YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 342a857536b12e82e2ffa377d2646e02173646aff6ee7b2499753e69855f0e49.

Scan Results


SHA256 hash: 342a857536b12e82e2ffa377d2646e02173646aff6ee7b2499753e69855f0e49
File size:2'604'539 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: edc38bc1d18f516a9fc47cb6bc0fd39f
SHA1 hash: 3ce15ec091523255424173467f58acf0db36f40c
SHA3-384 hash: 45a9dd04a368db09cd058466fb658bacc7fef301514eabb518e947e94dcc644c8fcb4aa3318f6a93145397141a4b8112
First seen:2026-03-14 15:29:59 UTC
Last seen:Never
Sightings:1
imphash : 98b62dfdc3e59f86e2d70c4065393d47
ssdeep : 24576:Re6u/O8D3RSJ0YKkytHy3jieQ8xc35K4Za5mcmL1BGRmYywKceokaLPe:ROm8zYEgGhm8K4Z2zmLCqvo/Le
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon : 71f0b28a8cc8e061

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:a9b942e3-1fba-11f1-b47f-42010aa4000b
File name:edc38bc1d18f516a9fc47cb6bc0fd39f
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:PUA.Win.Packer.AcprotectUltraprotect-1
Signature:Win.Trojan.CosmicDuke-3

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:CosmicDuke
TLP:TLP:WHITE
Repository:Intezer
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP:TLP:WHITE
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP:TLP:WHITE
Rule name:detect_apt_APT29
Author:@malgamy12
Description:detect_APT32_malware
TLP:TLP:WHITE
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
TLP:TLP:WHITE
Repository:YARAify
Rule name:UPX20030XMarkusOberhumerLaszloMolnarJohnReiser
Author:malware-lu
TLP:TLP:WHITE
Repository:
Rule name:UPXV200V290MarkusOberhumerLaszloMolnarJohnReiser
Author:malware-lu
TLP:TLP:WHITE
Repository:
Rule name:UPXv20MarkusLaszloReiser
Author:malware-lu
TLP:TLP:WHITE
Repository:
Rule name:win_cosmicduke_w0
Author:@malgamy12
Description:detect cosmicduke
TLP:TLP:WHITE
Repository:Malpedia

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.