YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 0c24001cf880f54c7518794488bacc84797d9e10a643e8243f0ea9a5852fd1b3.

Scan Results


SHA256 hash: 0c24001cf880f54c7518794488bacc84797d9e10a643e8243f0ea9a5852fd1b3
File size:841'643 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: a5ae95cef2c9e6924e04878a339f98f1
SHA1 hash: 0394054beed70c8358e9ce518561727c9f99bc6c
SHA3-384 hash: 934c0d3c4dd7043ecd5c25565c2616896564c8e654eab796ef86a0ec7316d35bb152a92de4e159eb7f9f22086c30e3d8
First seen:2026-01-04 01:44:29 UTC
Last seen:Never
Sightings:1
imphash : ac05741865f7fcff1a3700a970c86a61
ssdeep : 6144:/sxEdGse9NMXPk5Ay/v6VNF5oJiq1IrSFzbsX1pKEWWcNim2SQNtBXC0bSePY5+/:Y9n1IrB1pKEUCA5BiivCt
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon :n/a

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:e91ab3b1-e90e-11f0-9df4-42010aa4000b
File name:7ff7a9f00000.49702c3a-ef42-49cb-b19a-31177e23d4d2.exe
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:Check_Debugger
TLP:TLP:WHITE
Repository:
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
TLP:TLP:WHITE
Repository:YARAify
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP:TLP:WHITE
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP:TLP:WHITE
Rule name:DebuggerCheck__RemoteAPI
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP:TLP:WHITE
Rule name:DebuggerHiding__Active
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP:TLP:WHITE
Rule name:dgaagas
Author:Harshit
Description:Uses certutil.exe to download a file named test.txt
TLP:TLP:WHITE
Repository:YARAify
Rule name:INDICATOR_SUSPICIOUS_EXE_NoneWindowsUA
Author:ditekSHen
Description:Detects Windows executables referencing non-Windows User-Agents
TLP:TLP:WHITE
Repository:diˈtekSHən
Rule name:SUSP_XORed_URL_In_EXE
Author:Florian Roth (Nextron Systems)
Description:Detects an XORed URL in an executable
Reference:https://twitter.com/stvemillertime/status/1237035794973560834
TLP:TLP:WHITE
Repository:Neo23x0
Rule name:SUSP_XORed_URL_in_EXE_RID2E46
Author:Florian Roth
Description:Detects an XORed URL in an executable
Reference:https://twitter.com/stvemillertime/status/1237035794973560834
TLP:TLP:WHITE
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP:TLP:WHITE
Rule name:upx_largefile
Author:k3nr9
TLP:TLP:WHITE
Repository:YARAify
Rule name:win_bazarbackdoor_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.bazarbackdoor.
TLP:TLP:WHITE
Repository:Malpedia
Rule name:classified
Author:classified
Description:classified
TLP :TLP:AMBER

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.