Overview
overview
4Static
static
1Yaagl HSR..../Yaagl
macos-10.15-amd64
1Yaagl HSR....erized
ubuntu-18.04-amd64
3Yaagl HSR....erized
debian-9-armhf
3Yaagl HSR....erized
debian-9-mips
3Yaagl HSR....erized
debian-9-mipsel
3Yaagl HSR....ces.js
windows10-2004-x64
3Yaagl HSR....ces.js
windows11-21h2-x64
3Yaagl HSR....7z/7zz
macos-10.15-amd64
4Yaagl HSR....aria2c
macos-10.15-amd64
4Yaagl HSR....patchz
macos-10.15-amd64
4Yaagl HSR....delta3
macos-10.15-amd64
4Analysis
-
max time kernel
71s -
max time network
103s -
platform
macos-10.15_amd64 -
resource
macos-20250410-en -
resource tags
arch:amd64arch:i386image:macos-20250410-enkernel:19b77alocale:en-usos:macos-10.15-amd64system -
submitted
08/05/2025, 08:02
Static task
static1
Behavioral task
behavioral1
Sample
Yaagl HSR.app/Contents/MacOS/Yaagl
Resource
macos-20241101-en
Behavioral task
behavioral2
Sample
Yaagl HSR.app/Contents/MacOS/parameterized
Resource
ubuntu1804-amd64-20250410-en
Behavioral task
behavioral3
Sample
Yaagl HSR.app/Contents/MacOS/parameterized
Resource
debian9-armhf-20250410-en
Behavioral task
behavioral4
Sample
Yaagl HSR.app/Contents/MacOS/parameterized
Resource
debian9-mipsbe-20240729-en
Behavioral task
behavioral5
Sample
Yaagl HSR.app/Contents/MacOS/parameterized
Resource
debian9-mipsel-20240729-en
Behavioral task
behavioral6
Sample
Yaagl HSR.app/Contents/Resources/resources.js
Resource
win10v2004-20250502-en
Behavioral task
behavioral7
Sample
Yaagl HSR.app/Contents/Resources/resources.js
Resource
win11-20250502-en
Behavioral task
behavioral8
Sample
Yaagl HSR.app/Contents/Resources/sidecar/7z/7zz
Resource
macos-20250410-en
Behavioral task
behavioral9
Sample
Yaagl HSR.app/Contents/Resources/sidecar/aria2/aria2c
Resource
macos-20250410-en
Behavioral task
behavioral10
Sample
Yaagl HSR.app/Contents/Resources/sidecar/hpatchz/hpatchz
Resource
macos-20241101-en
Behavioral task
behavioral11
Sample
Yaagl HSR.app/Contents/Resources/sidecar/xdelta/xdelta3
Resource
macos-20241101-en
General
-
Target
Yaagl HSR.app/Contents/Resources/sidecar/7z/7zz
-
Size
5.0MB
-
MD5
a9c17a27dea8ae6d13e452c3f8d27aeb
-
SHA1
027d4c0fb3802cb99a056067649b9aa923f21bb3
-
SHA256
10bba361f87be5882e362df8f283646fb5fff1a7f63246149a5809be286897f5
-
SHA512
20b49005e2cdeb0e01a61934e4dbf8d23255597ae3f4c9b0daa0c8dd6a456affed8b3e5e6ff695a8d3011af7f3b42e65af4231a97821f452fd63d29f8a72fffd
-
SSDEEP
98304:gtfGlTtbFK3FEiKI3q+Ez0TKGvGLRWa1gSYL/xz+trKIcVwmlpT23jrb2YJgsG:gtfco2z0TKUUHws
Malware Config
Signatures
-
Resource Forking 1 TTPs 4 IoCs
Adversaries may abuse resource forks to hide malicious code or executables to evade detection and bypass security applications. A resource fork provides applications a structured way to store resources such as thumbnail images, menu definitions, icons, dialog boxes, and code.
ioc Process /bin/zsh -c "/Users/run/Yaagl HSR.app/Contents/Resources/sidecar/7z/7zz" Process not Found /Users/run/Yaagl HSR.app/Contents/Resources/sidecar/7z/7zz Process not Found sh -c "sudo /bin/zsh -c \"/Users/run/Yaagl HSR.app/Contents/Resources/sidecar/7z/7zz\"" Process not Found sudo /bin/zsh -c "/Users/run/Yaagl HSR.app/Contents/Resources/sidecar/7z/7zz" Process not Found
Processes
-
/bin/shsh -c "sudo /bin/zsh -c \"/Users/run/Yaagl HSR.app/Contents/Resources/sidecar/7z/7zz\""1⤵PID:475
-
/bin/bashsh -c "sudo /bin/zsh -c \"/Users/run/Yaagl HSR.app/Contents/Resources/sidecar/7z/7zz\""1⤵PID:475
-
/usr/bin/sudosudo /bin/zsh -c "/Users/run/Yaagl HSR.app/Contents/Resources/sidecar/7z/7zz"1⤵PID:475
-
/bin/zsh/bin/zsh -c "/Users/run/Yaagl HSR.app/Contents/Resources/sidecar/7z/7zz"2⤵PID:476
-
-
/Users/run/Yaagl/Users/run/Yaagl HSR.app/Contents/Resources/sidecar/7z/7zz2⤵PID:476
-