YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash e791b4e5299f6c5a8d5a758ef90e336a3425f24a2feaa700f631772da8b1001f.

Scan Results


SHA256 hash: e791b4e5299f6c5a8d5a758ef90e336a3425f24a2feaa700f631772da8b1001f
File size:188'416 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: bf620cfb6ec5669b6c2304a75b398840
SHA1 hash: 29e39b80c07336bdce588bb98bd6af0de9ae9908
SHA3-384 hash: 7f4a19937687a059e197d4e3c59a63cb4914df7ce47c6ce04538ee5932e717d626b55373f73a651c2845968ee2a1e984
First seen:2025-11-21 02:58:03 UTC
Last seen:Never
Sightings:1
imphash :n/a
ssdeep : 3072:MWujjDoAbzHqZBWThxRlBTvMR1vNqnfiOdrO:MWeouyBWXB7MR11qnfiOdr
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon : 3004fc7c70e0a004

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:e578e507-c685-11f0-adeb-42010aa4000b
File name:400000.04b33f76074b4bc923059bfee25a7943.exe
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Win.Malware.Zusy-6878655-0

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:SEH__vba
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP:TLP:WHITE

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.