MALICIOUS — c3a9a848a694ed52090673170ce33477e38adb02c1085cd90193e47e57f5014a
MALICIOUS — c3a9a848a694ed52090673170ce33477e38adb02c1085cd90193e47e57f5014a is a macho sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 5 of 56 detection engines flagged it.
Identification
- SHA-256:
c3a9a848a694ed52090673170ce33477e38adb02c1085cd90193e47e57f5014a - SHA-1:
b931c09b7effb97ea8b910bbaa8b6b70aba02d38 - MD5:
60975d05bdaca135f750ba625292d110 - ssdeep:
98304:NOZtKd+WwPUg9AHLatzdinWW3fWTS8hY8:NGKd+WS9AraiWCsy8 - TLSH:
T1546033B11017882FC8B25D49700D9FAC65F7A0585836F7286B02E10F9AB65E7337727A - Submitted as: c3a9a848a694ed52090673170ce33477e38adb02c1085cd90193e47e57f5014a
- File type: macho · Size: 3749660 bytes
- Verdict: malicious (99/100)
Detections (5 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Osx.Trojan.Generic-9908330-0
- Microsoft Defender: Adware:MacOS/AdLoad.B!MTB
- Emsisoft (Emergency Kit): Gen:Variant.Adware.MAC.Adload.14
- Kaspersky (KVRT): not-a-virus:HEUR:AdWare.OSX.Cimpli.k
Why this verdict
The malicious score of 99/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Osx.Trojan.Generic-9908330-0 (rule
Osx.Trojan.Generic-9908330-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Adware:MacOS/AdLoad.B!MTB (rule
Adware:MacOS/AdLoad.B!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Adware.MAC.Adload.14 (rule
Gen:Variant.Adware.MAC.Adload.14) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged not-a-virus:HEUR:AdWare.OSX.Cimpli.k (rule
not-a-virus:HEUR:AdWare.OSX.Cimpli.k) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
This sample targets macOS, for which we operate no sandbox guest, so it was not detonated. The absence of runtime behaviour here is a coverage gap on our side, not a finding about the sample.
Embedded domains
- d.tw
- 7.su
- ac.fi
- e.me
- g.fr
- 9.ai
File paths
- r:\^G]
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report