AMOS Stealer Fake macOS Toolkit Distribution Domains
This rule monitors network connections and DNS query responses for activity associated with known suspicious domains: 'getmacouscloud.com', 'ferncore13.com', and 'grove-89.com'. It identifies communication attempts (successes, failures, or DNS lookups) between endpoints and these domains, which is indicative of potential command and control (C2) activity.
Microsoft Sentinel (KQL)

