MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fc2009166867bee88885f2f889a608260cb971c1e946bbb79ea7d75ae0d429f6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AMOS


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: fc2009166867bee88885f2f889a608260cb971c1e946bbb79ea7d75ae0d429f6
SHA3-384 hash: 41e488e5b6350477e27ce839ff562f92a8ae4fccec64475aff97e500a5b8a9781bfafef214bd2ddb05eeb1651fbf4261
SHA1 hash: e09bb220036fad6a30ad66539879a17fc0ed548e
MD5 hash: 2990c4b21076c457b7e11c117ba3b3ef
humanhash: nevada-apart-oranges-hotel
File name:malwarepayload
Download: download sample
Signature AMOS
File size:330'752 bytes
First seen:2026-07-22 13:04:03 UTC
Last seen:Never
File type:php macho
MIME type:application/x-mach-binary
ssdeep 6144:9YABwQQIWYEfNajahiOjMRABwQQIWUifN:9h6QQIWYEfsahiOjMK6QQIWUif
TLSH T19964CF37629DF8A5D015FE34FA4B46EF59457A3980DF29538BE2CC0008A39872B66F13
TrID 82.2% (.DYLIB) Mac OS X Mach-O universal Dynamically linked shared Library (32500/1/5)
17.7% (.O/DYLIB/BUNDLE) Mac OS X Universal Binary (generic) (7002/2)
Magika macho
Reporter tonik
Tags:AMOS machO


Avatar
tonik
Sample found here: https://mvm.lol/@merlin@kif.rocks/116963270035281731
Confirmed AMOS by cross-referencing this post:
https://www.linkedin.com/posts/phil-stokes-b74248181_amos-macos-malware-share-7485333244083683328-OSQG/

Intelligence


File Origin
# of uploads :
1
# of downloads :
46
Origin country :
HR HR
Vendor Threat Intelligence
No detections
Score:
100%
Verdict:
Malware
File Type:
Mach-O universal binary
Threat name:
MacOS.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-22 13:36:10 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
4 of 36 (11.11%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries

File information


The table below shows additional information about this malware sample such as delivery method and external references.

eae5bbfcd0e0c7a91546c6eb89d78f8c194b64ec6c7e8627a4ea1c2f8e90b012

AMOS

php macho fc2009166867bee88885f2f889a608260cb971c1e946bbb79ea7d75ae0d429f6

(this sample)

  
Dropped by
SHA256 eae5bbfcd0e0c7a91546c6eb89d78f8c194b64ec6c7e8627a4ea1c2f8e90b012
  
Delivery method
Distributed via web download

Comments