MalwareBazaar Database
This page shows some basic information the YARA rule Foxveil_Loader_B64_Variant including corresponding malware samples.
Database Entry
| YARA Rule: | Foxveil_Loader_B64_Variant |
|---|---|
| Description: | Foxveil macOS loader, 2026-09-18 apph4/cc2 repackaging: no dlsym and no ad-hoc setup- identity, symbols resolved by walking loaded images via __dyld_image_count/__dyld_get_image_header/__dyld_get_image_vmaddr_slide, empty __AUX |
| Firstseen: | 2026-09-19 23:56:13 UTC |
| Lastseen: | 2026-09-21 00:41:55 UTC |
| Sightings: | 11 |
Malware Samples
The table below shows all malware samples that matching this particular YARA rule (max 1000).
| Firstseen (UTC) | SHA256 hash | Tags | Signature | Reporter |
|---|