YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 12d4e186327e023aec4f4427218f0d363c89dbfcd3bfc4247eb58635ffac31bc.

Scan Results


SHA256 hash: 12d4e186327e023aec4f4427218f0d363c89dbfcd3bfc4247eb58635ffac31bc
File size:185'346 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: c9036b841c0e7f7e58368aad427d4c72
SHA1 hash: 8622860ce853a9b4ba74cc4cf9f27864940ccca5
SHA3-384 hash: cc98b687580b2e1ca58e6fe49a02f647edc8c3adac928c17117bb15d6828a2d125627c5d01d538d4a120906ec279607a
First seen:2025-01-10 21:26:18 UTC
Last seen:Never
Sightings:1
imphash : 46d56b44c2f42c46a90229f6b8a7313a
ssdeep : 3072:TBAp5XhKpN4eOyVTGfhEClj8jTk+0hg/eSZZvLf6CNsPrXJ8WYQKaL6:+bXE9OiTGfhEClq9vGSZZvLCCNsPrXJ+
TLSH :n/a
telfhash :n/a
gimphash :n/a
File icon (PE):PE icon
dhash icon : 00e0e8f8e8e8988a

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:87f6398f-cf99-11ef-a38e-42010aa4000b
File name:c9036b841c0e7f7e58368aad427d4c72
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:SecuriteInfo.com.PSW.Generic9.CAJN.UNOFFICIAL
Signature:SecuriteInfo.com.VBS.Dropper-6.UNOFFICIAL
Signature:Win.Trojan.Qhost-9811418-0

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:BobSoftMiniDelphiBoBBobSoft
Author:malware-lu
TLP:TLP:WHITE
Repository:
Rule name:NET
Author:malware-lu
TLP:TLP:WHITE
Repository:
Rule name:pe_detect_tls_callbacks
Author:
TLP:TLP:WHITE
Repository:YARAify
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
TLP:TLP:WHITE
Repository:YARAify

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.