Analysis

  • max time kernel
    142s
  • max time network
    146s
  • platform
    macos-10.15_amd64
  • resource
    macos-20240410-en
  • resource tags

    arch:amd64arch:i386image:macos-20240410-enkernel:19b77alocale:en-usos:macos-10.15-amd64system
  • submitted
    07-06-2024 19:13

General

  • Target

    NitroGen.exe

  • Size

    42KB

  • MD5

    f750a0d3e70a6decff53c6b7b68e8f45

  • SHA1

    67214581b14115a90a4cd769312006de2960014d

  • SHA256

    3597543888589ceef37913c4e4bb6b614e1007c3bc9bb08dadef7f1832e87e2e

  • SHA512

    42b6a6ad81045cf80821770b0310fb4b448d4ee13be126f9b9fbc993d0ecf26afad47161319f778f17ef8986d469a5d35dc1bd51532fe969d192024c567fad4d

  • SSDEEP

    768:ZpIqetQIxm8NuZMML1KTjFKZKfgm3Eh/u:LSQIvyL1KTpF7Edu

Score
1/10

Malware Config

Signatures

Processes

  • /bin/sh
    sh -c "sudo /bin/zsh -c \"/Users/run/NitroGen.exe\""
    1⤵
      PID:484
    • /bin/bash
      sh -c "sudo /bin/zsh -c \"/Users/run/NitroGen.exe\""
      1⤵
        PID:484
      • /usr/bin/sudo
        sudo /bin/zsh -c /Users/run/NitroGen.exe
        1⤵
          PID:484
          • /bin/zsh
            /bin/zsh -c /Users/run/NitroGen.exe
            2⤵
              PID:486
            • /Users/run/NitroGen.exe
              /Users/run/NitroGen.exe
              2⤵
                PID:486
            • /usr/bin/pluginkit
              /usr/bin/pluginkit -e ignore -i com.microsoft.OneDrive.FinderSync
              1⤵
                PID:489
              • /usr/sbin/spctl
                /usr/sbin/spctl --assess --type execute /var/folders/pq/yy2b5ptn4cz739jgclj4m1wm0000gp/T/OneDriveUpdater0BF23177/OneDrive.app
                1⤵
                  PID:490
                • /usr/libexec/xpcproxy
                  xpcproxy com.apple.corespotlightservice.725FD30A-6064-6C02-CC51-5DDB8891B57E
                  1⤵
                    PID:529
                  • /System/Library/Frameworks/CoreSpotlight.framework/CoreSpotlightService
                    /System/Library/Frameworks/CoreSpotlight.framework/CoreSpotlightService
                    1⤵
                      PID:529
                    • /usr/libexec/xpcproxy
                      xpcproxy com.apple.Terminal.2100
                      1⤵
                        PID:539
                      • /System/Applications/Utilities/Terminal.app/Contents/MacOS/Terminal
                        /System/Applications/Utilities/Terminal.app/Contents/MacOS/Terminal
                        1⤵
                          PID:539
                          • /usr/bin/login
                            login -pf run
                            2⤵
                              PID:540
                              • /bin/zsh
                                -zsh
                                3⤵
                                  PID:541
                                  • /usr/libexec/path_helper
                                    /usr/libexec/path_helper -s
                                    4⤵
                                      PID:542
                                    • /usr/bin/locale
                                      locale LC_CTYPE
                                      4⤵
                                        PID:543
                                      • /usr/bin/curl
                                        curl ipapi.org
                                        4⤵
                                          PID:544
                                        • /usr/bin/curl
                                          curl ipapi.org/json
                                          4⤵
                                            PID:545

                                    Network

                                    MITRE ATT&CK Matrix

                                    Replay Monitor

                                    Loading Replay Monitor...

                                    Downloads

                                    • /dev/ttys000
                                      MD5

                                      d41d8cd98f00b204e9800998ecf8427e

                                      SHA1

                                      da39a3ee5e6b4b0d3255bfef95601890afd80709

                                      SHA256

                                      e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855

                                      SHA512

                                      cf83e1357eefb8bdf1542850d66d8007d620e4050b5715dc83f4a921d36ce9ce47d0d13c5d85f2b0ff8318d2877eec2f63b931bd47417a81a538327af927da3e