Authenticate for API access | If you are experiencing issues with receiving data from abuse.ch platforms via API, please ensure your requests are authenticated. ➡️ Read here for more info

YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash cbe9469e25857e4ff0f3056e8e06f484984ed341d64e8fd33c5c520897fb0552.

Scan Results


SHA256 hash: cbe9469e25857e4ff0f3056e8e06f484984ed341d64e8fd33c5c520897fb0552
File size:352'421 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: 890560dc6143119e877197bd967dde6a
SHA1 hash: 08b22c8133d9a60b6167823600a1b393a4f296ce
SHA3-384 hash: 194835a8f26615e10b361f828baf08d6865e02ecb9df33194ea13c5e0f87f4554ed04b911e86c837532b98ba8a144a63
First seen:2022-11-24 19:55:00 UTC
Last seen:Never
Sightings:1
imphash : d91b0f983896ae442df4b223d1f3f182
ssdeep : 6144:2fDc1XbMVNjMtAjxHcBWaBIiVfDFhgfRG2cwNk5ucynQVExm:2fD0LMctAjxHcBWaBpfByfsPH5onQKx
TLSH : T1D3746D45F7F918A5EEB785388423861AF5B1BC982311C6EF0628811DBF37BD15E39392
telfhash :n/a
gimphash :n/a
dhash icon :n/a

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:e1604b7e-6c31-11ed-a71a-42010aa4000b
File name:7ffb408e0000.shlwapi.dll
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
TLP:TLP:WHITE
Repository:YARAify

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.