YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash f8b06153ec123efa1ff0d20a0394efdbc3d54a3c0d4b2234a92a1640e4e58538.

Scan Results


SHA256 hash: f8b06153ec123efa1ff0d20a0394efdbc3d54a3c0d4b2234a92a1640e4e58538
File size:768'000 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: e5341ddf15afd4f3d215a70600218fb0
SHA1 hash: 86ad13cc1e952056ef5f4b60855cf5ca5cf5d28d
SHA3-384 hash: 7b73021a3cabe284bdb27bc79ee2c8e915253e7ac32c242e2e64075d1fe53e693c639aaa46e7cb23dc88d20e6631c80d
First seen:2025-11-20 23:48:09 UTC
Last seen:Never
Sightings:1
imphash : 5271d5ce8b44dd47bc92563e27585466
ssdeep : 12288:JQMmCy3/GlfLw6M2e9aqP5vThTjVL61T8ZR3lF0J+E/FA37ZWoaJjxL7ebdg5VzF:JXmCy3+5wUIa2JThTjVL6Z8ZXFMx/aU1
TLSH : T1EBF49E21B691D073C07220300629D7B25D7BB9701035A8BBBBD99B3E5F747C1EA2776A
telfhash :n/a
gimphash :n/a
dhash icon :n/a

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:5e89f737-c66b-11f0-adeb-42010aa4000b
File name:6b680000.msvcr100.dll
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
TLP:TLP:WHITE
Repository:YARAify
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP:TLP:WHITE
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP:TLP:WHITE
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
TLP:TLP:WHITE
Repository:YARAify

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.