YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash a9d480e25ec6a4a03be9fad5fe9b25c609debf4f38ea74bf0c94430e31c1d63d.

Scan Results


SHA256 hash: a9d480e25ec6a4a03be9fad5fe9b25c609debf4f38ea74bf0c94430e31c1d63d
File size:2'207'744 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: 0a51f8020aea0ea45522185f1c069f46
SHA1 hash: c397626137b6e344c31a22e21c9b9618a2bf1943
SHA3-384 hash: 63880b0ff4bda1d4ce632273b85a94d26fd53f3b98d8d4c76ddde477c17aaa68d093429eeb2ab7d729285aa6b9f9f519
First seen:2025-11-21 02:52:27 UTC
Last seen:Never
Sightings:1
imphash : cf436b2d8382be2acb3225554d5da2ff
ssdeep : 12288:uOpnXc3ajG+hjQKymY8efKCpD7Gj9G6G1qT8nQkCu83L3Wl/np9DBDt3kbE:7xsqjnhMgeiCl7G0nehbGZpbD
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon : b8f0d8d1a061f1c1

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:1d4cfd99-c685-11f0-adeb-42010aa4000b
File name:0a51f8020aea0ea45522185f1c069f46
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:SecuriteInfo.com.Win32.Expiro-2.UNOFFICIAL

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP:TLP:WHITE

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.