🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash c871f39e7c4ec319d3faafcaaafca1811998ed6f9ee2d2e9f8863b02b1f7cb62.

Scan Results


SHA256 hash: c871f39e7c4ec319d3faafcaaafca1811998ed6f9ee2d2e9f8863b02b1f7cb62
File size:188'416 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: 9d2bf07ec579f4fec413ee39259e42ab
SHA1 hash: 13bd7dfd39eec6cc98db51ad925d1534b3d21a06
SHA3-384 hash: dd8ed4d0c7fc43defe862d41b43b95a8da305aa332900c79d1d81a80f8aed6be0dad0a81b6d56f0d8ac1a5aabb1b179b
First seen:2026-10-09 23:21:28 UTC
Last seen:Never
Sightings:1
imphash :n/a
ssdeep : 3072:GxffyfajdQkpZNuYClh8Sa5ElvnqXcGuKrS:Gx6a17NuT8p5ElPqXcGuKr
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon : 1003873db9313e16

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:27ae2869-c438-11f1-b2b6-42010aa4000b
File name:400000.28a1fd6f5370d594405e746d28d5bc50.exe
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Win.Malware.Zusy-6878655-0

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:MULTI_Malware_Unknown_ForgeAuto_9c694c2d_Extrait
Author:Marjoriefort
Description:Detects Unknown (inconnu, etat extrait)
TLP:TLP:WHITE
Repository:YARAify
Rule name:SEH__vba
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP:TLP:WHITE
Rule name:telebot_framework
Author:vietdx.mb
TLP:TLP:WHITE
Repository:YARAify

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.