YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 5151994bf34f651225b1be43ad72295729ec09f4410ba6ef8380d5432b06310d.

Scan Results


SHA256 hash: 5151994bf34f651225b1be43ad72295729ec09f4410ba6ef8380d5432b06310d
File size:253'952 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: 75faaeb216212acf4b4c9d7c48b588a0
SHA1 hash: 7a40df99e08b581597b082f071735c458d1f629f
SHA3-384 hash: 892f594cb01efa1f649c77754e02e0478c5f7625b92342fb34509767cc0638a32a87a2dbe1b19ff7cc66051c4fac9204
First seen:2025-11-21 02:49:21 UTC
Last seen:Never
Sightings:1
imphash : 664a2b324a8857d7d4ab8815c756b5bb
ssdeep : 3072:M2wk3EgRyqZdGGQNyOatAJOtCjGIlV8LOq7vVvz:0k3fcqZd8MOaN8ijdr
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon :n/a

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:ae99c8e9-c684-11f0-adeb-42010aa4000b
File name:34d0000.exe
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Win.Malware.Generic-10019342-0
Signature:Win.Packed.Copak-10019613-0
Signature:Win.Packed.Copak-10024554-0
Signature:Win.Packed.Copak-10025740-0
Signature:Win.Packed.Copak-10028743-0
Signature:Win.Packed.Generic-10021616-0
Signature:Win.Packed.Lazy-10023691-0

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
TLP:TLP:WHITE
Repository:YARAify
Rule name:pe_detect_tls_callbacks
Author:
TLP:TLP:WHITE
Repository:YARAify
Rule name:Windows_Generic_Threat_fca7f863
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.