PULSE NAME
ThreatFox Hunt: Unknown Stealer IOCs - 2026-02-04
WHITE pduggusa 2026-02-04 Modified: 2026-03-06
106
IOCs
HIGH VOLUME
Automated ThreatFox hunt for Unknown Stealer indicators. 107 IOCs collected via Pattern 49 intelligence streaming. MITRE ATT&CK: T1071.001, T1105. Reference: https://analytics.dugganusa.com
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Unknown Stealer
Indicators of Compromise (106)
All domain URL hostname
TYPEINDICATORDESCRIPTIONCREATED
domain maccloudfiles.com Unknown Stealer botnet_cc - ThreatFox ID: 1740048 2026-02-04
domain macpush.com Unknown Stealer botnet_cc - ThreatFox ID: 1740049 2026-02-04
domain mymacguides.com Unknown Stealer botnet_cc - ThreatFox ID: 1740050 2026-02-04
domain mac-file.com Unknown Stealer botnet_cc - ThreatFox ID: 1740051 2026-02-04
domain ultradatahost1.cfd Unknown Stealer botnet_cc - ThreatFox ID: 1740052 2026-02-04
domain macared.com Unknown Stealer botnet_cc - ThreatFox ID: 1740053 2026-02-04
domain macfilesharehub.com Unknown Stealer botnet_cc - ThreatFox ID: 1740054 2026-02-04
domain sendportal02.com Unknown Stealer botnet_cc - ThreatFox ID: 1740055 2026-02-04
domain megafilehub4.xyz Unknown Stealer botnet_cc - ThreatFox ID: 1740056 2026-02-04
domain fastsendportal02.com Unknown Stealer botnet_cc - ThreatFox ID: 1740057 2026-02-04
domain driveport38.com Unknown Stealer botnet_cc - ThreatFox ID: 1740058 2026-02-04
domain mymacanswers.com Unknown Stealer botnet_cc - ThreatFox ID: 1740059 2026-02-04
domain imacmigrator.com Unknown Stealer botnet_cc - ThreatFox ID: 1740060 2026-02-04
domain classicmacfiles.com Unknown Stealer botnet_cc - ThreatFox ID: 1740061 2026-02-04
domain maccloudstorage.com Unknown Stealer botnet_cc - ThreatFox ID: 1740062 2026-02-04
domain dropport49.com Unknown Stealer botnet_cc - ThreatFox ID: 1740063 2026-02-04
domain imacrestorehub.com Unknown Stealer botnet_cc - ThreatFox ID: 1740064 2026-02-04
domain cloudboxmac.com Unknown Stealer botnet_cc - ThreatFox ID: 1740065 2026-02-04
domain macfilestorage.com Unknown Stealer botnet_cc - ThreatFox ID: 1740066 2026-02-04
domain macfilebeam.com Unknown Stealer botnet_cc - ThreatFox ID: 1740067 2026-02-04
domain maccloudbeam.com Unknown Stealer botnet_cc - ThreatFox ID: 1740068 2026-02-04
domain imaczip.com Unknown Stealer botnet_cc - ThreatFox ID: 1740069 2026-02-04
domain imacloop.com Unknown Stealer botnet_cc - ThreatFox ID: 1740070 2026-02-04
domain imacdrivedock.com Unknown Stealer botnet_cc - ThreatFox ID: 1740071 2026-02-04
domain macclouddock.com Unknown Stealer botnet_cc - ThreatFox ID: 1740072 2026-02-04
domain maccloudarchive.com Unknown Stealer botnet_cc - ThreatFox ID: 1740073 2026-02-04
domain sharemacrelay.com Unknown Stealer botnet_cc - ThreatFox ID: 1740074 2026-02-04
domain macfilex.com Unknown Stealer botnet_cc - ThreatFox ID: 1740075 2026-02-04
domain macsendpath.com Unknown Stealer botnet_cc - ThreatFox ID: 1740076 2026-02-04
domain macauway.com Unknown Stealer botnet_cc - ThreatFox ID: 1740077 2026-02-04
domain macsendcloud.com Unknown Stealer botnet_cc - ThreatFox ID: 1740078 2026-02-04
domain mac-tours.com Unknown Stealer botnet_cc - ThreatFox ID: 1740079 2026-02-04
domain macfilesi.com Unknown Stealer botnet_cc - ThreatFox ID: 1740080 2026-02-04
domain safetransfer14.com Unknown Stealer botnet_cc - ThreatFox ID: 1740081 2026-02-04
domain quicksend10.com Unknown Stealer botnet_cc - ThreatFox ID: 1740082 2026-02-04
domain imacguide.com Unknown Stealer botnet_cc - ThreatFox ID: 1740083 2026-02-04
domain mac-backup.com Unknown Stealer botnet_cc - ThreatFox ID: 1740084 2026-02-04
domain ultradatahost3.cfd Unknown Stealer botnet_cc - ThreatFox ID: 1740085 2026-02-04
domain icloudmacs.com Unknown Stealer botnet_cc - ThreatFox ID: 1740086 2026-02-04
domain macsyncsend.com Unknown Stealer botnet_cc - ThreatFox ID: 1740087 2026-02-04
domain macfilelinkdrop.com Unknown Stealer botnet_cc - ThreatFox ID: 1740088 2026-02-04
domain maclinkbox.com Unknown Stealer botnet_cc - ThreatFox ID: 1740089 2026-02-04
domain macicloudtrack.com Unknown Stealer botnet_cc - ThreatFox ID: 1740090 2026-02-04
domain macprivateicloud.com Unknown Stealer botnet_cc - ThreatFox ID: 1740091 2026-02-04
domain macfiledesk.com Unknown Stealer botnet_cc - ThreatFox ID: 1740092 2026-02-04
domain macsyncbin.com Unknown Stealer botnet_cc - ThreatFox ID: 1740093 2026-02-04
domain macfilesafesend.com Unknown Stealer botnet_cc - ThreatFox ID: 1740094 2026-02-04
domain maccloudglide.com Unknown Stealer botnet_cc - ThreatFox ID: 1740095 2026-02-04
domain imacfolder.com Unknown Stealer botnet_cc - ThreatFox ID: 1740096 2026-02-04
domain syncport20.com Unknown Stealer botnet_cc - ThreatFox ID: 1740097 2026-02-04
domain maccloudjet.com Unknown Stealer botnet_cc - ThreatFox ID: 1740098 2026-02-04
domain cloudgate29.com Unknown Stealer botnet_cc - ThreatFox ID: 1740099 2026-02-04
domain macfileshare.com Unknown Stealer botnet_cc - ThreatFox ID: 1740100 2026-02-04
domain mymachelpdesk.com Unknown Stealer botnet_cc - ThreatFox ID: 1740101 2026-02-04
domain macabooart.com Unknown Stealer botnet_cc - ThreatFox ID: 1740102 2026-02-04
domain macflowy.com Unknown Stealer botnet_cc - ThreatFox ID: 1740103 2026-02-04
domain macclouddesk.com Unknown Stealer botnet_cc - ThreatFox ID: 1740104 2026-02-04
domain maccloudx.com Unknown Stealer botnet_cc - ThreatFox ID: 1740105 2026-02-04
domain safemacguard.com Unknown Stealer botnet_cc - ThreatFox ID: 1740106 2026-02-04
domain maciclouddock.com Unknown Stealer botnet_cc - ThreatFox ID: 1740107 2026-02-04
domain fileshadowtransfer87.com Unknown Stealer botnet_cc - ThreatFox ID: 1740108 2026-02-04
domain imacsimplesend.com Unknown Stealer botnet_cc - ThreatFox ID: 1740109 2026-02-04
domain imacfilesafe.com Unknown Stealer botnet_cc - ThreatFox ID: 1740110 2026-02-04
domain macdropnow.com Unknown Stealer botnet_cc - ThreatFox ID: 1740111 2026-02-04
domain maccloudzip.com Unknown Stealer botnet_cc - ThreatFox ID: 1740112 2026-02-04
domain primeshare33.com Unknown Stealer botnet_cc - ThreatFox ID: 1740113 2026-02-04
domain invesrting.com Unknown Stealer botnet_cc - ThreatFox ID: 1740713 2026-02-04
URL https://invesrting.com/ledger/270653f862f0ee21dce0a46e4801ec28db4ddc77b6fba9341b1b8db29909c514 Unknown Stealer botnet_cc - ThreatFox ID: 1740714 2026-02-04
domain ebemvsextiho.com Unknown Stealer botnet_cc - ThreatFox ID: 1740729 2026-02-04
domain maclinkgo.com Unknown Stealer payload_delivery - ThreatFox ID: 1740880 2026-02-04
domain macsharego.com Unknown Stealer payload_delivery - ThreatFox ID: 1740881 2026-02-04
domain maclinkon.com Unknown Stealer payload_delivery - ThreatFox ID: 1740883 2026-02-04
domain macshareup.com Unknown Stealer payload_delivery - ThreatFox ID: 1740884 2026-02-04
domain macspeedx.com Unknown Stealer payload_delivery - ThreatFox ID: 1740885 2026-02-04
domain macuplum.com Unknown Stealer payload_delivery - ThreatFox ID: 1740886 2026-02-04
domain macpathy.com Unknown Stealer payload_delivery - ThreatFox ID: 1740887 2026-02-04
domain macuplink.com Unknown Stealer payload_delivery - ThreatFox ID: 1740888 2026-02-04
domain okcreditcard.com Unknown Stealer botnet_cc - ThreatFox ID: 1741121 2026-02-04
hostname apisyncdata.onrender.com Unknown Stealer botnet_cc - ThreatFox ID: 1741127 2026-02-04
hostname apiv3.wincryptapi.com Unknown Stealer botnet_cc - ThreatFox ID: 1741195 2026-02-04
hostname tsxoihgri0uqyvuf.wincryptapi.com Unknown Stealer botnet_cc - ThreatFox ID: 1741196 2026-02-04
hostname kamal.wincryptapi.com Unknown Stealer botnet_cc - ThreatFox ID: 1741197 2026-02-04
hostname xevhlfcbjkzmjxr5.wincryptapi.com Unknown Stealer botnet_cc - ThreatFox ID: 1741198 2026-02-04
hostname vu4za2dgrqj0wmfi.wincryptapi.com Unknown Stealer botnet_cc - ThreatFox ID: 1741199 2026-02-04
hostname z3cwncdoqkqw7cpk.wincryptapi.com Unknown Stealer botnet_cc - ThreatFox ID: 1741200 2026-02-04
hostname pfwtdqyqngky5jwn.wincryptapi.com Unknown Stealer botnet_cc - ThreatFox ID: 1741201 2026-02-04
hostname upload.wincryptapi.com Unknown Stealer botnet_cc - ThreatFox ID: 1741202 2026-02-04
hostname down.wincryptapi.com Unknown Stealer botnet_cc - ThreatFox ID: 1741203 2026-02-04
hostname qrcqhinbvlv3ym3b.wincryptapi.com Unknown Stealer botnet_cc - ThreatFox ID: 1741204 2026-02-04
domain maccodenode.com Unknown Stealer payload_delivery - ThreatFox ID: 1741224 2026-02-04
domain maccouriergo.com Unknown Stealer payload_delivery - ThreatFox ID: 1741225 2026-02-04
domain macbeamsend.com Unknown Stealer payload_delivery - ThreatFox ID: 1741226 2026-02-04
domain macdatadrop.com Unknown Stealer payload_delivery - ThreatFox ID: 1741227 2026-02-04
domain macmigrate.com Unknown Stealer payload_delivery - ThreatFox ID: 1741228 2026-02-04
domain macfilejet.com Unknown Stealer payload_delivery - ThreatFox ID: 1741229 2026-02-04
domain macpipehub.com Unknown Stealer payload_delivery - ThreatFox ID: 1741230 2026-02-04
domain macpacket.com Unknown Stealer payload_delivery - ThreatFox ID: 1741231 2026-02-04
domain maccodestack.com Unknown Stealer payload_delivery - ThreatFox ID: 1741232 2026-02-04
domain maccaststream.com Unknown Stealer payload_delivery - ThreatFox ID: 1741233 2026-02-04
domain macdatapipeline.com Unknown Stealer payload_delivery - ThreatFox ID: 1741234 2026-02-04
domain macpassage.com Unknown Stealer payload_delivery - ThreatFox ID: 1741235 2026-02-04
domain maccastlink.com Unknown Stealer payload_delivery - ThreatFox ID: 1741236 2026-02-04
domain macsmartlink.com Unknown Stealer payload_delivery - ThreatFox ID: 1741237 2026-02-04
domain macswiftly.com Unknown Stealer payload_delivery - ThreatFox ID: 1741238 2026-02-04
domain macsharehub.com Unknown Stealer payload_delivery - ThreatFox ID: 1741239 2026-02-04
hostname www.lyraconnect.uk Unknown Stealer botnet_cc - ThreatFox ID: 1741241 2026-02-04