CLEAN — LicenseInstaller
CLEAN — LicenseInstaller is a macho sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (21/100). 0 of 55 detection engines flagged it.
Identification
- SHA-256:
5e525417f75afe3c9f848a04fbe053d5ed802c1f1b3af76f8b27f8746fe33e65 - SHA-1:
d6d5f219b1b4b9af104f64a692fd8e978678a9b6 - MD5:
6c0a1b971a133aadbb2a8020bb937fe8 - ssdeep:
49152:tTKne6jNp0/CY8EkWKPAIwxNt/kuVjsgYoRYxK:tkeyp0IEkWKPAIw9VjV+xK - TLSH:
T19F5A9EF49E023402ECF8F4BDAC14BC6C8B69B9B196BB274F649DC175808813779C9568 - Submitted as: LicenseInstaller
- File type: macho · Size: 1985232 bytes
- Verdict: clean (21/100)
Detections (0 of 55 engines)
No engine flagged this sample.
Why this verdict
The clean score of 21/100 is the fusion of 1 weighted signal:
- Embedded network infrastructure: http://www.apple.com/DTDs/PropertyList-1.0.dtd - static signal, weight 0.35, confidence 0.60
Dynamic analysis
This sample targets macOS, for which we operate no sandbox guest, so it was not detonated. The absence of runtime behaviour here is a coverage gap on our side, not a finding about the sample.
Embedded URLs
- http://www.apple.com/DTDs/PropertyList-1.0.dtd
Embedded domains
- www.apple.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report