YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 0305b5214b7cfe66c569dd6f7f12a34c35e9239d8572f361981b9f30c847a8ac.

Scan Results


SHA256 hash: 0305b5214b7cfe66c569dd6f7f12a34c35e9239d8572f361981b9f30c847a8ac
File size:72'995 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: 13a568fea83597988c31676a82a6b7d5
SHA1 hash: 1304a25016b3bc6e8a2d8ee3808ed769d8fcf3eb
SHA3-384 hash: 93708242537290736f16af30bd65ae9a3fc59ba0cd796acb71724c51850e1f59409a48d7f5eddd402f65b96b70527e3e
First seen:2025-11-21 02:54:27 UTC
Last seen:Never
Sightings:1
imphash : 310c492a8d1880254f85610f1e667d02
ssdeep : 1536:8g/9T8ROcQupqqusN3mrS/ztMhkywRFUnTmc5n4nIIIItEIIIIIIIIIIIIIIIII/:8g585LpPCrQt7F84nIIIIGIIIIIIIIIX
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon : aab2606469f096b3

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:65459183-c685-11f0-adeb-42010aa4000b
File name:13a568fea83597988c31676a82a6b7d5
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:PUA.Win.Packer.Aspack-29
Signature:PUA.Win.Packer.Aspack-30
Signature:PUA.Win.Packer.Asprotect-3
Signature:Win.Trojan.JS-37
Signature:Win.Worm.Torvil-1
Signature:Win.Worm.Torvil-3

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:ASPackv212AlexeySolodovnikov
Author:malware-lu
TLP:TLP:WHITE
Repository:
Rule name:ASProtectV2XDLLAlexeySolodovnikov
Author:malware-lu
TLP:TLP:WHITE
Repository:
Rule name:Borland
Author:malware-lu
TLP:TLP:WHITE
Repository:
Rule name:classified
Author:classified
Description:classified
Reference:classified
TLP :TLP:AMBER
Rule name:pe_detect_tls_callbacks
Author:
TLP:TLP:WHITE
Repository:YARAify

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.