MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 40ecec3216ca8cfadbc82f7bd0262f2daeb39ec2547cef1756606104ad2e0563. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 40ecec3216ca8cfadbc82f7bd0262f2daeb39ec2547cef1756606104ad2e0563
SHA3-384 hash: 191fe5f0140b715fa3f965c136587a37e9e9d9db645d78ceb15f61a0eceb9a235ce3d35e5366ad5a520203af53fce14b
SHA1 hash: 03b3cf69b6cbea5d39da3b4442b5d77e35256c1b
MD5 hash: 874b12d8846187716b5363196df09ba4
humanhash: table-princess-monkey-queen
File name:payload.txt
Download: download sample
File size:1'828 bytes
First seen:2026-08-06 19:02:52 UTC
Last seen:2026-08-06 19:07:16 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:n5m1m8XVmRpkwxbbb0ezV8jgbb/Z2xUnAL:5mI8X4RiwRv0Wbv/ExO8
TLSH T16531D5FAECAC36127241DEE1E49A96235E1A4A2ED8203C09A008948DE51E33B60C6126
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter novumanalytica
Tags:ClickFix Dante dropper macOS sh zsh


Avatar
novumanalytica
macOS ClickFix chain, campaign marker DANTE. Stage-2 script, retrieved with
curl … | zsh from the loader host after the stage-1 token gate answered ok once.

Roughly two thirds of the file is decoration: functions whose only effect is
[ -d "$HOME" ], loops that discard $((RANDOM % 256)), arrays never referenced, and a decoy base64 blob (etpuz87u) that is defined and then ignored. The working part is a single openssl base64 -d … | gunzip into a variable, followed by eval.

The decoded inner script builds every string from printf octal escapes — including the names of the binaries it invokes — then POSTs a conversion beacon carrying two non-standard headers, user and BuildID, at the moment the victim pastes and before anything is downloaded. Only afterwards does it fetch a universal Mach-O to /tmp/helper, strip extended attributes with xattr -c, set the execute bit and run it.

The xattr step is load-bearing: without it Gatekeeper would evaluate the binary.

Worth noting for triage: this script carries far better AV coverage than the Mach-O it drops (MD5 ab477021780e553be4271cb34bb8394b). Detection is landing on the obfuscation shape rather than on capability — backwards from a defender's point of view.
Family of the final payload assessed as AMOS lineage, not confirmed; the stealer itself sits encrypted inside the dropped binary and was not recovered. Full analysis and sources: https://github.com/raimurokko/macos-threat-tracking and https://github.com/raimurokko/research

Intelligence


File Origin
# of uploads :
2
# of downloads :
73
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
dropper masquerade stealer
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-08-06T17:52:00Z UTC
Last seen:
2026-08-08T00:08:00Z UTC
Hits:
~10
Threat name:
MacOS.Dropper.Generic
Status:
Suspicious
First seen:
2026-08-06 19:30:55 UTC
File Type:
Text (Shell)
AV detection:
10 of 24 (41.67%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 40ecec3216ca8cfadbc82f7bd0262f2daeb39ec2547cef1756606104ad2e0563

(this sample)

  
Delivery method
Distributed via web download

Comments