YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 2a135a499baa6b37df3dfb8133d57890dbb43e1a1f31aa7b30e7b23be2001879.

Scan Results


SHA256 hash: 2a135a499baa6b37df3dfb8133d57890dbb43e1a1f31aa7b30e7b23be2001879
File size:139'151 bytes
File download: Original
MIME type:text/html
MD5 hash: 226ea90080656e1873e5450f33e3cff3
SHA1 hash: 45c4d89ad56f9b3145bfd0ef7544373859c7f9b4
SHA3-384 hash: 5029814f77dce6243acb65ec7add377139d9f8067b3b0a51323a0ce2d628eb2bbeac69aac6de9c00eee256169f5c3f19
First seen:2026-02-10 06:17:02 UTC
Last seen:2026-02-10 06:20:02 UTC
Sightings:4
imphash :n/a
ssdeep : 1536:oUtL1vJaUS7N/QnRIOnRL4Y/DGO+5Ph8s0bjHiBokXCJ1vsT6cM7cLlqIK21h0T:oGL1BuinIh8sQjcBndM7cFK21W
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon :n/a

Tasks


There are 4 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:888d8e60-0648-11f1-82f6-42010aa4000b
File name:pub
Task parameters:ClamAV scan:True
Unpack:True
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:classified
Author:classified
Description:classified
TLP :TLP:GREEN
Rule name:html_auto_download_b64
Author:Tdawg
Description:html auto download
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:classified
Author:classified
Description:classified
TLP :TLP:AMBER
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
TLP:TLP:WHITE
Repository:YARAify
Rule name:SUSP_Websites
Author:SECUINFRA Falcon Team
Description:Detects the reference of suspicious sites that might be used to download further malware
TLP:TLP:WHITE
Repository:SIFalcon

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.

Task Information


Task ID:64a0d358-0648-11f1-82f6-42010aa4000b
File name:pub
Task parameters:ClamAV scan:True
Unpack:True
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:classified
Author:classified
Description:classified
TLP :TLP:GREEN
Rule name:html_auto_download_b64
Author:Tdawg
Description:html auto download
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:classified
Author:classified
Description:classified
TLP :TLP:AMBER
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
TLP:TLP:WHITE
Repository:YARAify
Rule name:SUSP_Websites
Author:SECUINFRA Falcon Team
Description:Detects the reference of suspicious sites that might be used to download further malware
TLP:TLP:WHITE
Repository:SIFalcon

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.

Task Information


Task ID:418dbcaa-0648-11f1-82f6-42010aa4000b
File name:pub
Task parameters:ClamAV scan:True
Unpack:True
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:classified
Author:classified
Description:classified
TLP :TLP:GREEN
Rule name:html_auto_download_b64
Author:Tdawg
Description:html auto download
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:classified
Author:classified
Description:classified
TLP :TLP:AMBER
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
TLP:TLP:WHITE
Repository:YARAify
Rule name:SUSP_Websites
Author:SECUINFRA Falcon Team
Description:Detects the reference of suspicious sites that might be used to download further malware
TLP:TLP:WHITE
Repository:SIFalcon

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.

Task Information


Task ID:1d8820f0-0648-11f1-82f6-42010aa4000b
File name:pub
Task parameters:ClamAV scan:True
Unpack:True
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:classified
Author:classified
Description:classified
TLP :TLP:GREEN
Rule name:html_auto_download_b64
Author:Tdawg
Description:html auto download
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:classified
Author:classified
Description:classified
TLP :TLP:AMBER
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
TLP:TLP:WHITE
Repository:YARAify
Rule name:SUSP_Websites
Author:SECUINFRA Falcon Team
Description:Detects the reference of suspicious sites that might be used to download further malware
TLP:TLP:WHITE
Repository:SIFalcon

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.