Malicious
Classifications
Spyware
Threat Names
AtomicStealer Mal/HTMLGen-A
Dynamic Analysis Report
Created on 2025-02-02T16:42:28+00:00
MacSoftware_v3.46_1738507697837.dmg
Shell Script
Remarks (1/1)
(0x02000050): This analysis has been updated with the latest reputation and static analysis results from the original analysis with the ID #24278253.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
/Volumes/MacSoftware/MacSoftware | Sample File | Shell Script |
Malicious
|
...
|
»
/tmp/Launcher | Dropped File | Binary |
Malicious
|
...
|
»
Memory Dumps (1)
»
Name | Process ID | Start VA | End VA | Dump Reason | Mach-O Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
launcher | 28 | 0x10B24E000 | 0x10B267FFF | Relevant Image |
![]() |
64-bit | 0x10B252FE8 |
![]() |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
AtomicStealer_Script_Launcher | macOS Atomic Stealer script launcher | Spyware |
5/5
|
...
|
/tmp/Launcher.zip | Dropped File | ZIP |
Malicious
Raised based on a child artifact.
|
...
|
»
Archive Information
»
Number of Files | 2 |
Number of Folders | 1 |
Size of Packed Archive Contents | 179.81 KB |
Size of Unpacked Archive Contents | 426.01 KB |
File Format | zip |
Contents (2)
»
File Name | Packed Size | Unpacked Size | Compression | Is Encrypted | Modify Time | Verdict | Recursively Submitted | Actions |
---|---|---|---|---|---|---|---|---|
__MACOSX/._Launcher | 129.38 KB | 163.20 KB | Deflate | False | 2025-02-02 12:02 (UTC+1) |
Clean
|
- |
...
|
Launcher | 50.42 KB | 262.81 KB | Deflate | False | 2025-02-02 12:02 (UTC+1) |
Malicious
|
- |
...
|
d52300b73611b55c10b05c97834f34715673551158388bde3ec69269d12893b3 | Extracted File | Binary |
Malicious
|
...
|
»
Mach-O Information
»
Arch Type | x86_64 |
Arch Subtype | x86_64_all |
Type | Executable |
Flags | noundefs, dyldlink, twolevel, binds_to_weak, pie |
UUID | ba4b37eb-4420-3a3a-8a6e-5961c1264067 |
Entry Point | 0x100000D67 |
Segments (5)
»
Segment: __PAGEZERO
»
Virtual Address | 0x00000000 |
Virtual Size | 0x100000000 |
Raw Data Offset | 0x00000000 |
Raw Data Size | 0x00000000 |
Initial Protection | - |
Maximum Protection | - |
Flags | - |
Entropy | 0.0 |
Segment: __TEXT
»
Virtual Address | 0x100000000 |
Virtual Size | 0x00012000 |
Raw Data Offset | 0x00000000 |
Raw Data Size | 0x00012000 |
Initial Protection | read, execute |
Maximum Protection | read, execute |
Flags | - |
Entropy | 5.04 |
Sections (6)
»
Name | Type | Virtual Address | Raw Data Offset | Size | Attributes |
---|---|---|---|---|---|
__text | regular | 0x1000009A8 | 0x000009A8 | 0x00004852 | pure_instructions, some_instructions |
__stubs | symbol_stubs | 0x1000051FA | 0x000051FA | 0x000000C0 | pure_instructions, some_instructions |
__stub_helper | regular | 0x1000052BA | 0x000052BA | 0x0000013C | pure_instructions, some_instructions |
__gcc_except_tab | regular | 0x1000053F8 | 0x000053F8 | 0x000003D4 | - |
__cstring | cstring_literals | 0x1000057CC | 0x000057CC | 0x0000C744 | - |
__unwind_info | regular | 0x100011F10 | 0x00011F10 | 0x000000F0 | - |
Segment: __DATA_CONST
»
Virtual Address | 0x100012000 |
Virtual Size | 0x00001000 |
Raw Data Offset | 0x00012000 |
Raw Data Size | 0x00001000 |
Initial Protection | read, write |
Maximum Protection | read, write |
Flags | - |
Entropy | 0.0 |
Sections (1)
»
Name | Type | Virtual Address | Raw Data Offset | Size | Attributes |
---|---|---|---|---|---|
__got | non_lazy_symbol_pointers | 0x100012000 | 0x00012000 | 0x00000058 | - |
Segment: __DATA
»
Virtual Address | 0x100013000 |
Virtual Size | 0x00001000 |
Raw Data Offset | 0x00013000 |
Raw Data Size | 0x00001000 |
Initial Protection | read, write |
Maximum Protection | read, write |
Flags | - |
Entropy | 0.23 |
Sections (2)
»
Name | Type | Virtual Address | Raw Data Offset | Size | Attributes |
---|---|---|---|---|---|
__la_symbol_ptr | lazy_symbol_pointers | 0x100013000 | 0x00013000 | 0x000000F0 | - |
__data | regular | 0x1000130F0 | 0x000130F0 | 0x00000008 | - |
Segment: __LINKEDIT
»
Virtual Address | 0x100014000 |
Virtual Size | 0x00008000 |
Raw Data Offset | 0x00014000 |
Raw Data Size | 0x00005A50 |
Initial Protection | read |
Maximum Protection | read |
Flags | - |
Entropy | 1.76 |
Imported Libraries (2)
»
Name | Version | Compatibility Version |
---|---|---|
/usr/lib/libc++.1.dylib | 1800.105.0 | 1.0.0 |
/usr/lib/libSystem.B.dylib | 1351.0.0 | 1.0.0 |
Load Commands: (11)
»
DYLD_INFO_ONLY
»
bind_off | 81928 |
bind_size | 256 |
export_off | 83368 |
export_size | 32 |
lazy_bind_off | 82240 |
lazy_bind_size | 1128 |
rebase_off | 81920 |
rebase_size | 8 |
weak_bind_off | 82184 |
weak_bind_size | 56 |
SYMTAB
»
nsyms | 43 |
stroff | 84416 |
strsize | 1192 |
symoff | 83432 |
DYSYMTAB
»
extrefsymoff | 0 |
extreloff | 0 |
iextdefsym | 1 |
ilocalsym | 0 |
indirectsymoff | 84120 |
iundefsym | 2 |
locreloff | 0 |
modtaboff | 0 |
nextdefsym | 1 |
nextrefsyms | 0 |
nextrel | 0 |
nindirectsyms | 73 |
nlocalsym | 1 |
nlocrel | 0 |
nmodtab | 0 |
ntoc | 0 |
nundefsym | 41 |
tocoff | 0 |
LOAD_DYLINKER
»
name | /usr/lib/dyld |
UUID
»
uuid | ba4b37eb-4420-3a3a-8a6e-5961c1264067 |
BUILD_VERSION
»
minos | 10.15.0 |
platform | PLATFORM_MACOS |
sdk | 15.2.0 |
tools | [{'tool': 'TOOL_LD', 'version': '1115.7.3'}] |
SOURCE_VERSION
»
version | 0.0.0.0.0 |
MAIN
»
entryoff | 3431 |
stacksize | 0 |
FUNCTION_STARTS
»
dataoff | 83400 |
datasize | 32 |
DATA_IN_CODE
»
dataoff | 83432 |
datasize | 0 |
CODE_SIGNATURE
»
dataoff | 85616 |
datasize | 19424 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
AtomicStealer_Script_Launcher | macOS Atomic Stealer script launcher | Spyware |
5/5
|
...
|
/tmp/__MACOSX/._Launcher | Dropped File | Stream |
Clean
|
...
|
»
/users/user/library/saved application state/com.apple.osascript.savedstate/windows.plist | Dropped File | Stream |
Clean
|
...
|
»
/users/user/library/saved application state/com.apple.osascript.savedstate/data.data | Dropped File | Stream |
Clean
|
...
|
»
844039272231e9527c3c4d3dbb664651fb3ffd01c426ea9631db5ae9c381429b | Extracted File | Binary |
Clean
|
...
|
»
Mach-O Information
»
Arch Type | ARM64 |
Arch Subtype | ARM64_all |
Type | Executable |
Flags | noundefs, dyldlink, twolevel, binds_to_weak, pie |
UUID | 48886806-4b72-3d0d-b7d6-d2092f4d3e99 |
Entry Point | 0x100003D84 |
Segments (5)
»
Segment: __PAGEZERO
»
Virtual Address | 0x00000000 |
Virtual Size | 0x100000000 |
Raw Data Offset | 0x00000000 |
Raw Data Size | 0x00000000 |
Initial Protection | - |
Maximum Protection | - |
Flags | - |
Entropy | 0.0 |
Segment: __TEXT
»
Virtual Address | 0x100000000 |
Virtual Size | 0x00014000 |
Raw Data Offset | 0x00000000 |
Raw Data Size | 0x00014000 |
Initial Protection | read, execute |
Maximum Protection | read, execute |
Flags | - |
Entropy | 4.64 |
Sections (7)
»
Name | Type | Virtual Address | Raw Data Offset | Size | Attributes |
---|---|---|---|---|---|
__text | regular | 0x10000398C | 0x0000398C | 0x00003670 | pure_instructions, some_instructions |
__stubs | symbol_stubs | 0x100006FFC | 0x00006FFC | 0x00000180 | pure_instructions, some_instructions |
__stub_helper | regular | 0x10000717C | 0x0000717C | 0x00000180 | pure_instructions, some_instructions |
__gcc_except_tab | regular | 0x1000072FC | 0x000072FC | 0x000003CC | - |
__const | regular | 0x1000076C8 | 0x000076C8 | 0x00000104 | - |
__cstring | cstring_literals | 0x1000077CC | 0x000077CC | 0x0000C744 | - |
__unwind_info | regular | 0x100013F10 | 0x00013F10 | 0x000000F0 | - |
Segment: __DATA_CONST
»
Virtual Address | 0x100014000 |
Virtual Size | 0x00004000 |
Raw Data Offset | 0x00014000 |
Raw Data Size | 0x00004000 |
Initial Protection | read, write |
Maximum Protection | read, write |
Flags | - |
Entropy | 0.0 |
Sections (1)
»
Name | Type | Virtual Address | Raw Data Offset | Size | Attributes |
---|---|---|---|---|---|
__got | non_lazy_symbol_pointers | 0x100014000 | 0x00014000 | 0x00000058 | - |
Segment: __DATA
»
Virtual Address | 0x100018000 |
Virtual Size | 0x00004000 |
Raw Data Offset | 0x00018000 |
Raw Data Size | 0x00004000 |
Initial Protection | read, write |
Maximum Protection | read, write |
Flags | - |
Entropy | 0.07 |
Sections (2)
»
Name | Type | Virtual Address | Raw Data Offset | Size | Attributes |
---|---|---|---|---|---|
__la_symbol_ptr | lazy_symbol_pointers | 0x100018000 | 0x00018000 | 0x000000F0 | - |
__data | regular | 0x1000180F0 | 0x000180F0 | 0x00000008 | - |
Segment: __LINKEDIT
»
Virtual Address | 0x10001C000 |
Virtual Size | 0x00008000 |
Raw Data Offset | 0x0001C000 |
Raw Data Size | 0x00005B40 |
Initial Protection | read |
Maximum Protection | read |
Flags | - |
Entropy | 1.87 |
Imported Libraries (2)
»
Name | Version | Compatibility Version |
---|---|---|
/usr/lib/libc++.1.dylib | 1800.105.0 | 1.0.0 |
/usr/lib/libSystem.B.dylib | 1351.0.0 | 1.0.0 |
Load Commands: (11)
»
DYLD_INFO_ONLY
»
bind_off | 114696 |
bind_size | 256 |
export_off | 116128 |
export_size | 32 |
lazy_bind_off | 115008 |
lazy_bind_size | 1120 |
rebase_off | 114688 |
rebase_size | 8 |
weak_bind_off | 114952 |
weak_bind_size | 56 |
SYMTAB
»
nsyms | 43 |
stroff | 117176 |
strsize | 1192 |
symoff | 116192 |
DYSYMTAB
»
extrefsymoff | 0 |
extreloff | 0 |
iextdefsym | 1 |
ilocalsym | 0 |
indirectsymoff | 116880 |
iundefsym | 2 |
locreloff | 0 |
modtaboff | 0 |
nextdefsym | 1 |
nextrefsyms | 0 |
nextrel | 0 |
nindirectsyms | 73 |
nlocalsym | 1 |
nlocrel | 0 |
nmodtab | 0 |
ntoc | 0 |
nundefsym | 41 |
tocoff | 0 |
LOAD_DYLINKER
»
name | /usr/lib/dyld |
UUID
»
uuid | 48886806-4b72-3d0d-b7d6-d2092f4d3e99 |
BUILD_VERSION
»
minos | 11.0.0 |
platform | PLATFORM_MACOS |
sdk | 15.2.0 |
tools | [{'tool': 'TOOL_LD', 'version': '1115.7.3'}] |
SOURCE_VERSION
»
version | 0.0.0.0.0 |
MAIN
»
entryoff | 15748 |
stacksize | 0 |
FUNCTION_STARTS
»
dataoff | 116160 |
datasize | 32 |
DATA_IN_CODE
»
dataoff | 116192 |
datasize | 0 |
CODE_SIGNATURE
»
dataoff | 118368 |
datasize | 19680 |
/Volumes/MacSoftware/.background/fnjeruCgdWB.png | Extracted File | Image |
Clean
|
...
|
»
/Volumes/MacSoftware/.VolumeIcon.icns | Extracted File | Image |
Clean
|
...
|
»