YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 1c6830002b5014efa5f59fd0f5e9e2b8f73cd1217cf4e9929e4a8df307a1c2e9.

Scan Results


SHA256 hash: 1c6830002b5014efa5f59fd0f5e9e2b8f73cd1217cf4e9929e4a8df307a1c2e9
File size:2'285'568 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: 17efbbb89a1f4734906a35043171652b
SHA1 hash: 169279b2f4f602fefe9ee5da4a692dd658be4664
SHA3-384 hash: 8ea8d6b6e2c1d9898ed2e812ad0d78e0c3868ddaaa9e50fc251e6918baa4f3b975d7518cfb0631984f5c81105e23158b
First seen:2025-11-20 23:58:38 UTC
Last seen:Never
Sightings:1
imphash : 7db1302420a17abe7314f2f27e8fa917
ssdeep : 24576:slQe1KBEyAf8FLzlD0YmX8goDiOZNd+SIWHURj57GHOQIKfKu+yrDXJSH96B8a7K:sl/KvLzlYjMgo7Hdrxy572dwS2
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon : 00e2968696b6ca00

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:d5193d57-c66c-11f0-adeb-42010aa4000b
File name:17efbbb89a1f4734906a35043171652b
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Win.Virus.PolyRansom-5704625-0
Signature:Win.Virus.PolyRansom-5704626-1

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
TLP:TLP:WHITE
Repository:YARAify

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.