🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a3dabccd14492f4c70658ece96a3ed7b4e275ff9d70c434298bd6f863d1e24b9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: a3dabccd14492f4c70658ece96a3ed7b4e275ff9d70c434298bd6f863d1e24b9
SHA3-384 hash: bc0f6ceaefe207ad8333bf3a146528dee4f0635a505440358ce33f5cb5579992af909325f8fe6b96738d966bbcce899c
SHA1 hash: 171411e11aedfcc13d42df5bd707858a9546165d
MD5 hash: 880dbdceb497cb8fd6a17691066a0147
humanhash: early-winner-beryllium-king
File name:macho_a3dabccd1449.bin
Download: download sample
File size:987'264 bytes
First seen:2026-09-18 20:32:20 UTC
Last seen:Never
File type:php macho
MIME type:application/x-mach-binary
ssdeep 12288:D3ad6e4xsaOPkJZ4nQh+P9yFOLIlmNZM3F588m/vI6qTbDHg/mzihry5qbqBiVZA:DKYisr4ndcQ5/ML8PqLGt24VHwFaI
TLSH T19125E100CEB290A9F48CDB352A2B47334D21A570468521DF53A66FA49D363F3F66B35E
TrID 82.2% (.DYLIB) Mac OS X Mach-O universal Dynamically linked shared Library (32500/1/5)
17.7% (.O/DYLIB/BUNDLE) Mac OS X Universal Binary (generic) (7002/2)
Magika macho
Reporter c4ffeine
Tags:ClickFix Foxveil Loader Mach-O machO macOS


Avatar
c4ffeine
Foxveil 'cc2' build Mach-O (fat x86_64+arm64, 987,264 B), downloaded by the ClickFix stage-1/stage-2 zsh chain from blueprint-71.com (stage-1 sha256 6e753133e537264247a08587d87b30b8d9a96caea1d6cc92d41fc8058073b8f7). Served under the long-standing Foxveil payload path token 2kqYRM0DCrnyJgoS4gVLl_FHJRRdTUhGCbjyuYwpZ6c, new subpath cc2. Host answers HTTP 200 only to a curl User-Agent; browsers get Cloudflare 520. Last-Modified 2026-09-18 20:01:18 GMT, fetched via Tor 2026-09-18 20:29 UTC, not executed. Every earlier build under this token was an AMOS reflective loader; this one is about 2.7x the size of the previous build and its analysis is pending.

Intelligence


File Origin
# of uploads :
1
# of downloads :
217
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  0/10
Confidence:
100%
Tags:
masquerade
Score:
100%
Verdict:
Malware
File Type:
Mach-O universal binary
Threat name:
Binary.Trojan.Generic
Status:
Suspicious
First seen:
2026-09-18 20:33:19 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
3 of 24 (12.50%)
Threat level:
  5/5
Malware family:
AtomicStealer
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

php macho a3dabccd14492f4c70658ece96a3ed7b4e275ff9d70c434298bd6f863d1e24b9

(this sample)

Comments