YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 0b9f33bd07f7d1bd6dc36f233fbf776c90ad8a13851d4d4ad528ceef3308d67a.

Scan Results


SHA256 hash: 0b9f33bd07f7d1bd6dc36f233fbf776c90ad8a13851d4d4ad528ceef3308d67a
File size:6'148'096 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: 2ad88bb8c0ff8dfebc375ca249896378
SHA1 hash: c700065bcc38c82b634eaea839dcd80e1224cc9d
SHA3-384 hash: ce7de34b9e067e35ddc01816ded00226f5932b0a0d66002e0efaa22a64847ee627818d0f473e6c7d4a289343be0e09db
First seen:2025-12-16 06:02:07 UTC
Last seen:Never
Sightings:1
imphash : 12ee69b26840b5fea9d3312170f5182e
ssdeep : 98304:64to7Jn5r1V1et+ucDB5ad6Eqw+GtlCVXbIswQ2H/Dyb+BreEoShKfC+QXKQ8:6ZJnyt+ucc6Eqw3tCXbIfQ2NxeiUfC/8
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon :n/a

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:c0f144b1-da44-11f0-9df4-42010aa4000b
File name:10000000.dll
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:PUA.Win.Adware.Neoreklami-9785360-0

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP:TLP:WHITE
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
TLP:TLP:WHITE
Repository:YARAify
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
TLP:TLP:WHITE
Repository:YARAify
Rule name:Windows_Generic_Threat_24191082
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.