MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 54bbf9a07b0b89c0501359077aa98d707ac42b22b0f628265f70237e8a71194f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 2 File information Comments

SHA256 hash: 54bbf9a07b0b89c0501359077aa98d707ac42b22b0f628265f70237e8a71194f
SHA3-384 hash: 5a69dd8cb91d5b69ef5eed923c332af72ef86fe996cda176ac53ee5a1c05c21762324d3607d3a594e4aea35f717004dd
SHA1 hash: 3f17c5a7d1e7fd138163d8039e614b8a967a56cb
MD5 hash: 0f5ae560bbaadc7244c6c75da30a101b
humanhash: mobile-diet-zulu-three
File name:54bbf9a07b0b89c0501359077aa98d707ac42b22b0f628265f70237e8a71194f.zip
Download: download sample
File size:453'150 bytes
First seen:2024-11-14 11:38:27 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:4oBOs+FxFNZxORxdWAQf76q8tvKmp9szYx09:4oIZxpfJ6pvDg
TLSH T1F2A423E3C1013B34EFA6F83441BB54ACFA5BA8426FAD39B6460148BE0F5EF4E5C65119
Magika zip
Reporter JAMESWT_WT
Tags:apt BlueNoroff zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
116
Origin country :
IT IT
File Archive Information

This file archive contains 10 file(s), sorted by their relevance:

File name:MainMenu.nib
File size:29'342 bytes
SHA256 hash: ccf2182ce8e1d07cd0a6570174d3e854a216c666b0261e0e8e2ba3be8d513e60
MD5 hash: 15fb803e6cacf8bcbe436acb06f2d41c
MIME type:application/octet-stream
File name:XfG-lQ-9wD-view-m2S-Jp-Qdl.nib
File size:1'034 bytes
SHA256 hash: 1394f275e5b29e87bb8a45137ddd87f3bc0512ee257880cf194c33aa000ce34a
MD5 hash: 967b60df4ec9ac035370bf8861e5945e
MIME type:application/octet-stream
File name:Assets.car
File size:391'112 bytes
SHA256 hash: fc7774c96d3aead0d641545ecc3bf0610afd50b9f8a4646ce5436d7c2e33c82b
MD5 hash: c6daf9b7ec5c11a723e3fb77a8878e3d
MIME type:application/octet-stream
File name:NSWindowController-B8D-0N-5wS.nib
File size:2'667 bytes
SHA256 hash: cc7920d993c62f4b960a181e862f202c5a5dba29064ddf25e9c878a5b7127343
MD5 hash: e96250c0a1b2f7d1b344840aa6c6761a
MIME type:application/octet-stream
File name:Info.plist
File size:445 bytes
SHA256 hash: 5cae82bf7b921c390bfe32228bafc9778aa23fd63d3088bc23ac9782fd4bc188
MD5 hash: 7b88fb5241b47e17429082d630bdbcdf
MIME type:application/octet-stream
File name:Icon
File size:0 bytes
SHA256 hash: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
MD5 hash: d41d8cd98f00b204e9800998ecf8427e
MIME type:inode/x-empty
File name:LessonOne
File size:230'128 bytes
SHA256 hash: 75c81169d679fab821d77ea672f5a878626eb22d2110ffd7407623cb154ededd
MD5 hash: 501ee5b43833e35a6be3a2f0f977bb7c
MIME type:application/x-mach-binary
File name:AppIcon.icns
File size:35'725 bytes
SHA256 hash: 7b55462edf2e131b534ba24775c208849c8050b80af3104744df96df6061b5f4
MD5 hash: 011e060cf98d963827f8cad4d9ffe43b
MIME type:image/x-icns
File name:PkgInfo
File size:8 bytes
SHA256 hash: 82502191c9484b04d685374f9879a0066069c49b8acae7a04b01d38d07e8eca0
MD5 hash: 23b7d7d024abb0f558420e098800bf27
MIME type:text/plain
File name:CodeResources
File size:3'890 bytes
SHA256 hash: 36e757ed47427d532dd67a4c7a1cf26a0adfd6429a0af414a135d5c96d5f4c08
MD5 hash: 525b26b9db88fbd52b353d61f03023e3
MIME type:text/xml
Vendor Threat Intelligence
Threat name:
MacOS.Trojan.NukeSpeed
Status:
Malicious
First seen:
2024-11-07 15:59:24 UTC
File Type:
Binary (Archive)
Extracted files:
15
AV detection:
16 of 38 (42.11%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
macos
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:RansomPyShield_Antiransomware
Author:XiAnzheng
Description:Check for Suspicious String and Import combination that Ransomware mostly abuse(can create FP)
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments