YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash b1f2bef25c79e1691c57be3fb882576e060b0f99bcc2f01ac38691fefc38deae.

Scan Results


SHA256 hash: b1f2bef25c79e1691c57be3fb882576e060b0f99bcc2f01ac38691fefc38deae
File size:1'298'432 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: 144be983d49c878b231cf04870765342
SHA1 hash: dc9a1d58112a41339915f0d5957618acc4cefdff
SHA3-384 hash: 3b7c78fa70112d40f070d5fd8d047579971fe89bc09a80538eb33830602bc9861ea272ffd52351e69dff4d65ea1d10c6
First seen:2025-11-21 02:45:49 UTC
Last seen:Never
Sightings:1
imphash : cf79fce90fced31836373f3e48251a5d
ssdeep : 12288:QYiJw/9Rrw0R1u4V/0YG3wx6EcJHUEhPUotFZr+1izHGNe8jKk34z:Qq/TwSfVcYG3K/cJHlnFR+IGNe8j3Iz
TLSH : T13C5523D2158955F1EAFD003E86364428B1886E2C9B6659E3D2403D1FA13DFEFCF38566
telfhash :n/a
gimphash :n/a
dhash icon :n/a

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:30507589-c684-11f0-adeb-42010aa4000b
File name:144be983d49c878b231cf04870765342
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:SecuriteInfo.com.Win32.Expiro-3.UNOFFICIAL
Signature:SecuriteInfo.com.Win32.Expiro.153.14732.17738.UNOFFICIAL
Signature:Win.Trojan.Generic-10039872-0

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP:TLP:WHITE
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
TLP:TLP:WHITE
Repository:YARAify

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.