Statistics
YARAIfy produces various statistics on files scanned by YARAify, including their detections. The available statistics can be found below.
File Scans
The chart below shows the number of file scans conducted by YARAify over the past 30 days.
Data Scanned
This chart shows the amount of data scanned in Megabytes over the past 30 days.
API requests
The illustration below documents the number of API requests over the past 30 days.
Most matching YARA rules
YARA rules that matched most on files scanned on YARAify in the past 14 days.
Task count | YARA Rule | Author | Last match |
---|---|---|---|
298'895 | SEH__vba | 2024-10-30 | |
168'242 | DebuggerCheck__API | 2024-10-30 | |
144'348 | RANSOMWARE | ToroGuitar | 2024-10-30 |
117'373 | pe_detect_tls_callbacks | 2024-10-30 | |
75'789 | UPXV200V290MarkusOberhumerLaszloMolnarJohnReiser | malware-lu | 2024-10-30 |
69'995 | NET | malware-lu | 2024-10-30 |
65'005 | MD5_Constants | phoul (@phoul) | 2024-10-30 |
59'193 | UPXv20MarkusLaszloReiser | malware-lu | 2024-10-30 |
50'239 | command_and_control | CD_R0M_ | 2024-10-30 |
46'424 | DebuggerCheck__QueryInfo | 2024-10-30 | |
46'076 | SHA1_Constants | phoul (@phoul) | 2024-10-30 |
46'076 | RIPEMD160_Constants | phoul (@phoul) | 2024-10-30 |
43'459 | vmdetect | nex | 2024-10-30 |
38'862 | Borland | malware-lu | 2024-10-30 |
37'455 | ThreadControl__Context | 2024-10-30 |
Most matching ClamAV signature
ClamAV signature that matched most on files scanned on YARAify in the past 14 days.
Task count | ClamAV Signature | Last match |
---|---|---|
1'810'753 | PUA.Win.Packer.Lccwin-2 | 2024-10-30 |
1'206'154 | Win.Trojan.Qukart-6874817-0 | 2024-10-30 |
1'205'861 | Win.Trojan.Padodor-10016488-0 | 2024-10-30 |
1'202'122 | Win.Trojan.Obfus-38 | 2024-10-30 |
998'139 | Win.Malware.Qukart-6838239-0 | 2024-10-30 |
436'999 | Win.Trojan.Berbew-9845290-1 | 2024-10-30 |
428'512 | SecuriteInfo.com.BackDoor.HangUp.43874.UNOFFICIAL | 2024-10-30 |
255'084 | Win.Malware.Midie-6847981-0 | 2024-10-30 |
249'424 | Win.Trojan.Razy-10016933-0 | 2024-10-30 |
240'346 | Win.Dropper.Ajku-10014126-0 | 2024-10-30 |
234'298 | Win.Dropper.Vbclone-10036195-0 | 2024-10-30 |
233'795 | Win.Trojan.Barys-10005825-0 | 2024-10-30 |
217'067 | Win.Malware.Generickdz-10004857-0 | 2024-10-30 |
213'595 | Win.Malware.Midie-6848630-0 | 2024-10-30 |
212'144 | Win.Malware.Midie-6847894-0 | 2024-10-30 |
Most seen files
Most seen files scanned by YARAify in the past 14 days.
Top dhash icon
Top dhash icon observed on files scanned by YARAify in the past 14 days.
Task count | dhash icon | Last seen |
---|---|---|
154'618 | 18b1b1b17068c880 | 2024-10-30 |
54'206 | 58b1b1b17068c880 | 2024-10-30 |
30'873 | d8d0d4d8ececece4 | 2024-10-29 |
16'416 | 1003873db9313e10 | 2024-10-30 |
13'573 | 1003873d31213f10 | 2024-10-30 |
5'105 | 9919aca682a881a9 | 2024-10-30 |
4'235 | 69ccd4d49696cc71 | 2024-10-30 |
3'915 | 71e8d4968ecc68f9 | 2024-10-29 |
3'051 | 00ccc4d0c4fc7c00 | 2024-10-30 |
2'911 | 04ccfee2ece4a484 | 2024-10-30 |
2'601 | 19b1b1b17068c880 | 2024-10-29 |
2'390 | b298acbab2ca7a72 | 2024-10-30 |
2'380 | 33cce8ccf0cc700e | 2024-10-30 |
2'209 | 1001873db9313e10 | 2024-10-30 |
2'033 | 818da080a0a0a0a2 | 2024-10-30 |
Top imphash
Top imphash observed on files scanned by YARAify in the past 14 days.
Task count | imphash | Last seen |
---|---|---|
685'634 | 6db997463de98ce64bf5b6b8b0f77a45 | 2024-10-29 |
463'444 | 4dcbc0931c6f88874a69f966c86889d9 | 2024-10-29 |
460'275 | c9246f292a6fdc22d70e6e581898a026 | 2024-10-29 |
246'119 | 5d6cad172c5535e4b6b6bbd246571621 | 2024-10-29 |
170'918 | 46f03ef2495b21d7ad3e8d36dc03315d | 2024-10-29 |
70'402 | e4742a62fda2e64b586a5b84efe3f040 | 2024-10-29 |
39'306 | 87914047e74de74a89c530e3bb19409e | 2024-10-29 |
29'545 | c06ddfbe3366daddf0cfd3e63c1b5390 | 2024-10-29 |
20'966 | 3f8d79e42b0b7cecf379b1ddce4e422a | 2024-10-29 |
13'085 | f34d5f2d4577ed6d9ceec516c1f5a744 | 2024-10-29 |
9'545 | dae02f32a21e03ce65412f6e56942daa | 2024-10-29 |
8'611 | 91f4b88d25daa33c7443253d9beb1bb3 | 2024-10-29 |
8'156 | be6fa16f501de575a1d8eaaac5246ba0 | 2024-10-29 |
7'556 | a12d186f65c99f872323a61923ce70d8 | 2024-10-29 |
6'372 | 432c342c05744facf1143abcda5d68c4 | 2024-10-29 |
Top tlsh
Top tlsh observed on files scanned by YARAify in the past 14 days.
Top telfhash
Top telfhash observed on files scanned by YARAify in the past 14 days.
File Scans
The chart below shows the number of file scans conducted by YARAify over the past 12 months.
Data Scanned
This chart shows the amount of data scanned in Megabytes over the past past 12 months.
API requests
The illustration below documents the number of API requests over the past past 12 months.
Most matching YARA rules
YARA rules that matched most on files scanned on YARAify in the past 12 months.
Task count | YARA Rule | Author | Last match |
---|---|---|---|
33'674'165 | maldoc_getEIP_method_1 | Didier Stevens (https://DidierStevens.com) | 2024-10-26 |
33'504'640 | meth_get_eip | Willi Ballenthin | 2024-10-26 |
31'071'304 | QbotStuff | anonymous | 2024-08-15 |
11'996'884 | win_berbew_strings_dec_2023 | Matthew @ Embee_Research | 2024-10-25 |
5'218'632 | DebuggerCheck__API | 2024-10-30 | |
4'517'958 | classified | classified | 2024-09-24 |
3'043'697 | SEH__vba | 2024-10-30 | |
2'267'357 | maldoc_find_kernel32_base_method_1 | Didier Stevens (https://DidierStevens.com) | 2024-10-26 |
2'240'062 | NET | malware-lu | 2024-10-30 |
2'146'953 | SHA512_Constants | phoul (@phoul) | 2024-10-30 |
2'143'333 | UPXV200V290MarkusOberhumerLaszloMolnarJohnReiser | malware-lu | 2024-10-30 |
2'087'838 | malware_shellcode_hash | JPCERT/CC Incident Response Group | 2024-10-30 |
1'862'477 | UPXv20MarkusLaszloReiser | malware-lu | 2024-10-30 |
1'680'328 | DebuggerException__SetConsoleCtrl | 2024-10-30 | |
1'629'811 | DebuggerCheck__QueryInfo | 2024-10-30 |
Most matching ClamAV signature
ClamAV signature that matched most on files scanned on YARAify in the past 12 Mmonths.
Task count | ClamAV Signature | Last match |
---|---|---|
51'304'161 | PUA.Win.Packer.Lccwin-2 | 2024-10-30 |
34'267'485 | Win.Trojan.Obfus-38 | 2024-10-30 |
32'319'232 | Win.Trojan.Qukart-6874817-0 | 2024-10-30 |
27'700'010 | Win.Trojan.Padodor-10016488-0 | 2024-10-30 |
24'973'041 | Win.Malware.Qukart-6838239-0 | 2024-10-30 |
7'846'797 | Win.Trojan.Padodor-9877164-0 | 2024-10-30 |
6'235'995 | Win.Trojan.Berbew-9845290-1 | 2024-10-30 |
5'825'816 | SecuriteInfo.com.BackDoor.HangUp.43874.UNOFFICIAL | 2024-10-30 |
4'116'817 | Win.Packed.Razy-10010080-0 | 2024-10-30 |
3'502'966 | Win.Trojan.Berbew-10013977-0 | 2024-10-30 |
3'494'716 | Win.Packed.Lazy-10005437-0 | 2024-10-30 |
3'447'696 | Win.Trojan.Razy-10016933-0 | 2024-10-30 |
3'355'272 | Win.Trojan.Crypted-29 | 2024-10-30 |
3'333'627 | Win.Trojan.Crypted-30 | 2024-10-30 |
2'746'741 | Win.Malware.Renos-10003934-0 | 2024-10-30 |
Most seen files
Most seen files scanned by YARAify in the past 12 months.
Top dhash icon
Top dhash icon observed on files scanned by YARAify in the past 12 months.
Task count | dhash icon | Last seen |
---|---|---|
1'100'694 | 18b1b1b17068c880 | 2024-10-29 |
541'864 | 69ccd4d49696cc71 | 2024-10-29 |
538'955 | d8d0d4d8ececece4 | 2024-10-29 |
466'124 | 1003873db9313e10 | 2024-10-29 |
244'787 | 58b1b1b17068c880 | 2024-10-29 |
223'722 | 818da080a0a0a0a2 | 2024-10-29 |
206'930 | 1003873d31213f10 | 2024-10-29 |
125'030 | 00ccc4d0c4fc7c00 | 2024-10-29 |
121'256 | 5ab3a5b332c482a0 | 2024-10-29 |
120'195 | 9919aca682a881a9 | 2024-10-29 |
117'174 | b298acbab2ca7a72 | 2024-10-29 |
114'451 | 71e8d4968ecc68f9 | 2024-10-29 |
111'089 | 526e32661e3a2a10 | 2024-10-29 |
80'807 | 04ccfee2ece4a484 | 2024-10-29 |
51'428 | f8f0f4c8c8c8d8f0 | 2024-10-29 |
Top imphash
Top imphash observed on files scanned by YARAify in the past 12 months.
Task count | imphash | Last seen |
---|---|---|
16'212'230 | 6db997463de98ce64bf5b6b8b0f77a45 | 2024-10-30 |
11'953'689 | 46f03ef2495b21d7ad3e8d36dc03315d | 2024-10-30 |
11'029'320 | 4dcbc0931c6f88874a69f966c86889d9 | 2024-10-30 |
6'167'068 | c9246f292a6fdc22d70e6e581898a026 | 2024-10-30 |
2'497'453 | e4742a62fda2e64b586a5b84efe3f040 | 2024-10-30 |
1'402'867 | 5d6cad172c5535e4b6b6bbd246571621 | 2024-10-30 |
1'129'141 | 87914047e74de74a89c530e3bb19409e | 2024-10-30 |
786'384 | 91f4b88d25daa33c7443253d9beb1bb3 | 2024-10-30 |
703'110 | 3f8d79e42b0b7cecf379b1ddce4e422a | 2024-10-29 |
613'954 | 2c2ad1dd2c57d1bd5795167a7236b045 | 2024-10-29 |
459'969 | a3df475500e5e30f4680b397c2ee13f1 | 2024-10-30 |
390'084 | f34d5f2d4577ed6d9ceec516c1f5a744 | 2024-10-30 |
274'359 | c06ddfbe3366daddf0cfd3e63c1b5390 | 2024-10-29 |
274'064 | 1a611a7df1f3828b0157c4725145a721 | 2024-10-29 |
255'306 | dae02f32a21e03ce65412f6e56942daa | 2024-10-30 |
Top tlsh
Top tlsh observed on files scanned by YARAify in the past 14 months.
Top telfhash
Top telfhash observed on files scanned by YARAify in the past 12 months.