YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 2655ccaa683a8b0e4391427ba30f1a635c8df0f46c2022357e2a57671ec7872c.

Scan Results


SHA256 hash: 2655ccaa683a8b0e4391427ba30f1a635c8df0f46c2022357e2a57671ec7872c
File size:148'969 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: 1924d567e130800d9399d834a8129d7e
SHA1 hash: 8a164771a1f9880daa162eec5821d654915d556f
SHA3-384 hash: 017b3d5be8fed805b1ed56a838ab00e02356ada5cc704e9f034c00e1a63ba70811e6cdab6d66eda6a4d29b329ae7ec23
First seen:2025-11-21 19:03:17 UTC
Last seen:Never
Sightings:1
imphash : bfb29b927a1f40b5aa6bd78bd884cc53
ssdeep : 3072:3LVoDvPd+A4WhkhXDl+i1lApwH08TdTIIIIIIIIIIIIIIIIIIfIIIIyIIIITIIID:ZopGGgbiwU8Jv
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon : aab2606469f096b3

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:bce93b2b-c70c-11f0-a73e-42010aa4000b
File name:1924d567e130800d9399d834a8129d7e
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:PUA.Win.Packer.Aspack-29
Signature:PUA.Win.Packer.Aspack-30
Signature:PUA.Win.Packer.Asprotect-3
Signature:Win.Trojan.JS-37

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:Borland
Author:malware-lu
TLP:TLP:WHITE
Repository:
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
TLP:TLP:WHITE
Repository:YARAify
Rule name:classified
Author:classified
Description:classified
Reference:classified
TLP :TLP:AMBER
Rule name:pe_detect_tls_callbacks
Author:
TLP:TLP:WHITE
Repository:YARAify
Rule name:with_urls
Author:Antonio Sanchez <asanchez@hispasec.com>
Description:Rule to detect the presence of an or several urls
Reference:http://laboratorio.blogs.hispasec.com/
TLP:TLP:WHITE

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.