YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 370f6d63219acbc882c0d62e210de93065f4db761a2eaf854615f8ab271cd334.

Scan Results


SHA256 hash: 370f6d63219acbc882c0d62e210de93065f4db761a2eaf854615f8ab271cd334
File size:49'092 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: 183fcdde2c094ae53dd3050362337c76
SHA1 hash: d0b2c88e1e40e70fb5315c02d634f81dff8b33d7
SHA3-384 hash: ebc7434d6551d33d09b73116c42c815f8e1096687e6db5fe100b22fded8840148a760d8e4293d4b594824c27bd2bb2bd
First seen:2025-11-20 23:56:47 UTC
Last seen:Never
Sightings:1
imphash : 8af636ff0e5e0c6ac0997c0fa5292878
ssdeep : 384:R2Ni92NigRpKAlLy5j9XVrED1qzGDzeiUW/3U8OjZfJmuU4:RAAAJRpKANS/PJiE82fJD
TLSH : T1402344A34FED4564CAE1567110363F2BA328AC0201FC5C647E7AA846FF5FA85A7345B3
telfhash :n/a
gimphash :n/a
dhash icon :n/a

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:933f8cc9-c66c-11f0-adeb-42010aa4000b
File name:183fcdde2c094ae53dd3050362337c76
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Win.Packed.Kelihos-9652313-0

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:Windows_Generic_Threat_bbf2a354
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.