YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 9c7158d9ecfaaee443d3c73abebee4e2f16891f5929be26ac5687ebd08854c9b.

Scan Results


SHA256 hash: 9c7158d9ecfaaee443d3c73abebee4e2f16891f5929be26ac5687ebd08854c9b
File size:1'172'480 bytes
File download: Original
MIME type:application/vnd.ms-excel
MD5 hash: 39fa305ddf73dbd41bd96e2918b13558
SHA1 hash: 5d4a27936d0f3bf9f11b9a8835298c8066ffc551
SHA3-384 hash: 2bf6f2965360d8efd7e4ce0b92f78cbb9e189cdaf49d45708ce1b78045338807284d1789d825bb9cdc27cff93d057fe0
First seen:2025-11-21 19:01:46 UTC
Last seen:Never
Sightings:1
imphash :n/a
ssdeep : 12288:+lkkhl/l2F351XkKC1ggHDXnfXzu6SrNMOMt6nd5APgGB49YzQ7:+lkkhv297QXfK6S17
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon :n/a

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:873e523f-c70c-11f0-a73e-42010aa4000b
File name:39fa305ddf73dbd41bd96e2918b13558
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:informational_win_ole_protected
Author:Jeff White (karttoon@gmail.com) @noottrak
Description:Identify OLE Project protection within documents.
TLP:TLP:WHITE
Repository:karttoon

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.