YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 945b8d156f5398bd53118204567d0df0481f55f1bf7fc1ba6955e40e7ce077b2.

Scan Results


SHA256 hash: 945b8d156f5398bd53118204567d0df0481f55f1bf7fc1ba6955e40e7ce077b2
File size:421'951 bytes
File download: Original
MIME type:application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
MD5 hash: 7a2d9e34bb863f275cf62a1fc90425b3
SHA1 hash: 74739fcc89976772c5fa7f5233d97960b6efacce
SHA3-384 hash: 5ba9fbec19a59a5ccd63e7f52f905d95e45450eed2ef1b503f8c3a017ae77b634e049ccf46ca6e4e7d9af0ede020807f
First seen:2025-12-26 18:09:32 UTC
Last seen:Never
Sightings:1
imphash :n/a
ssdeep : 6144:24Bddr8/VkEDgkEfMcwDR0efQydNjtAIC1kBJGJYK4b:24Brrk8k/dNc12JHZ
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon :n/a

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:07454118-e286-11f0-9df4-42010aa4000b
File name:7a2d9e34bb863f275cf62a1fc90425b3
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:vbaproject_bin
Author:CD_R0M_
Description:{76 62 61 50 72 6f 6a 65 63 74 2e 62 69 6e} is hex for vbaproject.bin. Macros are often used by threat actors. Work in progress - Ran out of time
TLP:TLP:WHITE
Repository:CD-R0M

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.