🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 aa3934340337aaceee150fd8e2acaa5b5da71a59161585594e53d0477d9d87c6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 3 File information Comments

SHA256 hash: aa3934340337aaceee150fd8e2acaa5b5da71a59161585594e53d0477d9d87c6
SHA3-384 hash: d209705b5c4d6b264aa85ea398408bafe8bcaaa353da90c5b6579bf30a2bdd4ab98c4368b3aaf1a8041e6fbe16f5b544
SHA1 hash: 056f74c17ca7fab8ee7fb66cd0928126edbe4d0e
MD5 hash: 22777a448492f0b5b2e1bae53b90c5d5
humanhash: seventeen-moon-iowa-comet
File name:plasmagrid-corepayload-arm64e.dylib
Download: download sample
File size:412'584 bytes
First seen:2026-09-05 13:48:32 UTC
Last seen:Never
File type:php macho
MIME type:application/x-mach-binary
ssdeep 6144:eldIQ82eAj5vn7x4VAaX2aUBtCneILmCiip0p1iD2PT26cUm:uP8e5fAwaatCeILkimp1g2L2gm
TLSH T1AE9408D56E1D2C16C4CAB1BF8D505125242F77A163B5C3F82D2A510DCACDABA273FA32
Magika macho
Reporter KabirAcharya
Tags:arm64e backdoor Coruna iOS machO PLASMAGRID


Avatar
KabirAcharya
Confirmed PLASMAGRID CorePayload manager delivered by Coruna. It collects device identity, obtains encrypted configuration, downloads hash-verified modules, injects CorePayload, and uploads reports.

Intelligence


File Origin
# of uploads :
1
# of downloads :
103
Origin country :
AU AU
Vendor Threat Intelligence
No detections
Threat name:
MacOS.Trojan.Generic
Status:
Suspicious
First seen:
2026-09-05 13:49:18 UTC
File Type:
MachO64 Little (SO)
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:ldpreload
Author:xorseed
Reference:https://stuff.rop.io/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Distributed via drive-by

Comments