YARAify Task Results

YARAify scan results for task ID 26a7b62d-fa4f-11ec-9250-42010aa4000b.

Scan Results


Task ID:26a7b62d-fa4f-11ec-9250-42010aa4000b
Task parameters:clamav_scan:True
unpack:True
share_file:True
Submission time:2022-07-02 21:37:19 UTC
Scan time:Scan took 18 seconds
File name:wp-signuo.php
File size:20'715 bytes
File download: Original
MIME type:text/x-php
SHA256 hash: 79999ac67a9eb40012bdbfd0031b92ac6c1304fb11d9eb38ca6ac4cf389279fa
MD5 hash: c91c610780322e04ae1177fbae6eac71
SHA1 hash: 57270275527cd67ecf397d5e1572aea9e22b29e9
SHA3-384 hash: 23df186236267a1d3e3b13c420ecc3ee36bf2dd8c2bb7affcb901b69d3e900c2ff5b6559b855b6d9b5cf772daef7e858
First seen:2022-07-02 21:37:19 UTC
Last seen:Never
Sightings:1
imphash :n/a
ssdeep : 384:Lu/1j/jIujmjXjsjnijoAjo88JjPsjPJjLjY9FijnjdjnjWjtj0Z7b5:Lu/1j/jIujmjXjsjnijoAjo88JjPsjP9
TLSH : T15392F623A50358B533E29D9731833129D6D447AB80C6E02DE7721DE5AFEC801F6E96DE
telfhash :n/a
dhash icon :n/a

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Unpacker

The following YARA rules matched on the unpacked file.

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:SecuriteInfo.com.PHP.Agent-140.UNOFFICIAL
Signature:sigs.InterServer.net.HEX.Topline.malware.sarah.sanders.oO.curlopt.477.UNOFFICIAL