MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0517ca4649e33faefa3a6bfcd2707a8376a981be4b42b9d19146ebb93e7f8a35. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 10


Intelligence 10 IOCs YARA 3 File information Comments

SHA256 hash: 0517ca4649e33faefa3a6bfcd2707a8376a981be4b42b9d19146ebb93e7f8a35
SHA3-384 hash: 33b407402037ad4d848df32e48ba7599d1ab2f964384327123c313396b8bc7fd011ac4c03237e0d56b8aed6b2bac87e7
SHA1 hash: 1d4588a4d943f36a2ca16a5ff2cd5a307a2333ee
MD5 hash: 3da4d86f2fc94e560a6554a7dfabde39
humanhash: orange-aspen-maine-lithium
File name:winapp
Download: download sample
File size:2'236'912 bytes
First seen:2026-05-26 20:49:46 UTC
Last seen:Never
File type:php macho
MIME type:application/x-mach-binary
ssdeep 1536:z8ghSyjTm6hy39sN3QtRMDYHGfswY3L0s3PMtvWuWOCyjp2JWAEshqpg5u0bpzsx:z8CjTm6hyNsxQpfcvWuW3yjMuAqpgAT
TLSH T18BA5B793216B6503C4C5FBB47B8AA726E314FE51A8CE48B5B965E294DFD93CBD013380
Magika macho
Reporter smica83
Tags:machO

Intelligence


File Origin
# of uploads :
1
# of downloads :
52
Origin country :
HU HU
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
81.4%
Tags:
nukesped virus
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Verdict:
Malicious
File Type:
macho x64 le
First seen:
2026-05-26T12:24:00Z UTC
Last seen:
2026-05-27T08:45:00Z UTC
Hits:
~10
Verdict:
Malicious
Threat:
Trojan-Downloader.OSX.Nukesped
Threat name:
MacOS.Trojan.Nukesped
Status:
Malicious
First seen:
2026-05-26 11:58:10 UTC
AV detection:
4 of 38 (10.53%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Atomic_Stealer_Generic
Author:security-penguin
Description:Detects Atomic Stealer targeting MacOS
Rule name:telebot_framework
Author:vietdx.mb
Rule name:telegram_bot_api
Author:rectifyq
Description:Detects file containing Telegram Bot API

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments