YARAify Scan Results
You are viewing the YARAify database entry for the file with the SHA256 hash b7e993464969b92c09fa2c42517db02fd089f6f7345ca3de44a29743419bc5fa
.
Scan Results
SHA256 hash: | b7e993464969b92c09fa2c42517db02fd089f6f7345ca3de44a29743419bc5fa | |
---|---|---|
File size: | 47'196 bytes | |
File download: | Original | |
MIME type: | application/x-dosexec | |
MD5 hash: | ebb8e97156b4e6859e2745a4664107e6 | |
SHA1 hash: | 722c2fb3bbebbaf0a3f3fa713ebae4c9eb00b0d8 | |
SHA3-384 hash: | c87ffe1cb585f280dc2169355693ddd49a09fd6fa48e88e0fd82a08bcb8751f0f20bce922f04fad261eba640cb57a77f | |
First seen: | 2025-08-24 22:20:16 UTC | |
Last seen: | Never | |
Sightings: | 1 | |
imphash : | d7a3983dd5b3e8e81dabf4c8abb76430 | |
ssdeep : | 768:CcMJOcV8OrUpdJ8WbqpD3TORaEXowekfKg:yOcjUpkWb2TTgKwug | |
TLSH : | n/a | |
telfhash : | n/a | |
gimphash : | n/a | |
dhash icon : | 04ccfee2ece4a484 |
Tasks
There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.
Task Information
Task ID: | 83259f5f-8138-11f0-8fb7-42010aa4000b | |
---|---|---|
File name: | ebb8e97156b4e6859e2745a4664107e6 | |
Task parameters: | ClamAV scan: | True |
Unpack: | False | |
Share file: | True |
ClamAV Results
The file matched the following open source and commercial ClamAV rules.
Signature: | Legacy.Trojan.Agent-1388589 |
---|
Signature: | Win.Worm.Brontok-425 |
---|
YARA Results
Static Analysis
The following YARA rules matched on the file (static analysis).
Rule name: | CP_AllMal_Detector |
---|---|
Author: | DiegoAnalytics |
Description: | CrossPlatform All Malwares Detector: Detect PE, ELF, Mach-O, scripts, archives; overlay, obfuscation, encryption, spoofing, hiding, high entropy, network communication |
TLP: | TLP:WHITE |
Repository: | YARAify |
Rule name: | Sus_Obf_Enc_Spoof_Hide_PE |
---|---|
Author: | XiAnzheng |
Description: | Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP) |
TLP: | TLP:WHITE |
Repository: | YARAify |
Rule name: | upx_3 |
---|---|
Author: | Kevin Falcoz |
Description: | UPX 3.X |
TLP: | TLP:WHITE |
Rule name: | UPX290LZMAMarkusOberhumerLaszloMolnarJohnReiser |
---|---|
Author: | malware-lu |
TLP: | TLP:WHITE |
Repository: |
Rule name: | classified |
---|---|
Author: | classified |
Description: | classified |
TLP : | TLP:AMBER |
Unpacker
The following YARA rules matched on the unpacked file.
Disabled by submitter
Unpacked Files
The following files could be unpacked from this sample.
Disabled by submitter