YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 475a63718904b28dddd535d90f3cbf1966f26f86e08f694c97ceb8250d8d2173.

Scan Results


SHA256 hash: 475a63718904b28dddd535d90f3cbf1966f26f86e08f694c97ceb8250d8d2173
File size:172'072 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: 0b97731fbf3267e8fe0c4fc315196e87
SHA1 hash: a4bda15f299b7414b1b21611dde84b1f9534d3d7
SHA3-384 hash: 0569a2d096ca3d8760e83da0626d07c141dd9046125f3de634cbc2547c19f292c7709a51cba45f71638238c2429432a4
First seen:2025-11-21 00:00:18 UTC
Last seen:Never
Sightings:1
imphash : 74abd25a7ee82ed1dba6d64d69639ecd
ssdeep : 3072:ld/dIyYaurgKrX89KnnEmE7Z8lUj1LwvSkX:b/XIrLrMsEmS8Clg
TLSH : T19EF35B57B3E501BBE4768238C8631A06D7B678510771CBAF43A4526A2F273919F3EF60
telfhash :n/a
gimphash :n/a
dhash icon :n/a

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:111e1b6c-c66d-11f0-adeb-42010aa4000b
File name:0b97731fbf3267e8fe0c4fc315196e87
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
TLP:TLP:WHITE
Repository:YARAify
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP:TLP:WHITE
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
TLP:TLP:WHITE
Repository:YARAify
Rule name:maldoc_getEIP_method_1
Author:Didier Stevens (https://DidierStevens.com)
TLP:TLP:WHITE
Repository:
Rule name:malware_shellcode_hash
Author:JPCERT/CC Incident Response Group
Description:detect shellcode api hash value
TLP:TLP:WHITE
Repository:JPCERTCC
Rule name:meth_get_eip
Author:Willi Ballenthin
TLP:TLP:WHITE
Repository:YARAify

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.