YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 38966be86c8dd4c7975c9b331d3fc58fd31d801c01686d6a554d512f4c873a7b.

Scan Results


SHA256 hash: 38966be86c8dd4c7975c9b331d3fc58fd31d801c01686d6a554d512f4c873a7b
File size:294'912 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: 13a0a4941e05a85935d71944a64deac0
SHA1 hash: 13d52b0af3d705a7490383924b9b9beabab64f1b
SHA3-384 hash: 4b1572f1bd150a19d806c52f8ed23fb65816d495c73bb0a20cb337637852417756ace0d166217bcb2c1f06d787c7dcb3
First seen:2025-11-21 02:55:22 UTC
Last seen:Never
Sightings:1
imphash : c70e6717ce05fc35e3d0168c8fdea813
ssdeep : 6144:VNHLf3ZosY0SflGE9WRz59M0bNEIFGUR80KgsP:3Lf3ZosY0SSRt2WNQL
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon :n/a

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:85df019f-c685-11f0-adeb-42010aa4000b
File name:13a0a4941e05a85935d71944a64deac0
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:PUA.Win.Packer.AcprotectUltraprotect-1
Signature:PUA.Win.Packer.Embedpe-3
Signature:Win.Worm.Mytob-203

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
TLP:TLP:WHITE
Repository:YARAify

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.