MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9abf6b93eafb797a3556bea1fe8a3b7311d2864d5a9a3687fce84bc1ec4a428c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 2 File information Comments

SHA256 hash: 9abf6b93eafb797a3556bea1fe8a3b7311d2864d5a9a3687fce84bc1ec4a428c
SHA3-384 hash: 899164b25bcacb567decf979b3a0caa815902277dd11f9f37f9d2be28ef35233576b56a424b54d8c2ccf3747dc57722e
SHA1 hash: ae8fdc45746fb64036c41490c2ca34052584198b
MD5 hash: 91c89af52df3e3067ab2d3d619fcd345
humanhash: south-equal-lima-winner
File name:MiroTalk.dmg
Download: download sample
File size:20'784'310 bytes
First seen:2024-09-19 04:48:37 UTC
Last seen:2024-10-10 16:16:32 UTC
File type:
MIME type:application/zlib
ssdeep 393216:X6BaJdO4cW0o9XxvXrx+AXY+ZCf/yrp49xlDJT5Vkk/SAdNxOmwyR1hIsDGhXQ:waJ04Qo77x7Yl1ck/S4PtwyRDrDGhX
TLSH T18827333FCA79195EC4B14140AB5AB4A07D43A743DC62C904DF9A92D0AADFC03BD35EA7
TrID 97.6% (.DMG) Macintosh Disk image (BZlib compressed) (83000/1/20)
2.3% (.) ZLIB compressed data (low/no comp.) (2000/1)
Magika dmg
Reporter JAMESWT_WT
Tags:95-164-17-24 dmg

Intelligence


File Origin
# of uploads :
2
# of downloads :
89
Origin country :
IT IT
Vendor Threat Intelligence
Gathering data
Threat name:
MacOS.Trojan.BeaverTail
Status:
Malicious
First seen:
2024-07-12 20:09:00 UTC
File Type:
Binary (Archive)
Extracted files:
799
AV detection:
18 of 37 (48.65%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Detect_APT29_WINELOADER_Backdoor
Author:daniyyell
Description:Detects APT29's WINELOADER backdoor variant used in phishing campaigns, this rule also detect bad pdf,shtml,htm and vbs or maybe more depends
Reference:https://cloud.google.com/blog/topics/threat-intelligence/apt29-wineloader-german-political-parties
Rule name:Detect_Malicious_VBScript_Base64
Author:daniyyell
Description:Detects malicious VBScript patterns, including Base64 decoding, file operations, and PowerShell.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments