🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1d6cd5411bcbfea3f5328b40c62a57b9788a557efc00d927d9d921afe994c19e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AMOS


Vendor detections: 4


Intelligence 4 IOCs YARA 2 File information Comments

SHA256 hash: 1d6cd5411bcbfea3f5328b40c62a57b9788a557efc00d927d9d921afe994c19e
SHA3-384 hash: eb3f8011af8d8489cfde47299d0c9fe17a74f96ee4ef190fa242c1fc6871db328d35a45a057693268d97e1f209f0dee6
SHA1 hash: c1dfec2b7bd0746647bc565461a1c9654c7f4297
MD5 hash: c590ead487e0c7f9f6269da4e76725fb
humanhash: item-autumn-tennessee-paris
File name:stage1_1d6cd5411bcb.zsh
Download: download sample
Signature AMOS
File size:3'020 bytes
First seen:2026-10-10 23:26:22 UTC
Last seen:Never
File type:
MIME type:text/x-shellscript
ssdeep 48:CQ0cxki4OLzn7stU7EH7XQGQAp946wU1ptDmtYQLU1tPWv4uvx683ID6jggx9xP:hXxkiX7XoXIKT1ptDmtYIU1tP4vxL3I+
TLSH T15E510839C540A2F6C7F5222F7BC678244FA5738D58EAB07DF1817A8818FBB04ED24A55
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter c4ffeine
Tags:AMOS ClickFix dropper macOS zsh


Avatar
c4ffeine
macOS ClickFix zsh stage-1 dropper served to curl/8.7.1 from https://fable-shine.com/curl/g0xsutkb0/iwsnry04os3w6i7z3ufc.dat. The host is user-agent gated: a curl request receives the 3020-byte script, while a browser user-agent receives a Cloudflare 520. Captured over Tor on 2026-10-10, not executed. Registrar Dominet (HK) Limited, created 2026-10-10, Cloudflare-fronted. Attribution pending (ClickFix/AMOS-adjacent macOS loader family).

Intelligence


File Origin
# of uploads :
1
# of downloads :
22
Origin country :
US US
Vendor Threat Intelligence
No detections
Gathering data
Threat name:
MacOS.Dropper.Generic
Status:
Suspicious
First seen:
2026-10-11 00:17:30 UTC
File Type:
Text (Shell)
AV detection:
6 of 36 (16.67%)
Threat level:
  3/5
Malware family:
AtomicStealer
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Foxveil_Stage1_Zsh_ConstKey_AesCtr
Description:Foxveil ClickFix stage-1 zsh dropper: hex blobs -> md5(constant _kb) -> openssl AES-128-CTR IV 0 -> gunzip -> zsh, behind a decoy maintenance script
Rule name:MAC_Dropper_Shell_CacheMaintenance_AES_CTR
Author:Marjoriefort
Description:macOS fake cache-maintenance dropper - payload AES-128-CTR via openssl, noms de commandes fragmentes

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

AMOS

1d6cd5411bcbfea3f5328b40c62a57b9788a557efc00d927d9d921afe994c19e

(this sample)

  
Delivery method
Distributed via web download

Comments