File verdict·Decided by the MT AI Engine
Our call

Suspicious

Unsigned macOS installer package with clean engine results but direct-IP network activity flagged by heuristic.

Trust score55Caution
geode-installer-v5.8.2-mac (5).pkg
22.8 MB
2a1b617e24e9af8322adc19345db
Antivirus engines
0 of 74 flagged
Code signing
Unsigned
Age
First seen 9 days ago
MT AI Engine · Verdict analysis

The reasoning behind this verdict

The MT AI Engine weighs every signal from this scan — antivirus detections, sandbox behaviour, code signing, prevalence and historical matches — to reach a single, evidence-based verdict.

65%Confidence
High
Reasoning

All 61 reporting engines returned undetected with 17 tier-1 engines explicitly clean. The file is unsigned and carries no signer history. Sandbox execution showed only ambient techniques and no malicious verdict, yet the DirectIpC2 heuristic fired due to exclusive IP-based connections. Medium prevalence and installer naming reduce risk, but the unsigned nature and network pattern keep the file in mixed-signals territory.

Key signals · 5

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. engines.tier1ReportedClean=17 with tier1Malicious=0

  2. triggeredHeuristics[0].rule=MalwareTips.Synth.DirectIpC2 (16 direct IPs, zero domains)

  3. signing.signed=false

  4. prevalence.classification=medium (16 submitters)

  5. filenameAnalysis.hasInstallerHint=true

Points in its favour
  • Zero malicious detections across 61 engines
  • 17 tier-1 engines returned clean
  • No malicious sandbox verdict or dropped children
Points against
  • Unsigned package
  • Direct-IP network contacts without DNS
  • Medium prevalence (16 submitters)
Recommended action

Treat as untrusted until the source is verified; the clean engine consensus is reassuring but the unsigned status and network pattern warrant caution.

What this file does

What it attempted when executed in an isolated sandbox

  • High concern: Talks to a remote server to take commands or send out your data.

  • Moderate concern: Runs hidden system commands (script or shell).

Translated from the file's technical behaviour during analysis. It never ran on your device.

What to do now

We couldn't fully clear this file. Treat it with caution.

  1. Don't run it unless you're certain it came from a source you trust.

  2. Check where you got it — an email attachment or a random download link is a red flag.

  3. If you're unsure, delete it. You can always re-download a clean copy from the official source.

  4. If you're still unsure, scan it again in a day or two — detections often catch up on newer files.

Runtime behaviour

What this file did when executed

This file was detonated in 1 sandbox and its runtime behaviour was observed.

MITRE ATT&CK
5

Adversary techniques mapped to the MITRE ATT&CK framework.

T1059.002· Runs commandsT1071· Remote server (C2)T1090T1564.001· Hides artifactsT1573
Spawned processes
15
$(unnamed)
/bin/ps
$(unnamed)
/usr/bin/env
$(unnamed)
/usr/libexec/path_helper
$(unnamed)
/usr/bin/osascript
$(unnamed)
/bin/zsh
$(unnamed)
/System/Library/Frameworks/CryptoTokenKit.framework/UserSelector
$(unnamed)
/System/Library/PrivateFrameworks/PackageKit.framework/Versions/A/Resources/install_monitor
$(unnamed)
/System/Library/PrivateFrameworks/PackageKit.framework/Versions/A/Resources/shove
+7 more processes captured.
Network activity
22
IP addresses20
  • 8.8.4.4
  • 8.8.8.8
  • 104.76.210.15
  • 255.255.255.255
  • 104.18.38.233
  • 172.64.149.23
  • 23.43.87.76
  • 162.159.142.9
  • 23.2.22.49
  • 23.222.244.213
+10 more
URLs2
  • http://ocsp.comodoca.com/MFcwVaADAgEAME4wTDBKMAkGBSsOAwIaBQAEFOsl2JD%2BJyD0HX1qwV7vds9iz6t4BBR1cacZSBm8nZ3qQUfflMRId5nTeQIRAJjBcnaqg2kI3NxbTvi9QXQ%3D
  • http://ocsp.comodoca.com/MFcwVaADAgEAME4wTDBKMAkGBSsOAwIaBQAEFOsl2JD+JyD0HX1qwV7vds9iz6t4BBR1cacZSBm8nZ3qQUfflMRId5nTeQIRAJjBcnaqg2kI3NxbTvi9QXQ=
Filesystem & mutexes
30
Files written15
  • /Library/InstallerSandboxes/.PKInstallSandboxManager/F7B07D0E-8AE0-4AB6-A56F-BB480142A1C0.activeSandbox/Root/tmp/geode-install/resources/.BC.T_ASyQOg
  • /Library/InstallerSandboxes/.PKInstallSandboxManager/F7B07D0E-8AE0-4AB6-A56F-BB480142A1C0.activeSandbox/Root/tmp/geode-install/resources/.BC.T_w3cGh9
  • /Library/InstallerSandboxes/.PKInstallSandboxManager/F7B07D0E-8AE0-4AB6-A56F-BB480142A1C0.activeSandbox/Root/tmp/geode-install/resources/.BC.T_0V3iBu
  • /Library/InstallerSandboxes/.PKInstallSandboxManager/F7B07D0E-8AE0-4AB6-A56F-BB480142A1C0.activeSandbox/Root/tmp/geode-install/resources/.BC.T_tFLs0B
  • /Library/InstallerSandboxes/.PKInstallSandboxManager/F7B07D0E-8AE0-4AB6-A56F-BB480142A1C0.activeSandbox/Root/tmp/geode-install/.BC.T_Cjbvy0
+10 more
Files deleted15
  • /Users/admin/Library/Photos/Libraries/Syndication.photoslibrary/scopes/syndication/originals/3
  • /private/var/root/Library/Caches/com.apple.managedappdistributiond/fsCachedData
  • /Users/admin/Library/Photos/Libraries/Syndication.photoslibrary/scopes/syndication/originals/4
  • /Users/admin/Library/Containers/com.apple.photolibraryd/Data/tmp/.LINKS/05ECBC0B-9AC7-4F58-88F2-1233E8D86413
  • /Users/admin/Library/Containers/com.apple.photolibraryd/Data/tmp/TemporaryItems/NSIRD_photolibraryd_NfMWzL
+10 more
Dropped payload

Files this sample writes at runtime

This file drops 10 children at runtime. None are currently flagged malicious in our cache.

10 unseen
  • e3b0c44298fc1c149afb52b855Never scanned
    never seen before
  • 99ecb12312c04a13de39ccfbe1Never scanned
    never seen before
  • 08c75af3256416bb1dba27fc92Never scanned
    never seen before
  • 668d363db30caadddb62c3e21fNever scanned
    never seen before
  • e2ed884c5006d5af3a36febe58Never scanned
    never seen before
  • f05ee3fd5618a08d9d3e233ea1Never scanned
    never seen before
  • 2b5f8aa452bfbb0019be549ce0Never scanned
    never seen before
  • d954997e493ffff3637f1d7a15Never scanned
    never seen before
  • 55b331cd39292b0d25a311ace8Never scanned
    never seen before
  • 6a1d1e76994096096072f7a060Never scanned
    never seen before
No researcher-database hits
External threat-intel sources were not collected for this scan.
Signature matches

YARA & heuristic rule matches

One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.

1 synthesis
MITRE ATT&CK profile
C2× 1
MalwareTips synthesis rules
Our own detection rules, applied to the scan data and sandbox behaviour
  • DirectIpC2medium

    Sample contacted 16 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.

    Evidence
    8.8.4.4 · 8.8.8.8 · 104.76.210.15
Antivirus engine breakdown

0 detections across 74 engines

0 malicious0 suspicious74 clean
Tier-117 engines
0flag
Top commercial AVs (low FP rate)
Tier-240 engines
0flag
Mainstream engines with mixed FP rates
Low-trust17 engines
0flag
Heuristic / generic-AI engines (high FP rate)
All 74 engines report this file as clean.
Hash 2a1b617e24e9… cross-referenced against 74 AV engines via our AV network.
Prevalence

How widely this file has been seen

Moderate prevalence — neither rare nor common. No strong prior applies.

Medium
Unique uploaders
16
Moderate upload volume.
Total submissions
17
Includes repeat uploads by the same source.
First seen
8d ago
Jul 12, 2026
Prevalence quadrant
Rare · New
Targeted malware lives here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
7/12/2026, 12:25:03 PM
First seen (MalwareBazaar)
Last analysis (VT)
7/12/2026, 12:25:03 PM
Scanned here
7/20/2026, 3:34:07 PM
File name
geode-installer-v5.8.2-mac (5).pkg
Size
22.81 MB
MIME type
(unknown)
Detected type
unknown
SHA-256
2a1b617e24e9af83223ea5c1772ac9476560b599bb7bf44f838267adc19345db
MD5
46f1c2eed2f8422f3209f17ba2226678
SHA-1
7d37b8b74d81d081652a1ce03d33c12f8487cf45
First seen (VT)
7/12/2026, 12:25:03 PM
Last analysis (VT)
7/12/2026, 12:25:03 PM
First scan (MalwareTips)
7/20/2026, 3:34:07 PM
Last scan (MalwareTips)
7/20/2026, 3:34:07 PM
Behavior tags
checks-cpu-name
Frequently asked

Safety FAQ

Common questions about geode-installer-v5.8.2-mac (5).pkg, answered from the scan data above.

  • geode-installer-v5.8.2-mac (5).pkg is suspicious — treat it as unsafe until you're sure. 0 of 74 antivirus engines flag it, which isn't a strong consensus but is enough to be cautious. Don't run it unless you fully trust where it came from, and prefer downloading the software fresh from its official site.
  • geode-installer-v5.8.2-mac (5).pkg is a software installer, about 22.8 MB. We identify a file by its cryptographic hash rather than its name, because the same filename can be reused by completely different files — the hash below is the reliable fingerprint.
  • None — all 74 antivirus engines we queried report geode-installer-v5.8.2-mac (5).pkg as clean. That's reassuring, though brand-new malware can briefly evade detection before vendors add signatures, so we also weigh the file's behaviour and reputation.
  • Act quickly. 1) Disconnect the device from the internet to stop the malware communicating or spreading. 2) Run a full scan with reputable anti-malware software (such as Malwarebytes) and quarantine everything it finds. 3) Change your important passwords from a DIFFERENT, clean device — many threats log keystrokes or steal saved credentials. 4) If you bank or shop on this device, watch closely for fraud and alert your bank. 5) For a confirmed infection, the most reliable fix is to back up your personal files and reinstall the operating system for a clean start.
  • To remove geode-installer-v5.8.2-mac (5).pkg: 1) restart into Safe Mode (Safe Mode with Networking if you need to download a tool) so the malware doesn't auto-start. 2) Run a full scan with reputable anti-malware software and let it quarantine or delete the detections. 3) Delete the original geode-installer-v5.8.2-mac (5).pkg file and empty the Recycle Bin/Trash. 4) Check your browser extensions, startup items, and scheduled tasks for anything unfamiliar. 5) Reboot and scan again to confirm it's gone. If detections keep coming back, a clean operating-system reinstall is the most dependable cure.
  • The SHA-256 hash of geode-installer-v5.8.2-mac (5).pkg is 2a1b617e24e9af83223ea5c1772ac9476560b599bb7bf44f838267adc19345db, and its MD5 is 46f1c2eed2f8422f3209f17ba2226678. This hash is the file's unique fingerprint — two files with the same SHA-256 are identical. Use it to confirm you're looking at exactly this file (not just one with the same name) when comparing against antivirus databases or a download's published checksum.
  • This report reflects the scan run on July 20, 2026. Because a file's hash never changes, the identity of geode-installer-v5.8.2-mac (5).pkg is fixed — but antivirus coverage improves over time, so a file that looks clean today can pick up detections later (and vice-versa). If you need the latest picture, MalwareTips staff can re-run the analysis from scratch.
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.