🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ed980f2fa0642b1a5ba0bca65f5b3baee8a7b3f5d149bf295aa4ac7a70b92cec. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: ed980f2fa0642b1a5ba0bca65f5b3baee8a7b3f5d149bf295aa4ac7a70b92cec
SHA3-384 hash: 00ed8312cb409078b07dbd257ccf4571786c0390365d995eec53cc187c75f8eb16c71996b5c1b396b9dbe82e43b6c008
SHA1 hash: e280a3c41bef6e41260ad8467685df6da09de34d
MD5 hash: 745a192a25873d958f75a11de30e7880
humanhash: nuts-kentucky-april-carolina
File name:jxa_ed980f2fa064.scpt
Download: download sample
File size:56'380 bytes
First seen:2026-09-22 00:46:20 UTC
Last seen:Never
File type:
MIME type:application/octet-stream
ssdeep 768:QJLyC33h45ibpLO2Y3RJZzKpG0FQ3ykLqJGQj1rdecAVjctvcne6noX9NLZ/NCWC:QFyii2QkrjXLZVaG6eySDs0MB
TLSH T11E434C283AE5203EF1F38FD06BD43CD9AE5EF6FA2B63545A10A00BCE4781A44DD55639
Magika unknown
Reporter c4ffeine
Tags:dropper JXA macOS MacSync scpt


Avatar
c4ffeine
Compiled JXA (JavaScript for Automation) script extracted from the disk image Wavel.dmg (sha256 8c5586bda2bbdf63db30a0e3113ccd78bb1c0943a225d575c9eef1d992aa8254), where it sits as Wavel-Installer/.scpt with four invisible U+2060 characters in its file name. Most of the source is commented-out decoy installer code; the live part base64-decodes a zsh stage-2 and pipes it to /bin/zsh. The stage-2 is uploaded separately (sha256 e0e5925b48de691c187baa7dc6f98ff2c3c8d622272397eb88e3af96c48c6eaf). Extracted and decoded statically, not executed. Attribution pending.

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
text
First seen:
2026-09-21T22:51:00Z UTC
Last seen:
2026-09-21T23:00:00Z UTC
Hits:
~10
Gathering data
Threat name:
MacOS.Trojan.Multiverze
Status:
Malicious
First seen:
2026-09-18 16:54:48 UTC
File Type:
Binary
AV detection:
7 of 38 (18.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ed980f2fa0642b1a5ba0bca65f5b3baee8a7b3f5d149bf295aa4ac7a70b92cec

(this sample)

  
Delivery method
Distributed via web download

Comments