YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 495358cc3050daa6484cc5e54213889de12afa7c4117a07a3afd9c5ef0d5fd53.

Scan Results


SHA256 hash: 495358cc3050daa6484cc5e54213889de12afa7c4117a07a3afd9c5ef0d5fd53
File size:188'416 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: 26eccf0902d4c1704ee3dcd98ebab644
SHA1 hash: a319ec8425b752a3aad7a249799e8c9eccc7a4e3
SHA3-384 hash: 7c978cc26a288c9e069bb3cc572c727689d01b6aaddf2f96dee1c6ed1b378332debb34ad57fcc287ba79f40c8360102f
First seen:2026-02-11 17:30:02 UTC
Last seen:Never
Sightings:1
imphash :n/a
ssdeep : 3072:2xff9fojQQkRZNK6C+/8SB5g2vnqX0Gu7rS:2x1oIjNK+8+5g2PqX0Gu7r
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon : 1003873db9313e16

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:4c32f662-076f-11f1-82f6-42010aa4000b
File name:400000.1565982865b10fb8d8c11a99e6fb2e3a.exe
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Win.Malware.Zusy-6878655-0

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:SEH__vba
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP:TLP:WHITE
Rule name:telebot_framework
Author:vietdx.mb
TLP:TLP:WHITE
Repository:YARAify

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.