YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 7dbe52fae971c365b06851b11d80bd2e6ed4d17c8ebf70dd0fd148a1e9382d37.

Scan Results


SHA256 hash: 7dbe52fae971c365b06851b11d80bd2e6ed4d17c8ebf70dd0fd148a1e9382d37
File size:96'052 bytes
File download: Original
MIME type:application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
MD5 hash: 820e96fcf4c639c4318604913e876698
SHA1 hash: 7ea8b326611b6d79282ae4d6876130f3d18b9f76
SHA3-384 hash: 1d3c9fa1df6ec1003dcd0ed6243f3ab0b3f30ce928ea94c3d2fbe016bea0a9126c9569db7a47239d515d4f0961146ee5
First seen:2026-07-20 12:16:16 UTC
Last seen:Never
Sightings:1
imphash :n/a
ssdeep : 1536:JtLbqT3dHzgEbJU+qLBRgSdpgb4pofetuUYLIho2kxBQ/SE:gs4JU+KBXobT2Al2WQ6E
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon :n/a

Tasks


There are 0 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:ce96eeb9-8434-11f1-ad5e-42010aa4000b
File name:820e96fcf4c639c4318604913e876698
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:informational_win_ole_protected
Author:Jeff White (karttoon@gmail.com) @noottrak
Description:Identify OLE Project protection within documents.
TLP:TLP:WHITE
Repository:karttoon
Rule name:vbaproject_bin
Author:CD_R0M_
Description:{76 62 61 50 72 6f 6a 65 63 74 2e 62 69 6e} is hex for vbaproject.bin. Macros are often used by threat actors. Work in progress - Ran out of time
TLP:TLP:WHITE
Repository:CD-R0M

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.