NEW | Hunt across all abuse.ch platforms with one simple query - discover if an IPv4 address, domain, URL or file hash has been identified on any platform from a centralized search tool. Test it out here hunting.abuse.ch - and happy hunting 🔍

YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 411d55dbf7fa4a3d5c3eb2d6aa7cd402c28da38dd09f1c365d69e9e7a204ae47.

Scan Results


SHA256 hash: 411d55dbf7fa4a3d5c3eb2d6aa7cd402c28da38dd09f1c365d69e9e7a204ae47
File size:1'269'760 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: c3a6b07b85adede3cc008beb9d56d4ae
SHA1 hash: 294dd3a915413da5522db330d7006cec887f5902
SHA3-384 hash: bebb53a5ac9fa637445d7778e1128f6d08e88cee214020545988b7424e8ae18c5193c4d5299348336a608ee5a66716fc
First seen:2025-04-03 02:32:55 UTC
Last seen:Never
Sightings:1
imphash : 24c431641bc87ac39d557c4019b9c7e8
ssdeep : 24576:vlv3yIUPE1Bubmq3nT6j35WHRlMugdD+JsRgZRJ4fM430Eg6nET7M/IiN:vlfyIUPE1BuB3ujcxlMPdlR8v4UC0Egv
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon : 04c988cce6fc7012

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:f3687206-1033-11f0-b4a6-42010aa4000b
File name:c3a6b07b85adede3cc008beb9d56d4ae
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:SecuriteInfo.com.Win32.Expiro-3.UNOFFICIAL
Signature:Win.Trojan.Generic-9935365-0
Signature:Win.Virus.Expiro-10005424-0

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:Check_OutputDebugStringA_iat
TLP:TLP:WHITE
Repository:
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
TLP:TLP:WHITE
Repository:YARAify
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
TLP:TLP:WHITE
Repository:YARAify

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.