YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 04d60997aaf2f388901a4bcfbea4cfcaf8cad5e83bd8e3eca5ffd6a5e6ded7b5.

Scan Results


SHA256 hash: 04d60997aaf2f388901a4bcfbea4cfcaf8cad5e83bd8e3eca5ffd6a5e6ded7b5
File size:172'048 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: 131885696775214f8c4a20b5f0d3575f
SHA1 hash: 654f0c8ff9e3d0d4c5ff96af6a63803a623425d5
SHA3-384 hash: 84e4c005686ba8ba6ad68913d3d9c8be510fdde616fec06556eae1ad39eb5aaf6b39306d808ba5ce1a61a5cfd8bc34b0
First seen:2025-11-21 19:03:46 UTC
Last seen:Never
Sightings:1
imphash : 4259e393ea2c6d47b6c4d11a86e27606
ssdeep : 3072:tiUPBWryHbT6s37SD85NOXc9vSHGR+Hgoh36iW/IQdQuHxmO:11T6g/sc9eV1l2IaxmO
TLSH : T119F36C392EFCE137EAB185B1EFA085AEB154E17632029C17E54266479633C4376B132F
telfhash :n/a
gimphash :n/a
dhash icon : 4b4340000082c864

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:ce36d27d-c70c-11f0-a73e-42010aa4000b
File name:131885696775214f8c4a20b5f0d3575f
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Win.Dropper.DarkKomet-9996694-0
Signature:Win.Dropper.Vobfus-6611673-0

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
TLP:TLP:WHITE
Repository:YARAify
Rule name:NET
Author:malware-lu
TLP:TLP:WHITE
Repository:
Rule name:SEH__vba
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP:TLP:WHITE

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.