🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e45995e5e4368d79bc1ecbbc0e6236c24bb92ee470d4ad35f73882d63be40b15. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MacSync


Vendor detections: 6


Intelligence 6 IOCs YARA 12 File information Comments

SHA256 hash: e45995e5e4368d79bc1ecbbc0e6236c24bb92ee470d4ad35f73882d63be40b15
SHA3-384 hash: cdc9ee1f7416f7e0daaf322eced34d509e731c81239b0501bb4e45673de22ce1676196683304dabe2afb25ddd38a6c24
SHA1 hash: c34481a48b7f9e65c4351ddaa74d78f1b2374574
MD5 hash: a342a91ee2eb92cb6b2bda3ebcf8f7b3
humanhash: venus-fourteen-alpha-harry
File name:ledger_e45995e5e436.bin
Download: download sample
Signature MacSync
File size:2'029'838 bytes
First seen:2026-09-13 11:09:00 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 49152:BsMjAwz/5RHm941uLsC0D7mXNx0+tcaqHPXdK51m85+:GMjHjzmuALi2U+tcLHPC1f0
TLSH T1349533E857E2D25BB51120C1E4F1DFF8AAD6138638F46ED3252E12819953D32EE878CD
Magika zip
Reporter c4ffeine
Tags:Ledger macOS MacSync seed-phrase-stealer trojanized zip


Avatar
c4ffeine
MacSync Stealer: trojanized Ledger Wallet 2.133.0 (zip: app.asar + Info.plist) swapped in by the stealer. Seed phrase POSTed to https://x.eltofeq.com/modules/wallets.

Intelligence


File Origin
# of uploads :
1
# of downloads :
109
Origin country :
US US
File Archive Information

This file archive contains 2 file(s), sorted by their relevance:

File name:app.asar
File size:5'064'440 bytes
SHA256 hash: 6fa7543b68fe5b931a8fa7f4b1be3990b6e9ceaa90ec6c14d9f15cdaab98023e
MD5 hash: b137df2d7938e9a9afa10f24bc32b9bc
MIME type:application/octet-stream
Signature MacSync
File name:Info.plist
File size:4'341 bytes
SHA256 hash: e2e93efa7239dcbac1ef2db4a163adc1126d36bd9f9a0b438456053cb4a347ec
MD5 hash: 289e2336e474afacfae0441f511595ca
MIME type:text/xml
Signature MacSync
Vendor Threat Intelligence
Gathering data
Verdict:
Malicious
File Type:
zip
First seen:
2026-09-13T09:36:00Z UTC
Last seen:
2026-09-13T09:50:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
2 match(es)
Tags:
SVG Zip Archive
Threat name:
MacOS.Trojan.Generic
Status:
Suspicious
First seen:
2026-09-13 11:47:30 UTC
File Type:
Binary (Archive)
Extracted files:
81
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Bolonyokte
Author:Jean-Philippe Teissier / @Jipe_
Description:UnknownDotNet RAT - Bolonyokte
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:Detect_PowerShell_Obfuscation
Author:daniyyell
Description:Detects obfuscated PowerShell commands commonly used in malicious scripts.
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:html_auto_download_b64
Author:Tdawg
Description:html auto download
Rule name:mht_inside_word
Author:dPhish
Description:Detect embedded mht files inside microsfot word.
Rule name:NET
Author:malware-lu
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:Suspicious_Process
Author:Security Research Team
Description:Suspicious process creation
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:telebot_framework
Author:vietdx.mb

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

MacSync

zip e45995e5e4368d79bc1ecbbc0e6236c24bb92ee470d4ad35f73882d63be40b15

(this sample)

  
Delivery method
Distributed via web download

Comments