🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for sha256_hash 8c8c72b6149130a65f7d69fb97fad7eedd7580fa07f863a62b4d72aa460951bc.

Database Entry


IOC ID:1932394
IOC: 8c8c72b6149130a65f7d69fb97fad7eedd7580fa07f863a62b4d72aa460951bc
IOC Type :sha256_hash
Threat Type :payload
Malware: AMOS
Malware alias:Atomic macOS Stealer
Confidence Level : Confidence level is high (100%)
Is compromised? : False
First seen:2026-09-24 18:42:07 UTC
Last seen:never
UUID:1e8a1299-b846-11f1-abee-42010aa4000a
Reporter c4ffeine
Reward 5 credits from ThreatFox
Tags:Amos ClickFix DANTE Foxveil macOS
Reference: https://www.virustotal.com/gui/file/8c8c72b6149130a65f7d69fb97fad7eedd7580fa07f863a62b4d72aa460951bc

Avatar
c4ffeine
Foxveil/AMOS reflective loader Mach-O (fat x86_64+arm64, 1,003,392 B), the EIGHTEENTH payload served from https://journeylake11.com/2kqYRM0DCrnyJgoS4gVLl_FHJRRdTUhGCbjyuYwpZ6c/DANTE/update, fetched via Tor 2026-09-24 17:33:58 UTC, origin build time 17:15:16, 1 hour 9 minutes after the previous build (beefe66a3125211b8f62829521f59e50ed2a6f214129721cf3dbad6006f98c70, built 16:06:08). Loader code differs from the previous build by function-level CFG match (fv_codehash REVIEW, TLSH of __text 131) and a payload table of 195,520 B plaintext against 195,196 B, but the wrapper moved with this build: Rebuilt loader with new control-flow obfuscation (6 shared functions, jaccard 0.1071), PBKDF2 iterations 92258 instead of 106564, and 91 payload items (19 decoys) instead of 71 (13 decoys). Both payloads were decrypted and compared (new 195,520 B, baseline 195,196 B): 47 top-level handlers each, 0.9604 statement similarity, the 16 differing blocks are only string literals split in different places, same keywords, same seven URL paths and same known hosts on both sides. Not executed. VirusTotal: https://www.virustotal.com/gui/file/8c8c72b6149130a65f7d69fb97fad7eedd7580fa07f863a62b4d72aa460951bc Hybrid Analysis: https://hybrid-analysis.com/sample/8c8c72b6149130a65f7d69fb97fad7eedd7580fa07f863a62b4d72aa460951bc