MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e0eeb9b87c7ca8b812e9e9a3b6711e0200c80883780b59a3c258c8a3c0d73a29. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 6 File information Comments

SHA256 hash: e0eeb9b87c7ca8b812e9e9a3b6711e0200c80883780b59a3c258c8a3c0d73a29
SHA3-384 hash: 3b21ccf7588df2a33c6e4b6d46241441a042a272a898102ef22de290f8bd1c6071fc0599036270c203ee52c81a6425e2
SHA1 hash: 294bfc9b97092904bb5e216531b184e38fb2c11f
MD5 hash: cfca235a138eed9c173678377cf9ff05
humanhash: carbon-jig-skylark-william
File name:Destruction
Download: download sample
File size:7'958'136 bytes
First seen:2023-07-06 14:10:29 UTC
Last seen:2023-07-06 14:35:50 UTC
File type:php macho
MIME type:application/x-mach-binary
ssdeep 98304:YuxHp0hCwQFyYeyCrmu6kciN6OASP6sSP+:tSTmumdi
TLSH T1D9867C27B9A01925D297C0304AEF57A26B31F9354235EEEB2375E7392F22C06DB5D306
Reporter iamdeadlyz
Tags:machO macOS RealstStealer


Avatar
Iamdeadlyz
Fake Blockchain Games Deliver RedLine Stealer & Realst Stealer - A New macOS Infostealer Malware
https://iamdeadlyz.gitbook.io/malware-research/july-2023/fake-blockchain-games-deliver-redline-stealer-and-realst-stealer-a-new-macos-infostealer-malware

Intelligence


File Origin
# of uploads :
2
# of downloads :
129
Origin country :
SG SG
Vendor Threat Intelligence
Threat name:
MacOS.Trojan.Generic
Status:
Suspicious
First seen:
2023-07-06 14:11:06 UTC
File Type:
MachO64 Little (Exe)
AV detection:
4 of 38 (10.53%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:aix
Author:Tim Brown @timb_machine
Description:AIX binary
Rule name:BitcoinAddress
Author:Didier Stevens (@DidierStevens)
Description:Contains a valid Bitcoin address
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
Rule name:enterpriseunix2
Author:Tim Brown @timb_machine
Description:Enterprise UNIX
Rule name:Rustyloader_mem_loose
Author:James_inthe_box
Description:Corroded buerloader
Reference:https://app.any.run/tasks/83064edd-c7eb-4558-85e8-621db72b2a24
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

php macho e0eeb9b87c7ca8b812e9e9a3b6711e0200c80883780b59a3c258c8a3c0d73a29

(this sample)

Comments