Statistics

YARAIfy produces various statistics on files scanned by YARAify, including their detections. The available statistics can be found below.

File Scans


The chart below shows the number of file scans conducted by YARAify over the past 30 days.

Data Scanned


This chart shows the amount of data scanned in Megabytes over the past 30 days.

API requests


The illustration below documents the number of API requests over the past 30 days.

Most matching YARA rules


YARA rules that matched most on files scanned on YARAify in the past 14 days.

Task countYARA RuleAuthorLast match
165'357DebuggerCheck__API2024-06-17
146'834SHA512_Constantsphoul (@phoul)2024-06-17
145'855malware_shellcode_hashJPCERT/CC Incident Response Group2024-06-17
97'151maldoc_find_kernel32_base_method_1Didier Stevens (https://DidierStevens.com)2024-06-17
89'979SEH__vba2024-06-17
88'793vmdetectnex2024-06-17
79'005maldoc_getEIP_method_1Didier Stevens (https://DidierStevens.com)2024-06-17
78'930DebuggerException__SetConsoleCtrl2024-06-17
76'541DebuggerCheck__QueryInfo2024-06-17
76'176win_m0yv_autoFelix Bilstein2024-06-17
74'206meth_get_eipWilli Ballenthin2024-06-17
73'514classifiedclassified2024-06-17
63'114MAL_XMR_Miner_May19_1Florian Roth (Nextron Systems)2024-06-17
63'110MAL_XMR_Miner_May19_1_RID2E1BFlorian Roth2024-06-17
49'055INDICATOR_SUSPICIOUS_EXE_RawGitHub_URLditekSHen2024-06-14

ClamAV Most matching ClamAV signature


ClamAV signature that matched most on files scanned on YARAify in the past 14 days.

Task countClamAV SignatureLast match
795'0492024-06-17
66'876Win.Trojan.Xmrminer-9974342-02024-06-17
63'707Multios.Coinminer.Miner-6781728-22024-06-17
63'692Win.Coinminer.Generic-7155777-02024-06-17
63'692Win.Coinminer.Generic-7151447-02024-06-17
63'691Win.Coinminer.Generic-7151253-02024-06-17
63'622Win.Trojan.Coinminer-9866537-02024-06-17
63'516Win.Trojan.Generickdz-9867224-02024-06-17
63'498Win.Trojan.Generickdz-9866491-02024-06-17
63'484Win.Coinminer.Generic-7158858-02024-06-17
63'475Win.Coinminer.Generic-7151250-02024-06-17
42'721Win.Malware.Swisyn-9942393-02024-06-17
42'036PUA.Win.Packer.ProtectSharewar-32024-06-17
41'873PUA.Win.Packer.ProtectSharewar-22024-06-17
41'846Win.Virus.Sality-6747602-02024-06-17

Most seen files


Most seen files scanned by YARAify in the past 14 days.

Task countSHA256 hashLast seen
73376ab2836a9440a111301c272f3c40e889fa5f1766c1719b73c7876c2c8eb1f1f2024-06-07
437abd050f29768f391466a1a206d80ca784d287bcbc2a445cda0b16062f0a97c712024-06-07
307e4ee8f8dae24c3c2eb0418365e330d197be4bb543836a0427d15218eda3758a72024-06-07
297853a1ed056c761065c6382f3e1608f1598fb3999201160f222fc221637514f5f2024-06-04
19400ebdd82b66b0f338c9b462dae90bf82625ba37f1677311d8b88952a02e186c62024-06-06
164b2ef14ecd093abf7a25a98e940dbeb9bdc3c4ff6124d3c23d493d5af4d8dd71f2024-06-07
146cb6ba6ce7e1ab971f7e887987f4f8facf2e78c1768af47c6d4fda59ad88e97ce2024-06-06
1328ecad6002a4dd99a94fe7b134c5dd7308b9d2156726be0968419ded1e7a429ae2024-06-13
11155767df5077044876b8b49a4fc551209396713da4a5b2450e3d0ea110832e4f52024-06-07
9590ccd84f28e4dd03fb70b8739c4636acbcf8a030404b5a24264afd1acd09ecbc2023-06-26
958b784f68a231a019a7c839cad7e0d226c116bc2f92f459cf503e94a344561d592024-06-09
90b7aeedb5246f62fe3ee973578bc10858f56573ff28918956278bdc1405a4e5d42021-07-07
89212e6f56b7d298f403c3933d74b52ef4f5f035f735d5e5ad46b637339d0c0ed32024-06-07
88112f19b9654519b6e2a15fe5d781278112a2771df066dabbc6c0dac94ae8e0ba2021-07-08
8734cd31196d0bf4d9e41abf59662f4e5c7ebf02ef6dbcafd74455b1f4838dd9b22024-05-26

Top dhash icon


Top dhash icon observed on files scanned by YARAify in the past 14 days.

Task countdhash iconLast seen
30'637d8d0d4d8ececece42024-06-16
20'436e9f4aa8accc6c6642024-06-16
17'352e8b03c727a9ad0e82024-06-16
16'6021003873db9313e102024-06-16
5'2819919aca682a881a92024-06-16
4'66300ccc4d0c4fc7c002024-06-16
4'20704ccfee2ece4a4842024-06-16
4'10071e8d4968ecc68f92024-06-16
3'9021003873d31213f102024-06-16
3'13604c988cce6fc70122024-06-16
2'73169ccd4d49696cc712024-06-16
1'93518b1b1b17068c8802024-06-16
1'913526e32661e3a2a102024-06-16
1'592f8f0f4c8c8c8d8f02024-06-16
1'5041ad2a38edcb6b2dc2024-06-16

Top imphash


Top imphash observed on files scanned by YARAify in the past 14 days.

Task countimphashLast seen
52'41591f4b88d25daa33c7443253d9beb1bb32024-06-16
23'22609d0478591d4f788cb3e5ea416c252372024-06-16
14'4001a611a7df1f3828b0157c4725145a7212024-06-16
14'271c06ddfbe3366daddf0cfd3e63c1b53902024-06-16
12'067f34d5f2d4577ed6d9ceec516c1f5a7442024-06-16
10'04088478c1f74f94f7e1e9654193a1e02b32024-06-16
5'935cdf5bbb8693f29ef22aef04d2a161dd72024-06-16
4'4488abecba2211e61763c4c9ffcaa13369e2024-06-16
3'9465271d5ce8b44dd47bc92563e275854662024-06-16
3'8015c7397fd7c1832e37a3cb00b6ee7c3772024-06-16
3'449e4290fa6afc89d56616f34ebbd0b1f2c2024-06-16
3'20062ec3dce1eba1b68f6a4511bb09f8c2c2024-06-16
2'8932938fa2df7e806927b9ad495b8f205f32024-06-16
2'818dae02f32a21e03ce65412f6e56942daa2024-06-16
2'657a14fe147cbb35ac7afa52e2cceed81b72024-06-16

Top tlsh


Top tlsh observed on files scanned by YARAify in the past 14 days.

Task counttlshLast seen
297T1B83111E438EA6D5DDA4141D29B6C798C710C329706C21CAF333DB3402F82864F740DE82024-06-04
100T1F4D2F10E1AA4A0DDE59651B280C39E77EA8433D314A673C8C173AFFDD787F81B5912682023-06-26
95T1F7F46130E88C4CDDFC8ACD6E84BA39194E7D312727CD7882816ECE16F005AD55B966DB2024-06-09
91T176E48D61F185C075E0F116B0A6FE7A5B146C2975471D38E3EB98BEC929740F27A3C28B2021-08-11
91T1CF11126B87EAFEF1E14C00B0160B8B003329C42407E2974B4AA6012ABCA18BC4C96C012021-07-07
91T133E48D51F185C076E0F116B0A6FE7A5B146C2975471D38E3EB98BEC929740F27A3C28B2021-08-11
90T1FBE47D21F1C18079E4F5157096FF7A5B246C69A64B2838E3E7987EC928741F27A3C2C72021-07-08
90T19911802BC745A4F5C488193509DBCB01F300D1F170C7C745384D05D5EC44B540D36C502021-07-08
90T1BCE47D21F1C18079E4F5157096FF7A5B246C69A64B2838E3E7987EC928741F27A3C2C72021-07-08
88T12B348D1075A2C872E5B2013518F8DBF6852DBC300B6559EBB3D41F7E9E702D29632E7A2024-05-26
87T16211801BC7D1ADF1C44C01700F5786041735D42453D583574E94047EFC561BC6CD6C062021-07-08
86T1C362DA006A4D5633CABD16FE8AE3F2618776DB220A4FE39F5AB4097562CF79B01103572024-05-28
86T13F748D51F185C076E0F116B0A6FE7A5B146C2975471D38E3EB98BEC929740F27A3C28B2021-08-11
86T1A8748D61F185C075E0F116B0A6FE7A5B146C2975471D38E3EB98BEC929740F27A3C28B2021-08-11
84T131E48E23F1450075E4E525F1E5FF3A8A106C6E6647186CE3E790BEC929682F77A3C2872021-07-22

Top telfhash


Top telfhash observed on files scanned by YARAify in the past 14 days.

Task counttelfhashLast seen
23t140317403a83f8f3ac5a298b0dc650765516b5701b4f9d7109f3ca9d06c79016702aacd2024-06-16
10t17011f01361b6ca1d2bb659348dfc47f016512b236282bf71bf0dc5c88537042b93ad9b2024-06-09
8t1ad11e113a0b9ca286bf758349dbc47f105512b23b746be71bf0ac5c49537002b975d9b2024-06-14
7t1863111b19638512a59e1ec64edda5bb2501a96171340be33ee21c4cc380a04fe52bc0f2024-06-16
7t1ae3100b1963c512a59a1ec64edde9bb2501b96171310be33ef22c4cc680a04ee92bc0f2024-06-16
7t157110e13a0b9ca282bf348249dbc07f005502b23a782be71bf0ac5c49437002a875d9b2024-06-14
6t1e311f01361b6ca1d1bb659348dfc47f0155127236242be71bf09c5c88537042b93ad9b2024-06-09
6t19921cbb1572aa6245969cbec89ddb7b9022c82021246df33ff2080fca41949df629c4f2024-06-07
6t1af215052a1f6cb282bb38934adbc03f12151a6136282bf756f0ec9c45833043a934ddb2024-06-13
6t18811ce13a0baca286bf758249dbc47f105912b23b746be71bf0ac6c49537002a975d9b2024-06-14
6t171217622513542182fb3d928acbd567315222b2363597f716f26c4cc49370e2e93ad4f2024-06-06
6t195317722553546142fb3d928acfd56b315222b2363587f716f26c48c49370e2e93dd4f2024-06-06
6t1c6215352a1f5cb282bb389349dbc07f1225666136242bf756f0ec5c458330536938ddb2024-06-13
6t12f112113a0b9ca286bf758349dbc4bf105512b237742be71bf0ac5c49937042b979d9b2024-06-14
6t114215352a1f5cb282bb38934adbc03f51251a6136282bf756f0ec5c454331436934ddb2024-06-13

File Scans


The chart below shows the number of file scans conducted by YARAify over the past 12 months.

Data Scanned


This chart shows the amount of data scanned in Megabytes over the past past 12 months.

API requests


The illustration below documents the number of API requests over the past past 12 months.

Most matching YARA rules


YARA rules that matched most on files scanned on YARAify in the past 12 months.

Task countYARA RuleAuthorLast match
29'323'156meth_get_eipWilli Ballenthin2024-06-17
29'019'715maldoc_getEIP_method_1Didier Stevens (https://DidierStevens.com)2024-06-17
27'186'731QbotStuffanonymous2024-06-17
6'248'713win_berbew_strings_dec_2023Matthew @ Embee_Research2024-06-11
4'043'288DebuggerCheck__API2024-06-17
2'132'314maldoc_find_kernel32_base_method_1Didier Stevens (https://DidierStevens.com)2024-06-17
2'131'232NETmalware-lu2024-06-17
1'924'005UPXV200V290MarkusOberhumerLaszloMolnarJohnReisermalware-lu2024-06-17
1'725'419UPXv20MarkusLaszloReisermalware-lu2024-06-17
1'413'739SHA512_Constantsphoul (@phoul)2024-06-17
1'377'665malware_shellcode_hashJPCERT/CC Incident Response Group2024-06-17
1'151'641DebuggerException__SetConsoleCtrl2024-06-17
1'018'790MD5_Constantsphoul (@phoul)2024-06-17
1'018'312vmdetectnex2024-06-17
991'573SEH__vba2024-06-17

ClamAV Most matching ClamAV signature


ClamAV signature that matched most on files scanned on YARAify in the past 12 Mmonths.

Task countClamAV SignatureLast match
28'102'106PUA.Win.Packer.Lccwin-22024-06-16
18'846'451Win.Trojan.Obfus-382024-06-16
15'005'034Win.Trojan.Qukart-6874817-02024-06-11
11'037'103Win.Malware.Qukart-6838239-02024-06-16
9'803'298Win.Trojan.Padodor-10016488-02024-06-11
6'823'159Win.Trojan.Padodor-9877164-02024-06-11
5'576'1252024-06-16
2'747'476Win.Trojan.Berbew-10013977-02024-06-16
2'457'346Win.Trojan.Crypted-292024-06-11
2'441'612Win.Trojan.Crypted-302024-05-30
2'402'825Win.Packed.Razy-10010080-02024-06-16
2'193'156Win.Trojan.Berbew-9845290-12024-06-11
2'108'728Win.Packed.Lazy-10005437-02024-06-16
1'672'826Win.Malware.Padodor-10012877-02024-06-16
1'665'153Win.Trojan.Crypted-282024-05-30

Most seen files


Most seen files scanned by YARAify in the past 12 months.

Task countSHA256 hashLast seen
3'405b3986e04464339cec16157cf8c8bffec3a8a8c5eae57997974d45f5369fa16552021-07-07
3'402e0af7f483f4965dca90eb5921ae004a7e41593b39284a63af97a9105b96718e72022-01-06
3'39439e48a3fc7e67968ff5d6e3cf8e12a7256af93ccabbce4da20d28c79237d95e82022-01-06
3'349a4ec9fd2488f0b1734317beb74e1524838d0f7c907eb4e452d7cf40c03c7e5dd2021-07-08
3'3461115b6c913a207b9d81f8482613b2a9c2929ca81399861d2d2c47422e244060d2022-02-07
3'33723c2d2b0c6cec3e69cb07f942c9e56f2087aeb24015be25823897faafc4708ae2022-02-07
3'31087479e089e6852958dab4026e07bc01ed1f31af423b1d26db462ef7493a537f12022-02-08
3'2775ea4d94c695189639e9ab7afe8d76d231030921fbfdd95e1941c7c0a05fb8f032022-02-07
3'27553c22863323c0f5ff94f4ae86df27a51db4eae7232cc38333346ee8be9df5aa62022-02-07
3'259c8c158269c68d6b09d0c8b118b6588302816f2936c193579b35512d6a6af506e2022-02-08
3'2588718400c6ca71b5afb0534931628b2aace3e5cc515edaa33d1da678f947b5cd42022-02-08
3'253cdfb8e3d5bfb32850200759b0d3ccaa83ed5cb661cb2cccedf048d23959663602022-02-08
3'24896994840078a8dbaaa3175c80b72c01c3a7f258be338c94c58672cacf5e47a872022-02-08
3'187b1bce9d29dc58cf8e53382c61d200610a8200708cd32713b63b18b260db9bfa82022-02-09
3'1568c251ccc6eb0591c58ad3337729bcce081d8d65557523d21a6aee9cd6523d59f2022-02-07

Top dhash icon


Top dhash icon observed on files scanned by YARAify in the past 12 months.

Task countdhash iconLast seen
529'18369ccd4d49696cc712024-06-16
220'682d8d0d4d8ececece42024-06-16
212'898818da080a0a0a0a22024-06-16
210'7551003873db9313e102024-06-16
104'0785ab3a5b332c482a02024-06-16
94'289b298acbab2ca7a722024-06-16
85'5041003873d31213f102024-06-16
82'3089919aca682a881a92024-06-16
76'150f8f0f4c8c8c8d8f02024-06-16
67'146526e32661e3a2a102024-06-16
66'40300ccc4d0c4fc7c002024-06-16
47'30904ccfee2ece4a4842024-06-16
36'344e9f4aa8accc6c6642024-06-16
35'003e8b03c727a9ad0e82024-06-16
33'935b67ee8c2f2f0711a2024-06-15

Top imphash


Top imphash observed on files scanned by YARAify in the past 12 months.

Task countimphashLast seen
11'254'27446f03ef2495b21d7ad3e8d36dc03315d2024-05-30
7'382'5196db997463de98ce64bf5b6b8b0f77a452024-05-30
5'570'9294dcbc0931c6f88874a69f966c86889d92024-05-30
2'238'398c9246f292a6fdc22d70e6e581898a0262024-05-30
1'350'158e4742a62fda2e64b586a5b84efe3f0402024-05-30
1'038'2472c2ad1dd2c57d1bd5795167a7236b0452024-05-30
719'24287914047e74de74a89c530e3bb19409e2024-05-30
553'821a3df475500e5e30f4680b397c2ee13f12024-06-17
539'41591f4b88d25daa33c7443253d9beb1bb32024-06-17
462'726f34d5f2d4577ed6d9ceec516c1f5a7442024-06-17
334'5163f8d79e42b0b7cecf379b1ddce4e422a2024-05-30
271'362dae02f32a21e03ce65412f6e56942daa2024-06-17
165'9050141f24aaf1b810b9fcc5f6886f26f142024-05-04
151'296be6fa16f501de575a1d8eaaac5246ba02024-06-16
129'4691a611a7df1f3828b0157c4725145a7212024-06-17

Top tlsh


Top tlsh observed on files scanned by YARAify in the past 14 months.

Task counttlshLast seen
3'432T16D32F1F94DD4E7AC4ED46381A7DF2C341EA306743331368B99269AB8621277FA11B0D72022-11-21
3'398T1C8E052F688E090AC080023A82BDF2CA5437B03BD00202A0BF20BA04D022DF72E30A3F02021-07-07
3'394T10016DD42A3F94608F6F77F7469B916604E3BBCA6AD79C21C1284505E5EB2E40CDB0B732022-01-06
3'386T1EF16DD42A3F94608F6F77F7469B916604E3BBCA6AD79C21C1284505E5EB2E40CDB0B732022-01-06
3'349T16211801BC7D1ADF1C44C01700F5786041735D42453D583574E94047EFC561BC6CD6C062021-07-08
3'341T153819E61842314C4F557CFF0D61BD82AAFA5334684584E1123E0606A4BCF60427041E32022-02-07
3'331T1B5033E9736E31000FB09BE35C654834FEF06CF59B97A9B4ED39826C72371A78629E0592022-02-07
3'303T1D7819E61842314C4F557CEF4D51BE869BFA5734550584E1423E0705A4BCBA1427551A32022-02-08
3'271T160030B9736E31000FB09BE32E554C24FEF06CF59B976974ED39826C72350A78662E45B2022-02-07
3'265T1BD812B4525A230CAC056C270ED52C158ABD9BC37AF44D3BBF1B90FDD83112451CC1B0B2022-02-07
3'254T10E8132A0832FBA4ADC96847151DEE1E16667307604E5C50161DA26DEDB83AE4EF78C332022-02-08
3'253T1A58162A0432FB74ADC5680B151DEA0E16667707204E5CA0551C916ADDB829F0EF74C332022-02-08
3'248T1DD816250432BB64AEC9A84B0409EA1E13657217214F2C91161CA66DC8B82AF4AF68C332022-02-08
3'243T1688141C1405F2A7CF2ED8ABCA20506C43D46B4B324754D651184782DAA23E4C7722A332022-02-08
3'183T15B8193C992427125F5E380F0462798F237893566B1AE8AD402CEA83C28039C0C758A372022-02-09

Top telfhash


Top telfhash observed on files scanned by YARAify in the past 12 months.

Task counttelfhashLast seen
211t195317722553546142fb3d928acfd56b315222b2363587f716f26c48c49370e2e93dd4f2024-06-06
201t18c3112a19679512a5da1ec68edda57b2501a56172350bf33df21c0cc380a44ff527c0f2024-06-16
199t171217622513542182fb3d928acbd567315222b2363597f716f26c4cc49370e2e93ad4f2024-06-06
154t1dd21d0d8885ab05899828810e83f0981595bd257423cedc3bf34d8d20c7e5cdf887d7b2024-05-05
138t141217662513542182fb3d928acbd567315222b2363597f716f26c5cc49370e2f93ad4f2024-06-06
127t17141a2180d7817e0a7356c9d099dfb36d6a330de7e262d338f61e86aab69a435d11c0c2024-06-16
124t17011f01361b6ca1d2bb659348dfc47f016512b236282bf71bf0dc5c88537042b93ad9b2024-06-09
122t18a5106fa2dbe0cfcb3e56c08c74e2ad32a55da7b1951357184a79ca533f3a4080a5c362024-06-16
94t187313122943546142fb39928acbd56b315222f2363993e716f26c5cc492b0e2e93ad5f2024-06-06
89t13611d04270b6891d2bb659245cbc42b5165536236381be75bf0ec5c45537002ba79e8b2024-04-25
87t18c51acb12aa539d4a2fbeb7a730bd5a4ec340e2004e134d2edb7adf5de063410d658672024-05-23
85t14e21324271f68a282bb385245cbc03b5264665232341bf756f0ec5c45837012a534dcb2024-04-10
84t12a21419271f6ca2d3bb389746cbc43b52642b5132741bf75af0ec5c45833052a924ecb2024-04-09
79t15a416502643a8b31f76279b07c396bd6021797222515d7349f7499ccbc7a402f515fdb2024-03-18
74t15411cc5271fa895d2bf649249cbc43b4265026237392beb5bf0dc6d05937002b979e8f2024-05-01