Authenticate for API access | If you are experiencing issues with receiving data from abuse.ch platforms via API, please ensure your requests are authenticated. ➡️ Read here for more info

YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash bf95baa92c6ace4bc0b7398957ce832f7db338b5864d732463d8fe0e38e47d28.

Scan Results


SHA256 hash: bf95baa92c6ace4bc0b7398957ce832f7db338b5864d732463d8fe0e38e47d28
File size:77'853 bytes
File download: Original
MIME type:application/pdf
MD5 hash: d17508ca1b7ef4ccefd3e32bfb1a837c
SHA1 hash: bb3fca91bc25774aa2961a2dd3ab2b8a848e8fa2
SHA3-384 hash: 7db81bf83826461c0c90cf4c22a4c048157922bad906ab53a1b501d9b835346f124854e86757e22bb1fb87c492daf2f8
First seen:2025-07-03 09:21:33 UTC
Last seen:Never
Sightings:1
imphash :n/a
ssdeep : 1536:muKSAgSjfscwOWaCWVe7nZYK+69gdAGYY3e6H5pcNToRU+SHD/:rKSA1jfsc/o7nCHIg53VIzFHT
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon :n/a

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:1c466642-57ef-11f0-a223-42010aa4000b
File name:API_portfolioB1018.pdf
Task parameters:ClamAV scan:True
Unpack:False
Share file:False

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
TLP:TLP:WHITE
Repository:YARAify

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.