YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 631a322ca0b54a40cd1d5c6ee42e5091334e4afe733d4be99082f4f449a9293d.

Scan Results


SHA256 hash: 631a322ca0b54a40cd1d5c6ee42e5091334e4afe733d4be99082f4f449a9293d
File size:593'468 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: 0169c5e398367b11099461121a19968d
SHA1 hash: f645b8020d6e1b0a55500c4b9184df06c6b22a97
SHA3-384 hash: f3b4e76c24ed967d918be5884c616c44e948c9b50c1a035b852fb71cfc4281f4f9cb167e07a8af44d771483a35064267
First seen:2025-11-21 18:58:37 UTC
Last seen:Never
Sightings:1
imphash : 98aa7065495f35513795744857924eba
ssdeep : 6144:ot++Jbojf5Vq5OC4qZhZcKYhc/ZfUozYE:L+cff22qZhZcKYhc/5
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon : 0000000000000100

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:160b69f7-c70c-11f0-a73e-42010aa4000b
File name:0169c5e398367b11099461121a19968d
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Win.Dropper.Shiz-10025558-0
Signature:Win.Trojan.Agent-316200

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:PE_Digital_Certificate
Author:albertzsigovits
TLP:TLP:WHITE
Repository:

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.