YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 03dcceca8a1d9ba1eb59fbb072b5b77bccfe716dc17a17b0128a17e9c7999e87.

Scan Results


SHA256 hash: 03dcceca8a1d9ba1eb59fbb072b5b77bccfe716dc17a17b0128a17e9c7999e87
File size:601'557 bytes
File download: Original
MIME type:application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
MD5 hash: 9ee1b1f0a520526cbdff92694c21198d
SHA1 hash: af42cb22234cd49662c924c81c940460908078b7
SHA3-384 hash: c313f37f55f6b5386d62fb17eec3358fbf5708e8fc3c45a8b5b45f63499be1a3e6a821f783447c4a969bb94defe2485c
First seen:2026-03-10 03:20:50 UTC
Last seen:Never
Sightings:1
imphash :n/a
ssdeep : 6144:Rn1qs4ovK/FnJ3LqOYwp0+uFOllr8wW4cFbytFlbMrRbtw/qpq3zFVUzcT:PNAH0+e44wtcgrlgRJWpUzcT
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon :n/a

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:239bc2cd-1c30-11f1-b47f-42010aa4000b
File name:9ee1b1f0a520526cbdff92694c21198d
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:vbaproject_bin
Author:CD_R0M_
Description:{76 62 61 50 72 6f 6a 65 63 74 2e 62 69 6e} is hex for vbaproject.bin. Macros are often used by threat actors. Work in progress - Ran out of time
TLP:TLP:WHITE
Repository:CD-R0M

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.