YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 250fe358c7c5466751154a68dc148ba6ec135561582e2a14768770bf8314cfd4.

Scan Results


SHA256 hash: 250fe358c7c5466751154a68dc148ba6ec135561582e2a14768770bf8314cfd4
File size:5'275'648 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: d0dde54d933174a8325eeb10d7c07029
SHA1 hash: 0d2cffbb350fda856f8e96b31d4992843f66c026
SHA3-384 hash: 063f97af9fc6792ad34a280a3505a5971eebab1adedaae166fdc50d6f1d864caf22c848d078f8faf97fbbe17463a3b4a
First seen:2023-03-26 23:55:09 UTC
Last seen:Never
Sightings:1
imphash : 9ac3e4058009fa551a2beedecae0e575
ssdeep : 49152:MPDSHCMll7G0YHO35jRfPC0UFEGQKq1X8l8JCSBdx5xixDFifB/2F7rG0w/PGC92:M+GDOHcFEGQ3M5FAK7rG5/PGaJS7
TLSH : T156368D527386543DE4572A3748FBF362883EBF602A47C90B63F9294C9F36644793A253
telfhash :n/a
gimphash :n/a
dhash icon :n/a

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:a4339e59-cc31-11ed-866d-42010aa4000b
File name:400000.duplicatefilefinder.exe
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:APT_DustSquad_PE_Nov19_1
Author:Arkbird_SOLG
Description:Detection Rule for APT DustSquad campaign Nov19
Reference:https://twitter.com/Rmy_Reserve/status/1197448735422238721
TLP:TLP:WHITE
Repository:StrangerealIntel
Rule name:APT_DustSquad_PE_Nov19_2
Author:Arkbird_SOLG
Description:Detection Rule for APT DustSquad campaign Nov19
Reference:https://twitter.com/Rmy_Reserve/status/1197448735422238721
TLP:TLP:WHITE
Repository:StrangerealIntel
Rule name:SR_APT_DustSquad_PE_Nov19
Author:Arkbird_SOLG
Description:Super Rule for APT DustSquad campaign Nov19
Reference:https://twitter.com/Rmy_Reserve/status/1197448735422238721
TLP:TLP:WHITE
Repository:StrangerealIntel

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.