MalwareBazaar Database

This page shows some basic information the YARA rule MAC_Dropper_Shell_Base64Gzip_Heredoc including corresponding malware samples.

Database Entry


YARA Rule:MAC_Dropper_Shell_Base64Gzip_Heredoc
Author:Marjoriefort
Description:Dropper shell (zsh/bash) macOS : payload base64+gzip en heredoc PAYLOAD_, syntaxe BSD base64 -D, decompression inline puis eval/echo/printf
Firstseen:2026-09-20 13:14:27 UTC
Lastseen:2026-09-25 23:33:37 UTC
Sightings:4

Malware Samples


The table below shows all malware samples that matching this particular YARA rule (max 1000).

Firstseen (UTC)SHA256 hashTagsSignatureReporter