YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 850bd3eb1b38e3eda237fab19ee2545343c34ba1897edb7c5020a26bd61331bb.

Scan Results


SHA256 hash: 850bd3eb1b38e3eda237fab19ee2545343c34ba1897edb7c5020a26bd61331bb
File size:1'192'448 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: 308eb7ea955276c5057c5fe0703c8bc3
SHA1 hash: cc76c38c60cbc24d028e9b3533020d2dbcb3a7ae
SHA3-384 hash: 7d5f67182369c535485f2c2a82d31adebbfb196db0d56f7549da9eea667c791183fa38705ac3e298499119cbcf135d2c
First seen:2025-12-16 23:35:15 UTC
Last seen:Never
Sightings:1
imphash : bdf838c95fdf68e5cf5af880ac9ad833
ssdeep : 24576:HhJBpLX09RO9gpdGXUb9oz4zVzM4duT3x4onxYflnSVJ1EuDF5/39Ocd:bL6Iud/s4JI4duTx4qxYtSVnEuDL9n
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon :n/a

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:dff96d37-dad7-11f0-9df4-42010aa4000b
File name:7ffa88590000.clrjit.dll
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:Check_OutputDebugStringA_iat
TLP:TLP:WHITE
Repository:
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP:TLP:WHITE
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
TLP:TLP:WHITE
Repository:YARAify
Rule name:classified
Author:classified
Description:classified
Reference:classified
TLP :TLP:AMBER
Rule name:NET
Author:malware-lu
TLP:TLP:WHITE
Repository:
Rule name:pe_detect_tls_callbacks
Author:
TLP:TLP:WHITE
Repository:YARAify

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.