🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bedc5ef2bc2ad17fd0d627b2539a47e6ad55f9b83cfe3febaf8de2ee32e9c9af. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 2 File information Comments

SHA256 hash: bedc5ef2bc2ad17fd0d627b2539a47e6ad55f9b83cfe3febaf8de2ee32e9c9af
SHA3-384 hash: 4acebb86b1d84c0bb11b3a58fc1b112c4d482fa2f92ebbbaa7e9d7785436942dd0659f7b6d34d1f9f8846825c6c5f529
SHA1 hash: 26213db8719d23a11cb10313ed3bb2e9e6dda513
MD5 hash: 3a395a93c07d20a25ae5564be504efd8
humanhash: winner-xray-pip-moon
File name:macho_bedc5ef2bc2a.bin
Download: download sample
File size:1'036'144 bytes
First seen:2026-09-24 10:32:47 UTC
Last seen:Never
File type:php macho
MIME type:application/x-mach-binary
ssdeep 12288:ny/DjCrkZoB25qNVkjgBUZR5CptUaGqu3uRHhkuHPAX+wBzo1KyCdlv8wlmhiZnF:yrjCaodkUvwquCkuCzB6U8w8ViB
TLSH T13425E101CF668095F5CCD7302B3B9A375F356550894823DA67922E88EE323E3F56736A
TrID 69.8% (.DYLIB) Mac OS X Mach-O universal Dynamically linked shared Library (32500/1/5)
15.0% (.O/DYLIB/BUNDLE) Mac OS X Universal Binary (generic) (7002/2)
15.0% (.CLASS) Java bytecode (7001/2/1)
Magika macho
Reporter c4ffeine
Tags:ClickFix Foxveil Loader Mach-O machO macOS


Avatar
c4ffeine
Foxveil 'cc2' build Mach-O, the FIFTY-NINTH payload served from this one unchanged URL (fat x86_64+arm64, 1,036,144 B), fetched via Tor 2026-09-24 10:25:58 UTC, origin build time 10:04:39 (nginx Last-Modified and ETag), 2 hours 2 minutes after the previous build (5b7487d9528a49f6b83d41c772529b4d02d08a363c4501a60a3c8f9a3eeb53fa). Earlier builds in the series were unpacked statically and each held the same AMOS AppleScript stealer, with the same 47 handlers, hosts and persistence, decrypted with a key derived from the SHA-256 of the loader's own __text section, so each repack rekeys itself. This build compared against the previous one: 44 __text functions against 42, TLSH of __text 54. The encrypted payload table holds 61 items totalling 220,542 bytes of plaintext against 77 items and 194,352 bytes in the previous build, a 13.5 percent growth. Fetched at the same probe as the concurrent build on the other Foxveil payload URL of this operator, and the two share several per-function CFG hashes that neither predecessor carries, so the loader code was updated across both series in the same hour. The encrypted payload table grew by 13.5 percent, outside the few-percent band seen between the earlier scheduled repacks of this series, so this build is under static analysis rather than filed as a repack. Results will be added as a comment once the payload is opened. Host answers HTTP 200 only to a curl User-Agent; browser User-Agents get a Cloudflare 520. Not executed.

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
masquerade
Score:
100%
Verdict:
Malware
File Type:
Mach-O universal binary
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Foxveil_Loader_PadSeg_Variant
Description:Foxveil macOS loader (ClickFix -> AMOS), apph4/cc2 packer generation, 2026-09-23 wrapper: fat x86_64+arm64 linking CoreFoundation+libSystem+libc++, plus one randomly-named section-less LC_SEGMENT_64 per slice with zero vmsize and zero filesize whose vmaddr, small fileoff, prot (0/1) and flags (0/8) are randomised per slice
Rule name:telebot_framework
Author:vietdx.mb

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

php macho bedc5ef2bc2ad17fd0d627b2539a47e6ad55f9b83cfe3febaf8de2ee32e9c9af

(this sample)

Comments