YARAify Scan Results
You are viewing the YARAify database entry for the file with the SHA256 hash a164c747743cf9fb2e53cba26141d098e75d21230656e751dc106f685c0dcb24.
Scan Results
| SHA256 hash: | a164c747743cf9fb2e53cba26141d098e75d21230656e751dc106f685c0dcb24 | |
|---|---|---|
| File size: | 192'512 bytes | |
| File download: | Original | |
| MIME type: | application/x-dosexec | |
| MD5 hash: | bc8af00588acdb9729d253b1baff52b4 | |
| SHA1 hash: | f10d5750e67f63fbe3e59669760f5b5016d3e523 | |
| SHA3-384 hash: | e2f56ed60408c1ef89432ca7ac9f565c1505da84dc516fbc97e265b474011767c32a1863ece0c703b09453b45877e0a0 | |
| First seen: | 2022-11-24 19:45:07 UTC | |
| Last seen: | Never | |
| Sightings: | 1 | |
| imphash : | 8455877a10ec898a42c1f01f26551596 | |
| ssdeep : | 3072:GkbScxHZyCo400zJdRPT0WY0TlbRmHArXuLKr2/dF4oy5M1:GkbScxHZyGBzpbQUbRnD2H9y5M1 | |
| TLSH : | T1FC145C42F1CAC4FDE72B2AB110AF3B3797369049072257D3A754DE628927191FE3618E | |
| telfhash : | n/a | |
| gimphash : | n/a | |
| dhash icon : | n/a | |
Tasks
There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.
Task Information
| Task ID: | 7fd77884-6c30-11ed-a71a-42010aa4000b | |
|---|---|---|
| File name: | 10000000.dll | |
| Task parameters: | ClamAV scan: | True |
| Unpack: | False | |
| Share file: | True | |
ClamAV Results
The file matched the following open source and commercial ClamAV rules.
| Signature: | Win.Malware.Mikey-9957914-0 |
|---|
YARA Results
Static Analysis
The following YARA rules matched on the file (static analysis).
| Rule name: | MALWARE_Win_WinDealer |
|---|---|
| Author: | ditekSHen |
| Description: | Detects WinDealer |
| TLP: | TLP:WHITE |
| Repository: | diˈtekSHən |
| Rule name: | meth_stackstrings |
|---|---|
| Author: | Willi Ballenthin |
| TLP: | TLP:WHITE |
| Repository: | YARAify |
| Rule name: | win_windealer_auto |
|---|---|
| Author: | Felix Bilstein - yara-signator at cocacoding dot com |
| Description: | Detects win.windealer. |
| TLP: | TLP:WHITE |
| Repository: | Malpedia |
Unpacker
The following YARA rules matched on the unpacked file.
Disabled by submitter
Unpacked Files
The following files could be unpacked from this sample.
Disabled by submitter