🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 adba27615403539d9bde6f67a578237441e48076ea62d4e895f038a6c836d2d7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AMOS


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: adba27615403539d9bde6f67a578237441e48076ea62d4e895f038a6c836d2d7
SHA3-384 hash: eed069e2f9e8aefe0871bdb2611b4d2f1f2a8fb31333970c26dac123f16dcc84d37ade213a7c2121952b0c9089b39973
SHA1 hash: e3709d1202bb9fa15aaf3c452c7d2b33d18980b4
MD5 hash: 50c1ebba0f53b5db8da6170f665a37a6
humanhash: six-sink-uniform-ack
File name:stage1_script.txt
Download: download sample
Signature AMOS
File size:3'253 bytes
First seen:2026-09-14 04:38:09 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:gilg8qL00aJxYs0xM3iK8mXQmv6JWMxRxxDn:gil8LKJxYs0xqiwXTyJbD/
TLSH T14861E8E45CCC4961F46BCF90C784F57C1AA476A89FEAB79CE01463B4017DB3090D682C
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter c4ffeine
Tags:AMOS ClickFix dropper Foxveil macOS sh zsh


Avatar
c4ffeine
Foxveil stage-1 ClickFix zsh dropper served as .dat. Self-keyed: AES-128-CTR, key = md5 of a constant the script computes, zero IV, gunzip. Decrypts a stage-2 that POSTs a beacon to grove-satin.com/api/metrics/run?event=pasted and downloads the oo9 Mach-O loader (sha256 204b5d236e4384b23c1f0201bc52c06f32ef8eea679b975e9b432f2b111d1dbc) to /tmp/helper. Fetched via Tor 2026-09-14; not executed.

Intelligence


File Origin
# of uploads :
1
# of downloads :
291
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
masquerade
Threat name:
MacOS.Trojan.Multiverze
Status:
Malicious
First seen:
2026-08-19 15:23:01 UTC
File Type:
Text (Shell)
AV detection:
9 of 38 (23.68%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery linux
Behaviour
System Network Configuration Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

AMOS

sh adba27615403539d9bde6f67a578237441e48076ea62d4e895f038a6c836d2d7

(this sample)

  
Delivery method
Distributed via web download

Comments