YARAify Scan Results
You are viewing the YARAify database entry for the file with the SHA256 hash 5fcded4696b0c18569db329ec139d8cb0e0c41b05e877eef3e4ba198e6b2c821.
Scan Results
| SHA256 hash: | 5fcded4696b0c18569db329ec139d8cb0e0c41b05e877eef3e4ba198e6b2c821 | |
|---|---|---|
| File size: | 69'058'842 bytes | |
| File download: | Original | |
| MIME type: | application/x-dosexec | |
| MD5 hash: | b052f79d59e0319078925ebd45e03c08 | |
| SHA1 hash: | 4c7d33a28419d5d119aab007d3812a481daeb9b2 | |
| SHA3-384 hash: | 89a03f16a06ae32d0074a2e8ae64306635345164db66ad8042c3a2486f74a97a3244a875cac484bd73207ab0496e4724 | |
| First seen: | 2026-07-20 12:27:17 UTC | |
| Last seen: | Never | |
| Sightings: | 1 | |
| imphash : | b34f154ec913d2d2c435cbd644e91687 | |
| ssdeep : | 1572864:x4gPXMo7NT612by7rYjemXIdoddqdpCoJFsGLdhNkdG9czNIKs7:x4AcQJ612bMr1m4doKrCRYjNkG9WIKs7 | |
| TLSH : | n/a | |
| telfhash : | n/a | |
| gimphash : | n/a | |
| dhash icon : | 304a4f4f4f0f0400 | |
Tasks
There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.
Task Information
| Task ID: | 58fece4c-8436-11f1-ad5e-42010aa4000b | |
|---|---|---|
| File name: | b052f79d59e0319078925ebd45e03c08 | |
| Task parameters: | ClamAV scan: | True |
| Unpack: | False | |
| Share file: | True | |
ClamAV Results
The file matched the following open source and commercial ClamAV rules.
No matches
YARA Results
Static Analysis
The following YARA rules matched on the file (static analysis).
| Rule name: | Detect_NSIS_Nullsoft_Installer |
|---|---|
| Author: | Obscurity Labs LLC |
| Description: | Detects NSIS installers by .ndata section + NSIS header string |
| TLP: | TLP:WHITE |
| Rule name: | GenesisStealer_Installer_NSIS_MaaS_Template |
|---|---|
| Author: | n3r |
| Description: | GenesisStealer NSIS installer (MaaS template). Imphash-based broad detector - also catches ScarfaceStealer / RemusStealer / VoidStealer variants sharing the same installer shell. |
| TLP: | TLP:WHITE |
| Repository: | YARAify |
| Rule name: | NSIS |
|---|---|
| Author: | kevoreilly |
| Description: | NSIS Integrity Check function |
| TLP: | TLP:WHITE |
| Repository: | CAPE |
Unpacker
The following YARA rules matched on the unpacked file.
Disabled by submitter
Unpacked Files
The following files could be unpacked from this sample.
Disabled by submitter