YARAify Scan Results
You are viewing the YARAify database entry for the file with the SHA256 hash 87c1038d7d4a31cbd9af3959107816916c6b9e2b4b2255cb7e63be07bdd43066
.
Scan Results
SHA256 hash: | 87c1038d7d4a31cbd9af3959107816916c6b9e2b4b2255cb7e63be07bdd43066 | |
---|---|---|
File size: | 417'792 bytes | |
File download: | Original | |
MIME type: | application/x-dosexec | |
MD5 hash: | 5b413a17ba3f01d3349e63b54ed6e1b0 | |
SHA1 hash: | fee3da2d701346071721b4f4efbb004fa6cb9db3 | |
SHA3-384 hash: | 4048de93fa190064f277a3c88962a2d9bd4610e1208bbc0546bee1d7fcb9467713938792af867e78f14f511654763ff8 | |
First seen: | 2025-07-03 09:21:50 UTC | |
Last seen: | Never | |
Sightings: | 1 | |
imphash : | 88478c1f74f94f7e1e9654193a1e02b3 | |
ssdeep : | 6144:EUpiHop5lNrSiGWiYBlHZzAm+o8wf2EvFrhlLtG9WSHHo8cnc05m7+Qf3JV50DEr:yHU3Zzl+rS2eVlLtwccqm73/mD8rE0 | |
TLSH : | n/a | |
telfhash : | n/a | |
gimphash : | n/a | |
dhash icon : | n/a |
Tasks
There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.
Task Information
Task ID: | 26cb60d2-57ef-11f0-a223-42010aa4000b | |
---|---|---|
File name: | 2a00000.dll | |
Task parameters: | ClamAV scan: | True |
Unpack: | False | |
Share file: | True |
ClamAV Results
The file matched the following open source and commercial ClamAV rules.
Signature: | Win.Malware.Galg-10004505-0 |
---|
YARA Results
Static Analysis
The following YARA rules matched on the file (static analysis).
Rule name: | golang_bin_JCorn_CSC846 |
---|---|
Author: | Justin Cornwell |
Description: | CSC-846 Golang detection ruleset |
TLP: | TLP:WHITE |
Repository: | YARAify |
Rule name: | malware_shellcode_hash |
---|---|
Author: | JPCERT/CC Incident Response Group |
Description: | detect shellcode api hash value |
TLP: | TLP:WHITE |
Repository: | JPCERTCC |
Rule name: | SHA512_Constants |
---|---|
Author: | phoul (@phoul) |
Description: | Look for SHA384/SHA512 constants |
TLP: | TLP:WHITE |
Repository: |
Rule name: | Windows_Trojan_M0yv_92f66467 |
---|---|
Author: | Elastic Security |
TLP: | TLP:WHITE |
Repository: | elastic |
Unpacker
The following YARA rules matched on the unpacked file.
Disabled by submitter
Unpacked Files
The following files could be unpacked from this sample.
Disabled by submitter