🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 2a3aab2a262a9fccf8c35ebe2fdfe08f533395a4cf78b2cb202e5ca2129c5c4e.

Scan Results


SHA256 hash: 2a3aab2a262a9fccf8c35ebe2fdfe08f533395a4cf78b2cb202e5ca2129c5c4e
File size:427'208 bytes
File download: Original
MIME type:application/x-executable
MD5 hash: cb3093fddca8ff05818c13ab6d5ed980
SHA1 hash: 7db063ec4435602a1d948d3e73cfd339441eeaf9
SHA3-384 hash: be080e92280b47c0d95df7fdf0fbe0137ac69f7a3b845c02d1f8ba815f8688a9be7ddfcd1004c82b9f4955dace5f3221
First seen:2026-10-10 06:38:02 UTC
Last seen:2026-10-10 06:45:24 UTC
Sightings:6
imphash :n/a
ssdeep : 6144:MJUeEwphYKrmXY26cvp0a9d9cSeq7DXUkwB2a9pZQ:leC7R0a9d9cnq7DA2a9o
TLSH :n/a
telfhash : t15471bb7004a9347471d78a22b302e67ede3604f582ed7af96b27dce4adcaac10cc2c15
gimphash :n/a
dhash icon :n/a

Tasks


There are 6 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:2bfb3937-c476-11f1-b2b6-42010aa4000b
File name:2a3aab2a262a9fccf8c35ebe2fdfe08f533395a4cf78b2cb202e5ca2129c5c4e.elf
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Sanesecurity.Malware.30435.LC.UNOFFICIAL
Signature:SecuriteInfo.com.Linux.Mirai-44.UNOFFICIAL

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
TLP:TLP:WHITE
Repository:YARAify
Rule name:ELF_IoT_Persistence_Hunt
Author:4r4
Description:Hunts for ELF files with persistence and download capabilities
TLP:TLP:WHITE
Repository:YARAify
Rule name:ELF_Packer_Dropper_Fileless_Armhf
Author:Serhii Kocherhan
Description:Detects obfuscated Linux ELF packers/droppers featuring ChaCha20/RC4 decryption, memfd_create/execveat fileless execution capabilities, and unique binary artifacts.
TLP:TLP:WHITE
Repository:YARAify
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:EXPL_HKTL_LNX_DirtyFragShellcode_May26
Author:Pezier Pierre-Henri (Nextron Systems)
Description:Detects a shellcode observed in dirtyfrag, a local privilege escalation exploit for Linux.
Reference:https://github.com/V4bel/dirtyfrag/tree/master
TLP:TLP:WHITE
Repository:Neo23x0
Rule name:EXPL_LNX_DirtyFrag_ForensicArtefacts_May26
Author:Florian Roth
Description:Detects DirtyFrag exploit code POC usage in Linux environments
Reference:https://github.com/V4bel/dirtyfrag/tree/master
TLP:TLP:WHITE
Repository:Neo23x0
Rule name:F01_s1ckrule
Author:s1ckb017
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:ldpreload
Author:xorseed
Reference:https://stuff.rop.io/
TLP:TLP:WHITE
Repository:
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
TLP:TLP:WHITE
Repository:Stratosphere
Rule name:linux_generic_irc_catcher
Author:@_lubiedo
Description:Find new ELF IRC samples
TLP:TLP:WHITE
Repository:Stratosphere
Rule name:MIRAI_OHSHIT_payload
Author:AfterPacket
Description:MIRAI_OHSHIT ELF payload -- compiled-in C2 set, all architectures
Reference:https://github.com/Afterpacket/drosera-threat-intel
TLP:TLP:WHITE
Repository:YARAify
Rule name:NSVPS_Hydra_SSH_Bruteforce
Author:sanad (NSVPS-SOC)
Description:Hydra SSH brute-force campaign credentials pattern from NSVPS honeypot
TLP:TLP:WHITE
Repository:YARAify
Rule name:RANSOMWARE
Author:ToroGuitar
TLP:TLP:WHITE
Repository:YARAify
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
TLP:TLP:WHITE
Repository:
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
TLP:TLP:WHITE
Repository:YARAify
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags
TLP:TLP:WHITE
Repository:MalwareBazaar

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.

Task Information


Task ID:b2fb0449-c475-11f1-b2b6-42010aa4000b
File name:2a3aab2a262a9fccf8c35ebe2fdfe08f533395a4cf78b2cb202e5ca2129c5c4e
Task parameters:ClamAV scan:True
Unpack:True
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Sanesecurity.Malware.30435.LC.UNOFFICIAL
Signature:SecuriteInfo.com.Linux.Mirai-44.UNOFFICIAL

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
TLP:TLP:WHITE
Repository:YARAify
Rule name:ELF_IoT_Persistence_Hunt
Author:4r4
Description:Hunts for ELF files with persistence and download capabilities
TLP:TLP:WHITE
Repository:YARAify
Rule name:ELF_Packer_Dropper_Fileless_Armhf
Author:Serhii Kocherhan
Description:Detects obfuscated Linux ELF packers/droppers featuring ChaCha20/RC4 decryption, memfd_create/execveat fileless execution capabilities, and unique binary artifacts.
TLP:TLP:WHITE
Repository:YARAify
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:EXPL_HKTL_LNX_DirtyFragShellcode_May26
Author:Pezier Pierre-Henri (Nextron Systems)
Description:Detects a shellcode observed in dirtyfrag, a local privilege escalation exploit for Linux.
Reference:https://github.com/V4bel/dirtyfrag/tree/master
TLP:TLP:WHITE
Repository:Neo23x0
Rule name:EXPL_LNX_DirtyFrag_ForensicArtefacts_May26
Author:Florian Roth
Description:Detects DirtyFrag exploit code POC usage in Linux environments
Reference:https://github.com/V4bel/dirtyfrag/tree/master
TLP:TLP:WHITE
Repository:Neo23x0
Rule name:F01_s1ckrule
Author:s1ckb017
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:ldpreload
Author:xorseed
Reference:https://stuff.rop.io/
TLP:TLP:WHITE
Repository:
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
TLP:TLP:WHITE
Repository:Stratosphere
Rule name:linux_generic_irc_catcher
Author:@_lubiedo
Description:Find new ELF IRC samples
TLP:TLP:WHITE
Repository:Stratosphere
Rule name:MIRAI_OHSHIT_payload
Author:AfterPacket
Description:MIRAI_OHSHIT ELF payload -- compiled-in C2 set, all architectures
Reference:https://github.com/Afterpacket/drosera-threat-intel
TLP:TLP:WHITE
Repository:YARAify
Rule name:NSVPS_Hydra_SSH_Bruteforce
Author:sanad (NSVPS-SOC)
Description:Hydra SSH brute-force campaign credentials pattern from NSVPS honeypot
TLP:TLP:WHITE
Repository:YARAify
Rule name:RANSOMWARE
Author:ToroGuitar
TLP:TLP:WHITE
Repository:YARAify
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
TLP:TLP:WHITE
Repository:
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
TLP:TLP:WHITE
Repository:YARAify
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags
TLP:TLP:WHITE
Repository:MalwareBazaar

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.

Task Information


Task ID:8f510ac2-c475-11f1-b2b6-42010aa4000b
File name:2a3aab2a262a9fccf8c35ebe2fdfe08f533395a4cf78b2cb202e5ca2129c5c4e
Task parameters:ClamAV scan:True
Unpack:True
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Sanesecurity.Malware.30435.LC.UNOFFICIAL
Signature:SecuriteInfo.com.Linux.Mirai-44.UNOFFICIAL

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
TLP:TLP:WHITE
Repository:YARAify
Rule name:ELF_IoT_Persistence_Hunt
Author:4r4
Description:Hunts for ELF files with persistence and download capabilities
TLP:TLP:WHITE
Repository:YARAify
Rule name:ELF_Packer_Dropper_Fileless_Armhf
Author:Serhii Kocherhan
Description:Detects obfuscated Linux ELF packers/droppers featuring ChaCha20/RC4 decryption, memfd_create/execveat fileless execution capabilities, and unique binary artifacts.
TLP:TLP:WHITE
Repository:YARAify
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:EXPL_HKTL_LNX_DirtyFragShellcode_May26
Author:Pezier Pierre-Henri (Nextron Systems)
Description:Detects a shellcode observed in dirtyfrag, a local privilege escalation exploit for Linux.
Reference:https://github.com/V4bel/dirtyfrag/tree/master
TLP:TLP:WHITE
Repository:Neo23x0
Rule name:EXPL_LNX_DirtyFrag_ForensicArtefacts_May26
Author:Florian Roth
Description:Detects DirtyFrag exploit code POC usage in Linux environments
Reference:https://github.com/V4bel/dirtyfrag/tree/master
TLP:TLP:WHITE
Repository:Neo23x0
Rule name:F01_s1ckrule
Author:s1ckb017
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:ldpreload
Author:xorseed
Reference:https://stuff.rop.io/
TLP:TLP:WHITE
Repository:
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
TLP:TLP:WHITE
Repository:Stratosphere
Rule name:linux_generic_irc_catcher
Author:@_lubiedo
Description:Find new ELF IRC samples
TLP:TLP:WHITE
Repository:Stratosphere
Rule name:MIRAI_OHSHIT_payload
Author:AfterPacket
Description:MIRAI_OHSHIT ELF payload -- compiled-in C2 set, all architectures
Reference:https://github.com/Afterpacket/drosera-threat-intel
TLP:TLP:WHITE
Repository:YARAify
Rule name:NSVPS_Hydra_SSH_Bruteforce
Author:sanad (NSVPS-SOC)
Description:Hydra SSH brute-force campaign credentials pattern from NSVPS honeypot
TLP:TLP:WHITE
Repository:YARAify
Rule name:RANSOMWARE
Author:ToroGuitar
TLP:TLP:WHITE
Repository:YARAify
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
TLP:TLP:WHITE
Repository:
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
TLP:TLP:WHITE
Repository:YARAify
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags
TLP:TLP:WHITE
Repository:MalwareBazaar

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.

Task Information


Task ID:6bdf4cea-c475-11f1-b2b6-42010aa4000b
File name:2a3aab2a262a9fccf8c35ebe2fdfe08f533395a4cf78b2cb202e5ca2129c5c4e
Task parameters:ClamAV scan:True
Unpack:True
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Sanesecurity.Malware.30435.LC.UNOFFICIAL
Signature:SecuriteInfo.com.Linux.Mirai-44.UNOFFICIAL

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
TLP:TLP:WHITE
Repository:YARAify
Rule name:ELF_IoT_Persistence_Hunt
Author:4r4
Description:Hunts for ELF files with persistence and download capabilities
TLP:TLP:WHITE
Repository:YARAify
Rule name:ELF_Packer_Dropper_Fileless_Armhf
Author:Serhii Kocherhan
Description:Detects obfuscated Linux ELF packers/droppers featuring ChaCha20/RC4 decryption, memfd_create/execveat fileless execution capabilities, and unique binary artifacts.
TLP:TLP:WHITE
Repository:YARAify
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:EXPL_HKTL_LNX_DirtyFragShellcode_May26
Author:Pezier Pierre-Henri (Nextron Systems)
Description:Detects a shellcode observed in dirtyfrag, a local privilege escalation exploit for Linux.
Reference:https://github.com/V4bel/dirtyfrag/tree/master
TLP:TLP:WHITE
Repository:Neo23x0
Rule name:EXPL_LNX_DirtyFrag_ForensicArtefacts_May26
Author:Florian Roth
Description:Detects DirtyFrag exploit code POC usage in Linux environments
Reference:https://github.com/V4bel/dirtyfrag/tree/master
TLP:TLP:WHITE
Repository:Neo23x0
Rule name:F01_s1ckrule
Author:s1ckb017
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:ldpreload
Author:xorseed
Reference:https://stuff.rop.io/
TLP:TLP:WHITE
Repository:
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
TLP:TLP:WHITE
Repository:Stratosphere
Rule name:linux_generic_irc_catcher
Author:@_lubiedo
Description:Find new ELF IRC samples
TLP:TLP:WHITE
Repository:Stratosphere
Rule name:MIRAI_OHSHIT_payload
Author:AfterPacket
Description:MIRAI_OHSHIT ELF payload -- compiled-in C2 set, all architectures
Reference:https://github.com/Afterpacket/drosera-threat-intel
TLP:TLP:WHITE
Repository:YARAify
Rule name:NSVPS_Hydra_SSH_Bruteforce
Author:sanad (NSVPS-SOC)
Description:Hydra SSH brute-force campaign credentials pattern from NSVPS honeypot
TLP:TLP:WHITE
Repository:YARAify
Rule name:RANSOMWARE
Author:ToroGuitar
TLP:TLP:WHITE
Repository:YARAify
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
TLP:TLP:WHITE
Repository:
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
TLP:TLP:WHITE
Repository:YARAify
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags
TLP:TLP:WHITE
Repository:MalwareBazaar

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.

Task Information


Task ID:484547b2-c475-11f1-b2b6-42010aa4000b
File name:2a3aab2a262a9fccf8c35ebe2fdfe08f533395a4cf78b2cb202e5ca2129c5c4e
Task parameters:ClamAV scan:True
Unpack:True
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Sanesecurity.Malware.30435.LC.UNOFFICIAL
Signature:SecuriteInfo.com.Linux.Mirai-44.UNOFFICIAL

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
TLP:TLP:WHITE
Repository:YARAify
Rule name:ELF_IoT_Persistence_Hunt
Author:4r4
Description:Hunts for ELF files with persistence and download capabilities
TLP:TLP:WHITE
Repository:YARAify
Rule name:ELF_Packer_Dropper_Fileless_Armhf
Author:Serhii Kocherhan
Description:Detects obfuscated Linux ELF packers/droppers featuring ChaCha20/RC4 decryption, memfd_create/execveat fileless execution capabilities, and unique binary artifacts.
TLP:TLP:WHITE
Repository:YARAify
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:EXPL_HKTL_LNX_DirtyFragShellcode_May26
Author:Pezier Pierre-Henri (Nextron Systems)
Description:Detects a shellcode observed in dirtyfrag, a local privilege escalation exploit for Linux.
Reference:https://github.com/V4bel/dirtyfrag/tree/master
TLP:TLP:WHITE
Repository:Neo23x0
Rule name:EXPL_LNX_DirtyFrag_ForensicArtefacts_May26
Author:Florian Roth
Description:Detects DirtyFrag exploit code POC usage in Linux environments
Reference:https://github.com/V4bel/dirtyfrag/tree/master
TLP:TLP:WHITE
Repository:Neo23x0
Rule name:F01_s1ckrule
Author:s1ckb017
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:ldpreload
Author:xorseed
Reference:https://stuff.rop.io/
TLP:TLP:WHITE
Repository:
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
TLP:TLP:WHITE
Repository:Stratosphere
Rule name:linux_generic_irc_catcher
Author:@_lubiedo
Description:Find new ELF IRC samples
TLP:TLP:WHITE
Repository:Stratosphere
Rule name:MIRAI_OHSHIT_payload
Author:AfterPacket
Description:MIRAI_OHSHIT ELF payload -- compiled-in C2 set, all architectures
Reference:https://github.com/Afterpacket/drosera-threat-intel
TLP:TLP:WHITE
Repository:YARAify
Rule name:NSVPS_Hydra_SSH_Bruteforce
Author:sanad (NSVPS-SOC)
Description:Hydra SSH brute-force campaign credentials pattern from NSVPS honeypot
TLP:TLP:WHITE
Repository:YARAify
Rule name:RANSOMWARE
Author:ToroGuitar
TLP:TLP:WHITE
Repository:YARAify
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
TLP:TLP:WHITE
Repository:
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
TLP:TLP:WHITE
Repository:YARAify
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags
TLP:TLP:WHITE
Repository:MalwareBazaar

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.

Task Information


Task ID:2440fbaa-c475-11f1-b2b6-42010aa4000b
File name:2a3aab2a262a9fccf8c35ebe2fdfe08f533395a4cf78b2cb202e5ca2129c5c4e
Task parameters:ClamAV scan:True
Unpack:True
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Sanesecurity.Malware.30435.LC.UNOFFICIAL
Signature:SecuriteInfo.com.Linux.Mirai-44.UNOFFICIAL

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
TLP:TLP:WHITE
Repository:YARAify
Rule name:ELF_IoT_Persistence_Hunt
Author:4r4
Description:Hunts for ELF files with persistence and download capabilities
TLP:TLP:WHITE
Repository:YARAify
Rule name:ELF_Packer_Dropper_Fileless_Armhf
Author:Serhii Kocherhan
Description:Detects obfuscated Linux ELF packers/droppers featuring ChaCha20/RC4 decryption, memfd_create/execveat fileless execution capabilities, and unique binary artifacts.
TLP:TLP:WHITE
Repository:YARAify
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:EXPL_HKTL_LNX_DirtyFragShellcode_May26
Author:Pezier Pierre-Henri (Nextron Systems)
Description:Detects a shellcode observed in dirtyfrag, a local privilege escalation exploit for Linux.
Reference:https://github.com/V4bel/dirtyfrag/tree/master
TLP:TLP:WHITE
Repository:Neo23x0
Rule name:EXPL_LNX_DirtyFrag_ForensicArtefacts_May26
Author:Florian Roth
Description:Detects DirtyFrag exploit code POC usage in Linux environments
Reference:https://github.com/V4bel/dirtyfrag/tree/master
TLP:TLP:WHITE
Repository:Neo23x0
Rule name:F01_s1ckrule
Author:s1ckb017
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:ldpreload
Author:xorseed
Reference:https://stuff.rop.io/
TLP:TLP:WHITE
Repository:
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
TLP:TLP:WHITE
Repository:Stratosphere
Rule name:linux_generic_irc_catcher
Author:@_lubiedo
Description:Find new ELF IRC samples
TLP:TLP:WHITE
Repository:Stratosphere
Rule name:MIRAI_OHSHIT_payload
Author:AfterPacket
Description:MIRAI_OHSHIT ELF payload -- compiled-in C2 set, all architectures
Reference:https://github.com/Afterpacket/drosera-threat-intel
TLP:TLP:WHITE
Repository:YARAify
Rule name:NSVPS_Hydra_SSH_Bruteforce
Author:sanad (NSVPS-SOC)
Description:Hydra SSH brute-force campaign credentials pattern from NSVPS honeypot
TLP:TLP:WHITE
Repository:YARAify
Rule name:RANSOMWARE
Author:ToroGuitar
TLP:TLP:WHITE
Repository:YARAify
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
TLP:TLP:WHITE
Repository:
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
TLP:TLP:WHITE
Repository:YARAify
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags
TLP:TLP:WHITE
Repository:MalwareBazaar

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.