YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 20acb9f3bf81d3631cf3c7f273357e176f8f95920f3ddff00b7d8513c96d1bd4.

Scan Results


SHA256 hash: 20acb9f3bf81d3631cf3c7f273357e176f8f95920f3ddff00b7d8513c96d1bd4
File size:188'418 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: 0efdcca6d2801eba029db631789af69c
SHA1 hash: d1e2c6e28de91fc995ee38ebc49b210c7dd95887
SHA3-384 hash: 7b0d31f3f4b9423837c5ea1e77abf2c1f5d5bbeece4d8887ea94f94bde391c9c5d295ab6558fd91bd59c376783db635b
First seen:2025-11-21 19:00:45 UTC
Last seen:Never
Sightings:1
imphash :n/a
ssdeep : 3072:ESPf00oCvEH2ZlqJrHhG9lBflvnqXcGuN:ES/oPWlqDGnBflPqXcGu
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon : 1003873db9313e16

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:62aa22c2-c70c-11f0-a73e-42010aa4000b
File name:0efdcca6d2801eba029db631789af69c
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Win.Malware.Zusy-6878655-0

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:SEH__vba
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP:TLP:WHITE

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.