YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash f0e324ccd8755bc6018fdd09772cebcdb00b2bcdc8d80fb568a8b7a32b479087.

Scan Results


SHA256 hash: f0e324ccd8755bc6018fdd09772cebcdb00b2bcdc8d80fb568a8b7a32b479087
File size:4'202'496 bytes
File download: Original
MIME type:application/octet-stream
MD5 hash: b64c0834bab067aa1d3520a6e3a07b1e
SHA1 hash: d54b235848e52d0e828d650f4cd9b2d03c0c211f
SHA3-384 hash: 75a587402139180c687c1b73d71f7b4392847ccd5e0bdde0efc2f5833dd0a71b480fe6ec0d2a46e5db5d6cfb0caf3ac9
First seen:2026-06-29 04:42:43 UTC
Last seen:Never
Sightings:1
imphash :n/a
ssdeep : 12288:pBj2McrWZuX0vbW37CN0DH4Y8+XzRxYlZhnM9gJd4IQjlt:pBiNrhXUQH4Y8++CESIQH
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon :n/a

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:f7d5c1c0-7374-11f1-ad5e-42010aa4000b
File name:4fd0000.shc
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:Disable_Defender
Author:iam-py-test
Description:Detect files disabling or modifying Windows Defender, Windows Firewall, or Microsoft Smartscreen
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:NET
Author:malware-lu
TLP:TLP:WHITE
Repository:
Rule name:telebot_framework
Author:vietdx.mb
TLP:TLP:WHITE
Repository:YARAify

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.