🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cc922fb8fe4d86f2cf1f3cfea0e45fbed8f5982c5a7ba26405d3ad6b5af2a7c0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AMOS


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: cc922fb8fe4d86f2cf1f3cfea0e45fbed8f5982c5a7ba26405d3ad6b5af2a7c0
SHA3-384 hash: 2efa87aa0cca538f0518a48c34be5e5f9ba1182c739eb1c00907b3f8d712085dfdcca7bf16871135b9d003725d9c0542
SHA1 hash: 8d90c90c6e2943ea795238b179e86750b33bdbed
MD5 hash: 58d6b34e0269a5f7b2e76be2c1d8f0f4
humanhash: autumn-quiet-low-three
File name:stage1_cc922fb8fe4d.zsh
Download: download sample
Signature AMOS
File size:3'040 bytes
First seen:2026-09-18 02:35:23 UTC
Last seen:Never
File type:
MIME type:text/x-shellscript
ssdeep 48:22S6C4TbxGRDBf4r23HJwIA/acmxyWRZdJdAg3qL+TctOFHgT9gD0il/2/gxUxwj:2lAFGe23HJwSGWLdJ53qwctxKgiluoxb
TLSH T10F512AB6E4483872C46946E9D6E8FCBC15CE337D06E8774CB096835105EEE38A09D42E
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter c4ffeine
Tags:AES AMOS ClickFix dropper Foxveil macOS zsh


Avatar
c4ffeine
Foxveil stage-1 ClickFix dropper for the 'apph4' build, served as application/json. Self-keyed variant (not the _sync_id-keyed round-4 shape), so it decodes offline: _kb = (len("beta")*198 + len("stable")*7 + 48) % 90000 + 1000 = 1882, key = md5("1882") = e1314fc026da60d837353d20aefaf054, AES-128-CTR with a zero IV over the hex concat of _schema_id/_feature_flags/_vendor_ref/_rollout_key/_probe_salt, then gunzip -> a 1656 B stage-2 zsh (sha256 e7c01b9abe7afe90a30798009f1b3464c814fba913bf4a825b6b347fdac7d816). Command names are split across decoy variables (md5, xxd, openssl, gunzip) and the script is dressed as cache maintenance. Stage 2 beacons to leaf-core.com /api/metrics/run?event=pasted, downloads the Mach-O to /tmp/.sgip70, runs xattr -c + chmod +x, POSTs ?event=stager and execs it. Fetched over Tor; never executed.

Intelligence


File Origin
# of uploads :
1
# of downloads :
101
Origin country :
US US
Vendor Threat Intelligence
No detections
Threat name:
MacOS.Trojan.Multiverze
Status:
Malicious
First seen:
2026-09-18 05:11:28 UTC
File Type:
Text (Shell)
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

AMOS

cc922fb8fe4d86f2cf1f3cfea0e45fbed8f5982c5a7ba26405d3ad6b5af2a7c0

(this sample)

Comments