🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 24af069b8899893cfc7347a4e5b46d717d77994a4b140d58de0be029dba686c9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 3 File information Comments

SHA256 hash: 24af069b8899893cfc7347a4e5b46d717d77994a4b140d58de0be029dba686c9
SHA3-384 hash: 51b04fd539a7b3884222fedb0aa9f54418a4b01d4af47400af504ce86a813e242482361f13575037e3a4b36fd36ffbd0
SHA1 hash: b0c5cc36fa9132379186b1cccb55da67f78e8c53
MD5 hash: 211571fe53a767e37428005a5db04e6f
humanhash: potato-carolina-stairway-cup
File name:ZoomApp.zip
Download: download sample
File size:2'531'772 bytes
First seen:2026-04-21 17:59:57 UTC
Last seen:2026-04-23 08:13:19 UTC
File type: zip
MIME type:application/zip
ssdeep 49152:tbAYD2r/uSozF48yTQMVLvF37kTPC4/RvfIg36o8Rpr2BIPwEXJvp:tFeuSDZZtLOPC4/RIyvsLp3
TLSH T10EC533B897C2A081D98542771A8A71CC840B690EC86F1E5B69D671E3E3FF3CD6347E46
Magika zip
Reporter mauroeldritch
Tags:DPRK Mach-O Man macOS zip


Avatar
mauroeldritch
Lazarus' Mach-O Man Stage 2 - Fake Zoom App downloaded by teamsSDK.bin

Intelligence


File Origin
# of uploads :
3
# of downloads :
763
Origin country :
UY UY
File Archive Information

This file archive contains 9 file(s), sorted by their relevance:

File name:Assets.car
File size:839'672 bytes
SHA256 hash: 11ec2f05a1258548f41e805a6c68a2093e028b1382807b8058fdeb857d8ca62c
MD5 hash: a3e297d6515257d29445b1aec6698398
MIME type:application/octet-stream
File name:Appicon.png
File size:74'351 bytes
SHA256 hash: 0246ed77147561cf6a8e69f451e91c430cb29e8c5b8ea2f4682cb2d7053341aa
MD5 hash: 510ca4da674c2121e1f18dcff95f2888
MIME type:image/png
File name:TeamApp
File size:3'155'088 bytes
SHA256 hash: f58041c8c96b493f318f41b7e41445ec3352b077011291cb998772df00e33533
MD5 hash: fefca3e38a35e24ccd46dc03e23b89c7
MIME type:application/x-mach-binary
File name:Secrets.example.plist
File size:326 bytes
SHA256 hash: 11679c7f0705e97d7382d10e3542d4d611fcf0a7d3dee7ab3be93b05ddec9e91
MD5 hash: ef835f06eceb5b7515ac18970832f8f8
MIME type:text/xml
File name:AppIcon.icns
File size:88'548 bytes
SHA256 hash: 6b4950f0ea729e37d105f8f36155312ae10a3820dc15c605f69268dd05fea0c9
MD5 hash: e2f218e66547805e0ce59b0875b3cc65
MIME type:image/x-icns
File name:Info.plist
File size:1'377 bytes
SHA256 hash: fdebd69dff07886d04f6419c9966021c8791d71ecea871d857e01febde6efc0c
MD5 hash: 0d93f7fb23d9b98abea1842112aed93b
MIME type:text/xml
File name:PkgInfo
File size:8 bytes
SHA256 hash: 82502191c9484b04d685374f9879a0066069c49b8acae7a04b01d38d07e8eca0
MD5 hash: 23b7d7d024abb0f558420e098800bf27
MIME type:text/plain
File name:Secrets.plist
File size:345 bytes
SHA256 hash: 7293d5e568d883ba0aa19f08e78ae440dea5c174de1aecf20dd748257ba40a4c
MD5 hash: c5c3eb682c5a82b9ed6546e9c3149b9a
MIME type:text/xml
File name:CodeResources
File size:3'604 bytes
SHA256 hash: 70b357fd70e2f3ae13aada15ea85df0fb189574eafe4a31f29fd475e1b911359
MD5 hash: 54d663e660b50e81cf18cb518381c55a
MIME type:text/xml
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
zip
First seen:
2026-04-22T08:05:00Z UTC
Last seen:
2026-04-22T08:21:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
2 match(es)
Tags:
Zip Archive
Threat name:
MacOS.Trojan.NukeSpeed
Status:
Malicious
First seen:
2026-04-08 22:43:43 UTC
File Type:
Binary (Archive)
Extracted files:
24
AV detection:
8 of 38 (21.05%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
macos
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:telebot_framework
Author:vietdx.mb
Rule name:Weedhack_Family_Generic
Author:jlab
Description:Generic Weedhack family detection

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Dropped by
Mach-O Man
  
Delivery method
Other

Comments