🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for domain delta-canvas.com.

Database Entry


IOC ID:1932262
IOC: delta-canvas.com
IOC Type :domain
Threat Type :payload_delivery
Malware: AMOS
Malware alias:Atomic macOS Stealer
Confidence Level : Confidence level is high (90%)
Is compromised? : False
ASN:AS13335 CLOUDFLARENET
Country:- US
First seen:2026-09-24 12:56:36 UTC
Last seen:never
UUID:cca38077-b816-11f1-abee-42010aa4000a
Reporter c4ffeine
Reward 5 credits from ThreatFox
Tags:Amos cc2 ClickFix Foxveil macOS
Reference: https://www.virustotal.com/gui/file/b9aba591f9ea7faccc80e23b5821e14a0fd208979737019c6d61c86e4bb813e9

Avatar
c4ffeine
Foxveil second-stage module host for the cc2 and DANTE AMOS builds since cc2 build 28 (2026-09-22), replacing rudder-moss.com (ThreatFox 1916310). Registered 2026-09-22T13:58:20Z at Eranet International, Cloudflare-proxied, same day as the first build naming it. Serves /zxc/kito (WebSocket PTY bot, sha256 08074ec033c1a5dcfb0125a352f7f499f29f61d8ed2ce2f693d48813074810d4) and /zxc/mdw (multi-chain crypto clipper, sha256 a7c0d024ed24dcbc1b17cbda430a39edb52325c30ad9b7207c0267e43fbec4b7) as genuine Mach-Os to a curl User-Agent only (browser UAs get a 520), fetched via Tor 2026-09-22. Still named in DANTE and cc2 payloads opened 2026-09-24. Sample: https://www.virustotal.com/gui/file/b9aba591f9ea7faccc80e23b5821e14a0fd208979737019c6d61c86e4bb813e9