YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 96ee2f52b092709010b5dc737d002d628f1d31df2b1c4ea7c87893f4c5a36bd6.

Scan Results


SHA256 hash: 96ee2f52b092709010b5dc737d002d628f1d31df2b1c4ea7c87893f4c5a36bd6
File size:1'567'080 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: 0cb1afb9d2efaffeab8c379ced1e0827
SHA1 hash: 6c40ef2764a8ba487acaa3eb0ba3f05f8ea396fd
SHA3-384 hash: b257854d8142672f250c188e7a950120b3165132d83181f0cf6c2f161ad23bb2885e684f41f1b6905be251eb597c2809
First seen:2025-11-21 02:43:27 UTC
Last seen:Never
Sightings:1
imphash : eccb2c48cbcec191d8b774e3447b4047
ssdeep : 1536:HlnClZyscodkNBBCzpZVEkesuek/T4CMgtdfDwULv1hKSl8vH4QmWApW:FnCWscodUBQzLcsut/cgd7DkHrmng
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon : f0cc8e2f37a6c468

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:db631bd9-c683-11f0-adeb-42010aa4000b
File name:0cb1afb9d2efaffeab8c379ced1e0827
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:Detect_NSIS_Nullsoft_Installer
Author:Obscurity Labs LLC
Description:Detects NSIS installers by .ndata section + NSIS header string
TLP:TLP:WHITE

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.