Malicious
Classifications
Spyware
Threat Names
AMOS AtomicStealer Mal/Generic-S
Dynamic Analysis Report
Created on 2025-03-28T06:25:42+00:00
localfile~
macOS Executable
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
File Reputation Information
»
Verdict |
Malicious
|
Names | Mal/Generic-S |
Mach-O Information
»
Arch Type | x86_64 |
Arch Subtype | x86_64_all |
Type | Executable |
Flags | noundefs, dyldlink, twolevel, binds_to_weak, pie |
UUID | 3d472805-22a1-3d6d-bd5b-eca78d67b840 |
Entry Point | 0x100527680 |
Segments (5)
»
Segment: __PAGEZERO
»
Virtual Address | 0x00000000 |
Virtual Size | 0x100000000 |
Raw Data Offset | 0x00000000 |
Raw Data Size | 0x00000000 |
Initial Protection | - |
Maximum Protection | - |
Flags | - |
Entropy | 0.0 |
Segment: __TEXT
»
Virtual Address | 0x100000000 |
Virtual Size | 0x0052C000 |
Raw Data Offset | 0x00000000 |
Raw Data Size | 0x0052C000 |
Initial Protection | read, execute |
Maximum Protection | read, execute |
Flags | - |
Entropy | 5.34 |
Sections (7)
»
Name | Type | Virtual Address | Raw Data Offset | Size | Attributes |
---|---|---|---|---|---|
__text | regular | 0x100000680 | 0x00000680 | 0x0052B24A | pure_instructions, some_instructions |
__stubs | symbol_stubs | 0x10052B8CA | 0x0052B8CA | 0x000000D8 | pure_instructions, some_instructions |
__stub_helper | regular | 0x10052B9A2 | 0x0052B9A2 | 0x00000150 | pure_instructions, some_instructions |
__gcc_except_tab | regular | 0x10052BAF4 | 0x0052BAF4 | 0x00000278 | - |
__cstring | cstring_literals | 0x10052BD6C | 0x0052BD6C | 0x00000022 | - |
__const | regular | 0x10052BD90 | 0x0052BD90 | 0x00000020 | - |
__unwind_info | regular | 0x10052BDB0 | 0x0052BDB0 | 0x00000248 | - |
Segment: __DATA_CONST
»
Virtual Address | 0x10052C000 |
Virtual Size | 0x00001000 |
Raw Data Offset | 0x0052C000 |
Raw Data Size | 0x00001000 |
Initial Protection | read, write |
Maximum Protection | read, write |
Flags | - |
Entropy | 0.0 |
Sections (1)
»
Name | Type | Virtual Address | Raw Data Offset | Size | Attributes |
---|---|---|---|---|---|
__got | non_lazy_symbol_pointers | 0x10052C000 | 0x0052C000 | 0x00000068 | - |
Segment: __DATA
»
Virtual Address | 0x10052D000 |
Virtual Size | 0x00001000 |
Raw Data Offset | 0x0052D000 |
Raw Data Size | 0x00001000 |
Initial Protection | read, write |
Maximum Protection | read, write |
Flags | - |
Entropy | 0.31 |
Sections (2)
»
Name | Type | Virtual Address | Raw Data Offset | Size | Attributes |
---|---|---|---|---|---|
__la_symbol_ptr | lazy_symbol_pointers | 0x10052D000 | 0x0052D000 | 0x00000100 | - |
__data | regular | 0x10052D100 | 0x0052D100 | 0x00000008 | - |
Segment: __LINKEDIT
»
Virtual Address | 0x10052E000 |
Virtual Size | 0x00020000 |
Raw Data Offset | 0x0052E000 |
Raw Data Size | 0x0001DAC0 |
Initial Protection | read |
Maximum Protection | read |
Flags | - |
Entropy | 4.49 |
Imported Libraries (2)
»
Name | Version | Compatibility Version |
---|---|---|
/usr/lib/libc++.1.dylib | 1800.105.0 | 1.0.0 |
/usr/lib/libSystem.B.dylib | 1351.0.0 | 1.0.0 |
Load Commands: (11)
»
DYLD_INFO_ONLY
»
bind_off | 5431304 |
bind_size | 304 |
export_off | 5432816 |
export_size | 32 |
lazy_bind_off | 5431712 |
lazy_bind_size | 1104 |
rebase_off | 5431296 |
rebase_size | 8 |
weak_bind_off | 5431608 |
weak_bind_size | 104 |
SYMTAB
»
nsyms | 47 |
stroff | 5489960 |
strsize | 1200 |
symoff | 5488880 |
DYSYMTAB
»
extrefsymoff | 0 |
extreloff | 0 |
iextdefsym | 1 |
ilocalsym | 0 |
indirectsymoff | 5489632 |
iundefsym | 2 |
locreloff | 0 |
modtaboff | 0 |
nextdefsym | 1 |
nextrefsyms | 0 |
nextrel | 0 |
nindirectsyms | 81 |
nlocalsym | 1 |
nlocrel | 0 |
nmodtab | 0 |
ntoc | 0 |
nundefsym | 45 |
tocoff | 0 |
LOAD_DYLINKER
»
name | /usr/lib/dyld |
UUID
»
uuid | 3d472805-22a1-3d6d-bd5b-eca78d67b840 |
BUILD_VERSION
»
minos | 10.15.0 |
platform | PLATFORM_MACOS |
sdk | 15.2.0 |
tools | [{'tool': 'TOOL_LD', 'version': '1115.7.3'}] |
SOURCE_VERSION
»
version | 0.0.0.0.0 |
MAIN
»
entryoff | 5404288 |
stacksize | 0 |
FUNCTION_STARTS
»
dataoff | 5432848 |
datasize | 56032 |
DATA_IN_CODE
»
dataoff | 5488880 |
datasize | 0 |
CODE_SIGNATURE
»
dataoff | 5491168 |
datasize | 61664 |
Memory Dumps (1)
»
Name | Process ID | Start VA | End VA | Dump Reason | Mach-O Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
localfile~ | 1 | 0x10BFF0000 | 0x10C53BFFF | Relevant Image |
![]() |
64-bit | 0x10BFF1110 |
![]() |
...
|
/users/user/library/saved application state/com.apple.osascript.savedstate/windows.plist | Dropped File | Stream |
Clean
|
...
|
»
/users/user/library/saved application state/com.apple.osascript.savedstate/data.data | Dropped File | Stream |
Clean
|
...
|
»