× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: aa4873d29c29917c844ac81b9d363cfdcea25ffbd48420f90788377a616bb8da
File name: Unobtanium-Bluechist.dmg
Detection ratio: 0 / 57
Analysis date: 2017-06-22 13:32:28 UTC ( 1 year, 1 month ago )
Antivirus Result Update
Ad-Aware 20170622
AegisLab 20170622
AhnLab-V3 20170622
Alibaba 20170622
ALYac 20170622
Antiy-AVL 20170622
Arcabit 20170622
Avast 20170622
AVG 20170622
Avira (no cloud) 20170622
AVware 20170622
Baidu 20170622
BitDefender 20170622
Bkav 20170622
CAT-QuickHeal 20170622
ClamAV 20170622
CMC 20170619
Comodo 20170622
CrowdStrike Falcon (ML) 20170420
Cyren 20170622
DrWeb 20170622
Emsisoft 20170622
Endgame 20170615
ESET-NOD32 20170622
F-Prot 20170622
F-Secure 20170622
Fortinet 20170622
GData 20170622
Ikarus 20170622
Sophos ML 20170607
Jiangmin 20170622
K7AntiVirus 20170622
K7GW 20170622
Kaspersky 20170622
Kingsoft 20170622
Malwarebytes 20170622
McAfee 20170622
McAfee-GW-Edition 20170622
Microsoft 20170622
eScan 20170622
NANO-Antivirus 20170622
nProtect 20170622
Palo Alto Networks (Known Signatures) 20170622
Panda 20170621
Qihoo-360 20170622
Rising 20170621
SentinelOne (Static ML) 20170516
Sophos AV 20170622
SUPERAntiSpyware 20170622
Symantec 20170622
Symantec Mobile Insight 20170621
Tencent 20170622
TheHacker 20170621
TotalDefense 20170622
TrendMicro 20170622
TrendMicro-HouseCall 20170622
Trustlook 20170622
VBA32 20170622
VIPRE 20170622
ViRobot 20170622
Webroot 20170622
WhiteArmor 20170616
Yandex 20170621
Zillya 20170619
ZoneAlarm by Check Point 20170622
Zoner 20170622
The file being studied is an Apple Disk Image! More specifically it follows the Universal Disk Image Format, commonly found with the DMG extension.
Main executable
Package path /Unobtanium-Qt.app/Contents/MacOS/Unobtanium-Qt
Detection ratio 0 / 57 when this report was generated
File size 8441556 Bytes
HFS File ID 86
DMG HFS Property List
LSAppNapIsDisabled True
LSArchitecturePriority x86_64
CFBundleSignature ????
UTExportedTypeDeclarations {u'UTTypeIdentifier': u'org.bitcoin.paymentrequest', u'UTTypeDescription': u'Bitcoin payment request', u'UTTypeTagSpecification': {u'public.mime-type': u'application/x-bitcoin-payment-request', u'public.filename-extension': [u'bitcoinpaymentrequest']}, u'UTTypeConformsTo': [u'public.data']}
CFBundleIconFile bitcoin.icns
CFBundleGetInfoString 0.10.1, Copyright © 2009-2015 The Bitcoin Core developers
CFBundleIdentifier org.bitcoinfoundation.Bitcoin-Qt
CFBundleDocumentTypes {u'CFBundleTypeRole': u'Editor', u'LSItemContentTypes': [u'org.bitcoin.paymentrequest'], u'LSHandlerRank': u'Owner'}
CFBundleURLTypes {u'CFBundleURLName': u'org.bitcoin.BitcoinPayment', u'CFBundleTypeRole': u'Editor', u'CFBundleURLSchemes': [u'bitcoin']}
CFBundleVersion 0.10.1
LSMinimumSystemVersion 10.6.0
CFBundleShortVersionString 0.10.1
CFBundlePackageType APPL
NSPrincipalClass NSApplication
LSApplicationCategoryType public.app-category.finance
NSHighResolutionCapable True
CFBundleExecutable Unobtanium-Qt
Contained Mac OS X executables
BLKX Table
Entry Attributes
Protective Master Boot Record (MBR : 0) 0x0050
GPT Header (Primary GPT Header : 1) 0x0050
GPT Partition Data (Primary GPT Table : 2) 0x0050
(Apple_Free : 3) 0x0050
disk image (Apple_HFS : 4) 0x0050
GPT Partition Data (Backup GPT Table : 5) 0x0050
GPT Header (Backup GPT Header : 6) 0x0050
DMG XML Property List
Entry Attributes
ID:0 0x0050
DMG structural properties
DMG version
4
Data fork offset
0x0
Data fork length
16523514
Resource fork offset
0x0
Resource fork length
0
Resource fork keys
blkx, plst
Running data fork offset
0x0
XML offset
0x16523514
XML length
10292
PLST keys
resource-fork
File identification
MD5 1856f9579dbc47d84c92fa641aa14cd6
SHA1 09bd6462cfd9b81c8ee66a5e191b42bfaf6895ae
SHA256 aa4873d29c29917c844ac81b9d363cfdcea25ffbd48420f90788377a616bb8da
ssdeep
393216:K3yNqdgrgAow9hF2OUKZHiPrU86aqU7BM:K3o5w1KJizx6aq+M

File size 15.8 MB ( 16534318 bytes )
File type Macintosh Disk Image
Magic literal
VAX COFF executable - version 24939

TrID Macintosh Disk image (BZlib compressed) (100.0%)
Tags
dmg

VirusTotal metadata
First submission 2015-07-18 04:19:58 UTC ( 3 years, 1 month ago )
Last submission 2017-06-07 15:40:00 UTC ( 1 year, 2 months ago )
File names Unobtanium-Bluechist.dmg
Unobtanium-Blueschist.dmg
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!
Condensed report! The following is a condensed report of the behaviour of the file when executed in a controlled environment. The actions and events described were either performed by the file itself or by any other process launched by the executed file or subjected to code injection by the executed file.
Opened files
Read files
Created processes
DNS requests
TCP connections