MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 83e4d60e03ada6ba68a72384042db573ff7c29e0d2dbf5364e1ddb107d778317. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AMOS
Vendor detections: 6
| SHA256 hash: | 83e4d60e03ada6ba68a72384042db573ff7c29e0d2dbf5364e1ddb107d778317 |
|---|---|
| SHA3-384 hash: | fba46d08475fe3d5d662aaf6d5eca0320d1e27f5a609a619b7172d50d67e95d065c548e9d465e2abcae7b9b460ac3bf3 |
| SHA1 hash: | 5063dfd30fb126537363ead20deaafa494c08eb2 |
| MD5 hash: | afb461909a6291d3db7c5bb55ed4c428 |
| humanhash: | august-may-magnesium-apart |
| File name: | macho_83e4d60e03ad.bin |
| Download: | download sample |
| Signature | AMOS |
| File size: | 937'424 bytes |
| First seen: | 2026-09-19 23:56:13 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-mach-binary |
| ssdeep | 24576:rwMdL4UxI5yeHsJe5qqQ9lLAUF4zACHc9r:0Mbx4yDEoFuAtV |
| TLSH | T15615F1008FA65496F88CD7342B3F4A738F217564868512DE12653FC89E363E3F66B25E |
| TrID | 82.2% (.DYLIB) Mac OS X Mach-O universal Dynamically linked shared Library (32500/1/5) 17.7% (.O/DYLIB/BUNDLE) Mac OS X Universal Binary (generic) (7002/2) |
| Magika | macho |
| Reporter | |
| Tags: | AMOS ClickFix Foxveil kis Loader Mach-O machO macOS |
c4ffeine
Foxveil loader (Cato CTRL name), 'kis' build, fetched live over Tor 2026-09-19 from forgewillow.com. The host is served by Cloudflare and gates on User-Agent: a plain curl/8.7.1 receives this 937424 B Mach-O, while a Safari User-Agent receives a 16 B Cloudflare 520 - the same browser-gating seen on blueprint-71.com. forgewillow.com was registered 2026-09-14 at Dominet (HK) Limited, one day before the stage-1 build that names it. The host was recovered statically, not by scanning: the 2026-09-15 Foxveil stage-1 zsh dropper (sha256 ab9dd07884af5e249ab241e468da756bf3e6dcb2aea061d0e656d3812484256e) is the self-keyed const-key variant and decrypts offline - _kb = len("weekly")*202 + len("weekly")%12 + 12 = 1230, key = md5("1230") = 4122cb13c7a474c1976c9706ae36521d, AES-128-CTR with a zero IV over the hex concat of _feature_flags/_cache_seed/_license_salt/_rollout_key (_probe_salt is a decoy and must be left out), then gunzip to a 1220 B stage-2 zsh (sha256 105763aed0f3d1f847475748eca2ca2ee1b07c7a6a4c11c5ade0fa9769535795). That stage-2 beacons to lyric-8.com /api/metrics/run and downloads this payload to /tmp/.tmcxpkr89, strips the quarantine attribute and chmods it. The '/kis/' subpath is new; the path token 2kqYRM0D... is the same one seen on earlier Foxveil rotations. Differs from the 2026-09-18 'apph4' build (sha256 a3dabccd1449...): 987264 -> 937424 B, both embedded payload blobs slightly smaller, both LC_UUIDs changed. Not yet unpacked - attribution here rests on the stage-2 decode and the delivery path, not on an independent body fingerprint; forgewillow.com does NOT serve the forged 139 B 404 seen on other Foxveil hosts. Fetched over Tor; never executed.Intelligence
File Origin
USVendor Threat Intelligence
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | Foxveil_Loader_B64_Variant |
|---|---|
| Description: | Foxveil macOS loader, 2026-09-18 apph4/cc2 repackaging: no dlsym and no ad-hoc setup- identity, symbols resolved by walking loaded images via __dyld_image_count/__dyld_get_image_header/__dyld_get_image_vmaddr_slide, empty __AUX |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.