MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 92ff08773995ebc8d55ec4b8e1a225d0d1e51efa4ef88b8849d0071230c9645a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 92ff08773995ebc8d55ec4b8e1a225d0d1e51efa4ef88b8849d0071230c9645a
SHA3-384 hash: a0f958bb27cfc8894e7721312b9ae3cf685946863f42b852ae814edc9d9b7c4e0dfedb0e96cd629a4be3240aa0e5aa9a
SHA1 hash: 13ab317c5dcab9af2d1bdb22118b9f09f8a4038e
MD5 hash: 7a9ddef00f69477b96252ca234fcbeeb
humanhash: nitrogen-failed-ink-football
File name:com.apple.act.mond
Download: download sample
File size:657'424 bytes
First seen:2026-03-31 09:58:10 UTC
Last seen:Never
File type:php macho
MIME type:application/x-mach-binary
ssdeep 6144:xjazCtUlrLxJnzsOOAx2Y+AktJgRESAtxVZS63vYdCzsbAkuNjepym:xjazCtyJcYKgRESAT93AdUjepym
TLSH T1F4E40953678F2D03C98A23F8AA7B135DE220FD119C6267EBF59190515EF53902F2EB90
TrID 82.2% (.DYLIB) Mac OS X Mach-O universal Dynamically linked shared Library (32500/1/5)
17.7% (.O/DYLIB/BUNDLE) Mac OS X Universal Binary (generic) (7002/2)
Magika macho
Reporter smica83
Tags:Axios-NPM machO sfrclak-com

Intelligence


File Origin
# of uploads :
1
# of downloads :
120
Origin country :
HU HU
Vendor Threat Intelligence
Gathering data
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
masquerade nukesped threat unknown
Verdict:
Malicious
File Type:
macho fat
First seen:
2026-03-31T02:40:00Z UTC
Last seen:
2026-03-31T22:53:00Z UTC
Hits:
~10
Score:
100%
Verdict:
Malware
File Type:
Mach-O universal binary
Threat name:
MacOS.Trojan.Generic
Status:
Malicious
First seen:
2026-03-31 05:45:52 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
20 of 38 (52.63%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments