YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 27eda956479ae5ea007d5e58934fa046d8ac281b422f586c27fa4f7b8fa521e1.

Scan Results


SHA256 hash: 27eda956479ae5ea007d5e58934fa046d8ac281b422f586c27fa4f7b8fa521e1
File size:188'423 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: 11643d30fd5edf00da707185b705ff3d
SHA1 hash: 2fe840919283ad3f824f050270f28224d68db95b
SHA3-384 hash: d59230727d0cf3431ff02ed3d1214ab9a04c7ebaa1cc927bc90bbd9cc7540175cafadb6f7e12c8e9e086cdd49eb584d6
First seen:2025-11-20 23:55:26 UTC
Last seen:Never
Sightings:1
imphash :n/a
ssdeep : 3072:Avw1DFolpm+lqppLG+IBey2SOlvnqnviuG:AvcoJ6pLmeNSOlPqnviu
TLSH : T1B3049F628970BB13E951093517E06BFB801D3C2F4BE5060A7CADDA5F3763D9A349FA42
telfhash :n/a
gimphash :n/a
dhash icon : 1003873db9313e10

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:62cfd5d8-c66c-11f0-adeb-42010aa4000b
File name:11643d30fd5edf00da707185b705ff3d
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Win.Malware.Zusy-6878655-0

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:SEH__vba
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP:TLP:WHITE

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.