#!/bin/bash
set -e
RED='\033[0;31m'
GREEN='\033[0;32m'
YELLOW='\033[1;33m'
CYAN='\033[0;36m'
NC='\033[0m'
echo "========================================"
echo "OGF InfoStealer Detection Script v4.0"
echo "========================================"
echo ""
echo "Based on: https://rentry.co/ogf_malware & rentry.co/ogf_malware_behavior"
echo ""
DETECTIONS=0
WARNINGS=0
echo "[1/12] Checking for known infected releases in Downloads..."
echo ""
DOWNLOADS_DIR="$HOME/Downloads"
KNOWN_MALICIOUS_HASHES="5f37ea4e9c38e3ab9b8ae9403dc92ed9|8c1ca9899a3850f0302f2b4c2b76237d|d7f8b30accdebbd343e0a63b05b2d527|ea795c69ff68af3ea67dbf5f841dac1a|5bf80ea3e65a3327504120d5833b3b6a|ac60b72617c8ce08931a4fd424ed4565|c30ad49debf39d1e73350ee06d370e59|bb300ba91a09ba23fbd7af43247ad4b3|d79d030e383eccaf3142e593b9ab074c|18590ff4d9eb846e9db01ab2cfd6537f"
KNOWN_MALICIOUS_NAMES="ParallelsDesktop|CleanMyMac|Adobe.*DC|Adobe.*Pro|Photoshop.*[0-9]|Premiere.*Pro|DaVinci.*Resolve|Final.*Cut.*Pro|PDF.*Expert|Capture.*One|Logic.*Pro|Office.*2024|Microsoft.*Office"
if [ -d "$DOWNLOADS_DIR" ]; then
FOUND_INFECTED=""
while IFS= read -r -d '' f; do
NAME=$(basename "$f")
SIZE=$(ls -lh "$f" 2>/dev/null | awk '{print $5}')
MOD=$(stat -f "%Sm" -t "%Y-%m-%d" "$f" 2>/dev/null || stat -c "%y" "$f" 2>/dev/null | cut -d' ' -f1)
if echo "$NAME" | grep -qE "$KNOWN_MALICIOUS_NAMES"; then
echo -e " ${RED}[KNOWN INFECTED RELEASE]${NC} $NAME ($SIZE, $MOD)"
echo " ^ On the OGF malware infected list!"
FOUND_INFECTED="$FOUND_INFECTED$NAME\n"
WARNINGS=$((WARNINGS + 10))
fi
done < <(find "$DOWNLOADS_DIR" -maxdepth 2 \( -name "*.dmg" -o -name "*.iso" \) -print0 2>/dev/null)
if [ -z "$FOUND_INFECTED" ]; then
echo " No KNOWN INFECTED releases found in Downloads."
fi
fi
echo ""
echo "[2/12] Checking for 'Open Gatekeeper Friendly' files..."
echo ""
OGF_FILES=$(find "$DOWNLOADS_DIR" -maxdepth 3 -iname "*gatekeeper*" -o -iname "*Open*Gatekeeper*" 2>/dev/null)
if [ -n "$OGF_FILES" ]; then
echo " Found Open Gatekeeper Friendly files:"
echo "$OGF_FILES" | while read f; do
NAME=$(basename "$f")
SIZE=$(ls -lh "$f" 2>/dev/null | awk '{print $5}')
if [ -f "$f" ]; then
ACTUAL_SIZE=$(stat -f%z "$f" 2>/dev/null || stat -c%s "$f" 2>/dev/null || echo "0")
if [ "$ACTUAL_SIZE" -gt 500000 ]; then
echo -e " ${RED}[SUSPICIOUS]${NC} $NAME ($SIZE) - Large binary (>500KB), likely MALICIOUS"
WARNINGS=$((WARNINGS + 5))
else
echo -e " ${YELLOW}[REVIEW]${NC} $NAME ($SIZE)"
fi
fi
done
else
echo " No 'Open Gatekeeper Friendly' files found."
fi
echo ""
echo "[3/12] Checking for suspicious files in /tmp..."
echo ""
TMP_DIRS=$(ls -la /tmp/ 2>/dev/null | grep "^d" | awk '{print $NF}' | grep -E "^[a-z0-9]{4,10}$")
if [ -n "$TMP_DIRS" ]; then
echo " Random-looking directories in /tmp:"
echo "$TMP_DIRS" | while read dir; do
FULL_PATH="/tmp/$dir"
CONTENTS=$(ls -la "$FULL_PATH" 2>/dev/null | head -5)
if [ -n "$CONTENTS" ]; then
echo -e " ${RED}[DETECTED]${NC} $FULL_PATH"
echo " Contents:"
echo "$CONTENTS" | while read line; do
echo " $line"
done
DETECTIONS=$((DETECTIONS + 1))
else
echo " $FULL_PATH (empty)"
fi
done
else
echo " No suspicious random directories in /tmp."
fi
echo ""
echo "[4/12] Checking for suspicious /tmp/out.zip..."
echo ""
if [ -f "/tmp/out.zip" ]; then
echo -e " ${RED}[DETECTED]${NC} /tmp/out.zip - MALWARE STAGE!"
echo " This is where the malware stages stolen data before exfiltration."
DETECTIONS=$((DETECTIONS + 1))
else
echo " /tmp/out.zip not found (good)."
fi
echo ""
echo "[5/12] Checking for suspicious processes..."
echo ""
SUSPICIOUS_PROCS=$(ps aux | grep -v grep | grep -iE "(osascript.*curl|curl.*POST.*file|ditto.*tmp" | head -10)
if [ -n "$SUSPICIOUS_PROCS" ]; then
echo -e " ${RED}[DETECTED]${NC} Active malware process detected!"
echo "$SUSPICIOUS_PROCS" | while read line; do
echo " $line"
done
DETECTIONS=$((DETECTIONS + 1))
else
echo " No active malware processes found."
fi
echo ""
echo "[6/12] Checking for known malicious network connections..."
echo ""
EXFIL_SERVERS="81.19.135.54|82.115.223.9|85.209.11.155|141.98.9.20|141.98.9.203|185.7.214.148|193.124.185.54|odyssey1.to|zblong.com|rgueapp.com"
echo " Checking active connections against known exfil servers..."
ACTIVE_CONN=$(netstat -an 2>/dev/null | grep ESTABLISHED | awk '{print $5}' | cut -d: -f1 | sort -u || echo "")
if [ -n "$ACTIVE_CONN" ]; then
MALICIOUS_CONN=""
echo "$ACTIVE_CONN" | while read ip; do
if echo "$ip" | grep -qE "$EXFIL_SERVERS"; then
echo -e " ${RED}[DETECTED]${NC} Connection to KNOWN MALICIOUS SERVER: $ip"
MALICIOUS_CONN="$MALICIOUS_CONN$ip\n"
DETECTIONS=$((DETECTIONS + 1))
fi
done
if [ -z "$MALICIOUS_CONN" ]; then
echo " No connections to known exfil servers."
fi
else
echo " Unable to check connections (netstat failed)."
fi
echo ""
echo "[7/12] Checking launch agents/daemons..."
echo ""
LAUNCH_DIR="$HOME/Library/LaunchAgents"
if [ -d "$LAUNCH_DIR" ]; then
AGENTS=$(ls "$LAUNCH_DIR"/*.plist 2>/dev/null | wc -l | tr -d ' ')
echo " Found $AGENTS launch agents in ~/Library/LaunchAgents:"
ls "$LAUNCH_DIR"/*.plist 2>/dev/null | while read f; do
NAME=$(basename "$f")
if echo "$NAME" | grep -qE "(adobe|microsoft|parallels|cleanmymac|davinci)"; then
:
else
echo " [INFO] $NAME"
fi
done
fi
echo ""
echo "[8/12] Checking browser extensions for crypto theft..."
echo ""
echo " The malware steals these crypto extensions:"
echo " MetaMask, Ledger Live, Exodus, Atomic, Wasabi, Trezor, Binance, TON"
echo " Checking for these in Chrome..."
BROWSER_EXT_DIRS=(
"$HOME/Library/Application Support/Google/Chrome/Default/Extensions"
"$HOME/Library/Application Support/BraveSoftware/Brave-Browser/Default/Extensions"
)
for dir in "${BROWSER_EXT_DIRS[@]}"; do
if [ -d "$dir" ]; then
STOLEN_EXT="nkbihfbeogaeaoehlefnkodbefgpgknn|fhbohimaelbohpjbbldcngcnapndodjp|odpnjmimokcmjgojhnhfcnalnegdjmdn|jnlgamecbpmbajjfhmmmlhejkemejdma|aodkklnadndmjcnmkjhfamgmpcpfeghf"
FOUND_EXT=$(find "$dir" -maxdepth 2 -type d -name "*$STOLEN_EXT*" 2>/dev/null | head -5)
if [ -n "$FOUND_EXT" ]; then
echo " Found crypto extensions (could be legitimate):"
echo "$FOUND_EXT" | while read f; do
echo " $f"
done
echo " ^ These could be legitimate or stolen by malware."
fi
fi
done
echo ""
echo "[9/12] Checking for Telegram data collection..."
echo ""
TELEGRAM_TDATA=$(find "$HOME/Library/Application Support" -maxdepth 3 -path "*Telegram Desktop/tdata*" -type d 2>/dev/null)
if [ -n "$TELEGRAM_TDATA" ]; then
echo " Telegram data folder found:"
echo "$TELEGRAM_TDATA" | head -3 | while read f; do
echo " $f"
done
echo " ^ This is what the malware targets!"
fi
echo ""
echo "[10/12] Checking Downloads for known infected releases by hash patterns..."
echo ""
if [ -d "$DOWNLOADS_DIR" ]; then
echo " Scanning for 99+ known infected releases..."
while IFS= read -r -d '' f; do
NAME=$(basename "$f")
SIZE=$(ls -lh "$f" 2>/dev/null | awk '{print $5}')
case "$NAME" in
*ParallelsDesktop-20.1.2*|*ParallelsDesktop-20.2.0*|*ParallelsDesktop-20.2.1*|*ParallelsDesktop-20.1.1*)
echo -e " ${RED}[INFECTED]${NC} $NAME ($SIZE) - ON KNOWN INFECTED LIST!"
WARNINGS=$((WARNINGS + 10))
;;
*CleanMyMac*5.0.4*|*CleanMyMac*5.0.5*)
echo -e " ${RED}[INFECTED]${NC} $NAME ($SIZE) - ON KNOWN INFECTED LIST!"
WARNINGS=$((WARNINGS + 10))
;;
*PDF*Expert*3.10.18*)
echo -e " ${RED}[INFECTED]${NC} $NAME ($SIZE) - ON KNOWN INFECTED LIST!"
WARNINGS=$((WARNINGS + 10))
;;
*DaVinci*Resolve*Studio*19*|*DaVinci*Resolve*Studio*20*)
echo -e " ${RED}[INFECTED]${NC} $NAME ($SIZE) - ON KNOWN INFECTED LIST!"
WARNINGS=$((WARNINGS + 10))
;;
*Adobe*|*Final*Cut*Pro*|*Logic*Pro*)
echo -e " ${YELLOW}[POTENTIAL RISK]${NC} $NAME ($SIZE)"
WARNINGS=$((WARNINGS + 3))
;;
*)
;;
esac
done < <(find "$DOWNLOADS_DIR" -maxdepth 2 \( -name "*.dmg" -o -name "*.iso" \) -print0 2>/dev/null)
fi
echo ""
echo "[11/12] Checking Full Disk Access permissions..."
echo ""
FDA_APPS=$(sqlite3 "$HOME/Library/Application Support/com.apple.TCC/TCC.db" "SELECT client FROM access WHERE client NOT LIKE '%Apple%' AND client NOT LIKE '%com.apple%';" 2>/dev/null | head -20)
if [ -n "$FDA_APPS" ]; then
echo " Apps with Full Disk Access:"
echo "$FDA_APPS" | while read app; do
case "$app" in
*Terminal*|*Finder*|*Chrome*|*Safari*)
;;
*)
echo -e " ${YELLOW}[REVIEW]${NC} $app"
WARNINGS=$((WARNINGS + 1))
;;
esac
done
else
echo " No unusual Full Disk Access entries found (or TCC.db not readable)."
fi
echo ""
echo "[12/12] Checking Gatekeeper quarantine bypass..."
echo ""
NO_QUARANTINE=$(find "$DOWNLOADS_DIR" -maxdepth 2 \( -name "*.dmg" -o -name "*.app" -o -name "*.pkg" \) -print0 2>/dev/null | xargs -0 xattr 2>/dev/null | grep -l "com.apple.quarantine" || echo "found")
if [ "$NO_QUARANTINE" != "found" ]; then
NO_QUARANTINE_FILES=$(find "$DOWNLOADS_DIR" -maxdepth 2 \( -name "*.dmg" -o -name "*.app" -o -name "*.pkg" \) -exec sh -c 'xattr "$1" 2>/dev/null | grep -q "com.apple.quarantine" || echo "$1"' _ {} \; 2>/dev/null)
if [ -n "$NO_QUARANTINE_FILES" ]; then
echo -e " ${RED}[GATEKEEPER BYPASSED]${NC} Files without quarantine flag:"
echo "$NO_QUARANTINE_FILES" | head -5 | while read f; do
NAME=$(basename "$f")
echo " $NAME"
done
WARNINGS=$((WARNINGS + 1))
fi
fi
echo ""
echo "========================================"
echo "Scan Complete"
echo "========================================"
echo ""
if [ $DETECTIONS -gt 0 ]; then
echo -e "${RED}⚠️ CRITICAL: $DETECTIONS MALWARE INDICATORS DETECTED!${NC}"
echo ""
echo "IMMEDIATE ACTIONS:"
echo "1. DISCONNECT FROM INTERNET NOW"
echo "2. Run: sudo pkill -f osascript"
echo "3. Run: sudo rm -rf /tmp/[a-z0-9]* 2>/dev/null"
echo "4. Delete all pirated software from Downloads"
echo "5. Change ALL passwords (email, banking, crypto, etc.)"
echo "6. Consider reinstalling macOS"
elif [ $WARNINGS -gt 0 ]; then
echo -e "${YELLOW}⚠️ Found $WARNINGS potential risk indicators.${NC}"
echo ""
echo "Recommended actions:"
echo "1. Delete pirated software from Downloads"
echo "2. Change important passwords as precaution"
echo "3. Enable 2FA on all accounts"
echo "4. Run Malwarebytes or Combo Cleaner"
else
echo -e "${GREEN}✅ No obvious malware indicators detected.${NC}"
fi
echo ""
echo "Summary:"
echo " - Critical Detections: $DETECTIONS"
echo " - Warnings: $WARNINGS"
echo ""
echo "For cleanup instructions, see:"
echo " https://rentry.co/ogf_malware"
echo ""
echo "Known infected releases count: 99+"
echo "Known malicious binaries: 24+"
Comments
0 B
|👍
/👎
0 B
|👍
/👎
0 B
|👍
/👎
0 B
|👍
/👎
0 B
|👍
/👎
0 B
|👍
/👎
0 B
|👍
/👎
0 B
|👍
/👎
0 B
|👍
/👎
0 B
|👍
/👎
0 B
|👍
/👎
0 B
|👍
/👎
0 B
|👍
/👎
0 B
|👍
/👎
0 B
|👍
/👎
0 B
|👍
/👎
0 B
|0 👍
/0 👎