🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 56ee307d67450b05e8ce1318bb21e2ff2c047f04047bbe378c33d7784fdc9d57.

Scan Results


SHA256 hash: 56ee307d67450b05e8ce1318bb21e2ff2c047f04047bbe378c33d7784fdc9d57
File size:61'440 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: 36811af0ad8b68a8d67aace2fe5e3652
SHA1 hash: 27ee842b5c9d8c3d33e618fed939925d538dd092
SHA3-384 hash: d1ab9f3099d14199087c6cf1fa990ef7d34188428d01b7766a230ac26c5d734b9f2bd9e41dde6c183fb4a3017aa35d7a
First seen:2026-09-19 11:48:27 UTC
Last seen:Never
Sightings:1
imphash : 7f2fef7dadf7ad156d23052e80e872c3
ssdeep : 768:cMkDLkf5Qj7tyFeyGvIGjSplOBO7gqzpcm2GUO8zCXzwoedaAvt7F52o:EL4Q1yFepvxO7gq7YO8zCD9edrZEo
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon :n/a

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:0719b025-b420-11f1-a0cd-42010aa4000b
File name:10000000.dll
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:PUA.Win.Packer.Chinaprotect-1
Signature:Win.Trojan.BlackEnergy2-1

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:blackenergy3_installer
Author:Mike Schladt
Description:Matches unique code block for import name construction
Reference:https://www.f-secure.com/documents/996508/1030745/blackenergy_whitepaper.pdf
TLP:TLP:WHITE
Repository:Neo23x0
Rule name:CMD_Ping_Localhost
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP:TLP:WHITE
Rule name:Detect_PowerShell_Obfuscation
Author:daniyyell
Description:Detects obfuscated PowerShell commands commonly used in malicious scripts.
TLP:TLP:WHITE
Repository:YARAify
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
TLP:TLP:WHITE
Repository:YARAify
Rule name:IMPLANT_4_v10
Author:US CERT
Description:BlackEnergy / Voodoo Bear Implant by APT28
Reference:https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE
TLP:TLP:WHITE
Repository:Neo23x0
Rule name:IMPLANT_4_v13
Author:US CERT
Description:BlackEnergy / Voodoo Bear Implant by APT28
Reference:https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE
TLP:TLP:WHITE
Repository:Neo23x0
Rule name:IMPLANT_4_v2
Author:US CERT
Description:BlackEnergy / Voodoo Bear Implant by APT28
Reference:https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE
TLP:TLP:WHITE
Repository:Neo23x0
Rule name:IMPLANT_4_v5
Author:US CERT
Description:BlackEnergy / Voodoo Bear Implant by APT28
Reference:https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE
TLP:TLP:WHITE
Repository:Neo23x0
Rule name:IMPLANT_4_v7
Author:US CERT
Description:BlackEnergy / Voodoo Bear Implant by APT28
Reference:https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE
TLP:TLP:WHITE
Repository:Neo23x0
Rule name:malware_shellcode_hash
Author:JPCERT/CC Incident Response Group
Description:detect shellcode api hash value
TLP:TLP:WHITE
Repository:JPCERTCC
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.
TLP:TLP:WHITE
Repository:YARAify

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.