MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9d8b9090972ec013f3ad0236f5210bd70fe4ba87402fdefeac399cf11dba2efe. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 2 File information Comments

SHA256 hash: 9d8b9090972ec013f3ad0236f5210bd70fe4ba87402fdefeac399cf11dba2efe
SHA3-384 hash: 8d51113523d31483f1e3d20cc82ca86ef1a5d970fcd3ffa50cb8c782cd10e94d78eed48c72cb5eefc01665f734da789e
SHA1 hash: 96d4a3f100c3f620a4f6093d981d871269e49938
MD5 hash: 92a2eb113fb08b48275b67df7940b49b
humanhash: london-illinois-network-mobile
File name:Google Chrome Docs
Download: download sample
File size:6'313'728 bytes
First seen:2026-01-12 08:25:44 UTC
Last seen:Never
File type:php macho
MIME type:application/x-mach-binary
ssdeep 98304:fokgP52/Zp+6kiTWOgeurUQtd6MApD27RQGhq316YNBr:fCwbkiToDD6W1atr
TLSH T11356E1611E9E6B08F1F761B397404AA6D42FF3781444A8ED70A0DECBB5CFB9661093B1
Magika macho
Reporter smica83
Tags:machO

Intelligence


File Origin
# of uploads :
1
# of downloads :
92
Origin country :
HU HU
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
81.4%
Tags:
nukesped nukespe virus
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
base64 nukesped
Verdict:
Malicious
File Type:
macho x64 le
First seen:
2026-01-13T14:28:00Z UTC
Last seen:
2026-01-14T00:38:00Z UTC
Hits:
~10
Threat name:
MacOS.Trojan.NukeSpeed
Status:
Malicious
First seen:
2026-01-07 13:18:45 UTC
File Type:
MachO64 Little (Exe)
AV detection:
9 of 23 (39.13%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:ldpreload
Author:xorseed
Reference:https://stuff.rop.io/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments