YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash efcabb95179734429bf3cebe4ee83dafd9f743123296bedb841419c91b17355a.

Scan Results


SHA256 hash: efcabb95179734429bf3cebe4ee83dafd9f743123296bedb841419c91b17355a
File size:74'581 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: 14c605b722bf8a4fcfe0b8748a26d2ef
SHA1 hash: a11c2b9a3981711edc9887cccfedeeb644cbe867
SHA3-384 hash: e189af42aed038757adfddb60d265456eed84836dca0663623d33be84ce276f8bf8751e56b11102e4964288e3b098f99
First seen:2025-11-21 02:55:41 UTC
Last seen:Never
Sightings:1
imphash : 310c492a8d1880254f85610f1e667d02
ssdeep : 1536:8g/9T8ROcQupqqusN3mrS/ztMhkywRFUnTmc5n4nIIIItEIIIIIIIIIIIIIIIIIJ:8g585LpPCrQt7F84nIIIIGIIIIIIIIIx
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon : aab2606469f096b3

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:90eec866-c685-11f0-adeb-42010aa4000b
File name:14c605b722bf8a4fcfe0b8748a26d2ef
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:PUA.Win.Packer.Aspack-29
Signature:PUA.Win.Packer.Aspack-30
Signature:PUA.Win.Packer.Asprotect-3
Signature:Win.Trojan.JS-37
Signature:Win.Worm.Torvil-1
Signature:Win.Worm.Torvil-3

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:ASPackv212AlexeySolodovnikov
Author:malware-lu
TLP:TLP:WHITE
Repository:
Rule name:ASProtectV2XDLLAlexeySolodovnikov
Author:malware-lu
TLP:TLP:WHITE
Repository:
Rule name:Borland
Author:malware-lu
TLP:TLP:WHITE
Repository:
Rule name:classified
Author:classified
Description:classified
Reference:classified
TLP :TLP:AMBER
Rule name:pe_detect_tls_callbacks
Author:
TLP:TLP:WHITE
Repository:YARAify

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.