YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash b415ae8049eae06a515b7d6842e8b62a3c881d75b352ef6d81edfed4aad7340a.

Scan Results


SHA256 hash: b415ae8049eae06a515b7d6842e8b62a3c881d75b352ef6d81edfed4aad7340a
File size:2'000'010 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: b390e7a695b717e51ed7ce9f1466a7b4
SHA1 hash: e269af280fddd6f0649018877cf85d67a4167865
SHA3-384 hash: ea6419d04133a0eeadc31801e817d89fe262a6190f1f5d06098e6ca877ac7d58951ae6f3bcb1bd49c69853913c049536
First seen:2025-12-15 22:46:49 UTC
Last seen:Never
Sightings:1
imphash : 19d9a4c688b75c194767be89d3d7813b
ssdeep : 49152:gFx9+CVD2SouuFOnYIsEW7IMzHRX4YyRgFr:cx9vuFOnYHEWmgF
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon : 4d91d3f3d9cc750b

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:f1104194-da07-11f0-9df4-42010aa4000b
File name:400000.819f13a3-d0b8-46bb-82c3-a222cd057ba6.exe
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:APT_Sandworm_ArguePatch_Apr_2022_1
Author:Arkbird_SOLG
Description:Detect ArguePatch loader used by Sandworm group for load CaddyWiper
Reference:https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/
TLP:TLP:WHITE
Rule name:Check_OutputDebugStringA_iat
TLP:TLP:WHITE
Repository:
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP:TLP:WHITE
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP:TLP:WHITE
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
TLP:TLP:WHITE
Repository:YARAify
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
TLP:TLP:WHITE
Repository:YARAify
Rule name:pe_detect_tls_callbacks
Author:
TLP:TLP:WHITE
Repository:YARAify

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.