YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 13305bf6a57e88d455f91f3ec4bb234f34f87f6f3ca63fa5ef50dd7ae9c9993f.

Scan Results


SHA256 hash: 13305bf6a57e88d455f91f3ec4bb234f34f87f6f3ca63fa5ef50dd7ae9c9993f
File size:212'992 bytes
File download: Original
MIME type:application/octet-stream
MD5 hash: d7b386fc500adb441b67907dc9be0d7b
SHA1 hash: 0f20fc181efe0bf1ea2ca3f66c4eec8d37631e09
SHA3-384 hash: fdad647a6ca0989a7bc2dd13498ece77dd7c69c12e694465ddc43404b24bbfe207ff914bc1daa4d5ed57bd2431431709
First seen:2026-08-10 06:54:54 UTC
Last seen:Never
Sightings:1
imphash :n/a
ssdeep : 3072:MCjI+158l8O4h6I/Z0b0y7SI2Kg440akAQb4iCW:LrYvLIy7NNNFb4p
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon :n/a

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:64776226-9488-11f1-bf07-42010aa4000b
File name:14380000.shc
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:DebuggerCheck__RemoteAPI
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP:TLP:WHITE
Rule name:Detect_PowerShell_Obfuscation
Author:daniyyell
Description:Detects obfuscated PowerShell commands commonly used in malicious scripts.
TLP:TLP:WHITE
Repository:YARAify
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
TLP:TLP:WHITE
Repository:YARAify

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.