A forum for reverse engineering, OS internals and malware analysis 

Forum for completed malware requests.
 #32089  by r0ny
 Tue Sep 04, 2018 2:38 pm
Operation AppleJeus: Lazarus hits cryptocurrency exchange with fake installer and macOS malware

ref:https://securelist.com/operation-applejeus/87553/

IOCs:

d555dcb6da4a6b87e256ef75c0150780b8a343c4a1e09935b0647f01d974d94d
e2199fc4e4b31f7e4c61f6d9038577633ed6ad787718ed7c39b36f316f38befd
08012e68f4f84bba8b74690c379cb0b1431cdcadc9ed076ff068de289e0f6774
ef400d73c6920ac811af401259e376458b498eb0084631386136747dfc3dcfa8
1b8d3e69fc214cb7a08bef3c00124717f4b4d7fd6be65f2829e9fd337fc7c03c
e088c3a0b0f466df5329d9a66ff618de3d468d8a5981715303babb1452631eef
3c809a10106990ba93ec0ed3b63ec8558414c6680f6187066b1aacd4d8c58210
8ae766795cda6336fd5cad9e89199ea2a1939a35e03eb0e54c503b1029d870c4
d3ef262bae0beb5d35841d131b3f89a9b71a941a86dab1913bda72b935744d2e
ca70aa2f89bee0c22ebc18bd5569e542f09d3c4a060b094ec6abeeeb4768a143