Statistics

YARAIfy produces various statistics on files scanned by YARAify, including their detections. The available statistics can be found below.

File Scans


The chart below shows the number of file scans conducted by YARAify over the past 30 days.

Data Scanned


This chart shows the amount of data scanned in Megabytes over the past 30 days.

API requests


The illustration below documents the number of API requests over the past 30 days.

Most matching YARA rules


YARA rules that matched most on files scanned on YARAify in the past 14 days.

Task countYARA RuleAuthorLast match
176'059meth_get_eipWilli Ballenthin2022-10-04
75'940pdb_YARAify@wowabiy3142022-10-04
65'240RansomwareTest4Daoyuan Wu2022-09-28
54'209RansomwareTest5Daoyuan Wu2022-09-28
49'078RansomwareTest6Daoyuan Wu2022-09-28
41'705RansomwareTest7Daoyuan Wu2022-09-28
37'080Skystars_Malware_ImphashSkystars LightDefender2022-10-04
37'080pe_imphash2022-10-04
35'206BitcoinAddressDidier Stevens (@DidierStevens)2022-10-04
33'161RansomwareTest3Daoyuan Wu2022-09-28
27'695command_and_controlCD_R0M_2022-10-04
27'200win_sality_autoFelix Bilstein2022-10-04
19'391meth_stackstringsWilli Ballenthin2022-10-04
15'152RansomwareTest2Daoyuan Wu2022-09-28
14'652extracted_at_0x44bcb2022-10-04

ClamAV Most matching ClamAV signature


ClamAV signature that matched most on files scanned on YARAify in the past 14 days.

Task countClamAV SignatureLast match
66'361PUA.Win.Packer.Lccwin-22022-10-04
62'548Win.Trojan.Qukart-6874817-02022-10-04
57'636PUA.Win.Packer.Upx-42022-10-04
40'863Win.Trojan.Obfus-382022-10-04
30'025PUA.Win.Packer.Pequake-42022-10-04
25'765Win.Trojan.Crypted-292022-10-04
25'622Win.Trojan.Crypted-302022-10-04
23'959Win.Malware.Qukart-6838239-02022-10-04
11'925Multios.Coinminer.Miner-6781728-22022-10-04
11'675Win.Dropper.Berbew-9106192-02022-09-21
11'626PUA.Win.Packer.AcprotectUltraprotect-12022-10-04
11'271Win.Coinminer.Generic-7151447-02022-10-04
11'266Win.Coinminer.Generic-7151253-02022-10-04
11'265Win.Coinminer.Generic-7155777-02022-10-04
11'056Win.Trojan.Crypted-312022-10-04

Most seen files


Most seen files scanned by YARAify in the past 14 days.

Task countSHA256 hashLast seen
14123c2d2b0c6cec3e69cb07f942c9e56f2087aeb24015be25823897faafc4708ae2022-02-07
1405ea4d94c695189639e9ab7afe8d76d231030921fbfdd95e1941c7c0a05fb8f032022-02-07
14053c22863323c0f5ff94f4ae86df27a51db4eae7232cc38333346ee8be9df5aa62022-02-07
140b3986e04464339cec16157cf8c8bffec3a8a8c5eae57997974d45f5369fa16552021-07-07
14039e48a3fc7e67968ff5d6e3cf8e12a7256af93ccabbce4da20d28c79237d95e82022-01-06
140e19b0ba085a6c6f754df5f6f3a2ad8d490eafb62ad14606a943e7de2d0e3e03f2021-07-07
140e0af7f483f4965dca90eb5921ae004a7e41593b39284a63af97a9105b96718e72022-01-06
1395d2c578c6f0fe65a39e920bf03b5023ca0ace5efa80c316f7f454067cfea87b32021-07-07
139c25bd3702ca723b9b9427079397e4f5905e2f3a9ef86810a694be4faa8cb32c32021-07-07
1368c251ccc6eb0591c58ad3337729bcce081d8d65557523d21a6aee9cd6523d59f2022-02-07
134c8c158269c68d6b09d0c8b118b6588302816f2936c193579b35512d6a6af506e2022-02-08
13496994840078a8dbaaa3175c80b72c01c3a7f258be338c94c58672cacf5e47a872022-02-08
1348718400c6ca71b5afb0534931628b2aace3e5cc515edaa33d1da678f947b5cd42022-02-08
134cdfb8e3d5bfb32850200759b0d3ccaa83ed5cb661cb2cccedf048d23959663602022-02-08
1331115b6c913a207b9d81f8482613b2a9c2929ca81399861d2d2c47422e244060d2022-02-07

Top dhash icon


Top dhash icon observed on files scanned by YARAify in the past 14 days.

Task countdhash iconLast seen
8949919aca682a881a92022-07-23
3109a9acadecee6eaee2022-10-03
242ccf0f0c8d496e0f02022-10-03
18269ccd4d49696cc712022-09-11
165f8fcec9e8e88c0e82022-10-03
1309a9acadecee6eae62022-10-03
121414555c0d4d445032022-07-22
1189a9acafecee6eaee2022-10-03
90338be5f1f1a9adb72022-07-23
89b2dacabecee6baa62022-10-01
70008c0db2ca8ecad32022-09-20
709a9acadecee6eaea2022-10-03
6874f4c898b6b698d02022-07-22
65d4d4d4a2afb7b3b22022-09-20
58ba12f29a9dd2a2a22022-10-03

Top imphash


Top imphash observed on files scanned by YARAify in the past 14 days.

Task countimphashLast seen
38'361e4742a62fda2e64b586a5b84efe3f0402022-10-03
37'011f34d5f2d4577ed6d9ceec516c1f5a7442022-10-04
18'288dae02f32a21e03ce65412f6e56942daa2022-10-04
13'1316db997463de98ce64bf5b6b8b0f77a452022-10-04
12'593a12d186f65c99f872323a61923ce70d82022-10-04
10'254be6fa16f501de575a1d8eaaac5246ba02022-10-03
6'9486ed4f5f04d62b18d96b26d6db7c188402022-10-03
6'268a56705099ec07c676809955bdcce8d092022-10-03
6'17268d9776cadfeba9a6849d2f603b34a8f2022-09-21
5'7928abecba2211e61763c4c9ffcaa13369e2022-10-03
5'6392c2ad1dd2c57d1bd5795167a7236b0452022-10-03
4'67284706849fa809feaa385711a628be0292022-10-03
4'3714dcbc0931c6f88874a69f966c86889d92022-10-03
3'7353d76acaa0ea7f33b32e74149aa1f88482022-10-04
3'1467d55d950abf60b9ca05ce35790cded412022-10-04

Top tlsh


Top tlsh observed on files scanned by YARAify in the past 14 days.

Task counttlshLast seen
725T106156E2291C7D2F1F3F724B197D002BF5D289127C68A9D35F8252548A3861D6BC3DBEA2022-10-02
646T1EE156E2291C7D2F1F3F724B197D002BF5D289127C68A9D35F8252548A3861D6BC3DBEA2022-10-03
178T1A485AE7DC12BCA1AC81C747E684467813E9DC7F8A56582AC678EFB3F924C87850BD6702022-10-03
173T106256E2291C7D2F1F3F724B197D002BF5D289127C68A9D35F8252548A3861D6BC3DBEA2022-10-03
169T1EE256E2291C7D2F1F3F724B197D002BF5D289127C68A9D35F8252548A3861D6BC3DBEA2022-10-03
141T1B5033E9736E31000FB09BE35C654834FEF06CF59B97A9B4ED39826C72371A78629E0592022-02-07
140T1BD812B4525A230CAC056C270ED52C158ABD9BC37AF44D3BBF1B90FDD83112451CC1B0B2022-02-07
140T18CC048F380E010420460231313EF1E452B5F235C77462623F42C7D808320A3A37A39722021-07-07
140T1C8E052F688E090AC080023A82BDF2CA5437B03BD00202A0BF20BA04D022DF72E30A3F02021-07-07
140T1EF16DD42A3F94608F6F77F7469B916604E3BBCA6AD79C21C1284505E5EB2E40CDB0B732022-01-06
140T10016DD42A3F94608F6F77F7469B916604E3BBCA6AD79C21C1284505E5EB2E40CDB0B732022-01-06
140T160030B9736E31000FB09BE32E554C24FEF06CF59B976974ED39826C72350A78662E45B2022-02-07
139T179E06CFA88EC219D5A80435517DF6DB4976B02BD18263813F530928D831DB76E6633B62021-07-07
139T192D002F380E0149A4460331317DF1D451B5F136DB78A2613F83D7E84432093A37539712021-07-07
135T1F9033F8736E31004BB09BE35C754834FEF46CF59B97A9B4ED39826C72370A78629E0592022-02-07

Top telfhash


Top telfhash observed on files scanned by YARAify in the past 14 days.

Task counttelfhashLast seen
13t18ce02600fc7a8a2898db9e749ddc07bca500621254578b14df14d7e0c83f454a319b5f2022-10-03
12t14e11ef4321ba892c6bf758245cbc47b1295626233352be70af09c584993b007b979e8b2022-10-02
11t15d11214271fa892d2bf209285cfc43b0154026237741be70bf0dc5e84437002a639e8b2022-09-30
11t13611214271fa892d2bf209385cfc43b0154066237741be70bf0dc5e84837002b639e8b2022-09-30
9t1bb11ed4321ba855c2bf718345cbc47b1295226232792be70af09c5c44937002ba79e8f2022-10-02
9t195317722553546142fb3d928acfd56b315222b2363587f716f26c48c49370e2e93dd4f2022-10-02
9t171217622513542182fb3d928acbd567315222b2363597f716f26c4cc49370e2e93ad4f2022-10-02
9t11111ed4321ba855c2bf718345cbc47b1295226232792be70af09c5c44937002ba79e8f2022-10-02
8t1e3e0df00bc699a1988d7aab49d9d07b4a9116223506a8b10cf52d6e4c83f498a718eae2022-09-30
6t141217662513542182fb3d928acbd567315222b2363597f716f26c5cc49370e2f93ad4f2022-10-02
6t15c213352a0fa8a282bf349249cfc47f015502a237746be71bf0dc5d48537003a639ddb2022-09-30
6t12e210352a1f98a186bf359249cfc47f015506a137746be71bf0dc5d48537003a639ddb2022-09-30
6t185110e5261ba89292bf20a385cfc47b0164166233741be71bf0dc5e85837002ba2de8b2022-09-30
6t19d11324271ba89282bf209245cfc43b0169026233745be70bf0dc594983b002a638e8b2022-09-30
6t1d9e0c240adb89a1e9ce35bb8ddcd07b1a1116253a4270b10cf58e6e0c83f988a60de6d2022-10-03

File Scans


The chart below shows the number of file scans conducted by YARAify over the past 12 months.

Data Scanned


This chart shows the amount of data scanned in Megabytes over the past past 12 months.

API requests


The illustration below documents the number of API requests over the past past 12 months.

Most matching YARA rules


YARA rules that matched most on files scanned on YARAify in the past 12 months.

Task countYARA RuleAuthorLast match
1'331'070meth_get_eipWilli Ballenthin2022-10-04
1'015'069classifiedclassified2022-10-01
782'225BitcoinAddressDidier Stevens (@DidierStevens)2022-10-04
775'759pdb_YARAify@wowabiy3142022-10-04
569'917pe_imphash2022-10-04
569'917Skystars_Malware_ImphashSkystars LightDefender2022-10-04
537'415crime_win64_emotet_unpackedRony (r0ny_123)2022-10-02
429'785classifiedclassified2022-10-03
387'840win_heodo2022-10-02
359'497exploit_any_poppopretJeff White [karttoon@gmail.com] @noottrak2022-06-22
301'156win_sality_autoFelix Bilstein2022-10-04
274'546Emotet_BotnetHarish Kumar P2022-10-02
243'234INDICATOR_EXE_Packed_ASPackditekSHen2022-10-04
236'593win_vobfus_autoFelix Bilstein2022-10-04
236'044extracted_at_0x44bcb2022-10-04

ClamAV Most matching ClamAV signature


ClamAV signature that matched most on files scanned on YARAify in the past 12 Mmonths.

Task countClamAV SignatureLast match
617'445PUA.Win.Packer.Upx-42022-10-04
379'944PUA.Win.Packer.Lccwin-22022-10-04
365'885PUA.Win.Packer.Asprotect-32022-10-04
352'185Win.Trojan.Qukart-6874817-02022-10-04
266'348Win.Virus.Wapomi-1382022-09-20
249'718Win.Malware.Qukart-6838239-02022-10-04
229'644Win.Trojan.Obfus-382022-10-04
186'204Win.Dropper.Berbew-9106192-02022-09-21
164'419PUA.Win.Packer.Pequake-42022-10-04
145'206Win.Trojan.Crypted-302022-10-04
144'671Win.Trojan.Crypted-292022-10-04
143'471Win.Malware.Generickdz-9938530-02022-10-04
138'631Win.Trojan.Cosmu-10582022-10-04
123'436Win.Malware.Bdld-9770176-02022-10-04
110'098PUA.Win.Packer.AcprotectUltraprotect-12022-10-04

Most seen files


Most seen files scanned by YARAify in the past 12 months.

Task countSHA256 hashLast seen
150'031bfc6bff6a3be4c198b51f7ac0a28a8b61baaadbffcdcca8f25ef35b616c53cc52022-07-14
120'1062d93837ee387916c4a6060912fcb2b9fdaa836f419d2a038500299b376b5fbcd2021-07-08
118'96923c2d2b0c6cec3e69cb07f942c9e56f2087aeb24015be25823897faafc4708ae2022-02-07
115'1111665e0d57f7f62035a0f720ca385a82a27502283bf131d1628c877159e79a2102021-07-08
71'269f914ff8baa3bea7a4bde2f0554ddbaaea9d8090eabb277f1486648854a7f967a2022-01-11
50'2455881513fca390bfea60468b7b8085da7448efeeca39f52c8ac56745024afe2692021-07-08
38'525997f39432702a13c47ff2fbe1396b99663eb9debad312ede79978db122cf735e2022-01-27
36'0545ea4d94c695189639e9ab7afe8d76d231030921fbfdd95e1941c7c0a05fb8f032022-02-07
29'880e19b0ba085a6c6f754df5f6f3a2ad8d490eafb62ad14606a943e7de2d0e3e03f2021-07-07
28'3017f94107c9becbcc6ca42070fca7e1e63f29cdd85cbbd8953bbca32a1b4f912192022-01-11
26'36176cf234b9b0004e3c87633ebf8ff38a175576bc9baa6f34d863fc8eef0fa50b72022-01-28
24'672cf581ab47fabfc401ebca29130781037fb56b3bc54515f845f6f26bb4cbf96702022-06-08
24'540e0af7f483f4965dca90eb5921ae004a7e41593b39284a63af97a9105b96718e72022-01-06
24'46039e48a3fc7e67968ff5d6e3cf8e12a7256af93ccabbce4da20d28c79237d95e82022-01-06
23'636daf3d4175396ad0f2d639ea6dcfb166d701cdce5fd545fe3a320a88bd267ec7e2022-05-12

Top dhash icon


Top dhash icon observed on files scanned by YARAify in the past 12 months.

Task countdhash iconLast seen
86'33237373339294935872022-07-23
72'4619919aca682a881a92022-07-23
41'632399998ecd4d46c0e2022-09-07
29'980e94a6e71e932f0332022-07-23
27'893e0e4a2aaa4b8a8882022-07-23
27'015d0c4a2a2a4bcbcb82022-07-23
20'99271b119dcce5763332022-08-25
20'924c271cc9cae8de9722022-07-23
18'4901003873d31213f102022-10-02
17'907338be5f1f1a9adb72022-07-23
17'3591ad2a38edcb6b2dc2022-07-23
14'229818da080a0a0a0a22022-09-17
13'22730d4f0e8ccdcf0712022-07-23
12'909f8fcec9e8e88c0e82022-10-03
10'02300ccc4d0c4fc7c002022-07-23

Top imphash


Top imphash observed on files scanned by YARAify in the past 12 months.

Task countimphashLast seen
393'833f34d5f2d4577ed6d9ceec516c1f5a7442022-10-04
228'702dae02f32a21e03ce65412f6e56942daa2022-10-04
180'84968d9776cadfeba9a6849d2f603b34a8f2022-09-21
126'4828abecba2211e61763c4c9ffcaa13369e2022-10-03
115'788e4742a62fda2e64b586a5b84efe3f0402022-10-03
94'191ed86c2ba483c37b0e2cfeecbd5fca8762022-10-03
90'995be6fa16f501de575a1d8eaaac5246ba02022-10-03
82'6656db997463de98ce64bf5b6b8b0f77a452022-10-04
61'500b87b5fb150cfc5c490bcca7572133d9f2022-09-20
58'2912c2ad1dd2c57d1bd5795167a7236b0452022-10-03
56'5450bfb4502b7427d90a9fa0442dea9af552022-10-03
55'328359d89624a26d1e756c3e9d6782d6eb02022-10-03
49'587a12d186f65c99f872323a61923ce70d82022-10-04
47'3275271d5ce8b44dd47bc92563e275854662022-10-03
44'4575c7397fd7c1832e37a3cb00b6ee7c3772022-10-03

Top tlsh


Top tlsh observed on files scanned by YARAify in the past 14 months.

Task counttlshLast seen
118'969T1B5033E9736E31000FB09BE35C654834FEF06CF59B97A9B4ED39826C72371A78629E0592022-02-07
71'269T1CAE33A01F3D341F3DC970CF629B6B22EDB791E126068EE9987981F576D71249E2B980C2022-01-11
38'525T19DE35A11F39381F3DC960CF219B6B22F9F7D0E036164DEA593981F57ADB2245A2B981C2022-01-27
36'054T160030B9736E31000FB09BE32E554C24FEF06CF59B976974ED39826C72350A78662E45B2022-02-07
29'880T18CC048F380E010420460231313EF1E452B5F235C77462623F42C7D808320A3A37A39722021-07-07
28'301T105E34B01F39381F7DC960CF2297AB62FDF7D1E032064DE9593945F1BAC72609A2A991C2022-01-11
26'361T192E35A11F39381F3DC9608F219B6B22FDF7D0E036164DEA593981F57ADB2245A2B981C2022-01-28
24'694T129F36C24E84345E7F87B1932D0077A2FD4647D295220EE7BD954CE9AFF22B14A20F25E2022-06-12
24'540T10016DD42A3F94608F6F77F7469B916604E3BBCA6AD79C21C1284505E5EB2E40CDB0B732022-01-06
24'460T1EF16DD42A3F94608F6F77F7469B916604E3BBCA6AD79C21C1284505E5EB2E40CDB0B732022-01-06
23'636T173045B65E49345E7F8BB0872904A7B5FD8242D41D210DE3F9554CEDABF22B25A20F22F2022-05-12
22'528T192D002F380E0149A4460331317DF1D451B5F136DB78A2613F83D7E84432093A37539712021-07-07
22'214T1BD812B4525A230CAC056C270ED52C158ABD9BC37AF44D3BBF1B90FDD83112451CC1B0B2022-02-07
20'124T117E35A11F39381F3DC960CF219B6B22F9F7D0E036164DEA593981F57ADB2245A2B981C2022-01-25
19'464T1EDD34B11F7C341F3DC9608F169B6A22FDFB90E137064DEA587A81F576CB2605A2B990C2022-01-28

Top telfhash


Top telfhash observed on files scanned by YARAify in the past 12 months.

Task counttelfhashLast seen
106t171217622513542182fb3d928acbd567315222b2363597f716f26c4cc49370e2e93ad4f2022-10-02
98t195317722553546142fb3d928acfd56b315222b2363587f716f26c48c49370e2e93dd4f2022-10-02
88t13611d04270b6891d2bb659245cbc42b5165536236381be75bf0ec5c45537002ba79e8b2022-09-24
73t15411cc5271fa895d2bf649249cbc43b4265026237392beb5bf0dc6d05937002b979e8f2022-09-11
72t141217662513542182fb3d928acbd567315222b2363597f716f26c5cc49370e2f93ad4f2022-10-02
71t1fe11104270b6891c2bb259245cbc42b0165532232381be74bf0ec5c05937002ba79e8b2022-09-24
66t1d211020260b689282bb259205cbc42f1165526233341be75bf0ec5c4993b002aa78e8b2022-09-24
50t19ee0df40ac699e2c98d7aa74dddd07a496016223556a4b10cf10dbe4883f458e30ce5e2022-06-17
47t1ae11e10271f689282bf259245cbc43f4265126233341be71bf0dc5c0593b003b939e8b2022-09-11
46t1ace07200ec75871c88dbaab49c8c07b0da012226606b0b10cf10daf4c83f444f30ce4a2022-07-17
44t1c1e02c40acb58a1898dbaa74ed8d0ba49a012222606a0b10cf10daf4c83f448e308e4a2022-07-17
41t107110c4371fa895c2bf249249cbc43b0265026237382beb0bf0dc6c05937002b979e8f2022-09-11
38t11ee07200ec75871c88dbaa749d8d07b4ca012216606b0b10cf10daf4c83f448f30ce4a2022-09-27
37t1d911d01371f6896d2bf259245cbc43b4255026237351be75bf0dc5d4593b002b979ecb2022-08-27
35t13c2120251b31522a6e71dd64dcec57b10528472313847f32df26c4cc652a48dea2fc1f2022-05-31