YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash e1b60da9526416aad1f7b07e1090d28b1a339747296101dc4bd4ab619ba22ee7.

Scan Results


SHA256 hash: e1b60da9526416aad1f7b07e1090d28b1a339747296101dc4bd4ab619ba22ee7
File size:3'797'269 bytes
File download: Original Unpacked
MIME type:application/x-dosexec
MD5 hash: 1bba57cb4cf9eb6aad663d40db22a847
SHA1 hash: eb3c1edad89bf1e8403c6aa60a81c270b20a47d8
SHA3-384 hash: 5e53123fb48abefaff7ef866332073409bd3e99583134edf0035e6fd09cb91ddf3f6a7c1c8d22291c5095923a1e5e278
First seen:2026-04-07 15:43:58 UTC
Last seen:Never
Sightings:1
imphash : 37c6c0cc4d20c311c793c6b743da8942
ssdeep : 98304:ZdByXcdnlLwOrI5Vfeg91hZOhkRpsinjH:Zdien+OrFuBR6cH
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon : ccb67168796986cc

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:97d6136e-3298-11f1-b47f-42010aa4000b
File name:1bba57cb4cf9eb6aad663d40db22a847
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:PUA.Win.Packer.EnigmaProtector-1
Signature:PUA.Win.Packer.EnigmaProtector-9852682-0
Signature:Win.Malware.Fragtor-10028300-0

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:BobSoftMiniDelphiBoBBobSoft
Author:malware-lu
TLP:TLP:WHITE
Repository:
Rule name:EnigmaProtector11X13XSukhovVladimirSergeNMarkin
Author:malware-lu
TLP:TLP:WHITE
Repository:
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
TLP:TLP:WHITE
Repository:YARAify
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns
TLP:TLP:WHITE
Repository:MalwareBazaar

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.