YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash b57ac2bc3d67bb738a830a8a5743772bf77e3e08cb27bb81e07828b17fff93c2.

Scan Results


SHA256 hash: b57ac2bc3d67bb738a830a8a5743772bf77e3e08cb27bb81e07828b17fff93c2
File size:11'599'872 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: d0e3cbaee6077e2831e91507e3ee9be1
SHA1 hash: de5cac69c0883b6db0ef23badbe6b6b07b04a47e
SHA3-384 hash: caf4911553ff1f83d051710fcbfc626fb5c3931b7ad5a879b6c4efc8347a3b77be8fbe38958f44dcb8489a44dda5a43b
First seen:2026-08-10 06:44:14 UTC
Last seen:Never
Sightings:1
imphash : f34d5f2d4577ed6d9ceec516c1f5a744
ssdeep : 98304:cS2dN8sHf7pKato808O6v1Cx2j2rvuixEPTjM2GjjnbXKmMTvKetv:R2dmsZRv1Cx2j2rvLxMjsvb4K2
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon : e0a3835010343030

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:e6c9d681-9486-11f1-bf07-42010aa4000b
File name:910000.1f50e7516db47322175391759bc83c78.exe
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:PUA.Win.Packer.EnigmaProtector-9852682-0
Signature:SecuriteInfo.com.W32.Troj_Obfusc.Z.gen.Eldorado.UNOFFICIAL
Signature:Win.Trojan.Generic-9885003-0
Signature:Win.Trojan.Zpevdo-10036185-0

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:Borland
Author:malware-lu
TLP:TLP:WHITE
Repository:
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
TLP:TLP:WHITE
Repository:YARAify
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP:TLP:WHITE
Rule name:EnigmaStub
Author:@bartblaze
Description:Identifies Enigma packer stub.
TLP:TLP:WHITE
Repository:bartblaze
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
TLP:TLP:WHITE
Repository:YARAify
Rule name:HeavensGate
Author:kevoreilly
Description:Heaven's Gate: Switch from 32-bit to 64-mode
TLP:TLP:WHITE
Repository:CAPE
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
TLP:TLP:WHITE
Repository:
Rule name:NET
Author:malware-lu
TLP:TLP:WHITE
Repository:
Rule name:NETexecutableMicrosoft
Author:malware-lu
TLP:TLP:WHITE
Repository:
Rule name:pe_imphash
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
TLP:TLP:WHITE
Repository:
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
TLP:TLP:WHITE
Repository:
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
TLP:TLP:WHITE
Repository:
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:telebot_framework
Author:vietdx.mb
TLP:TLP:WHITE
Repository:YARAify
Rule name:test_Malaysia
Author:rectifyq
Description:Detects file containing malaysia string
TLP:TLP:WHITE
Repository:YARAify
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP:TLP:WHITE
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques
TLP:TLP:WHITE
Repository:

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.