🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 204b5d236e4384b23c1f0201bc52c06f32ef8eea679b975e9b432f2b111d1dbc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AMOS


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 204b5d236e4384b23c1f0201bc52c06f32ef8eea679b975e9b432f2b111d1dbc
SHA3-384 hash: 8012d7f202ee3ed065e01fc3e12f7d7ca286e310acd818aa7d8107d81f07c6c9783bc80f55ad9d6ba0b941d0d8f459c3
SHA1 hash: f2b405e6f5c8efebc73773cb2e2ee224549aa0e0
MD5 hash: 5f89411fe64c83e60a78a96a0d569bab
humanhash: autumn-idaho-mirror-kilo
File name:macho_204b5d236e43.bin
Download: download sample
Signature AMOS
File size:609'184 bytes
First seen:2026-09-14 04:38:06 UTC
Last seen:Never
File type:php macho
MIME type:application/x-mach-binary
ssdeep 12288:95iE27E/mrCt6KsUkiIG27EPmrit66sUki:95AAmrCtfRUimritfR
TLSH T12CD4F1F982A49816E252ED37BD8A4BEF3D15613495BF9E235FD55B201CE24C32248B33
TrID 82.2% (.DYLIB) Mac OS X Mach-O universal Dynamically linked shared Library (32500/1/5)
17.7% (.O/DYLIB/BUNDLE) Mac OS X Universal Binary (generic) (7002/2)
Magika macho
Reporter c4ffeine
Tags:AMOS ClickFix Foxveil Loader Mach-O machO macOS


Avatar
c4ffeine
Foxveil loader (Cato CTRL name), 'oo9' build under a third payload path token 2kqYRM0DCrnyJgoS4gVLl_FHJRRdTUhGCbjyuYwpZ6c. Fat x86_64+arm64, ad-hoc signed 'setup-<hex>'; decrypts an embedded AMOS AppleScript stealer and runs it in-process. Exfil C2 http://165.22.199.85/contact, fallback jadeleap15.com; stage-2 beacon grove-satin.com. Same file also served from trekworkshop3.com. Delivered by a ClickFix 'curl ... | zsh' self-keyed dropper at aspenriver6.com/curl/epf215dtv0l/2otso19m8v27gj0d381.dat. Fetched via Tor 2026-09-14; not executed. YARA: Foxveil_Loader_MachO.

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
masquerade stealer
Score:
100%
Verdict:
Malware
File Type:
Mach-O universal binary
Threat name:
MacOS.Infostealer.Generic
Status:
Suspicious
First seen:
2026-09-14 03:15:34 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
8 of 38 (21.05%)
Threat level:
  5/5
Malware family:
PoseidonStealer
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

AMOS

php macho 204b5d236e4384b23c1f0201bc52c06f32ef8eea679b975e9b432f2b111d1dbc

(this sample)

Comments