🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash d4eaa7f7fd91f35928e03f285fc0d2e10d6a45eeb47c735f08ad9cba08d63792.

Scan Results


SHA256 hash: d4eaa7f7fd91f35928e03f285fc0d2e10d6a45eeb47c735f08ad9cba08d63792
File size:2'867'893 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: b8c10e7602ec6421885b022079f66809
SHA1 hash: 38c68b2b42f6614a079cd389b7cda9663ee3307c
SHA3-384 hash: eb485ab79ea03c1428e2af1d23e86044de068c5df3d1d095293dc810465f989baf2c26c1ebdf2a35da8f0fec25b075c3
First seen:2026-10-09 23:02:59 UTC
Last seen:Never
Sightings:1
imphash : 4a627e007733257778501dcefd70fcdd
ssdeep : 49152:lLSuF8IZ9lNQt1QajqOoQ+pTFXCA9hKNup7mLO5ehm:1ZDg6CA7sAwO0Q
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon :n/a

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:927db781-c435-11f1-b2b6-42010aa4000b
File name:7ff739da0000.9b19ad84-c2a5-417a-8a50-65813d0c8827.exe
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:SecuriteInfo.com.Trojan.Siggen34.94.30666.3487.UNOFFICIAL

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
TLP:TLP:WHITE
Repository:YARAify
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP:TLP:WHITE
Rule name:dsc
Author:Aaron DeVera
Description:Discord domains
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
TLP:TLP:WHITE
Repository:YARAify
Rule name:MULTI_Malware_Unknown_ForgeAuto_9d9a5cf9
Author:Marjoriefort
Description:Detects Unknown (inconnu, etat binaire)
TLP:TLP:WHITE
Repository:YARAify
Rule name:MULTI_Malware_Unknown_ForgeAuto_de8d8480
Author:Marjoriefort
Description:Detects Unknown (inconnu, etat binaire)
TLP:TLP:WHITE
Repository:YARAify
Rule name:pe_detect_tls_callbacks
Author:
TLP:TLP:WHITE
Repository:YARAify
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP:TLP:WHITE
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
TLP:TLP:WHITE
Repository:YARAify
Rule name:WIN_Malware_Fantom_ForgeAuto_98e6f354_Extrait
Author:Marjoriefort
Description:Detects Fantom (pe, etat extrait)
TLP:TLP:WHITE
Repository:YARAify
Rule name:WIN_Malware_Unknown_ForgeAuto_3ee43008
Author:Marjoriefort
Description:Detects Unknown (pe, etat binaire)
TLP:TLP:WHITE
Repository:YARAify
Rule name:WIN_Malware_Unknown_ForgeAuto_4fa7e284_Extrait
Author:Marjoriefort
Description:Detects Unknown (pe, etat extrait)
TLP:TLP:WHITE
Repository:YARAify
Rule name:WIN_Malware_Unknown_ForgeAuto_7e8e91c4
Author:Marjoriefort
Description:Detects Unknown (pe, etat binaire)
TLP:TLP:WHITE
Repository:YARAify

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.