YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash e86f629759a6c2c8ddfff717f216a66c0bde17cc60afd91a1b9774a663694668.

Scan Results


SHA256 hash: e86f629759a6c2c8ddfff717f216a66c0bde17cc60afd91a1b9774a663694668
File size:318'528 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: 036dc20cf77e25fe6f659eb0fa614270
SHA1 hash: 22548e76bd1f0d62a9957fc305d2df26d5394f32
SHA3-384 hash: 030b8eee9c5fcaecd7ee1082a2b47e8d18dc44821cd8cca0a963f3bf5d1c2dd773f68fc9b1b3584b782d2276d84dedb5
First seen:2025-11-21 18:57:17 UTC
Last seen:Never
Sightings:1
imphash :n/a
ssdeep : 6144:6pYOYU1PTaCSZo3OEk1BmpypE3P5Xhsi1mALE25feIvOAvG6s1P9N:8ruy3wfmmE3Tsi15ojIvZ749N
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon :n/a

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:e6af6216-c70b-11f0-a73e-42010aa4000b
File name:036dc20cf77e25fe6f659eb0fa614270
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:SecuriteInfo.com.InstallRex-1.UNOFFICIAL
Signature:Win.Adware.Agent-1388696
Signature:Win.Adware.Agent-1388697
Signature:Win.Trojan.Antifw-173

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:PUP_InstallRex_AntiFWb
Author:Florian Roth (Nextron Systems)
Description:Malware InstallRex / AntiFW
TLP:TLP:WHITE
Repository:Neo23x0

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.