YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 79afdfceebcae4fcdfbb793241eb652536d2f29e787832b76db7dcbadcf68cc9.

Scan Results


SHA256 hash: 79afdfceebcae4fcdfbb793241eb652536d2f29e787832b76db7dcbadcf68cc9
File size:12'042'752 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: 0ea0414c52d544d7bdea97406907369d
SHA1 hash: e3adfba2651fa7e50dfe54e776b69c87ca012700
SHA3-384 hash: fee5d55f02046479da99b48b311e91a2922ffec56fc1ee6ad40034b5d5f22a38b16d4af6aa1048359f9d79c929ce5828
First seen:2026-04-01 16:53:46 UTC
Last seen:Never
Sightings:1
imphash : 9b1a200c894929ce96d61dcad12096ce
ssdeep : 12288:mlraEMM7iLYQH8SwAWbE7Eer5+nmer5+n:mlraERiLYQHNYbE
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon : 9a9ecececee6cee6

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:59a91a7e-2deb-11f1-b47f-42010aa4000b
File name:0ea0414c52d544d7bdea97406907369d
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:SecuriteInfo.com.Trojan.Siggen19.16369.UNOFFICIAL
Signature:Win.Dropper.Tofsee-9982843-0
Signature:Win.Packed.Stop-9982526-0
Signature:Win.Packed.Stop-9982527-0
Signature:Win.Packed.Stop-9982530-0
Signature:Win.Ransomware.Tofsee-9982587-0

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP:TLP:WHITE
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
TLP:TLP:WHITE
Repository:YARAify
Rule name:Windows_Trojan_Smokeloader_ea14b2a5
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.