🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7a8aac687ea67207c19e1c74edb73e8a1a341a0fae0b75f2b434054922763f99. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA 4 File information Comments 1

SHA256 hash: 7a8aac687ea67207c19e1c74edb73e8a1a341a0fae0b75f2b434054922763f99
SHA3-384 hash: 20f65188e7b023beb8ebde5d2b749bc9a56cb0ad11bbafe42fa6194a1741cc26de6b72edc62fc5a1d5656e156531f511
SHA1 hash: 83de5b7c35801b92c9f5f370e452714f22af167b
MD5 hash: b5d80fd9330f57957e74d553247b054c
humanhash: network-tango-bluebird-emma
File name:proram_macos_agent
Download: download sample
File size:198'608 bytes
First seen:2026-09-05 11:02:43 UTC
Last seen:Never
File type:php macho
MIME type:application/x-mach-binary
ssdeep 3072:jTmvasEnAL3rAEasw589rII/wU6MJGfexNQPqF6:FnMhE89FUexNQo6
TLSH T169145A43A21C2C37C2CAB5BD8B558BA07636F1B042B1D3797E16849DC99D385397CFA2
Magika macho
Reporter KabirAcharya
Tags:arm64 machO macOS ProRAM RAT


Avatar
KabirAcharya
Confirmed ARM64 ProRAM implant. Ad-hoc signature identifier proram_macos_agent, no TeamIdentifier; PRORAMCFGv1; same primary WebSocket path as Windows; host survey, persistent identity, payload download and dynamic loading, upload and uninstall. Credential theft was not established.

Intelligence


File Origin
# of uploads :
1
# of downloads :
97
Origin country :
AU AU
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
base64
Verdict:
Unknown
File Type:
macho x64 le
First seen:
2026-09-04T05:52:00Z UTC
Last seen:
2026-09-04T06:09:00Z UTC
Hits:
~10
Threat name:
MacOS.Trojan.Generic
Status:
Suspicious
First seen:
2026-09-04 08:46:34 UTC
File Type:
MachO64 Little (Exe)
AV detection:
5 of 24 (20.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:ldpreload
Author:xorseed
Reference:https://stuff.rop.io/
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:WIN_WebSocket_Base64_C2_20250726
Author:dogsafetyforeverone
Description:Detects configuration strings used by malware to specify WebSocket command-and-control endpoints inside Base64-encoded data. It looks for prefixes such as '#ws://' or '#wss://' that were found in QuasarRAT configuration data.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Distributed via drive-by

Comments



Avatar
commented on 2026-09-05 12:12:44 UTC

Infrastructure update: 20.187.77.65:443 is the exposed origin of the ProRAM C2 clash-verge-upgrade.com. Direct HTTP to the IP redirects to that domain, and TLS presents a matching certificate (SHA-256 f0de85fc8ca45c16e53c56e697f80714eb41c1cca307815ef0412227e46be4f). Censys historically associated 435ggtrgberwtw.duckdns.org with the same IP; the DuckDNS name no longer resolved during later verification.