YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 317e49559c133175f22897cdb178ae8bc6898e646a101a243739ac4967e5c67a.

Scan Results


SHA256 hash: 317e49559c133175f22897cdb178ae8bc6898e646a101a243739ac4967e5c67a
File size:237'568 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: 01053aeddce20bdacfba8fd038678e45
SHA1 hash: 628a1dccf1f8cb23ada54f9d439fea3f7a491abd
SHA3-384 hash: bb4716d479b6868fbf00cb99e959a72743c16476a86487d18e4e5185d28aacbe586f64840f4c44f2c22b053dd2019b37
First seen:2026-01-15 15:29:18 UTC
Last seen:Never
Sightings:1
imphash : 58d4df5b618ee57ca79c0b354e3e2c79
ssdeep : 3072:4RLiYu+vf3ybLycGuN+e8+Sjv21gy7pYq8+BvZdRpigtTrS:uZuoSN+5qn7jBxpPrS
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon :n/a

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:f587da8a-f226-11f0-9df4-42010aa4000b
File name:01053aeddce20bdacfba8fd038678e45
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:SecuriteInfo.com.Variant.Babar.68190.UNOFFICIAL

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:Check_OutputDebugStringA_iat
TLP:TLP:WHITE
Repository:
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP:TLP:WHITE
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP:TLP:WHITE
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
TLP:TLP:WHITE
Repository:YARAify
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
TLP:TLP:WHITE
Repository:YARAify
Rule name:INDICATOR_EXE_Packed_VMProtect
Author:ditekSHen
Description:Detects executables packed with VMProtect.
TLP:TLP:WHITE
Repository:diˈtekSHən

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.