YARAify Scan Results
You are viewing the YARAify database entry for the file with the SHA256 hash 513284d4919eee5f62edfab032aa49c350e0c5927de8a0f21fe6d0feddf7dfff.
Scan Results
| SHA256 hash: | 513284d4919eee5f62edfab032aa49c350e0c5927de8a0f21fe6d0feddf7dfff | |
|---|---|---|
| File size: | 954'054 bytes | |
| File download: | Original | |
| MIME type: | text/html | |
| MD5 hash: | b65cd83648db0a18764b1994cef19d4b | |
| SHA1 hash: | e5e733335538f70d18131cfc347d3575cbf1121d | |
| SHA3-384 hash: | c1c7fbaf5e150eed8b7a31a17c83994348485baa926c5c860aa173e26025b7a2e304e9c3c7d981155ae925b52b56aefa | |
| First seen: | 2026-09-19 11:22:06 UTC | |
| Last seen: | 2026-09-19 11:25:03 UTC | |
| Sightings: | 4 | |
| imphash : | n/a | |
| ssdeep : | 6144:YCQq3j6/8+Gq3j6/8+Iq3j6/8+tq3j6/8+eq3j6/8++ISQISNt1/HabHS2whJ22m:YCWIrabHSLhk2W3cpWN3P3J | |
| TLSH : | n/a | |
| telfhash : | n/a | |
| gimphash : | n/a | |
| dhash icon : | n/a | |
Tasks
There are 4 tasks on YARAify for this particular file. The 10 most recent ones are shown below.
Task Information
| Task ID: | c204ff37-b41c-11f1-a0cd-42010aa4000b | |
|---|---|---|
| File name: | download | |
| Task parameters: | ClamAV scan: | True |
| Unpack: | True | |
| Share file: | True | |
ClamAV Results
The file matched the following open source and commercial ClamAV rules.
YARA Results
Static Analysis
The following YARA rules matched on the file (static analysis).
| Rule name: | classified |
|---|---|
| Author: | classified |
| Description: | classified |
| TLP : | TLP:AMBER |
| Rule name: | classified |
|---|---|
| Author: | classified |
| Description: | classified |
| TLP : | TLP:AMBER |
| Rule name: | Sus_CMD_Powershell_Usage |
|---|---|
| Author: | XiAnzheng |
| Description: | May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP) |
| TLP: | TLP:WHITE |
| Repository: | YARAify |
| Rule name: | SUSP_HTML_XMLHTTP_Redirect_Kit |
|---|---|
| Author: | Marjoriefort |
| Description: | HTML avec exfiltration XMLHTTP + redirection window.location - kit phishing frais |
| Reference: | Veille fraicheur 2026-09-14 / cluster HTML |
| TLP: | TLP:WHITE |
| Repository: | YARAify |
| Rule name: | test_Malaysia |
|---|---|
| Author: | rectifyq |
| Description: | Detects file containing malaysia string |
| TLP: | TLP:WHITE |
| Repository: | YARAify |
Unpacker
The following YARA rules matched on the unpacked file.
Unpacked Files
The following files could be unpacked from this sample.
Task Information
| Task ID: | 9eecd87d-b41c-11f1-a0cd-42010aa4000b | |
|---|---|---|
| File name: | download | |
| Task parameters: | ClamAV scan: | True |
| Unpack: | True | |
| Share file: | True | |
ClamAV Results
The file matched the following open source and commercial ClamAV rules.
YARA Results
Static Analysis
The following YARA rules matched on the file (static analysis).
| Rule name: | classified |
|---|---|
| Author: | classified |
| Description: | classified |
| TLP : | TLP:AMBER |
| Rule name: | classified |
|---|---|
| Author: | classified |
| Description: | classified |
| TLP : | TLP:AMBER |
| Rule name: | Sus_CMD_Powershell_Usage |
|---|---|
| Author: | XiAnzheng |
| Description: | May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP) |
| TLP: | TLP:WHITE |
| Repository: | YARAify |
| Rule name: | SUSP_HTML_XMLHTTP_Redirect_Kit |
|---|---|
| Author: | Marjoriefort |
| Description: | HTML avec exfiltration XMLHTTP + redirection window.location - kit phishing frais |
| Reference: | Veille fraicheur 2026-09-14 / cluster HTML |
| TLP: | TLP:WHITE |
| Repository: | YARAify |
| Rule name: | test_Malaysia |
|---|---|
| Author: | rectifyq |
| Description: | Detects file containing malaysia string |
| TLP: | TLP:WHITE |
| Repository: | YARAify |
Unpacker
The following YARA rules matched on the unpacked file.
Unpacked Files
The following files could be unpacked from this sample.
Task Information
| Task ID: | 7b0b990f-b41c-11f1-a0cd-42010aa4000b | |
|---|---|---|
| File name: | download | |
| Task parameters: | ClamAV scan: | True |
| Unpack: | True | |
| Share file: | True | |
ClamAV Results
The file matched the following open source and commercial ClamAV rules.
YARA Results
Static Analysis
The following YARA rules matched on the file (static analysis).
| Rule name: | classified |
|---|---|
| Author: | classified |
| Description: | classified |
| TLP : | TLP:AMBER |
| Rule name: | classified |
|---|---|
| Author: | classified |
| Description: | classified |
| TLP : | TLP:AMBER |
| Rule name: | Sus_CMD_Powershell_Usage |
|---|---|
| Author: | XiAnzheng |
| Description: | May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP) |
| TLP: | TLP:WHITE |
| Repository: | YARAify |
| Rule name: | SUSP_HTML_XMLHTTP_Redirect_Kit |
|---|---|
| Author: | Marjoriefort |
| Description: | HTML avec exfiltration XMLHTTP + redirection window.location - kit phishing frais |
| Reference: | Veille fraicheur 2026-09-14 / cluster HTML |
| TLP: | TLP:WHITE |
| Repository: | YARAify |
| Rule name: | test_Malaysia |
|---|---|
| Author: | rectifyq |
| Description: | Detects file containing malaysia string |
| TLP: | TLP:WHITE |
| Repository: | YARAify |
Unpacker
The following YARA rules matched on the unpacked file.
Unpacked Files
The following files could be unpacked from this sample.
Task Information
| Task ID: | 5887801c-b41c-11f1-a0cd-42010aa4000b | |
|---|---|---|
| File name: | download | |
| Task parameters: | ClamAV scan: | True |
| Unpack: | True | |
| Share file: | True | |
ClamAV Results
The file matched the following open source and commercial ClamAV rules.
YARA Results
Static Analysis
The following YARA rules matched on the file (static analysis).
| Rule name: | classified |
|---|---|
| Author: | classified |
| Description: | classified |
| TLP : | TLP:AMBER |
| Rule name: | classified |
|---|---|
| Author: | classified |
| Description: | classified |
| TLP : | TLP:AMBER |
| Rule name: | Sus_CMD_Powershell_Usage |
|---|---|
| Author: | XiAnzheng |
| Description: | May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP) |
| TLP: | TLP:WHITE |
| Repository: | YARAify |
| Rule name: | SUSP_HTML_XMLHTTP_Redirect_Kit |
|---|---|
| Author: | Marjoriefort |
| Description: | HTML avec exfiltration XMLHTTP + redirection window.location - kit phishing frais |
| Reference: | Veille fraicheur 2026-09-14 / cluster HTML |
| TLP: | TLP:WHITE |
| Repository: | YARAify |
| Rule name: | test_Malaysia |
|---|---|
| Author: | rectifyq |
| Description: | Detects file containing malaysia string |
| TLP: | TLP:WHITE |
| Repository: | YARAify |
Unpacker
The following YARA rules matched on the unpacked file.
Unpacked Files
The following files could be unpacked from this sample.