Is com.apphousekitchen.aldente-pro safe?
No antivirus engine detected this disk image, and the completed sandbox found no malicious outcome, though keychain access and unverified signing warrant source verification.
All 75 antivirus engines were free of detections, including 17 tier-1 engines, and one completed sandbox issued no malicious verdict. The sample did access the macOS login keychain under T1555.001, while its signature lacks verification and historical trust, so it should still come from the developer's official channel.
3651f6a2f69e7bbce5…7fe1f3b3d19d25Recommended next actions
Before opening
Open it only when its sender or download source is one you independently trust.
If you already opened it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
All 75 antivirus engines were free of detections, including 17 tier-1 engines, and one completed sandbox issued no malicious verdict. The sample did access the macOS login keychain under T1555.001, while its signature lacks verification and historical trust, so it should still come from the developer's official channel.
The strongest evidence is the absence of detections across 75 antivirus engines, including 17 tier-1 products. One completed sandbox observed execution without issuing a malicious verdict, and none of ten inspected dropped hashes was identified as malicious. All six observed domains received a completed reputation check with no malicious or suspicious matches, although the separately listed IP contacts were not fully covered by that result. T1555.001 and access involving the login keychain are meaningful counter-signals, but they lack corroboration from engine detections, external intelligence, persistence, or a malicious sandbox conclusion. Confidence is moderated because the file is recent, the signature verification state is unavailable, the signer has no history, and every dropped child's individual verdict remains unknown.
What We Detected
No detections were reported by 75 antivirus engines, including Avast, BitDefender, ESET-NOD32, Kaspersky, and Microsoft. External checks also returned no CIRCL, MalwareBazaar, or YARAify match.
Threat Behavior
One completed sandbox observed the application contacting six domains associated with Apple content delivery, the named application vendor, Paddle checkout, and Akamai delivery infrastructure. The six domains were checked against the host cache with no malicious or suspicious matches; the additional contacted IP addresses were not fully covered by that domain-level result. The run included T1555.001 and activity involving the macOS login keychain, but produced no malicious sandbox verdict or persistence indicators. Ten dropped hashes were inspected without a malicious child finding, although their individual verdicts remain unknown.
What To Do Now
Obtain the disk image only from the developer's official release channel and confirm its macOS signature or notarization before opening it. Keep endpoint protection enabled, and avoid installation if the publisher identity or download source cannot be verified.
Where this verdict could be wrong4 caveats
- T1555.001 is an offensive credential-access technique, although the single sandbox produced no malicious verdict and the activity may relate to legitimate keychain use.
- The signature's verification state is unavailable, and 'TEAM EDiSO' has no signer history or trusted-publisher match.
- All ten dropped children have unknown individual verdicts, so hasMaliciousChild=false does not establish that each child is benign.
- The file was first submitted one day ago, limiting the value of its current detection history.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/75 antivirus engines reported a malicious or suspicious result.
- 17/17 tier-1 engines that reported results had no detection.
- behaviour.hasMaliciousSandboxVerdict=false in one completed sandbox.
- contactedHosts found no malicious or suspicious matches for all six observed domains.
- externalIntel.yaraify.ruleCount=0, externalIntel.circl.hit=false, and externalIntel.malwareBazaar.hit=false.
- behaviour.offensiveTechniques includes T1555.001 credential access.
- signing.verified is unavailable for signer 'TEAM EDiSO'.
- signing.signerStats.found=false and signing.trustedPublisher.matched=false.
- The sample was first submitted only one day ago.
- All 10 dropped children have unknown individual verdicts.
Use this disk image only if it came from the application's official release channel, and verify its macOS signature or notarization before installation. Keep endpoint protection enabled.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial6 of 16 contacted hosts were cross-checked; coverage is incomplete.
YARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 6MITRE ATT&CK techniques
- 13spawned processes
- 16network contacts
- 27filesystem & mutex artifacts
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- s.mzstatic.com
- apphousekitchen.com
- checkout.paddle.com
- e4805.dsca.akamaiedge.net
- e3528.dscg.akamaiedge.net
- e673.dsce9.akamaiedge.net
- 172.66.41.13
- 213.133.104.40
- 23.215.57.10
- 104.18.38.233
- 17.253.83.152
- 17.248.193.49
- 17.33.203.20
- 17.57.144.122
- 17.8.129.55
- 54.69.185.163
- /Users/admin/Library/Application Support/AlDente/647568.spadl
- /private/var/folders/z_/k17lf9ys2m7fm4q2_3lj07680000gn/T/CFNetworkDownload_uhOD4u.tmp
- /Users/admin/Library/Caches/com.apphousekitchen.aldente-pro/Cache.db-journal
- /Users/admin/Library/HTTPStorages/com.apphousekitchen.aldente-pro.binarycookies_tmp_912.dat
- /Users/admin/Library/HTTPStorages/com.apphousekitchen.aldente-pro/httpstorages.sqlite-journal
- /Users/admin/Library/Caches/com.apphousekitchen.aldente-pro/fsCachedData_remove
- /Users/admin/Library/HTTPStorages/com.apphousekitchen.aldente-pro/httpstorages.sqlite-journal
- /private/var/folders/z_/k17lf9ys2m7fm4q2_3lj07680000gn/T/CFNetworkDownload_EoBMIh.tmp
- /Users/admin/Library/Caches/com.apphousekitchen.aldente-pro/fsCachedData
- /Users/admin/Library/Caches/com.apphousekitchen.aldente-pro/Cache.db-journal
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- 3ba6d39b43166fe371e9…db3926Never scannednever seen before
- 1b3ec5c99b5a8dcc4ccb…942fd7Never scannednever seen before
- ccb58013df29d57b9201…7c943dNever scannednever seen before
- be14b5cf1d70e71b06cc…d6cfbdNever scannednever seen before
- 9f1dcbc35c350d6027f9…913d47Never scannednever seen before
- 0b35937fb5fa622931ec…a96dd3Never scannednever seen before
- c6c7e80932a03aab8edf…6aef7cNever scannednever seen before
- 84b068bca932c167804d…040580Never scannednever seen before
- f2ab3b5a52997fa3545d…34d969Never scannednever seen before
- 053b78bf5d1060b78555…ebeec1Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 0 / 75engines flagged
- 5sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 75 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has been submitted 5 times from 5 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 03
Scanned file: com.apphousekitchen.aldente-pro — 3651f6a2f69e7bbce5dbb52c6c9eefeb65f986aefb6fb6e1cf7fe1f3b3d19d25
ProvenanceObservedSourceUploaded fileObserved at - 04
Observed process — /bin/zsh
ProvenanceObservedSourceIsolated runtime analysisObserved at - 05
Observed process — /usr/bin/env
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
File written: 647568.spadl — /Users/admin/Library/Application Support/AlDente/647568.spadl
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: CFNetworkDownload_uhOD4u.tmp — /private/var/folders/z_/k17lf9ys2m7fm4q2_3lj07680000gn/T/CFNetworkDownload_uhOD4u.tmp
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
Contacted host: s.mzstatic.com — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: apphousekitchen.com — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
0 of 75 engines flagged this file
View all 75 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- com.apphousekitchen.aldente-pro
- Format
- Macintosh Disk Image
- Code signing
- Signature not verified: TEAM EDiSO
- Size
- 11.2 MB
- Last analyzed
- Sep 24, 2026, 9:42 PM UTC
3651f6a2f69e7bbce5dbb52c6c9eefeb65f986aefb6fb6e1cf7fe1f3b3d19d25Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Open it only when its sender or download source is one you independently trust.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is com.apphousekitchen.aldente-pro safe?
What is com.apphousekitchen.aldente-pro?
How many antivirus engines detected com.apphousekitchen.aldente-pro?
Is com.apphousekitchen.aldente-pro digitally signed?
What is the SHA-256 hash of com.apphousekitchen.aldente-pro?
Is it safe to open com.apphousekitchen.aldente-pro?
How up to date is this analysis of com.apphousekitchen.aldente-pro?
Community
Member reviews and reports for this exact file hash.