YARAify Scan Results
You are viewing the YARAify database entry for the file with the SHA256 hash 3f67f08eba96273e307c9fdbc1463af3929c472fe27106bfb9513fcb56dbdae8.
Scan Results
| SHA256 hash: | 3f67f08eba96273e307c9fdbc1463af3929c472fe27106bfb9513fcb56dbdae8 | |
|---|---|---|
| File size: | 16'384 bytes | |
| File download: | Original | |
| MIME type: | application/x-dosexec | |
| MD5 hash: | 05d4118d2262ea5ccb137d5a7ffe72de | |
| SHA1 hash: | 42ee286f1f51b21fdc1619d78042a4c2de9bccf2 | |
| SHA3-384 hash: | 166a595c901eabf36495c2c6bcef21e84a800115409a5ec33ed37cb830d23cf58b88ba46f8f8db1442d45f0d21cb7ac2 | |
| First seen: | 2025-11-21 02:57:40 UTC | |
| Last seen: | Never | |
| Sightings: | 1 | |
| imphash : | 87bed5a7cba00c7e1f4015f1bdae2183 | |
| ssdeep : | 48:2PBii7XH83kBTXMqo6rPRLKORYgAMjDEv8Dld1tp78Bl6Wi+5pv/OjFDSXlC/Hjh:OvUkTK8Y9Hglftls6x+/mDS1sj4sP | |
| TLSH : | n/a | |
| telfhash : | n/a | |
| gimphash : | n/a | |
| dhash icon : | c9949489945cc989 | |
Tasks
There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.
Task Information
| Task ID: | d7c8592f-c685-11f0-adeb-42010aa4000b | |
|---|---|---|
| File name: | 05d4118d2262ea5ccb137d5a7ffe72de | |
| Task parameters: | ClamAV scan: | True |
| Unpack: | False | |
| Share file: | True | |
ClamAV Results
The file matched the following open source and commercial ClamAV rules.
| Signature: | PUA.Win.Packer.FSG-1 |
|---|
| Signature: | PUA.Win.Packer.Fsg-17 |
|---|
| Signature: | PUA.Win.Packer.Fsg-40 |
|---|
| Signature: | PUA.Win.Packer.Fsg-63 |
|---|
| Signature: | PUA.Win.Packer.Fsg-89 |
|---|
YARA Results
Static Analysis
The following YARA rules matched on the file (static analysis).
| Rule name: | FSGv133 |
|---|---|
| Author: | malware-lu |
| TLP: | TLP:WHITE |
| Repository: |
| Rule name: | FSGv133Engdulekxt |
|---|---|
| Author: | malware-lu |
| TLP: | TLP:WHITE |
| Repository: |
Unpacker
The following YARA rules matched on the unpacked file.
Disabled by submitter
Unpacked Files
The following files could be unpacked from this sample.
Disabled by submitter