MALICIOUS — 558249bfc71fcb2654b100ff5a2df595827c2a91e2d020131fd05693acac9f27
MALICIOUS — 558249bfc71fcb2654b100ff5a2df595827c2a91e2d020131fd05693acac9f27 is a macho sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Flashback family. 4 of 56 detection engines flagged it.
Identification
- SHA-256:
558249bfc71fcb2654b100ff5a2df595827c2a91e2d020131fd05693acac9f27 - SHA-1:
e14aa1b5ca6f378b390e6e59f6064aff80b844c5 - MD5:
12a451429e952484e527e6ce347befb0 - ssdeep:
768:J8YcCAT7Gwzjf1HxE2SRnPzrwLEYqLhYTGj:GCAT7Gw3tH+1rww6TGj - TLSH:
T1012D5CD420779860D6FDF5C934706EED6907B992B2BB022C962FA00E12B95FB9572007 - Submitted as: 558249bfc71fcb2654b100ff5a2df595827c2a91e2d020131fd05693acac9f27
- File type: macho · Size: 27245 bytes
- Verdict: malicious (98/100) · Family: Flashback
Detections (4 of 56 engines)
- ClamAV (daily): Win.Trojan.Flashback-16
- Microsoft Defender: Backdoor:MacOS_X/Flashback.H
- Emsisoft (Emergency Kit): Trojan.MAC.FlashFake.B
- Kaspersky (KVRT): Trojan-Downloader.OSX.Flashfake.ab
Why this verdict
The malicious score of 98/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Flashback-16 (rule
Win.Trojan.Flashback-16) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Backdoor:MacOS_X/Flashback.H (rule
Backdoor:MacOS_X/Flashback.H) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.MAC.FlashFake.B (rule
Trojan.MAC.FlashFake.B) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan-Downloader.OSX.Flashfake.ab (rule
Trojan-Downloader.OSX.Flashfake.ab) - engine signal, weight 0.55, confidence 0.85
Dynamic analysis
This sample targets macOS, for which we operate no sandbox guest, so it was not detonated. The absence of runtime behaviour here is a coverage gap on our side, not a finding about the sample.
More Flashback samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report