× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: b59af72f24103a82c914fd83fab4da1715614db729cb5c3b4efcb480640e2f17
File name: AppYS
Detection ratio: 1 / 56
Analysis date: 2015-06-23 06:09:29 UTC ( 1 year, 11 months ago ) View latest
Antivirus Result Update
ESET-NOD32 a variant of OSX/Adware.Genieo.AA 20150623
Ad-Aware 20150623
AegisLab 20150623
Yandex 20150622
AhnLab-V3 20150622
Alibaba 20150623
ALYac 20150623
Antiy-AVL 20150623
Arcabit 20150623
Avast 20150623
AVG 20150623
Avira (no cloud) 20150623
AVware 20150623
Baidu-International 20150622
BitDefender 20150623
Bkav 20150622
ByteHero 20150623
CAT-QuickHeal 20150622
ClamAV 20150623
Comodo 20150623
Cyren 20150623
DrWeb 20150623
Emsisoft 20150623
F-Prot 20150622
F-Secure 20150623
Fortinet 20150623
GData 20150623
Ikarus 20150623
Jiangmin 20150620
K7AntiVirus 20150623
K7GW 20150623
Kaspersky 20150623
Kingsoft 20150623
Malwarebytes 20150623
McAfee 20150623
McAfee-GW-Edition 20150623
Microsoft 20150623
eScan 20150623
NANO-Antivirus 20150622
nProtect 20150622
Panda 20150622
Qihoo-360 20150623
Rising 20150618
Sophos 20150623
SUPERAntiSpyware 20150623
Symantec 20150623
Tencent 20150623
TheHacker 20150622
TotalDefense 20150622
TrendMicro 20150623
TrendMicro-HouseCall 20150623
VBA32 20150622
VIPRE 20150623
ViRobot 20150623
Zillya 20150622
Zoner 20150622
The file being studied is a Mac OS X executable! More specifically it is a executable file Mach-O for x86_64 based machines.
File signature
Identifier com.yshur.AppYS
Format Mach-O thin (x86_64)
CDHash 7ea053bd8be8e7382b5f56a5452a1078bac34776
Signature size 8518
Authority Developer ID Application: Yaron Shur (433RV4L49M)
Authority Developer ID Certification Authority
Authority Apple Root CA
Timestamp Jun 1, 2015, 9:32:58 AM
Info.plist not bound
TeamIdentifier 433RV4L49M
Sealed Resources none
Signers
[+] Yaron Shur
Status Valid
Issuer Apple Inc.
Valid from 06:13 AM 04/08/2015
Valid to 06:13 AM 04/08/2020
Valid usage Digital Signature, Code Signing
Algorithm sha256WithRSAEncryption
Thumbprint ED2A7F4E4C8CD052DAA61F6067AB2682ABF74AC6
Serial number 1A 6E 95 F6 DC D4 31 46
[+] Apple Inc.
Status Valid
Issuer Apple Inc.
Valid from 10:12 PM 02/01/2012
Valid to 10:12 PM 02/01/2027
Valid usage Digital Signature, Certificate Sign, CRL Sign
Algorithm sha256WithRSAEncryption
Thumbprint 3B166C3B7DC4B751C9FE2AFAB9135641E388E186
Serial number 18 7A A9 A8 C2 96 21 0C
[+] Apple Inc.
Status Valid
Issuer Apple Inc.
Valid from 09:40 PM 04/25/2006
Valid to 09:40 PM 02/09/2035
Valid usage Certificate Sign, CRL Sign
Algorithm sha1WithRSAEncryption
Thumbprint 611E5B662C593A08FF58D14AE22452D198DF6C60
Serial number 2
Interesting properties
This file is signed by Apple's Root Certificate Authority.
File header
File type executable file
Magic 0xfeedfacf
Required architecture x86_64
Sub-architecture X86_64_ALL
Entry point 0x100001a20
Reserved 0x0
Load commands 28
Load commands size 4592
Flags BINDS_TO_WEAK
DYLDLINK
NOUNDEFS
TWOLEVEL
File segments
Shared libraries
Load commands
File identification
MD5 62f59f0e200f965e2f5e2904f058737f
SHA1 123c5f878730787f7a5548171a6b015c5674a383
SHA256 b59af72f24103a82c914fd83fab4da1715614db729cb5c3b4efcb480640e2f17
ssdeep
12288:rDKESx00iUcMhzgYUENAkkMRVXwwlRVXwwtF:rDKnx00iZCcsHRVXwwlRVXww

File size 447.7 KB ( 458448 bytes )
File type Mach-O
Magic literal
Mach-O 64-bit executable

TrID Mac OS X Mach-O 64bit Intel executable (100.0%)
Tags
64bits macho signed

VirusTotal metadata
First submission 2015-06-23 06:09:29 UTC ( 1 year, 11 months ago )
Last submission 2015-06-23 06:09:29 UTC ( 1 year, 11 months ago )
File names AppYS
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!
Condensed report! The following is a condensed report of the behaviour of the file when executed in a controlled environment. The actions and events described were either performed by the file itself or by any other process launched by the executed file or subjected to code injection by the executed file.
Output
Opened files
Read files
Written files
Moved files
Created processes
HTTP requests
DNS requests
TCP connections