YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 8c649bc62bcb9510c4ff798f3c8245e2babb6cf3390debb5e0a3fbf315a7e203.

Scan Results


SHA256 hash: 8c649bc62bcb9510c4ff798f3c8245e2babb6cf3390debb5e0a3fbf315a7e203
File size:542'229 bytes
File download: Original
MIME type:application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
MD5 hash: 09fb7c32d270b9222fc8ced04b1f66f7
SHA1 hash: 336ac1877f141ec1151e086eb067f3c2e33bb5bc
SHA3-384 hash: b77de91d7568e57b2031dc544b37fb4e436d5d05cb97abced4112ac4327133975705c6e1dd70a00e10f6e7b17ae8c5b8
First seen:2026-06-08 19:45:35 UTC
Last seen:Never
Sightings:1
imphash :n/a
ssdeep : 12288:/zEQXu5qdjhWmsXQzfrWnIfZW9Cc6mWxfqKe/ldUV7XU:aUdjhWms8uY/1or/M1U
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon :n/a

Tasks


There are 0 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:9e4ae5fc-6372-11f1-a8a0-42010aa4000b
File name:09fb7c32d270b9222fc8ced04b1f66f7
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:informational_win_ole_protected
Author:Jeff White (karttoon@gmail.com) @noottrak
Description:Identify OLE Project protection within documents.
TLP:TLP:WHITE
Repository:karttoon
Rule name:TA505_Maldoc_21Nov_2
Author:Arkbird_SOLG
Description:invitation (1).xls
Reference:https://twitter.com/58_158_177_102/status/1197432303057637377
TLP:TLP:WHITE
Repository:StrangerealIntel
Rule name:vbaproject_bin
Author:CD_R0M_
Description:{76 62 61 50 72 6f 6a 65 63 74 2e 62 69 6e} is hex for vbaproject.bin. Macros are often used by threat actors. Work in progress - Ran out of time
TLP:TLP:WHITE
Repository:CD-R0M
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques
TLP:TLP:WHITE
Repository:

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.