YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash df96476f030b5cef2fd4134b23da394482592361448fdbe9320503295be9d475.

Scan Results


SHA256 hash: df96476f030b5cef2fd4134b23da394482592361448fdbe9320503295be9d475
File size:2'987'520 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: 1cd72a5a2ce212e02423592bed8ee3d7
SHA1 hash: c5f37f1cbf4f0902d33c982c15e35d01b5479248
SHA3-384 hash: c598ec82352ee905cffde5a0ba97d3af26799687016c8671c9f1350bec1a307467c1bc459334047715f88e9ad435701d
First seen:2026-03-29 17:21:14 UTC
Last seen:Never
Sightings:1
imphash : b5ad65145f76f13703a397413c887af7
ssdeep : 24576:UjG8Upbl1F68ZlXb5Jb/4FcC8/NwYM9dtVq68VO9BESfPh9FxXj5RgI1cnEOPQ6K:Bjpbn4bp9KO9SS3h9RcnS6Kn
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon : e88e352b2b07cee8

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:b08e45e2-2b93-11f1-b47f-42010aa4000b
File name:1cd72a5a2ce212e02423592bed8ee3d7
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:BobSoftMiniDelphiBoBBobSoft
Author:malware-lu
TLP:TLP:WHITE
Repository:
Rule name:Borland
Author:malware-lu
TLP:TLP:WHITE
Repository:
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP:TLP:WHITE
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
TLP:TLP:WHITE
Repository:YARAify
Rule name:classified
Author:classified
Description:classified
Reference:classified
TLP :TLP:AMBER
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
TLP:TLP:WHITE
Repository:
Rule name:pe_detect_tls_callbacks
Author:
TLP:TLP:WHITE
Repository:YARAify
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:telebot_framework
Author:vietdx.mb
TLP:TLP:WHITE
Repository:YARAify

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.