Statistics

YARAIfy produces various statistics on files scanned by YARAify, including their detections. The available statistics can be found below.

File Scans


The chart below shows the number of file scans conducted by YARAify over the past 30 days.

Data Scanned


This chart shows the amount of data scanned in Megabytes over the past 30 days.

API requests


The illustration below documents the number of API requests over the past 30 days.

Most matching YARA rules


YARA rules that matched most on files scanned on YARAify in the past 14 days.

Task countYARA RuleAuthorLast match
93'863meth_get_eipWilli Ballenthin2022-08-18
76'326pdb_YARAify@wowabiy3142022-08-18
36'828BitcoinAddressDidier Stevens (@DidierStevens)2022-08-18
34'389pe_imphash2022-08-18
34'389Skystars_Malware_ImphashSkystars LightDefender2022-08-18
29'005command_and_controlCD_R0M_2022-08-18
19'649extracted_at_0x44bcb2022-08-18
19'222meth_stackstringsWilli Ballenthin2022-08-18
13'264win_sality_autoFelix Bilstein2022-08-18
11'783malware_shellcode_hashJPCERT/CC Incident Response Group2022-08-18
9'811reverse_httpCD_R0M_2022-08-18
9'296AutoIT_Compiled@bartblaze2022-08-18
9'155MALWARE_Win_BlackMoonditekSHen2022-08-18
8'272cobalt_strike_tmp01925d3fThe DFIR Report2022-08-18
7'093win_vobfus_autoFelix Bilstein2022-08-18

ClamAV Most matching ClamAV signature


ClamAV signature that matched most on files scanned on YARAify in the past 14 days.

Task countClamAV SignatureLast match
71'854PUA.Win.Packer.Upx-42022-08-18
13'138PUA.Win.Packer.AcprotectUltraprotect-12022-08-18
12'211Win.Malware.Dqqw-9951425-02022-08-18
12'203Win.Trojan.QQPass-5710308-02022-08-18
12'203Win.Malware.Zusy-6804618-02022-08-18
10'753Win.Malware.Generickdz-9938530-02022-08-18
10'644Win.Malware.Nevereg-9916351-02022-08-18
10'145Win.Trojan.Cosmu-10582022-08-18
9'309PUA.Win.Packer.Pequake-42022-08-18
8'948Win.Dropper.Tiggre-9845940-02022-08-18
8'780Win.Malware.Blackmoon-9864920-12022-08-17
8'780Win.Dropper.Ganelp-9866440-02022-08-17
8'468PUA.Win.Packer.Pseudosigner-362022-08-18
7'892Win.Malware.Blackmoon-9753196-12022-08-17
7'247PUA.Win.Packer.Lccwin-22022-08-18

Most seen files


Most seen files scanned by YARAify in the past 14 days.

Task countSHA256 hashLast seen
1400c03e4a8c7a3bad994c5de501cae72c5ade792c990ea3517d010fd7c7e8f8f832022-01-07
140a17d9acf160f17ea803733b8d36efd209a1d0ce6210008f8090a86499ccb7a302021-07-07
1401115b6c913a207b9d81f8482613b2a9c2929ca81399861d2d2c47422e244060d2022-02-07
140b3986e04464339cec16157cf8c8bffec3a8a8c5eae57997974d45f5369fa16552021-07-07
14032996a04eeead4de0813ca803033429fd38e0aa4ab8d603508e1d2c6bd38aba72022-02-08
140c25bd3702ca723b9b9427079397e4f5905e2f3a9ef86810a694be4faa8cb32c32021-07-07
1400af2babf55bcd69683cee4c3043d58aff2e1ff91fb4d170c98963601a321b2612022-01-24
1405ea4d94c695189639e9ab7afe8d76d231030921fbfdd95e1941c7c0a05fb8f032022-02-07
14023c2d2b0c6cec3e69cb07f942c9e56f2087aeb24015be25823897faafc4708ae2022-02-07
1405d2c578c6f0fe65a39e920bf03b5023ca0ace5efa80c316f7f454067cfea87b32021-07-07
14066c4c5083d01f12c0e40e79d07f626380779dd83640a4f4e1a0878fff34c4dac2022-01-24
1408c251ccc6eb0591c58ad3337729bcce081d8d65557523d21a6aee9cd6523d59f2022-02-07
14053c22863323c0f5ff94f4ae86df27a51db4eae7232cc38333346ee8be9df5aa62022-02-07
14067531d9270ee87d1025c9a35c6250cef9f7b0eefc6ecbefc0e406f3b5568f4382022-01-07
14039e48a3fc7e67968ff5d6e3cf8e12a7256af93ccabbce4da20d28c79237d95e82022-01-06

Top dhash icon


Top dhash icon observed on files scanned by YARAify in the past 14 days.

Task countdhash iconLast seen
9029919aca682a881a92022-07-23
751f8fcec9e8e88c0e82022-08-17
704399998ecd4d46c0e2022-08-17
668696a6ee2b2b2c2cc2022-08-13
626ccf0f0c8d496e0f02022-08-17
5988432f99cf870a2482022-08-13
37838b078cccacccc432022-08-17
301414555c0d4d445032022-07-22
270aad4c0d4d4e46aa02022-08-17
270b2dacabecee6baa62022-08-16
244ba12f29a9dd2a2a22022-08-17
24059b06cd2d6fcf2d02022-08-17
20638b078eccacccc432022-08-17
196badacabecee6baa62022-08-16
17969ccd4d49696cc712022-07-24

Top imphash


Top imphash observed on files scanned by YARAify in the past 14 days.

Task countimphashLast seen
34'441f34d5f2d4577ed6d9ceec516c1f5a7442022-08-18
23'820dae02f32a21e03ce65412f6e56942daa2022-08-18
12'1922c2ad1dd2c57d1bd5795167a7236b0452022-08-18
9'2458abecba2211e61763c4c9ffcaa13369e2022-08-18
5'2759c3076658fe99e27b2a5d06cd805dc7e2022-08-17
5'2082af425137b80f9222ed4562e4bfba1f32022-08-18
5'12614257997e0ca768516e946a837c52bc02022-08-17
4'72784706849fa809feaa385711a628be0292022-08-17
4'297a8edba105869c8b0330adec370df50cc2022-08-18
4'1357d55d950abf60b9ca05ce35790cded412022-08-18
3'708e4742a62fda2e64b586a5b84efe3f0402022-08-18
3'646cdf5bbb8693f29ef22aef04d2a161dd72022-08-17
3'455a56705099ec07c676809955bdcce8d092022-08-17
3'446f481ea8169d367d8b0e94d0bf02da2202022-08-18
2'7685271d5ce8b44dd47bc92563e275854662022-08-18

Top tlsh


Top tlsh observed on files scanned by YARAify in the past 14 days.

Task counttlshLast seen
1'128T1A485AE7DC12BCA1AC81C747E684467813E9DC7F8A56582AC678EFB3F924C87850BD6702022-08-17
918T1EE056E2291C7D2F1F3F724B197D002BF5D289127C68A9D35F8252548A3861D6BC3DBEA2022-08-18
827T106056E2291C7D2F1F3F724B197D002BF5D289127C68A9D35F8252548A3861D6BC3DBEA2022-08-18
421T1EEF46E2291C7D2F1F3F724B197D002BF5D289127C68A9D35F8252548A3861D6BC3DBEA2022-08-16
384T106F46E2291C7D2F1F3F724B197D002BF5D289127C68A9D35F8252548A3861D6BC3DBEA2022-08-14
140T18965CB4163F94618F6F73F746AB51A604E3ABC92AD79C22D2248505E5FB2E40DCB0B732022-01-24
140T1BD812B4525A230CAC056C270ED52C158ABD9BC37AF44D3BBF1B90FDD83112451CC1B0B2022-02-07
140T13A03389736E31100FB08FE32C554838FEF86CF69B976974AD79826C72350A78621E45E2022-02-08
140T160030B9736E31000FB09BE32E554C24FEF06CF59B976974ED39826C72350A78662E45B2022-02-07
140T153819E61842314C4F557CFF0D61BD82AAFA5334684584E1123E0606A4BCF60427041E32022-02-07
140T18CC048F380E010420460231313EF1E452B5F235C77462623F42C7D808320A3A37A39722021-07-07
140T179E06CFA88EC219D5A80435517DF6DB4976B02BD18263813F530928D831DB76E6633B62021-07-07
140T18E031A44A75D9773CBAD06FEF8F3762102F499A9BA07E34B6CCC60A059427F447109AB2022-01-07
140T10016DD42A3F94608F6F77F7469B916604E3BBCA6AD79C21C1284505E5EB2E40CDB0B732022-01-06
140T192D002F380E0149A4460331317DF1D451B5F136DB78A2613F83D7E84432093A37539712021-07-07

Top telfhash


Top telfhash observed on files scanned by YARAify in the past 14 days.

Task counttelfhashLast seen
16t15411cc5271fa895d2bf649249cbc43b4265026237392beb5bf0dc6d05937002b979e8f2022-08-11
12t12a213613b4b98a285ff228249cbc57a41642653332617eb19f5dc1c0dc2b007e875ecf2022-08-08
12t1ae11e10271f689282bf259245cbc43f4265126233341be71bf0dc5c0593b003b939e8b2022-08-11
9t1d911d01371f6896d2bf259245cbc43b4255026237351be75bf0dc5d4593b002b979ecb2022-08-10
8t1fe11104270b6891c2bb259245cbc42b0165532232381be74bf0ec5c05937002ba79e8b2022-08-15
8t141217662513542182fb3d928acbd567315222b2363597f716f26c5cc49370e2f93ad4f2022-08-16
8t10601ef0269484fe80be0414d408afb3350d520f42d723d99afaa3e8f1847de1347243a2022-08-14
8t184212353b4ba8a191ff228249cbc5ba41642a52332617eb19f5dc1c49c3b003f975e8f2022-08-08
8t107110c4371fa895c2bf249249cbc43b0265026237382beb0bf0dc6c05937002b979e8f2022-08-11
8t1a4212353b4ba8a191ff228249cbc57a41642a52332617eb19f5dc1c4d83b003f975e8f2022-08-08
8t171217622513542182fb3d928acbd567315222b2363597f716f26c4cc49370e2e93ad4f2022-08-16
8t195317722553546142fb3d928acfd56b315222b2363587f716f26c48c49370e2e93dd4f2022-08-16
7t12211dc515bc916ecf7c1c20d834a633f2b5938b96e312068dbaf8f8b01979c1712083a2022-08-08
7t1aa315009483d4a023ef08d785caaaac210ae1f2167050e31cf7c806d9e0e0f3e57396a2022-08-11
7t15321ee314b2052266ba1dda4ccee53a2152987265348af37cf32c5cc651a0deea37c4f2022-08-11

File Scans


The chart below shows the number of file scans conducted by YARAify over the past 12 months.

Data Scanned


This chart shows the amount of data scanned in Megabytes over the past past 12 months.

API requests


The illustration below documents the number of API requests over the past past 12 months.

Most matching YARA rules


YARA rules that matched most on files scanned on YARAify in the past 12 months.

Task countYARA RuleAuthorLast match
1'016'357classifiedclassified2022-08-16
854'874meth_get_eipWilli Ballenthin2022-08-18
663'968BitcoinAddressDidier Stevens (@DidierStevens)2022-08-18
537'113crime_win64_emotet_unpackedRony (r0ny_123)2022-08-17
524'200pdb_YARAify@wowabiy3142022-08-18
491'345Skystars_Malware_ImphashSkystars LightDefender2022-08-18
491'345pe_imphash2022-08-18
480'030classifiedclassified2022-08-17
387'538win_heodo2022-08-17
359'497exploit_any_poppopretJeff White [karttoon@gmail.com] @noottrak2022-06-22
279'775win_sality_autoFelix Bilstein2022-08-18
274'244Emotet_BotnetHarish Kumar P2022-08-17
240'613INDICATOR_EXE_Packed_ASPackditekSHen2022-08-18
213'942win_vobfus_autoFelix Bilstein2022-08-18
205'678classifiedclassified2022-08-17

ClamAV Most matching ClamAV signature


ClamAV signature that matched most on files scanned on YARAify in the past 12 Mmonths.

Task countClamAV SignatureLast match
424'370PUA.Win.Packer.Upx-42022-08-18
339'919PUA.Win.Packer.Asprotect-32022-08-18
266'291Win.Virus.Wapomi-1382022-07-17
239'197PUA.Win.Packer.Lccwin-22022-08-18
227'487Win.Trojan.Qukart-6874817-02022-08-18
194'225Win.Malware.Qukart-6838239-02022-08-17
156'972Win.Dropper.Berbew-9106192-02022-08-04
142'002Win.Trojan.Obfus-382022-08-18
126'090Win.Malware.Generickdz-9938530-02022-08-18
122'191Win.Trojan.Cosmu-10582022-08-18
121'635Win.Malware.Bdld-9770176-02022-08-17
90'634Win.Trojan.Crypted-302022-08-18
90'263Win.Trojan.Crypted-292022-08-18
81'044Win.Trojan.Ulise-9792178-02022-08-18
81'017Win.Trojan.Ulise-9792179-02022-08-18

Most seen files


Most seen files scanned by YARAify in the past 12 months.

Task countSHA256 hashLast seen
150'031bfc6bff6a3be4c198b51f7ac0a28a8b61baaadbffcdcca8f25ef35b616c53cc52022-07-14
120'0652d93837ee387916c4a6060912fcb2b9fdaa836f419d2a038500299b376b5fbcd2021-07-08
118'50823c2d2b0c6cec3e69cb07f942c9e56f2087aeb24015be25823897faafc4708ae2022-02-07
114'7811665e0d57f7f62035a0f720ca385a82a27502283bf131d1628c877159e79a2102021-07-08
71'269f914ff8baa3bea7a4bde2f0554ddbaaea9d8090eabb277f1486648854a7f967a2022-01-11
49'9575881513fca390bfea60468b7b8085da7448efeeca39f52c8ac56745024afe2692021-07-08
38'525997f39432702a13c47ff2fbe1396b99663eb9debad312ede79978db122cf735e2022-01-27
35'5945ea4d94c695189639e9ab7afe8d76d231030921fbfdd95e1941c7c0a05fb8f032022-02-07
29'410e19b0ba085a6c6f754df5f6f3a2ad8d490eafb62ad14606a943e7de2d0e3e03f2021-07-07
28'2867f94107c9becbcc6ca42070fca7e1e63f29cdd85cbbd8953bbca32a1b4f912192022-01-11
26'36176cf234b9b0004e3c87633ebf8ff38a175576bc9baa6f34d863fc8eef0fa50b72022-01-28
24'669cf581ab47fabfc401ebca29130781037fb56b3bc54515f845f6f26bb4cbf96702022-06-08
24'080e0af7f483f4965dca90eb5921ae004a7e41593b39284a63af97a9105b96718e72022-01-06
24'00039e48a3fc7e67968ff5d6e3cf8e12a7256af93ccabbce4da20d28c79237d95e82022-01-06
23'635daf3d4175396ad0f2d639ea6dcfb166d701cdce5fd545fe3a320a88bd267ec7e2022-05-12

Top dhash icon


Top dhash icon observed on files scanned by YARAify in the past 12 months.

Task countdhash iconLast seen
86'33237373339294935872022-07-23
79'0959919aca682a881a92022-07-23
40'511399998ecd4d46c0e2022-08-17
29'980e94a6e71e932f0332022-07-23
27'893e0e4a2aaa4b8a8882022-07-23
27'015d0c4a2a2a4bcbcb82022-07-23
20'98971b119dcce5763332022-08-15
20'923c271cc9cae8de9722022-07-23
20'917338be5f1f1a9adb72022-07-23
18'4151003873d31213f102022-08-17
17'3591ad2a38edcb6b2dc2022-07-23
14'218818da080a0a0a0a22022-08-14
13'22830d4f0e8ccdcf0712022-07-23
10'667f8fcec9e8e88c0e82022-08-17
10'02300ccc4d0c4fc7c002022-07-23

Top imphash


Top imphash observed on files scanned by YARAify in the past 12 months.

Task countimphashLast seen
259'321f34d5f2d4577ed6d9ceec516c1f5a7442022-08-18
164'90768d9776cadfeba9a6849d2f603b34a8f2022-08-04
164'293dae02f32a21e03ce65412f6e56942daa2022-08-18
110'8318abecba2211e61763c4c9ffcaa13369e2022-08-18
94'060ed86c2ba483c37b0e2cfeecbd5fca8762022-08-17
61'498b87b5fb150cfc5c490bcca7572133d9f2022-07-17
56'2220bfb4502b7427d90a9fa0442dea9af552022-08-18
52'994359d89624a26d1e756c3e9d6782d6eb02022-08-17
49'8006db997463de98ce64bf5b6b8b0f77a452022-08-17
45'741e4742a62fda2e64b586a5b84efe3f0402022-08-18
40'1973e4757b6c44f364955a909104e3b2b4d2022-08-14
39'0775271d5ce8b44dd47bc92563e275854662022-08-18
38'1082c2ad1dd2c57d1bd5795167a7236b0452022-08-18
36'7425c7397fd7c1832e37a3cb00b6ee7c3772022-08-18
33'182bf5a4aa99e5b160f8521cadd6bfe73b82022-08-18

Top tlsh


Top tlsh observed on files scanned by YARAify in the past 14 months.

Task counttlshLast seen
118'508T1B5033E9736E31000FB09BE35C654834FEF06CF59B97A9B4ED39826C72371A78629E0592022-02-07
71'269T1CAE33A01F3D341F3DC970CF629B6B22EDB791E126068EE9987981F576D71249E2B980C2022-01-11
38'525T19DE35A11F39381F3DC960CF219B6B22F9F7D0E036164DEA593981F57ADB2245A2B981C2022-01-27
35'594T160030B9736E31000FB09BE32E554C24FEF06CF59B976974ED39826C72350A78662E45B2022-02-07
29'410T18CC048F380E010420460231313EF1E452B5F235C77462623F42C7D808320A3A37A39722021-07-07
28'286T105E34B01F39381F7DC960CF2297AB62FDF7D1E032064DE9593945F1BAC72609A2A991C2022-01-11
26'361T192E35A11F39381F3DC9608F219B6B22FDF7D0E036164DEA593981F57ADB2245A2B981C2022-01-28
24'691T129F36C24E84345E7F87B1932D0077A2FD4647D295220EE7BD954CE9AFF22B14A20F25E2022-06-12
24'080T10016DD42A3F94608F6F77F7469B916604E3BBCA6AD79C21C1284505E5EB2E40CDB0B732022-01-06
24'000T1EF16DD42A3F94608F6F77F7469B916604E3BBCA6AD79C21C1284505E5EB2E40CDB0B732022-01-06
23'635T173045B65E49345E7F8BB0872904A7B5FD8242D41D210DE3F9554CEDABF22B25A20F22F2022-05-12
22'059T192D002F380E0149A4460331317DF1D451B5F136DB78A2613F83D7E84432093A37539712021-07-07
21'754T1BD812B4525A230CAC056C270ED52C158ABD9BC37AF44D3BBF1B90FDD83112451CC1B0B2022-02-07
20'124T117E35A11F39381F3DC960CF219B6B22F9F7D0E036164DEA593981F57ADB2245A2B981C2022-01-25
19'464T1EDD34B11F7C341F3DC9608F169B6A22FDFB90E137064DEA587A81F576CB2605A2B990C2022-01-28

Top telfhash


Top telfhash observed on files scanned by YARAify in the past 12 months.

Task counttelfhashLast seen
62t13611d04270b6891d2bb659245cbc42b5165536236381be75bf0ec5c45537002ba79e8b2022-08-15
59t171217622513542182fb3d928acbd567315222b2363597f716f26c4cc49370e2e93ad4f2022-08-16
52t15411cc5271fa895d2bf649249cbc43b4265026237392beb5bf0dc6d05937002b979e8f2022-08-11
50t19ee0df40ac699e2c98d7aa74dddd07a496016223556a4b10cf10dbe4883f458e30ce5e2022-06-17
50t195317722553546142fb3d928acfd56b315222b2363587f716f26c48c49370e2e93dd4f2022-08-16
50t1fe11104270b6891c2bb259245cbc42b0165532232381be74bf0ec5c05937002ba79e8b2022-08-15
46t1ace07200ec75871c88dbaab49c8c07b0da012226606b0b10cf10daf4c83f444f30ce4a2022-07-17
45t1d211020260b689282bb259205cbc42f1165526233341be75bf0ec5c4993b002aa78e8b2022-08-15
44t1c1e02c40acb58a1898dbaa74ed8d0ba49a012222606a0b10cf10daf4c83f448e308e4a2022-07-17
40t141217662513542182fb3d928acbd567315222b2363597f716f26c5cc49370e2f93ad4f2022-08-16
35t13c2120251b31522a6e71dd64dcec57b10528472313847f32df26c4cc652a48dea2fc1f2022-05-31
35t1d911d01371f6896d2bf259245cbc43b4255026237351be75bf0dc5d4593b002b979ecb2022-08-10
32t11ee07200ec75871c88dbaa749d8d07b4ca012216606b0b10cf10daf4c83f448f30ce4a2022-08-17
31t1012134f7297e1de8e7d5a404831a6e521e9ee03f291032a005238a2137a7dc290b9c792022-06-27
30t1ae11e10271f689282bf259245cbc43f4265126233341be71bf0dc5c0593b003b939e8b2022-08-11