YARAify Scan Results
You are viewing the YARAify database entry for the file with the SHA256 hash c6eb189382005b3ce2b0c9119440f185192503adcbafdebe27b7a924050789f5
.
Scan Results
SHA256 hash: | c6eb189382005b3ce2b0c9119440f185192503adcbafdebe27b7a924050789f5 | |
---|---|---|
File size: | 1'128'448 bytes | |
File download: | Original | |
MIME type: | application/x-dosexec | |
MD5 hash: | 91062a387880b032611dfaebc01de80c | |
SHA1 hash: | d5f5f7e8392c18ff76ba2fce2b36f59c36539422 | |
SHA3-384 hash: | eae86012c728cf14826a7d84dd65ac0e4753c579b9e3dde90a825ee9e21ed12e29fe9f0341ea6b06fafa6909b6fa24ea | |
First seen: | 2025-03-08 21:04:11 UTC | |
Last seen: | Never | |
Sightings: | 1 | |
imphash : | 646167cce332c1c252cdcb1839e0cf48 | |
ssdeep : | 24576:5yKPPTR5fmoamvQPgmYBTOoq+jO5jzls9c/Nd7YM8TX:sKPPTR5fm/pgmYgV+svlsi/N9YM8T | |
TLSH : | n/a | |
telfhash : | n/a | |
gimphash : | n/a | |
dhash icon : | f8f0f4c8c8c8d8f0 |
Tasks
There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.
Task Information
Task ID: | e25efa1d-fc60-11ef-b4a6-42010aa4000b | |
---|---|---|
File name: | 2012_134903832627112025 | |
Task parameters: | ClamAV scan: | True |
Unpack: | False | |
Share file: | True |
ClamAV Results
The file matched the following open source and commercial ClamAV rules.
Signature: | Win.Packed.Crifi-10011314-0 |
---|
YARA Results
Static Analysis
The following YARA rules matched on the file (static analysis).
Rule name: | detect_Redline_Stealer |
---|---|
Author: | Varp0s |
TLP: | TLP:WHITE |
Repository: | YARAify |
Rule name: | Sus_Obf_Enc_Spoof_Hide_PE |
---|---|
Author: | XiAnzheng |
Description: | Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP) |
TLP: | TLP:WHITE |
Repository: | YARAify |
Rule name: | win_redline_wextract_hunting_oct_2023 |
---|---|
Author: | Matthew @ Embee_Research |
Description: | Detects wextract archives related to redline/amadey |
TLP: | TLP:WHITE |
Repository: | embee-research |
Unpacker
The following YARA rules matched on the unpacked file.
Unpacked Files
The following files could be unpacked from this sample.