YARAify Scan Results
You are viewing the YARAify database entry for the file with the SHA256 hash 63cb1fc9efaf069d651b212625a7b529761d2c1128a9cf95e7bf9e71457d7de4.
Scan Results
| SHA256 hash: | 63cb1fc9efaf069d651b212625a7b529761d2c1128a9cf95e7bf9e71457d7de4 | |
|---|---|---|
| File size: | 380'928 bytes | |
| File download: | Original | |
| MIME type: | application/x-dosexec | |
| MD5 hash: | 17bc36a286b14e9f2265bd6d116c3a80 | |
| SHA1 hash: | 1faee4df104ef07ed1c165a3d3dc6e21e701f519 | |
| SHA3-384 hash: | 44cdf0e4d574b642bce53b937424af07b4eb346a6691e2129a42bcf88fa97157568040ea4053f3298569f79729285a1b | |
| First seen: | 2025-11-21 02:49:15 UTC | |
| Last seen: | Never | |
| Sightings: | 1 | |
| imphash : | 08b656407b8d307979dc72c3fcc683a8 | |
| ssdeep : | 6144:TL+rqKbSOkbS/bSgZ16iW/ynJP1Ypy68gf+sG/xawrI7qVcNaMZkHdesa1Xko6u4:TLy9C0fawJP1P4vG/cciqakMZTsaNB6F | |
| TLSH : | T1AA842336C1427964F91E4DB20FE97CC585A320BC9CAA5F342E21AEE7DC1B761CD22856 | |
| telfhash : | n/a | |
| gimphash : | n/a | |
| dhash icon : | n/a | |
Tasks
There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.
Task Information
| Task ID: | aae23d81-c684-11f0-adeb-42010aa4000b | |
|---|---|---|
| File name: | 17bc36a286b14e9f2265bd6d116c3a80 | |
| Task parameters: | ClamAV scan: | True |
| Unpack: | False | |
| Share file: | True | |
ClamAV Results
The file matched the following open source and commercial ClamAV rules.
| Signature: | MiscreantPunch.SingleXOR.EXE.5.UNOFFICIAL |
|---|
| Signature: | SecuriteInfo.com.Win32.HLLW.Randex.45071.14752.20683.UNOFFICIAL |
|---|
| Signature: | Win.Worm.Socks-10 |
|---|
| Signature: | Win.Worm.Socks-9892592-0 |
|---|
YARA Results
Static Analysis
The following YARA rules matched on the file (static analysis).
| Rule name: | upx_3 |
|---|---|
| Author: | Kevin Falcoz |
| Description: | UPX 3.X |
| TLP: | TLP:WHITE |
| Rule name: | upx_largefile |
|---|---|
| Author: | k3nr9 |
| TLP: | TLP:WHITE |
| Repository: | YARAify |
| Rule name: | UPX290LZMAMarkusOberhumerLaszloMolnarJohnReiser |
|---|---|
| Author: | malware-lu |
| TLP: | TLP:WHITE |
| Repository: |
| Rule name: | UPXV200V290MarkusOberhumerLaszloMolnarJohnReiser |
|---|---|
| Author: | malware-lu |
| TLP: | TLP:WHITE |
| Repository: |
| Rule name: | UPXv20MarkusLaszloReiser |
|---|---|
| Author: | malware-lu |
| TLP: | TLP:WHITE |
| Repository: |
| Rule name: | vmdetect |
|---|---|
| Author: | nex |
| Description: | Possibly employs anti-virtualization techniques |
| TLP: | TLP:WHITE |
| Repository: |
| Rule name: | classified |
|---|---|
| Author: | classified |
| Description: | classified |
| TLP : | TLP:AMBER |
| Rule name: | win_upx_packed |
|---|---|
| Author: | Reedus0 |
| Description: | Rule for detecting UPX packed malware |
| TLP: | TLP:WHITE |
| Repository: | YARAify |
Unpacker
The following YARA rules matched on the unpacked file.
Disabled by submitter
Unpacked Files
The following files could be unpacked from this sample.
Disabled by submitter