MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 89616a503ffee8fc70f13c82c4a5e4fa4efafa61410971f4327ed38328af2938. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 9 File information Comments

SHA256 hash: 89616a503ffee8fc70f13c82c4a5e4fa4efafa61410971f4327ed38328af2938
SHA3-384 hash: c36ca3c88707f562462ca0c6d65c209ba0fe354bfaa5da9f4447659dc9b077d76b0e176aa207c32477dbd0ee4c3be815
SHA1 hash: 8800a6660a53dc1fc8ff4af5c31312a1e81ac6cf
MD5 hash: c62dffe79a634516543a32511ad3e0db
humanhash: april-equal-twelve-mike
File name:SystemApp.zip
Download: download sample
File size:3'232'031 bytes
First seen:2026-04-21 18:01:02 UTC
Last seen:2026-04-23 08:13:43 UTC
File type: zip
MIME type:application/zip
ssdeep 49152:/QQnGaMHCjk9JnhoF9ew3wuNEe8+qxoPskmI9uH3ZIYtCbea7e398:/QQnGaMHM5P3wxe8+c+O3gaaa3i
TLSH T1ADE5331499E23327E64F413296E2AF1FD97AD80612E0D999E2F1C14B857FCB8B63035D
TrID 60.0% (.USDZ) Universal Scene Description Zipped AR format (generic) (6000/1/1)
40.0% (.ZIP) ZIP compressed archive (4000/1)
Magika zip
Reporter mauroeldritch
Tags:DPRK Mach-O Man macOS zip


Avatar
mauroeldritch
Lazarus' Mach-O Man Stage 2 - Fake System App downloaded by teamsSDK.bin

Intelligence


File Origin
# of uploads :
2
# of downloads :
409
Origin country :
UY UY
File Archive Information

This file archive contains 7 file(s), sorted by their relevance:

File name:segment_pad.bin
File size:4'194'304 bytes
SHA256 hash: bb9f8df61474d25e71fa00722318cd387396ca1736605e1248821cc0de3d3af8
MD5 hash: b5cfa9d6c8febd618f91ac2843d50a1c
MIME type:application/octet-stream
File name:Appicon.png
File size:74'351 bytes
SHA256 hash: c7a72a69749dbc3bdb5396e2256ecf5479788b03f1e3698f105f1faebfebff82
MD5 hash: 048317f76f5b302fc5c5e635335ffdd7
MIME type:image/png
File name:AppIcon.icns
File size:1'099'855 bytes
SHA256 hash: 6178a79aa1e8ccfb98ddaf4eeeeee1f942ff485fe785467a33886675c56ccc87
MD5 hash: 5521f3aa7b474063a8fb184b92255194
MIME type:image/x-icns
File name:Info.plist
File size:880 bytes
SHA256 hash: 10fefca84520054013bd56262651c80032ca914f45be2332bd531a660639aca1
MD5 hash: d780a0f798fc3861c339b1cc84646d9d
MIME type:text/xml
File name:SystemApp
File size:2'854'112 bytes
SHA256 hash: 0908f2906e0d8a007ca37f0791866cd75e982baecf51e207b7e6b293831f9033
MD5 hash: b28978c94cc8c2cbdbcc839c8e0a465c
MIME type:application/x-mach-binary
File name:PkgInfo
File size:8 bytes
SHA256 hash: 82502191c9484b04d685374f9879a0066069c49b8acae7a04b01d38d07e8eca0
MD5 hash: 23b7d7d024abb0f558420e098800bf27
MIME type:text/plain
File name:CodeResources
File size:3'358 bytes
SHA256 hash: 0268409ff106a86fb4b687601b6ed05802ee9e99a91daca9cec03cc57c482646
MD5 hash: 5a2beeb2fbef736b71233e0c6672e765
MIME type:text/xml
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
zip
First seen:
2026-04-21T17:01:00Z UTC
Last seen:
2026-04-21T17:10:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
2 match(es)
Tags:
Zip Archive
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2026-04-21 18:02:08 UTC
File Type:
Binary (Archive)
Extracted files:
23
AV detection:
7 of 38 (18.42%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
defense_evasion macos
Behaviour
Resource Forking
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DetectTelegramTokens
Author:TTK
Description:Detect Telegram Bot Tokens (TTK)
Rule name:telebot_framework
Author:vietdx.mb
Rule name:telegram_bot_api
Author:rectifyq
Description:Detects file containing Telegram Bot API
Rule name:test_something_rule
Author:test
Rule name:Weedhack_Family_Generic
Author:jlab
Description:Generic Weedhack family detection

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Dropped by
Mach-O Man
  
Delivery method
Other

Comments