YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash e76d453b748c5bbb7cfa31a44087cf7f57d624f9d96cd1bbc1652545ddff1d85.

Scan Results


SHA256 hash: e76d453b748c5bbb7cfa31a44087cf7f57d624f9d96cd1bbc1652545ddff1d85
File size:77'960 bytes
File download: Original
MIME type:application/x-executable
MD5 hash: 3c79558a17b5d7d0f9d62f957b5cd572
SHA1 hash: 299ada7f5eff969df676a60db3e591f5bbc7c81a
SHA3-384 hash: 4e756ffe48d707624aff8b7209d54ed659954254bb79cf2f1d3bb1ca159bd7401f98afdde80faab3601ccfa0f51b0829
First seen:2025-12-26 18:11:02 UTC
Last seen:2025-12-26 18:14:20 UTC
Sightings:5
imphash :n/a
ssdeep : 1536:0dz81RGvOQUwEAF8ESPqcEZdl1NL+8Q5ZOs9RiWgUPCn3sTlWWTPG:0dz86hEAKnyp1haMHWbPCn3shWB
TLSH :n/a
telfhash :n/a
gimphash :n/a
dhash icon :n/a

Tasks


There are 5 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:b2f4d32b-e286-11f0-9df4-42010aa4000b
File name:e76d453b748c5bbb7cfa31a44087cf7f57d624f9d96cd1bbc1652545ddff1d85.elf
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Sanesecurity.Malware.31075.LX.BOT.UNOFFICIAL
Signature:Unix.Trojan.Gafgyt-6735924-0
Signature:Unix.Trojan.Mirai-10008934-0
Signature:Unix.Trojan.Mirai-10018298-0
Signature:Unix.Trojan.Mirai-6981989-0
Signature:Unix.Trojan.Mirai-7755770-0
Signature:Unix.Trojan.Mirai-9885259-0
Signature:Unix.Trojan.Mirai-9940650-0

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags
TLP:TLP:WHITE
Repository:MalwareBazaar

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.

Task Information


Task ID:a7f9d541-e286-11f0-9df4-42010aa4000b
File name:e76d453b748c5bbb7cfa31a44087cf7f57d624f9d96cd1bbc1652545ddff1d85
Task parameters:ClamAV scan:True
Unpack:True
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Sanesecurity.Malware.31075.LX.BOT.UNOFFICIAL
Signature:Unix.Trojan.Gafgyt-6735924-0
Signature:Unix.Trojan.Mirai-10008934-0
Signature:Unix.Trojan.Mirai-10018298-0
Signature:Unix.Trojan.Mirai-6981989-0
Signature:Unix.Trojan.Mirai-7755770-0
Signature:Unix.Trojan.Mirai-9885259-0
Signature:Unix.Trojan.Mirai-9940650-0

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags
TLP:TLP:WHITE
Repository:MalwareBazaar

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.

Task Information


Task ID:8485395b-e286-11f0-9df4-42010aa4000b
File name:e76d453b748c5bbb7cfa31a44087cf7f57d624f9d96cd1bbc1652545ddff1d85
Task parameters:ClamAV scan:True
Unpack:True
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Sanesecurity.Malware.31075.LX.BOT.UNOFFICIAL
Signature:Unix.Trojan.Gafgyt-6735924-0
Signature:Unix.Trojan.Mirai-10008934-0
Signature:Unix.Trojan.Mirai-10018298-0
Signature:Unix.Trojan.Mirai-6981989-0
Signature:Unix.Trojan.Mirai-7755770-0
Signature:Unix.Trojan.Mirai-9885259-0
Signature:Unix.Trojan.Mirai-9940650-0

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags
TLP:TLP:WHITE
Repository:MalwareBazaar

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.

Task Information


Task ID:60eabc17-e286-11f0-9df4-42010aa4000b
File name:e76d453b748c5bbb7cfa31a44087cf7f57d624f9d96cd1bbc1652545ddff1d85
Task parameters:ClamAV scan:True
Unpack:True
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Sanesecurity.Malware.31075.LX.BOT.UNOFFICIAL
Signature:Unix.Trojan.Gafgyt-6735924-0
Signature:Unix.Trojan.Mirai-10008934-0
Signature:Unix.Trojan.Mirai-10018298-0
Signature:Unix.Trojan.Mirai-6981989-0
Signature:Unix.Trojan.Mirai-7755770-0
Signature:Unix.Trojan.Mirai-9885259-0
Signature:Unix.Trojan.Mirai-9940650-0

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags
TLP:TLP:WHITE
Repository:MalwareBazaar

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.

Task Information


Task ID:3d22eabc-e286-11f0-9df4-42010aa4000b
File name:e76d453b748c5bbb7cfa31a44087cf7f57d624f9d96cd1bbc1652545ddff1d85
Task parameters:ClamAV scan:True
Unpack:True
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Sanesecurity.Malware.31075.LX.BOT.UNOFFICIAL
Signature:Unix.Trojan.Gafgyt-6735924-0
Signature:Unix.Trojan.Mirai-10008934-0
Signature:Unix.Trojan.Mirai-10018298-0
Signature:Unix.Trojan.Mirai-6981989-0
Signature:Unix.Trojan.Mirai-7755770-0
Signature:Unix.Trojan.Mirai-9885259-0
Signature:Unix.Trojan.Mirai-9940650-0

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags
TLP:TLP:WHITE
Repository:MalwareBazaar

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.