Statistics

YARAIfy produces various statistics on files scanned by YARAify, including their detections. The available statistics can be found below.

File Scans


The chart below shows the number of file scans conducted by YARAify over the past 30 days.

Data Scanned


This chart shows the amount of data scanned in Megabytes over the past 30 days.

API requests


The illustration below documents the number of API requests over the past 30 days.

Most matching YARA rules


YARA rules that matched most on files scanned on YARAify in the past 14 days.

Task countYARA RuleAuthorLast match
3'247'020maldoc_getEIP_method_1Didier Stevens (https://DidierStevens.com)2023-11-30
3'236'104meth_get_eipWilli Ballenthin2023-11-30
3'132'284QbotStuffanonymous2023-11-30
226'410DebuggerCheck__API2023-11-30
159'468maldoc_find_kernel32_base_method_1Didier Stevens (https://DidierStevens.com)2023-11-30
130'418NETmalware-lu2023-11-30
123'572Check_Dlls2023-11-30
109'636SUSP_XORed_URL_in_EXE_RID2E46Florian Roth2023-11-30
109'578SUSP_XORed_URL_In_EXEFlorian Roth (Nextron Systems)2023-11-30
82'607malware_shellcode_hashJPCERT/CC Incident Response Group2023-11-30
81'281SHA512_Constantsphoul (@phoul)2023-11-30
80'124SHA1_Constantsphoul (@phoul)2023-11-30
80'124RIPEMD160_Constantsphoul (@phoul)2023-11-30
77'808MD5_Constantsphoul (@phoul)2023-11-30
66'696DebuggerException__SetConsoleCtrl2023-11-30

ClamAV Most matching ClamAV signature


ClamAV signature that matched most on files scanned on YARAify in the past 14 days.

Task countClamAV SignatureLast match
3'093'454PUA.Win.Packer.Lccwin-22023-11-30
2'065'163Win.Trojan.Obfus-382023-11-30
1'326'272Win.Trojan.Qukart-6874817-02023-11-30
977'227Win.Malware.Qukart-6838239-02023-11-30
910'7502023-11-30
896'516Win.Trojan.Padodor-9877164-02023-11-30
550'618Win.Trojan.Berbew-10013977-02023-11-30
315'512Win.Trojan.Crypted-292023-11-30
312'224Win.Trojan.Crypted-302023-11-30
264'099Win.Trojan.Berbew-9845290-12023-11-30
255'953Win.Malware.Padodor-10012877-02023-11-30
231'536Win.Packed.Razy-10010080-02023-11-30
204'077Win.Packed.Razy-10009896-02023-11-30
202'784Win.Packed.Lazy-10005437-02023-11-30
201'864Win.Trojan.Crypted-282023-11-30

Most seen files


Most seen files scanned by YARAify in the past 14 days.

Task countSHA256 hashLast seen
14223c2d2b0c6cec3e69cb07f942c9e56f2087aeb24015be25823897faafc4708ae2022-02-07
141e0af7f483f4965dca90eb5921ae004a7e41593b39284a63af97a9105b96718e72022-01-06
141443ee14013c64a893e1a3ffac2b4afcbaa2136e44846319aca7631536b3237e02022-02-07
141b3986e04464339cec16157cf8c8bffec3a8a8c5eae57997974d45f5369fa16552021-07-07
14096994840078a8dbaaa3175c80b72c01c3a7f258be338c94c58672cacf5e47a872022-02-08
14039e48a3fc7e67968ff5d6e3cf8e12a7256af93ccabbce4da20d28c79237d95e82022-01-06
1405ea4d94c695189639e9ab7afe8d76d231030921fbfdd95e1941c7c0a05fb8f032022-02-07
140cdfb8e3d5bfb32850200759b0d3ccaa83ed5cb661cb2cccedf048d23959663602022-02-08
1408718400c6ca71b5afb0534931628b2aace3e5cc515edaa33d1da678f947b5cd42022-02-08
14008f5c5fbacc0c31ea5d54cef04d4fd35596402f3f02c00e607bb98aa7ad96c492022-02-09
14087479e089e6852958dab4026e07bc01ed1f31af423b1d26db462ef7493a537f12022-02-08
14053c22863323c0f5ff94f4ae86df27a51db4eae7232cc38333346ee8be9df5aa62022-02-07
140b1bce9d29dc58cf8e53382c61d200610a8200708cd32713b63b18b260db9bfa82022-02-09
1401115b6c913a207b9d81f8482613b2a9c2929ca81399861d2d2c47422e244060d2022-02-07
14032996a04eeead4de0813ca803033429fd38e0aa4ab8d603508e1d2c6bd38aba72022-02-08

Top dhash icon


Top dhash icon observed on files scanned by YARAify in the past 14 days.

Task countdhash iconLast seen
17'74769ccd4d49696cc712023-11-30
13'7111003873db9313e102023-11-30
8'5749919aca682a881a92023-11-30
5'8421003873d31213f102023-11-30
5'23400ccc4d0c4fc7c002023-11-30
4'716526e32661e3a2a102023-11-30
4'454818da080a0a0a0a22023-11-30
4'318f8f0f4c8c8c8d8f02023-11-30
3'996d8d0d4d8ececece42023-11-30
3'51004ccfee2ece4a4842023-11-30
3'234b298acbab2ca7a722023-11-30
2'6911ad2a38edcb6b2dc2023-11-30
2'3225ab3a5b332c482a02023-11-30
1'82000ca80c2c28082002023-11-30
1'538bae2e5e7e5a5a69a2023-11-30

Top imphash


Top imphash observed on files scanned by YARAify in the past 14 days.

Task countimphashLast seen
1'475'21046f03ef2495b21d7ad3e8d36dc03315d2023-11-30
534'0366db997463de98ce64bf5b6b8b0f77a452023-11-30
493'7574dcbc0931c6f88874a69f966c86889d92023-11-30
261'380c9246f292a6fdc22d70e6e581898a0262023-11-30
118'313e4742a62fda2e64b586a5b84efe3f0402023-11-30
112'80387914047e74de74a89c530e3bb19409e2023-11-30
41'2093f8d79e42b0b7cecf379b1ddce4e422a2023-11-30
28'56591f4b88d25daa33c7443253d9beb1bb32023-11-30
26'3382c2ad1dd2c57d1bd5795167a7236b0452023-11-30
21'462f34d5f2d4577ed6d9ceec516c1f5a7442023-11-30
19'399dae02f32a21e03ce65412f6e56942daa2023-11-30
17'9980141f24aaf1b810b9fcc5f6886f26f142023-11-29
15'495a3df475500e5e30f4680b397c2ee13f12023-11-30
11'898be6fa16f501de575a1d8eaaac5246ba02023-11-30
6'0685271d5ce8b44dd47bc92563e275854662023-11-30

Top tlsh


Top tlsh observed on files scanned by YARAify in the past 14 days.

Task counttlshLast seen
144T1E0D4642D0327604ED089F036233FDA9A7A06ACBF5F78B775F581254EBDE15CB806A5242022-08-22
142T153819E61842314C4F557CFF0D61BD82AAFA5334684584E1123E0606A4BCF60427041E32022-02-07
141T1C8E052F688E090AC080023A82BDF2CA5437B03BD00202A0BF20BA04D022DF72E30A3F02021-07-07
140T1868174CC65537044EDA5C834BF0A14FA321818B3F1BD0F1116DAA86D564D8C5BF449332022-02-09
140T1A4818BC84803B090F87AEE765F2BE9FA2214316371B9AA941052B869A147FD413A527B2022-02-09
140T1D7819E61842314C4F557CEF4D51BE869BFA5734550584E1423E0705A4BCBA1427551A32022-02-08
139T16B11229FBABDDCF3C48C05340613AA8120290C280FE087030E8808FFB6B12AC00E8B012021-07-08
139T130755D99FA87A0F0CA630DB0514BE73FDA312E054034EAB7EFC9EB49E873B55A2051552023-09-12
139T1B2654C99FA87A0F0CB630DB1514BE73FDA312E054034EAB7EF89EB48E873765A2051552023-01-18
138T104942955F242C23BC0523DB84A4989F55672DD303C32E0EB77DA1E1F6B75EA26F286062023-10-26
138T10016DD42A3F94608F6F77F7469B916604E3BBCA6AD79C21C1284505E5EB2E40CDB0B732022-01-06
138T1B68130E0D3C23230F2AE09F1A687B6E1520125260DA4DD85A2934C9D4DA2D88B731C3B2022-02-07
137T1EF16DD42A3F94608F6F77F7469B916604E3BBCA6AD79C21C1284505E5EB2E40CDB0B732022-01-06
137T1C0813FCC8287A001E5AA88F1041FD0DA36097692A5FC9AC852CA619D7483625BB65A332022-02-09
137T15B8193C992427125F5E380F0462798F237893566B1AE8AD402CEA83C28039C0C758A372022-02-09

Top telfhash


Top telfhash observed on files scanned by YARAify in the past 14 days.

Task counttelfhashLast seen
8t1ec21dc314b2492256b91eea0ccfd5763052997663344ab37ef32c18d24090faea37c8f2023-11-28
6t17141a2180d7817e0a7356c9d099dfb36d6a330de7e262d338f61e86aab69a435d11c0c2023-11-29
6t18c3112a19679512a5da1ec68edda57b2501a56172350bf33df21c0cc380a44ff527c0f2023-11-29
6t11701ce5370ba89592bf308285cbd53f425802a236792fe75bf0dc9d05837002f974d8b2023-11-26
6t1a6e0cdbdcda42a9cf6f51e84505e73313dd437f8a9515d181d962d482553c80a12553d2023-11-27
5t16a31de544ecd16dc86f08a85954d633b3aa134b19f122d1a4f977f8f8753cd170294362023-11-27
5t137e07228e890258cecb04a2ec1ecf32231b0b29e6d012d6801e03e888823cc4d050e3e2023-11-18
5t18a5106fa2dbe0cfcb3e56c08c74e2ad32a55da7b1951357184a79ca533f3a4080a5c362023-11-29
5t1b701b8248f44a4fdfbb08c38c3ddb322b52234b5fd0328601aab4c9d0b23992a5358182023-11-27
4t16a014f18543813f4d7854ddd7bedff31e01150df5e561e338d10e99aab21a468c00c2c2023-11-27
4t1b801ab5370ba89592bf208285cbd57b425806a236792be75bf0dc9d05837002b964d8b2023-11-19
4t16a01c09ed1f2d52d8c62247448bc09f0a561b31b27159e10bf3ac494ac36420a57fe5b2023-11-18
4t18c51acb12aa539d4a2fbeb7a730bd5a4ec340e2004e134d2edb7adf5de063410d658672023-11-29
4t10ce07200fcb88b2c9cdaaab4adcd07b4aa00220260178b10cf10daf0c83f448e30ce5e2023-11-27
4t12601d6e139961da9e1e7f1a5335ad0601c3c1d1400d13af6d1b1b9eaab62b825b78c372023-11-27

File Scans


The chart below shows the number of file scans conducted by YARAify over the past 12 months.

Data Scanned


This chart shows the amount of data scanned in Megabytes over the past past 12 months.

API requests


The illustration below documents the number of API requests over the past past 12 months.

Most matching YARA rules


YARA rules that matched most on files scanned on YARAify in the past 12 months.

Task countYARA RuleAuthorLast match
14'733'645meth_get_eipWilli Ballenthin2023-11-30
12'732'880QbotStuffanonymous2023-11-30
11'269'797maldoc_getEIP_method_1Didier Stevens (https://DidierStevens.com)2023-11-30
1'388'801DebuggerCheck__API2023-11-30
1'063'326pdb_YARAify@wowabiy3142023-05-30
935'811NETmalware-lu2023-11-30
805'545maldoc_find_kernel32_base_method_1Didier Stevens (https://DidierStevens.com)2023-11-30
741'150UPXV200V290MarkusOberhumerLaszloMolnarJohnReisermalware-lu2023-11-30
655'137UPXv20MarkusLaszloReisermalware-lu2023-11-30
624'538BitcoinAddressDidier Stevens (@DidierStevens)2023-11-30
587'331shellcodenex2023-11-30
559'795pe_imphash2023-11-30
559'794Skystars_Malware_ImphashSkystars LightDefender2023-11-30
541'465malware_shellcode_hashJPCERT/CC Incident Response Group2023-11-30
528'484command_and_controlCD_R0M_2023-11-30

ClamAV Most matching ClamAV signature


ClamAV signature that matched most on files scanned on YARAify in the past 12 Mmonths.

Task countClamAV SignatureLast match
9'888'914PUA.Win.Packer.Lccwin-22023-11-30
6'612'231Win.Trojan.Obfus-382023-11-30
4'402'328Win.Trojan.Qukart-6874817-02023-11-30
2'990'742Win.Malware.Qukart-6838239-02023-11-30
2'925'708Win.Trojan.Padodor-9877164-02023-11-30
1'655'140Win.Malware.Dqqw-9951425-02023-11-30
1'651'699Win.Malware.Zusy-6804618-02023-11-30
1'651'693Win.Trojan.QQPass-5710308-02023-11-30
1'490'3242023-11-30
1'441'801Win.Trojan.Crypted-292023-11-30
1'438'609Win.Trojan.Crypted-302023-11-30
786'984Win.Trojan.Crypted-282023-11-30
758'383Win.Trojan.Berbew-10013977-02023-11-30
721'747Win.Trojan.Berbew-9845290-12023-11-30
720'802Win.Malware.Zusy-6878655-02023-11-30

Most seen files


Most seen files scanned by YARAify in the past 12 months.

Task countSHA256 hashLast seen
3'593e0af7f483f4965dca90eb5921ae004a7e41593b39284a63af97a9105b96718e72022-01-06
3'59139e48a3fc7e67968ff5d6e3cf8e12a7256af93ccabbce4da20d28c79237d95e82022-01-06
3'584b3986e04464339cec16157cf8c8bffec3a8a8c5eae57997974d45f5369fa16552021-07-07
3'54823c2d2b0c6cec3e69cb07f942c9e56f2087aeb24015be25823897faafc4708ae2022-02-07
3'5245ea4d94c695189639e9ab7afe8d76d231030921fbfdd95e1941c7c0a05fb8f032022-02-07
3'50753c22863323c0f5ff94f4ae86df27a51db4eae7232cc38333346ee8be9df5aa62022-02-07
3'5001115b6c913a207b9d81f8482613b2a9c2929ca81399861d2d2c47422e244060d2022-02-07
3'46487479e089e6852958dab4026e07bc01ed1f31af423b1d26db462ef7493a537f12022-02-08
3'4168718400c6ca71b5afb0534931628b2aace3e5cc515edaa33d1da678f947b5cd42022-02-08
3'415c8c158269c68d6b09d0c8b118b6588302816f2936c193579b35512d6a6af506e2022-02-08
3'41196994840078a8dbaaa3175c80b72c01c3a7f258be338c94c58672cacf5e47a872022-02-08
3'410cdfb8e3d5bfb32850200759b0d3ccaa83ed5cb661cb2cccedf048d23959663602022-02-08
3'37832996a04eeead4de0813ca803033429fd38e0aa4ab8d603508e1d2c6bd38aba72022-02-08
3'3648c251ccc6eb0591c58ad3337729bcce081d8d65557523d21a6aee9cd6523d59f2022-02-07
3'343b1bce9d29dc58cf8e53382c61d200610a8200708cd32713b63b18b260db9bfa82022-02-09

Top dhash icon


Top dhash icon observed on files scanned by YARAify in the past 12 months.

Task countdhash iconLast seen
121'80769ccd4d49696cc712023-11-30
64'405f8f0f4c8c8c8d8f02023-11-30
30'6729919aca682a881a92023-11-30
22'2321003873db9313e102023-11-30
17'2371003873d31213f102023-11-30
15'468818da080a0a0a0a22023-11-30
10'67400ccc4d0c4fc7c002023-11-30
9'24504ccfee2ece4a4842023-11-30
8'836b298acbab2ca7a722023-11-30
8'530526e32661e3a2a102023-11-30
7'088d8d0d4d8ececece42023-11-30
6'342399998ecd4d46c0e2023-11-30
5'4719494b494d4aeaeac2023-11-30
3'8771ad2a38edcb6b2dc2023-11-30
3'585e0e4a2aaa4b8a8882023-11-30

Top imphash


Top imphash observed on files scanned by YARAify in the past 12 months.

Task countimphashLast seen
5'085'30546f03ef2495b21d7ad3e8d36dc03315d2023-11-29
1'926'9124dcbc0931c6f88874a69f966c86889d92023-11-29
1'815'2376db997463de98ce64bf5b6b8b0f77a452023-11-29
1'646'5562c2ad1dd2c57d1bd5795167a7236b0452023-11-29
754'965c9246f292a6fdc22d70e6e581898a0262023-11-29
559'299f34d5f2d4577ed6d9ceec516c1f5a7442023-11-29
443'885e4742a62fda2e64b586a5b84efe3f0402023-11-29
426'001dae02f32a21e03ce65412f6e56942daa2023-11-29
363'50087914047e74de74a89c530e3bb19409e2023-11-29
327'033a3df475500e5e30f4680b397c2ee13f12023-11-29
195'55584706849fa809feaa385711a628be0292023-11-29
178'944be6fa16f501de575a1d8eaaac5246ba02023-11-29
174'3890141f24aaf1b810b9fcc5f6886f26f142023-11-25
148'836646167cce332c1c252cdcb1839e0cf482023-11-29
143'66491f4b88d25daa33c7443253d9beb1bb32023-11-29

Top tlsh


Top tlsh observed on files scanned by YARAify in the past 14 months.

Task counttlshLast seen
3'593T10016DD42A3F94608F6F77F7469B916604E3BBCA6AD79C21C1284505E5EB2E40CDB0B732022-01-06
3'591T1EF16DD42A3F94608F6F77F7469B916604E3BBCA6AD79C21C1284505E5EB2E40CDB0B732022-01-06
3'585T1C8E052F688E090AC080023A82BDF2CA5437B03BD00202A0BF20BA04D022DF72E30A3F02021-07-07
3'544T1B5033E9736E31000FB09BE35C654834FEF06CF59B97A9B4ED39826C72371A78629E0592022-02-07
3'524T160030B9736E31000FB09BE32E554C24FEF06CF59B976974ED39826C72350A78662E45B2022-02-07
3'508T1BD812B4525A230CAC056C270ED52C158ABD9BC37AF44D3BBF1B90FDD83112451CC1B0B2022-02-07
3'500T153819E61842314C4F557CFF0D61BD82AAFA5334684584E1123E0606A4BCF60427041E32022-02-07
3'464T1D7819E61842314C4F557CEF4D51BE869BFA5734550584E1423E0705A4BCBA1427551A32022-02-08
3'416T1A58162A0432FB74ADC5680B151DEA0E16667707204E5CA0551C916ADDB829F0EF74C332022-02-08
3'415T10E8132A0832FBA4ADC96847151DEE1E16667307604E5C50161DA26DEDB83AE4EF78C332022-02-08
3'411T1688141C1405F2A7CF2ED8ABCA20506C43D46B4B324754D651184782DAA23E4C7722A332022-02-08
3'410T1DD816250432BB64AEC9A84B0409EA1E13657217214F2C91161CA66DC8B82AF4AF68C332022-02-08
3'407T16D32F1F94DD4E7AC4ED46381A7DF2C341EA306743331368B99269AB8621277FA11B0D72022-11-21
3'378T13A03389736E31100FB08FE32C554838FEF86CF69B976974AD79826C72350A78621E45E2022-02-08
3'367T1F9033F8736E31004BB09BE35C754834FEF46CF59B97A9B4ED39826C72370A78629E0592022-02-07

Top telfhash


Top telfhash observed on files scanned by YARAify in the past 12 months.

Task counttelfhashLast seen
244t1d9e0c240adb89a1e9ce35bb8ddcd07b1a1116253a4270b10cf58e6e0c83f988a60de6d2023-11-06
216t15821e2bf1e6709fcb3c4a898c32b62931679d273056132b401b3ad9923f2ec05169d3a2023-11-08
211t171217622513542182fb3d928acbd567315222b2363597f716f26c4cc49370e2e93ad4f2023-11-18
211t15c2131705336a115aea1cc64dcee87f2111996232744af73ee36c0cc68060cae52bc0f2023-11-08
201t195317722553546142fb3d928acfd56b315222b2363587f716f26c48c49370e2e93dd4f2023-11-18
183t19311f718893853f497b21d9e6becfb76e45171db4a265e338d40e96e9b2dd029d00c1c2023-11-06
151t18421fe46a1f6856d2ff368345dbc46b5188227133361bf70af0985c01c7b002a936ecb2023-09-03
146t13611d04270b6891d2bb659245cbc42b5165536236381be75bf0ec5c45537002ba79e8b2023-11-14
136t1ad210246a1f68a685ff368205dbc46b5199217273351af70af1984c01c7b002a939ecb2023-10-03
134t1992121a2ba6509a0f1fbf561b304d0450d200a1416fa36f2c275b9fadba5b820f78c372023-11-08
130t141217662513542182fb3d928acbd567315222b2363597f716f26c5cc49370e2f93ad4f2023-11-16
113t15411cc5271fa895d2bf649249cbc43b4265026237392beb5bf0dc6d05937002b979e8f2023-10-17
109t1e54105facb940ddc27d4cb54858d7219a5e435fc1b103176ce2a97178216cd2761f4362023-10-06
98t10111ef501e540fdccdf08f18c38e716a765b28b5ff3638119c47596f870349170340162023-10-04
96t1c421fe47a1f6856d2ff368345dbc46b5188227133361bf70af0985c01c7b002a93aecb2023-09-24