MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 63f6dcab9e0dabb78449efda7aa7ecd2c10a8ef4e35b7f7346df76c60d17e12f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MacSync


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 63f6dcab9e0dabb78449efda7aa7ecd2c10a8ef4e35b7f7346df76c60d17e12f
SHA3-384 hash: d67688486c63ccd971017bfc4034b03da994b05bb84b0ee4336034b38fe9c1c6817342246da31b1a278569479d1397d9
SHA1 hash: e804bc60e9cc13a62340386b5e6e21b87e7fc1f2
MD5 hash: 1db78cd4f71d5743c9a5719430d6ffb6
humanhash: july-bulldog-angel-yellow
File name:63f6dcab9e0dabb78449efda7aa7ecd2c10a8ef4e35b7f7346df76c60d17e12f.sh
Download: download sample
Signature MacSync
File size:1'305 bytes
First seen:2026-05-29 06:35:39 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:jt2WAEzJNxNL2r9gP5SYPmxuMTyHlkFIXueplaI79kkoKfUo9c2B4vnZsYc:sWAEzJ7B2CPsYeUHeFIh33R6KfUU4vWt
TLSH T1D021FBA69E30333474809E4E5D852787AB69CBC670A2349A56ECB4061A84020511E752
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter JAMESWT_WT
Tags:MacSync MacSyncStealer sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
54
Origin country :
IT IT
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-05-28T20:32:00Z UTC
Last seen:
2026-05-30T23:06:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan.Shell.Agent.da
Threat name:
MacOS.Trojan.MacSyncStealer
Status:
Malicious
First seen:
2026-05-28 21:35:00 UTC
File Type:
Text (Shell)
AV detection:
16 of 36 (44.44%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Malware family:
SHubStealer
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments