Authenticate for API access | If you are experiencing issues with receiving data from abuse.ch platforms via API, please ensure your requests are authenticated. ➡️ Read here for more info

YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 03b18a119ef5a834ef5382d694974ae5801d5364b7e97e3ad44068d2e8b0dfad.

Scan Results


SHA256 hash: 03b18a119ef5a834ef5382d694974ae5801d5364b7e97e3ad44068d2e8b0dfad
File size:1'244'127 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: 504d246085d5c0abfaa06ca2ae6d1d2f
SHA1 hash: db8ffb5d1a7d24bc9e85c9f7cb67b431cfbc19ea
SHA3-384 hash: b8f2c4cc9977c19fe2274d0e92022a7ae907ecb1df9ab337d707f554e34389e886bf5abf2ae71d942a062fcb4b57b42c
First seen:2025-05-25 18:34:50 UTC
Last seen:Never
Sightings:1
imphash : 9165ea3e914e03bda3346f13edbd6ccd
ssdeep : 24576:+vghg41N+L+s79FIY4ponf0e56xh3liEKKO7AynQedLSEgG:+vg//q9FOC0esxh1i/ldQ2GEx
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon : 00ccc4d0c4fc7c02

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:f21b26c0-3996-11f0-9b97-42010aa4000b
File name:504d246085d5c0abfaa06ca2ae6d1d2f
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Win.Dropper.Flystudio-7049423-1
Signature:Win.Malware.Flystudio-6937682-0
Signature:Win.Trojan.Zloyfly-1
Signature:Win.Worm.Autorun-405

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
TLP:TLP:WHITE
Repository:YARAify
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
TLP:TLP:WHITE
Repository:YARAify

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.