MalwareBazaar Database
This page shows some basic information the YARA rule Foxveil_Loader_PadSeg_Variant including corresponding malware samples.
Database Entry
| YARA Rule: | Foxveil_Loader_PadSeg_Variant |
|---|---|
| Description: | Foxveil macOS loader (ClickFix -> AMOS), apph4/cc2 packer generation, 2026-09-23 wrapper: fat x86_64+arm64 linking CoreFoundation+libSystem+libc++, plus one randomly-named section-less LC_SEGMENT_64 per slice with zero vmsize and zero filesize whose vmaddr, small fileoff, prot (0/1) and flags (0/8) are randomised per slice |
| Firstseen: | 2026-09-24 10:32:47 UTC |
| Lastseen: | 2026-09-25 16:47:01 UTC |
| Sightings: | 3 |
Malware Samples
The table below shows all malware samples that matching this particular YARA rule (max 1000).
| Firstseen (UTC) | SHA256 hash | Tags | Signature | Reporter |
|---|