MalwareBazaar Database
This page shows some basic information the YARA rule Gibberdrop_AMOS_ConfigRolXor including corresponding malware samples.
Database Entry
| YARA Rule: | Gibberdrop_AMOS_ConfigRolXor |
|---|---|
| Description: | AMOS macOS stealer (mainline panel builds) - rolling-key XOR decrypt loop of the embedded __data config (key rotated right by 1 per byte), arm64 and x86_64 |
| Firstseen: | 2026-09-28 06:19:47 UTC |
| Lastseen: | 2026-09-28 06:19:53 UTC |
| Sightings: | 5 |
Malware Samples
The table below shows all malware samples that matching this particular YARA rule (max 1000).
| Firstseen (UTC) | SHA256 hash | Tags | Signature | Reporter |
|---|