YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash cb54f5c8527e5ce028dbc39498e8a3544e857ab5c970629e69a8ac81b14d2fae.

Scan Results


SHA256 hash: cb54f5c8527e5ce028dbc39498e8a3544e857ab5c970629e69a8ac81b14d2fae
File size:376'832 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: 11f44c8ca9c3387f124a12bb36deb5a7
SHA1 hash: 3b69efc0d2c5b2e87144089a192d3432be67c4e5
SHA3-384 hash: c776fdd0b0aff68f2d3c6b6323bfad1dc7e4ac7288068221016e9881362afe262510b5775dfb464bc8eaa75dcfaab374
First seen:2025-11-21 00:00:37 UTC
Last seen:Never
Sightings:1
imphash : 30e5df4fdb501cc0bf738d65c89185b6
ssdeep : 6144:Vn3MhIIIIIIIIIIIIIIIha3BiZ2oUZgyShAYbBiB1uY3LbeAFaKD:Vn3Mka3e2oCRYbfYfeAFaKD
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon : 18bca4d2d2a4a484

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:1c4d4815-c66d-11f0-adeb-42010aa4000b
File name:11f44c8ca9c3387f124a12bb36deb5a7
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Win.Trojan.Agent-1344924
Signature:Win.Trojan.VBGeneric-6735767-0

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:SEH__vba
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP:TLP:WHITE

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.