YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash c9dfe9121f184fd0e5dda9166370fb9bbff90fa91577323797a6863ad45025f7.

Scan Results


SHA256 hash: c9dfe9121f184fd0e5dda9166370fb9bbff90fa91577323797a6863ad45025f7
File size:366'848 bytes
File download: Original
MIME type:application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
MD5 hash: 28dc51a642d2f9fea046cf443c8ba5e2
SHA1 hash: fbb970df372ac04187e69ae345e724db7c09ebef
SHA3-384 hash: ae979f2a32b7595fb844f50eafd91764d0cdc3a1021b40858bad358d1e67d723008d4687c75356580af8299f379b056c
First seen:2026-03-14 15:36:40 UTC
Last seen:Never
Sightings:1
imphash :n/a
ssdeep : 6144:Shsn9ovbPEEqntxxDmbhovmEAB9gj2xHEmCNfGPm7ldr9uY+F2qVyppz4Hi:xn9ojPCntx0NRB2ymmqGO3BV+F2qQfEC
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon :n/a

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:98d48168-1fbb-11f1-b47f-42010aa4000b
File name:28dc51a642d2f9fea046cf443c8ba5e2
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:vbaproject_bin
Author:CD_R0M_
Description:{76 62 61 50 72 6f 6a 65 63 74 2e 62 69 6e} is hex for vbaproject.bin. Macros are often used by threat actors. Work in progress - Ran out of time
TLP:TLP:WHITE
Repository:CD-R0M

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.