YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash ff9710e1eb4ec8d774efc4a18c9423635b0a80c6785f053ac7dce68d3c608064.

Scan Results


SHA256 hash: ff9710e1eb4ec8d774efc4a18c9423635b0a80c6785f053ac7dce68d3c608064
File size:31'232 bytes
File download: Original
MIME type:application/x-dosexec
MD5 hash: 1dd4e0c994e2d9ed85ff3aa0f73611c7
SHA1 hash: e5700fbffe1db8a82b57119e494ac7cdc14bbcbd
SHA3-384 hash: 7236a4ec48fb39f796a52b969690153558824cbda52fe7b20e473e187835d83297edce9847e75fd24428908172b5a0cb
First seen:2026-03-25 16:25:24 UTC
Last seen:Never
Sightings:1
imphash : 02549ff92b49cce693542fc9afb10102
ssdeep : 384:yBTkmAxOro2eCD1Wgm3LCu1460ok8EQ7C7UX8DefwmoX81wV9lYG+4jR:BhOwChWX32uDctQmyd4m68ClD+4
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon :n/a

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:39c8fd42-2867-11f1-b47f-42010aa4000b
File name:1dd4e0c994e2d9ed85ff3aa0f73611c7
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:SecuriteInfo.com.Trojan.DownLoader6.32179.28410.UNOFFICIAL

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.
TLP:TLP:WHITE
Repository:YARAify

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.