🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://104.248.194.193/contact.

Database Entry


IOC ID:1932260
IOC: http://104.248.194.193/contact
IOC Type :url
Threat Type :botnet_cc
Malware: AMOS
Malware alias:Atomic macOS Stealer
Confidence Level : Confidence level is high (90%)
Is compromised? : False
ASN:AS14061 DIGITALOCEAN-ASN
Country:- US
First seen:2026-09-24 12:56:34 UTC
Last seen:never
UUID:cc5914cc-b816-11f1-abee-42010aa4000a
Reporter c4ffeine
Reward 5 credits from ThreatFox
Tags:Amos cc2 ClickFix Foxveil macOS
Reference: https://www.virustotal.com/gui/file/b9aba591f9ea7faccc80e23b5821e14a0fd208979737019c6d61c86e4bb813e9

Avatar
c4ffeine
Foxveil/AMOS telemetry and exfil endpoints on 104.248.194.193 (DigitalOcean), carried by Foxveil cc2 builds 28 to 47 and DANTE builds 1 to 6 (2026-09-22 to 2026-09-23 22:03 UTC), then replaced by the same paths on 206.189.104.97. Both paths answer the forged 139 B Foxveil 404 (sha256 5d1d75b702f13e1bb14ff8d52cac1690acacec3a15821af7fe482a79afda5b99) to GET, confirmed via Tor 2026-09-22; never POSTed. Sample: https://www.virustotal.com/gui/file/b9aba591f9ea7faccc80e23b5821e14a0fd208979737019c6d61c86e4bb813e9