6bb146fbdbffac3e398894074c0fa0

Avatar
c4ffeine
MacSync ClickFix chain on genovaw.com, live 2026-09-18 16:2x UTC: /curl/<64hex> stage-1 zsh (sha256 2a3a49a04d3addb433bd56181f1b95b94a2467926790059ddb3669860c76ce93), /dynamic?txd=<64hex> plaintext AppleScript stealer (per-fetch hash, templated IP/label), and /loader/agent/<64hex> the reverse-tunnel backdoor Mach-O (sha256 6e4b84389afb4683e19f921ce3f54703fb6bb146fbdbffac3e398894074c0fa0, YARA-hits Seedhook_LoaderAgent_Tunnel/XorAA, C2 wsecurite.com).