🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 658795aec64a3fc84cdc6ccd8af9d2013c52882e9015b659a0fe7139cb8cd3ca. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 658795aec64a3fc84cdc6ccd8af9d2013c52882e9015b659a0fe7139cb8cd3ca
SHA3-384 hash: 583a652739dfe9f62f7b41a9fec2a2e48309fffa1d10bdab175dfaeb912211d1fa50eb150a31d2352b99a25b12e536cf
SHA1 hash: 31fd1f4dba4916fbdb04363ef3a2eff1dc19bc3e
MD5 hash: 9f17840cb42a5352910ab0fe66f7ed9c
humanhash: ohio-monkey-ohio-fix
File name:stage2.sh
Download: download sample
File size:1'139 bytes
First seen:2026-09-15 09:23:21 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:HVYKk/YMOXCJAVFlpKC0dzcwAmWmyxKCJoehHUA/0V35U8cNCV5wCwXCV3RZ4ldZ:HeKk/YZAAVFlpKGw6myQA5h0AC35ECsV
TLSH T1CC213FB05910359AF0DB2DC4FD6BA9A730B182C99F57A3DF4EE656B8758DB00D883930
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter Anonymous
Tags:fingerprinting Gatekeeper-bypass Loader macOS sh shell


Avatar
Anonymous
Stage 2, decrypted from stage1.sh. Sends a fingerprinting beacon (POST with custom 'user'/'BuildID' headers) to mark the host as infected, then downloads and executes the stage-3 Mach-O payload after stripping the quarantine xattr with 'xattr -c' to bypass Gatekeeper.

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
EG EG
Vendor Threat Intelligence
No detections
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

da50d3c4803cfca814db10be4ef7f0ed2933ebd0bfa1ed52502c5b416f74c64b

sh 658795aec64a3fc84cdc6ccd8af9d2013c52882e9015b659a0fe7139cb8cd3ca

(this sample)

  
Dropped by
SHA256 da50d3c4803cfca814db10be4ef7f0ed2933ebd0bfa1ed52502c5b416f74c64b
  
Delivery method
Other

Comments