MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 92f9d5ac6813ca77e92a511f584bbc2017dd8b92cebb60bfc20a83df33f2631e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 4
| SHA256 hash: | 92f9d5ac6813ca77e92a511f584bbc2017dd8b92cebb60bfc20a83df33f2631e |
|---|---|
| SHA3-384 hash: | 4bf3e1c87b39735c64410eb43946ede013e59a8e224cece20594dc65651d5333b5959a9fb0209ad5634bc3dc8a590038 |
| SHA1 hash: | f4ddfbef286bbf42b6b717a4473a7e8d6f219f94 |
| MD5 hash: | b13641e5d100b2f67404aa2685f7db9b |
| humanhash: | steak-alanine-lima-cola |
| File name: | stage1_92f9d5ac6813.zsh |
| Download: | download sample |
| File size: | 1'440 bytes |
| First seen: | 2026-09-30 01:52:58 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | text/x-shellscript |
| ssdeep | 24:QZstezSANMeKyuC05Hp9SftVs0hCH43GJVqnhBco2t+ifygVvjdEBwjRBke6VJaB:QhzS470Np94PCrJVqnhBgNvDkPV8XrVD |
| TLSH | T1AE21E9DC574824D8BA58912D18287763609B07AFA813E8CE24088F9F51DB287908E13B |
| TrID | 70.0% (.SH) Linux/UNIX shell script (7000/1) 30.0% (.) Unix-like shebang (var.3) (gen) (3000/1) |
| Magika | shell |
| Reporter | |
| Tags: | ClickFix macOS stage1 zsh |
c4ffeine
1,440 B zsh script (23 lines, #!/bin/zsh) served with HTTP 200 as application/octet-stream at https://pevrix.com/curl/42403afd2906a8f3062e3ddb19b28572d88db9ae74b147319383bd280c6bec0a to both a curl/8.7.1 and a Safari User-Agent, fetched via Tor 2026-09-30 01:44 UTC. Same URL served a different 1,438 B script (sha256 594a664773b84fbc55649a138f96ff65ae7187951f90aa3aba3e23bea1233a12) on 2026-09-29. At fetch time the domain was SUSPENDED in RDAP and returned NXDOMAIN on public resolvers, while the Cloudflare edge still answered. Not executed, not yet decoded; family attribution pending.Intelligence
File Origin
USVendor Threat Intelligence
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | MAC_Dropper_Shell_Base64Gzip_Heredoc |
|---|---|
| Author: | Marjoriefort |
| Description: | Dropper shell (zsh/bash) macOS : payload base64+gzip en heredoc PAYLOAD_ |
| Reference: | Grand Scan InTheWild.0440 / 11 misses .sh a structure identique |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
92f9d5ac6813ca77e92a511f584bbc2017dd8b92cebb60bfc20a83df33f2631e
(this sample)
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.