Statistics

YARAIfy produces various statistics on files scanned by YARAify, including their detections. The available statistics can be found below.

File Scans


The chart below shows the number of file scans conducted by YARAify over the past 30 days.

Data Scanned


This chart shows the amount of data scanned in Megabytes over the past 30 days.

API requests


The illustration below documents the number of API requests over the past 30 days.

Most matching YARA rules


YARA rules that matched most on files scanned on YARAify in the past 14 days.

Task countYARA RuleAuthorLast match
1'399'788maldoc_getEIP_method_1Didier Stevens (https://DidierStevens.com)2024-04-13
1'392'133meth_get_eipWilli Ballenthin2024-04-13
1'300'566QbotStuffanonymous2024-04-13
605'585win_berbew_strings_dec_2023Matthew @ Embee_Research2024-04-13
158'502DebuggerCheck__API2024-04-13
82'466UPXV200V290MarkusOberhumerLaszloMolnarJohnReisermalware-lu2024-04-13
76'173UPXv20MarkusLaszloReisermalware-lu2024-04-13
74'403NETmalware-lu2024-04-13
66'093maldoc_find_kernel32_base_method_1Didier Stevens (https://DidierStevens.com)2024-04-13
53'014Check_Dlls2024-04-12
42'048DebuggerException__SetConsoleCtrl2024-04-13
41'701SEH__vba2024-04-13
40'496SUSP_XORed_URL_in_EXE_RID2E46Florian Roth2024-04-13
40'493SUSP_XORed_URL_In_EXEFlorian Roth (Nextron Systems)2024-04-13
37'328malware_shellcode_hashJPCERT/CC Incident Response Group2024-04-13

ClamAV Most matching ClamAV signature


ClamAV signature that matched most on files scanned on YARAify in the past 14 days.

Task countClamAV SignatureLast match
1'255'128PUA.Win.Packer.Lccwin-22024-04-13
836'835Win.Trojan.Obfus-382024-04-13
601'6162024-04-13
598'256Win.Trojan.Qukart-6874817-02024-04-13
598'053Win.Trojan.Padodor-10016488-02024-04-13
462'359Win.Malware.Qukart-6838239-02024-04-13
375'169Win.Trojan.Padodor-9877164-02024-04-13
179'402Win.Trojan.Berbew-10013977-02024-04-13
124'208Win.Trojan.Razy-10015064-02024-04-13
110'975Win.Packed.Lazy-10005437-02024-04-13
109'915Win.Packed.Generickdz-10022900-02024-04-11
103'241Win.Packed.Razy-10010080-02024-04-13
97'164Win.Trojan.Packz-10017161-02024-04-12
96'240Win.Malware.Padodor-10012877-02024-04-13
84'136Win.Packed.Zpack-10013399-02024-04-13

Most seen files


Most seen files scanned by YARAify in the past 14 days.

Task countSHA256 hashLast seen
1818ca5974b9dc830a3f63caae3c39ad62d4ad8e1cb5613eb2c896676e7fd6dbfb42024-04-10
14432db789ed5f5a2eda146a192261afafd715185711a1b86430a0f1bbf819d3bea2024-04-08
138197e9e7523f08c0f990ef6ada4017d8bb69e3b286cb6ff43141cbfb8e5ca9b1a2024-04-03
130e0af7f483f4965dca90eb5921ae004a7e41593b39284a63af97a9105b96718e72022-01-06
13039e48a3fc7e67968ff5d6e3cf8e12a7256af93ccabbce4da20d28c79237d95e82022-01-06
128b3986e04464339cec16157cf8c8bffec3a8a8c5eae57997974d45f5369fa16552021-07-07
1211115b6c913a207b9d81f8482613b2a9c2929ca81399861d2d2c47422e244060d2022-02-07
11887479e089e6852958dab4026e07bc01ed1f31af423b1d26db462ef7493a537f12022-02-08
116c33f67a18ad931a7ae9957fc79e304178c7fa450aa471c544139018c45aad0832024-04-02
115c25bd3702ca723b9b9427079397e4f5905e2f3a9ef86810a694be4faa8cb32c32021-07-07
113c8c158269c68d6b09d0c8b118b6588302816f2936c193579b35512d6a6af506e2022-02-08
1128718400c6ca71b5afb0534931628b2aace3e5cc515edaa33d1da678f947b5cd42022-02-08
112cdfb8e3d5bfb32850200759b0d3ccaa83ed5cb661cb2cccedf048d23959663602022-02-08
11153c22863323c0f5ff94f4ae86df27a51db4eae7232cc38333346ee8be9df5aa62022-02-07
111a4ec9fd2488f0b1734317beb74e1524838d0f7c907eb4e452d7cf40c03c7e5dd2021-07-08

Top dhash icon


Top dhash icon observed on files scanned by YARAify in the past 14 days.

Task countdhash iconLast seen
24'54569ccd4d49696cc712024-04-13
18'331818da080a0a0a0a22024-04-13
10'4671003873db9313e102024-04-13
7'959d8d0d4d8ececece42024-04-09
5'9475ab3a5b332c482a02024-04-13
5'2241003873d31213f102024-04-13
5'1389919aca682a881a92024-04-13
3'88086696ddce4f4d2692024-04-13
3'549526e32661e3a2a102024-04-10
3'0522171d95b2b37e2f92024-04-10
2'38204ccfee2ece4a4842024-04-13
1'920b298acbab2ca7a722024-04-13
1'91273719d94ccc633232024-04-10
1'892b67ee8c2f2f0711a2024-04-10
1'67100c4daced6d6cc002024-04-13

Top imphash


Top imphash observed on files scanned by YARAify in the past 14 days.

Task countimphashLast seen
552'07446f03ef2495b21d7ad3e8d36dc03315d2024-04-10
324'4636db997463de98ce64bf5b6b8b0f77a452024-04-10
180'3524dcbc0931c6f88874a69f966c86889d92024-04-09
64'503c9246f292a6fdc22d70e6e581898a0262024-04-09
47'987e4742a62fda2e64b586a5b84efe3f0402024-04-10
25'6992c2ad1dd2c57d1bd5795167a7236b0452024-04-09
20'137a3df475500e5e30f4680b397c2ee13f12024-04-13
14'0653f8d79e42b0b7cecf379b1ddce4e422a2024-04-09
11'18187914047e74de74a89c530e3bb19409e2024-04-09
10'675f34d5f2d4577ed6d9ceec516c1f5a7442024-04-13
10'58191f4b88d25daa33c7443253d9beb1bb32024-04-13
5'7551a611a7df1f3828b0157c4725145a7212024-04-09
5'353dae02f32a21e03ce65412f6e56942daa2024-04-13
5'280be6fa16f501de575a1d8eaaac5246ba02024-04-10
4'1395271d5ce8b44dd47bc92563e275854662024-04-13

Top tlsh


Top tlsh observed on files scanned by YARAify in the past 14 days.

Task counttlshLast seen
181T19E6413FC8667C1A4F92395B5D20F2FEE4697F820D8C488B22DD897653381CE9583E4D62024-04-10
130T1C8E052F688E090AC080023A82BDF2CA5437B03BD00202A0BF20BA04D022DF72E30A3F02021-07-07
127T10016DD42A3F94608F6F77F7469B916604E3BBCA6AD79C21C1284505E5EB2E40CDB0B732022-01-06
127T1EF16DD42A3F94608F6F77F7469B916604E3BBCA6AD79C21C1284505E5EB2E40CDB0B732022-01-06
120T153819E61842314C4F557CFF0D61BD82AAFA5334684584E1123E0606A4BCF60427041E32022-02-07
113T1D7819E61842314C4F557CEF4D51BE869BFA5734550584E1423E0705A4BCBA1427551A32022-02-08
112T176E48D61F185C075E0F116B0A6FE7A5B146C2975471D38E3EB98BEC929740F27A3C28B2021-08-11
112T133E48D51F185C076E0F116B0A6FE7A5B146C2975471D38E3EB98BEC929740F27A3C28B2021-08-11
111T179E06CFA88EC219D5A80435517DF6DB4976B02BD18263813F530928D831DB76E6633B62021-07-07
110T196045A10B4D2C073E972053518F4EBB5897EFC350B615AFB67D80B3A4E342D29A35A7A2024-04-01
109T168966B91FA9B00F5EA13543084A7623F9331BD064B25CFCBD6506F2AED73AD20E366592023-11-08
108T16211801BC7D1ADF1C44C01700F5786041735D42453D583574E94047EFC561BC6CD6C062021-07-08
108T1FBE47D21F1C18079E4F5157096FF7A5B246C69A64B2838E3E7987EC928741F27A3C2C72021-07-08
108T1BCE47D21F1C18079E4F5157096FF7A5B246C69A64B2838E3E7987EC928741F27A3C2C72021-07-08
107T1BD812B4525A230CAC056C270ED52C158ABD9BC37AF44D3BBF1B90FDD83112451CC1B0B2022-02-07

Top telfhash


Top telfhash observed on files scanned by YARAify in the past 14 days.

Task counttelfhashLast seen
45t12a21419271f6ca2d3bb389746cbc43b52642b5132741bf75af0ec5c45833052a924ecb2024-04-09
43t14e21324271f68a282bb385245cbc03b5264665232341bf756f0ec5c45837012a534dcb2024-04-10
39t149212e9271f68a293bb389746cbc43b52646a5132741bf75af0ec5c45833152a924ecb2024-04-08
18t12221419271f6ca2d3bb389746cbc43b52242b5132341bf75af0ec5c85433052a924dcb2024-04-08
18t1ed213152a1f6cb282bb38924adbc03f51652aa236282bf756f0ec5c45437143a934ddb2024-04-13
16t18521449271f6ca2d3bb385746cbc43b5225275232741bf756f0ec5c45433052a924dcb2024-04-09
16t1ed215e9271f68a283bb38a346cbc03b52246a1132341bf75af0ec5c45833112a928ecb2024-04-08
16t1b2119c205936563d5e5299744c9c6272252c2b03eb165fb6df39c8cc51308f2e67fe0d2024-04-13
14t18c3112a19679512a5da1ec68edda57b2501a56172350bf33df21c0cc380a44ff527c0f2024-04-11
13t1ad210246a1f68a685ff368205dbc46b5199217273351af70af1984c01c7b002a939ecb2024-04-09
13t16841931809b817f0a7266d5d089dff36d6a731db7e166c238e11e86eab29f834d10c1c2024-04-08
12t195317722553546142fb3d928acfd56b315222b2363587f716f26c48c49370e2e93dd4f2024-04-01
12t171217622513542182fb3d928acbd567315222b2363597f716f26c4cc49370e2e93ad4f2024-04-01
12t18a5106fa2dbe0cfcb3e56c08c74e2ad32a55da7b1951357184a79ca533f3a4080a5c362024-04-11
12t1ae11e10271f689282bf259245cbc43f4265126233341be71bf0dc5c0593b003b939e8b2024-04-07

File Scans


The chart below shows the number of file scans conducted by YARAify over the past 12 months.

Data Scanned


This chart shows the amount of data scanned in Megabytes over the past past 12 months.

API requests


The illustration below documents the number of API requests over the past past 12 months.

Most matching YARA rules


YARA rules that matched most on files scanned on YARAify in the past 12 months.

Task countYARA RuleAuthorLast match
25'577'112meth_get_eipWilli Ballenthin2024-04-13
24'006'714maldoc_getEIP_method_1Didier Stevens (https://DidierStevens.com)2024-04-13
23'613'233QbotStuffanonymous2024-04-13
3'559'883win_berbew_strings_dec_2023Matthew @ Embee_Research2024-04-13
3'081'694DebuggerCheck__API2024-04-13
1'790'309NETmalware-lu2024-04-13
1'608'087maldoc_find_kernel32_base_method_1Didier Stevens (https://DidierStevens.com)2024-04-13
1'565'034UPXV200V290MarkusOberhumerLaszloMolnarJohnReisermalware-lu2024-04-13
1'408'781UPXv20MarkusLaszloReisermalware-lu2024-04-13
968'014malware_shellcode_hashJPCERT/CC Incident Response Group2024-04-13
887'265SHA512_Constantsphoul (@phoul)2024-04-13
834'439SHA1_Constantsphoul (@phoul)2024-04-13
834'255RIPEMD160_Constantsphoul (@phoul)2024-04-13
831'526MD5_Constantsphoul (@phoul)2024-04-13
798'168Check_Dlls2024-04-12

ClamAV Most matching ClamAV signature


ClamAV signature that matched most on files scanned on YARAify in the past 12 Mmonths.

Task countClamAV SignatureLast match
23'978'037PUA.Win.Packer.Lccwin-22024-04-13
16'070'563Win.Trojan.Obfus-382024-04-13
12'444'032Win.Trojan.Qukart-6874817-02024-04-13
9'087'843Win.Malware.Qukart-6838239-02024-04-13
7'116'361Win.Trojan.Padodor-10016488-02024-04-13
5'975'782Win.Trojan.Padodor-9877164-02024-04-13
2'417'2382024-04-13
2'376'273Win.Trojan.Crypted-292024-04-10
2'362'590Win.Trojan.Crypted-302024-04-10
2'315'220Win.Trojan.Berbew-10013977-02024-04-13
2'025'208Win.Packed.Razy-10010080-02024-04-13
2'004'106Win.Malware.Dqqw-9951425-02024-04-10
2'000'756Win.Trojan.QQPass-5710308-02024-04-10
1'999'315Win.Malware.Zusy-6804618-02024-04-09
1'955'350Win.Trojan.Berbew-9845290-12024-04-13

Most seen files


Most seen files scanned by YARAify in the past 12 months.

Task countSHA256 hashLast seen
3'526b3986e04464339cec16157cf8c8bffec3a8a8c5eae57997974d45f5369fa16552021-07-07
3'525e0af7f483f4965dca90eb5921ae004a7e41593b39284a63af97a9105b96718e72022-01-06
3'51839e48a3fc7e67968ff5d6e3cf8e12a7256af93ccabbce4da20d28c79237d95e82022-01-06
3'49323c2d2b0c6cec3e69cb07f942c9e56f2087aeb24015be25823897faafc4708ae2022-02-07
3'4771115b6c913a207b9d81f8482613b2a9c2929ca81399861d2d2c47422e244060d2022-02-07
3'4465ea4d94c695189639e9ab7afe8d76d231030921fbfdd95e1941c7c0a05fb8f032022-02-07
3'44587479e089e6852958dab4026e07bc01ed1f31af423b1d26db462ef7493a537f12022-02-08
3'42853c22863323c0f5ff94f4ae86df27a51db4eae7232cc38333346ee8be9df5aa62022-02-07
3'409a4ec9fd2488f0b1734317beb74e1524838d0f7c907eb4e452d7cf40c03c7e5dd2021-07-08
3'402c8c158269c68d6b09d0c8b118b6588302816f2936c193579b35512d6a6af506e2022-02-08
3'4018718400c6ca71b5afb0534931628b2aace3e5cc515edaa33d1da678f947b5cd42022-02-08
3'398cdfb8e3d5bfb32850200759b0d3ccaa83ed5cb661cb2cccedf048d23959663602022-02-08
3'39596994840078a8dbaaa3175c80b72c01c3a7f258be338c94c58672cacf5e47a872022-02-08
3'332b1bce9d29dc58cf8e53382c61d200610a8200708cd32713b63b18b260db9bfa82022-02-09
3'32478131658b0ceb924e4885e88a0f3c53b509d04e4a9bf0f8b4413d6b16fd8b7fa2021-07-08

Top dhash icon


Top dhash icon observed on files scanned by YARAify in the past 12 months.

Task countdhash iconLast seen
522'74869ccd4d49696cc712024-04-13
199'433818da080a0a0a0a22024-04-13
116'2971003873db9313e102024-04-13
90'068b298acbab2ca7a722024-04-13
87'4275ab3a5b332c482a02024-04-13
78'426f8f0f4c8c8c8d8f02024-04-13
64'6879919aca682a881a92024-04-13
60'6161003873d31213f102024-04-13
53'609526e32661e3a2a102024-04-10
48'663d8d0d4d8ececece42024-04-09
40'89400ccc4d0c4fc7c002024-04-13
32'149b67ee8c2f2f0711a2024-04-10
27'58404ccfee2ece4a4842024-04-13
26'67100c4daced6d6cc002024-04-13
18'07900ca80c2c28082002024-04-10

Top imphash


Top imphash observed on files scanned by YARAify in the past 12 months.

Task countimphashLast seen
9'921'04046f03ef2495b21d7ad3e8d36dc03315d2024-04-10
6'039'2196db997463de98ce64bf5b6b8b0f77a452024-04-10
4'719'6984dcbc0931c6f88874a69f966c86889d92024-04-09
1'993'845c9246f292a6fdc22d70e6e581898a0262024-04-09
1'605'1002c2ad1dd2c57d1bd5795167a7236b0452024-04-09
1'080'729e4742a62fda2e64b586a5b84efe3f0402024-04-10
659'92987914047e74de74a89c530e3bb19409e2024-04-09
618'768a3df475500e5e30f4680b397c2ee13f12024-04-13
469'608f34d5f2d4577ed6d9ceec516c1f5a7442024-04-13
378'40691f4b88d25daa33c7443253d9beb1bb32024-04-13
310'233dae02f32a21e03ce65412f6e56942daa2024-04-13
246'1033f8d79e42b0b7cecf379b1ddce4e422a2024-04-09
189'6580141f24aaf1b810b9fcc5f6886f26f142024-03-13
172'59984706849fa809feaa385711a628be0292024-04-09
164'918be6fa16f501de575a1d8eaaac5246ba02024-04-10

Top tlsh


Top tlsh observed on files scanned by YARAify in the past 14 months.

Task counttlshLast seen
3'979T16D32F1F94DD4E7AC4ED46381A7DF2C341EA306743331368B99269AB8621277FA11B0D72022-11-21
3'531T1C8E052F688E090AC080023A82BDF2CA5437B03BD00202A0BF20BA04D022DF72E30A3F02021-07-07
3'527T10016DD42A3F94608F6F77F7469B916604E3BBCA6AD79C21C1284505E5EB2E40CDB0B732022-01-06
3'520T1EF16DD42A3F94608F6F77F7469B916604E3BBCA6AD79C21C1284505E5EB2E40CDB0B732022-01-06
3'493T1B5033E9736E31000FB09BE35C654834FEF06CF59B97A9B4ED39826C72371A78629E0592022-02-07
3'473T153819E61842314C4F557CFF0D61BD82AAFA5334684584E1123E0606A4BCF60427041E32022-02-07
3'445T160030B9736E31000FB09BE32E554C24FEF06CF59B976974ED39826C72350A78662E45B2022-02-07
3'444T1D7819E61842314C4F557CEF4D51BE869BFA5734550584E1423E0705A4BCBA1427551A32022-02-08
3'432T1BD812B4525A230CAC056C270ED52C158ABD9BC37AF44D3BBF1B90FDD83112451CC1B0B2022-02-07
3'405T16211801BC7D1ADF1C44C01700F5786041735D42453D583574E94047EFC561BC6CD6C062021-07-08
3'399T10E8132A0832FBA4ADC96847151DEE1E16667307604E5C50161DA26DEDB83AE4EF78C332022-02-08
3'398T1A58162A0432FB74ADC5680B151DEA0E16667707204E5CA0551C916ADDB829F0EF74C332022-02-08
3'394T1DD816250432BB64AEC9A84B0409EA1E13657217214F2C91161CA66DC8B82AF4AF68C332022-02-08
3'391T1688141C1405F2A7CF2ED8ABCA20506C43D46B4B324754D651184782DAA23E4C7722A332022-02-08
3'328T15B8193C992427125F5E380F0462798F237893566B1AE8AD402CEA83C28039C0C758A372022-02-09

Top telfhash


Top telfhash observed on files scanned by YARAify in the past 12 months.

Task counttelfhashLast seen
272t195317722553546142fb3d928acfd56b315222b2363587f716f26c48c49370e2e93dd4f2024-04-01
267t171217622513542182fb3d928acbd567315222b2363597f716f26c4cc49370e2e93ad4f2024-04-01
179t141217662513542182fb3d928acbd567315222b2363597f716f26c5cc49370e2f93ad4f2024-04-01
137t18c3112a19679512a5da1ec68edda57b2501a56172350bf33df21c0cc380a44ff527c0f2024-04-11
130t1d9e0c240adb89a1e9ce35bb8ddcd07b1a1116253a4270b10cf58e6e0c83f988a60de6d2024-04-03
127t13611d04270b6891d2bb659245cbc42b5165536236381be75bf0ec5c45537002ba79e8b2024-04-10
116t1ad210246a1f68a685ff368205dbc46b5199217273351af70af1984c01c7b002a939ecb2024-04-09
114t18421fe46a1f6856d2ff368345dbc46b5188227133361bf70af0985c01c7b002a936ecb2024-04-10
114t17011f01361b6ca1d2bb659348dfc47f016512b236282bf71bf0dc5c88537042b93ad9b2024-03-31
106t15c2131705336a115aea1cc64dcee87f2111996232744af73ee36c0cc68060cae52bc0f2024-04-12
97t13e215462513552182fb3d928acbd5a7316222a2363597e716f26c5cc48370e2e93ee4f2024-04-01
96t17141a2180d7817e0a7356c9d099dfb36d6a330de7e262d338f61e86aab69a435d11c0c2024-04-10
89t1d6217622513542182fb3d928acbd567311222b2363593f71af26c4cc49370e2e93ad4f2024-04-01
89t15821e2bf1e6709fcb3c4a898c32b62931679d273056132b401b3ad9923f2ec05169d3a2024-04-03
87t187313122943546142fb39928acbd56b315222f2363993e716f26c5cc492b0e2e93ad5f2024-04-01