YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 9eed75ceb3376fd0e3ce4cbf97148a3f067a35148f62df7181702221169fbad4.

Scan Results


SHA256 hash: 9eed75ceb3376fd0e3ce4cbf97148a3f067a35148f62df7181702221169fbad4
File size:19'456 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: 084c78756801bba9075c80eb0728ea77
SHA1 hash: c4be1befa41d3b9093a5547428cb8164f6fcfef2
SHA3-384 hash: 23fcce867ffec04169b6b76e2a720cc222ead61d529830ee113645f607c20acb9a794976da29510b2cc59036b2b596fd
First seen:2025-11-21 19:03:03 UTC
Last seen:Never
Sightings:1
imphash : 7bef13f58538df84f5270fe7542e9811
ssdeep : 384:QQZqSstnLmJ1d6dzkT8OwNrSfB73TtWMiS2R3Xbr17vvxlL:9qSsE1EdgT8rgDtWfSW3Lx7D
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon :n/a

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:b4fa3eff-c70c-11f0-a73e-42010aa4000b
File name:084c78756801bba9075c80eb0728ea77
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Win.Malware.Shifu-6804440-0
Signature:Win.Trojan.Gamarue-9832405-0
Signature:Win.Trojan.Tinba-6390856-0

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:INDICATOR_EXE_Packed_MPress
Author:ditekSHen
Description:Detects executables built or packed with MPress PE compressor
TLP:TLP:WHITE
Repository:diˈtekSHən
Rule name:mpress_2_xx_x86
Author:Kevin Falcoz
Description:MPRESS v2.XX x86 - no .NET
TLP:TLP:WHITE
Rule name:TeslaCryptPackedMalware
TLP:TLP:WHITE
Repository:MalwareBazaar

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.