YARAify Scan Results
You are viewing the YARAify database entry for the file with the SHA256 hash 63795a77b6bac601057dad3c5cbf0db1c29ffb531839839db97e08667f1a47af.
Scan Results
| SHA256 hash: | 63795a77b6bac601057dad3c5cbf0db1c29ffb531839839db97e08667f1a47af | |
|---|---|---|
| File size: | 12'810'240 bytes | |
| File download: | Original | |
| MIME type: | application/x-dosexec | |
| MD5 hash: | 801bf8eabae5defcf28cb19177897dbe | |
| SHA1 hash: | 282da4ec5bd32ae01d4b87e458cea43257af5381 | |
| SHA3-384 hash: | c2347650927b4ad97749dc26791e1bdfb9f7d11e6ca3cfa3b566ec4b7bda10292819a17006cddca38bf523db4d40c05a | |
| First seen: | 2022-11-24 19:55:08 UTC | |
| Last seen: | Never | |
| Sightings: | 1 | |
| imphash : | n/a | |
| ssdeep : | 196608:Vuf2r7ZT4v1eOY471t9ekefuf8aeU4aZoRE8Tb9:VufgJEN/wkef+NZoT1 | |
| TLSH : | T1BDD67C15FAE40D21E06AD63884A2865EF6B1FC56173ECACF1254763C0EF3BD12E76492 | |
| telfhash : | n/a | |
| gimphash : | n/a | |
| dhash icon : | n/a | |
Tasks
There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.
Task Information
| Task ID: | e630f4e7-6c31-11ed-a71a-42010aa4000b | |
|---|---|---|
| File name: | 7ffb15d80000.System.ni.dll | |
| Task parameters: | ClamAV scan: | True | 
| Unpack: | False | |
| Share file: | True | |
ClamAV Results
The file matched the following open source and commercial ClamAV rules.
| Signature: | ditekSHen.MALWARE.Win.Trojan.DLAgent02.UNOFFICIAL | 
|---|
YARA Results
Static Analysis
The following YARA rules matched on the file (static analysis).
| Rule name: | BAZT_B5_NOCEXInvalidStream | 
|---|---|
| TLP: | TLP:WHITE | 
| Repository: | MalwareBazaar | 
Unpacker
The following YARA rules matched on the unpacked file.
      Disabled by submitter
    
                    
                Unpacked Files
The following files could be unpacked from this sample.
      Disabled by submitter