YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 4f4b78cac5f32b48eb643ff247db5fe656f2ca9ab1c78b111f9cf1bbabbf64ff.

Scan Results


SHA256 hash: 4f4b78cac5f32b48eb643ff247db5fe656f2ca9ab1c78b111f9cf1bbabbf64ff
File size:1'123'872 bytes
File download: Original Unpacked
MIME type:application/x-dosexec
MD5 hash: 03622bf17c12efc146364902a3754405
SHA1 hash: ca162fdb85c2861d3cbab737653ee55699db0547
SHA3-384 hash: 6ddde886dd993e18eef4522c2f98b813809e01b73ecba527cd5df13dbdfd1404ad0b9778dc77d20c5ce1fa83880e8e7f
First seen:2026-03-11 15:38:37 UTC
Last seen:Never
Sightings:1
imphash : f34d5f2d4577ed6d9ceec516c1f5a744
ssdeep : 24576:MUB9jH0g+2DR7BWYpBdo44PUdmOBWNpXb:HV7V7K87SL
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon : c4ccb392f1f192cc

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:5f7838a2-1d60-11f1-b47f-42010aa4000b
File name:03622bf17c12efc146364902a3754405
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:NET
Author:malware-lu
TLP:TLP:WHITE
Repository:
Rule name:PE_Digital_Certificate
Author:albertzsigovits
TLP:TLP:WHITE
Repository:
Rule name:pe_imphash
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:Runtime_Broker_Variant_1
Author:Sn0wFr0$t
Description:Detecting malicious Runtime Broker
TLP:TLP:WHITE
Repository:YARAify
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
TLP:TLP:WHITE
Repository:YARAify
Rule name:telebot_framework
Author:vietdx.mb
TLP:TLP:WHITE
Repository:YARAify
Rule name:classified
Author:classified
Description:classified
TLP :TLP:AMBER

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.