🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 76544a4a87d91cd4c03539756c8ceb7b78c128cbe42fa03742c2ddec0eb18854. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 76544a4a87d91cd4c03539756c8ceb7b78c128cbe42fa03742c2ddec0eb18854
SHA3-384 hash: acac7ed55501c1759ee56c306cd28a13321afa8110e6a311e817fa6f78070fda37f7adea642494b2f18b51702a2ba620
SHA1 hash: 4dd148683906822fd815aad5e13c665dcc1a66c2
MD5 hash: 96c266a8a0da12e70f29834267f287a1
humanhash: purple-sixteen-apart-spring
File name:Files.zip
Download: download sample
File size:7'409 bytes
First seen:2026-10-01 06:09:05 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 192:sKzvxB3bbeG374SARKzvxB3bbeG374SApKzvxB3bbeG374SAmo:JD/nz74tgD/nz74tYD/nz74tmo
TLSH T168E11A235ED3C811EE13A9B704F208F2E1DCFB9505A49836657E222CF027BB5169BF94
Magika zip
Reporter Anonymous
Tags:zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
US US
File Archive Information

This file archive contains 11 file(s), sorted by their relevance:

File name:__TEXT__text
File size:636 bytes
SHA256 hash: 50d308585e2b5f7871f9fece0587875b51417b123adeba1ddf51542ec2373c5e
MD5 hash: 1b4bae3bf652cd907c32cd3881fa95b2
MIME type:application/octet-stream
File name:__DATA__la_symbol_ptr
File size:104 bytes
SHA256 hash: 6b357a1cf713691b82143562fddada6964621165919ee771a73aca57622f2e56
MD5 hash: f3d36598b29529d825444f309d018934
MIME type:application/octet-stream
File name:__LINKEDIT
File size:7'536 bytes
SHA256 hash: 832e73d4993f84e6212535e31eb6553658341b7fd74e69e60e8c5320c4182b42
MD5 hash: a56881010088d0d98cc699a28e2f73fe
MIME type:application/octet-stream
File name:__TEXT__stub_helper
File size:180 bytes
SHA256 hash: 237d14b44988dbaeb09786db57227e7c6ef5bca09a749e0134fe3fea86f98151
MD5 hash: 42865fae0cbf0ad1a2cacc1b0bfa2387
MIME type:application/octet-stream
File name:__TEXT__stubs
File size:156 bytes
SHA256 hash: a4855d52a7bf05cd885d205d5c348fc98932abf7ceaa3917bba26384801a7c0f
MD5 hash: 738a7725118ddec93ccc8141dcb2b076
MIME type:application/octet-stream
File name:__DATA__data
File size:8 bytes
SHA256 hash: af5570f5a1810b7af78caf4bc70a660f0df51e42baf91d4de5b2328de0e83dfc
MD5 hash: 7dea362b3fac8e00956a4952a3d4f474
MIME type:application/octet-stream
File name:__TEXT__cstring
File size:2 bytes
SHA256 hash: 102b51b9765a56a3e899f7cf0ee38e5251f9c503b357b330a49183eb7b155604
MD5 hash: 9dd94c5a4b02914af42e8e6372e0b709
MIME type:application/octet-stream
File name:__PAGEZERO
File size:0 bytes
SHA256 hash: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
MD5 hash: d41d8cd98f00b204e9800998ecf8427e
MIME type:inode/x-empty
File name:__DATA_CONST__got
File size:32 bytes
SHA256 hash: 66687aadf862bd776c8fc18b8e9f8e20089714856ee233b3902a591d0d5f2925
MD5 hash: 70bc8f4b72a86921468bf8e8441dce51
MIME type:application/octet-stream
File name:__TEXT__unwind_info
File size:72 bytes
SHA256 hash: c67c00b28bd96741c94a22499b608501d8c9e08355bb7b6472756c926bf4bef2
MD5 hash: 0c33ec880ed458c0d29c9ead57939ce8
MIME type:application/octet-stream
File name:Software Assistant
File size:56'688 bytes
SHA256 hash: 6c31c29b8b90b296287046a3d712c0b8143dc687dee092b836016c02fe69f20b
MD5 hash: 9b59cdc0a68d3c1c363ff14ffb3de44f
MIME type:application/x-mach-binary
Vendor Threat Intelligence
Verdict:
inconclusive
YARA:
2 match(es)
Tags:
Zip Archive
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion macos
Behaviour
Resource Forking
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:evilcrackz
Author:stu
Description:test - file evilcrackz.macho
Reference:https://github.com/Neo23x0/yarGen

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments