🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash 56ba71e217d13c871fc4a4e491a1f147da88bfc32acd7d8da204e14295208eb0.

Scan Results


SHA256 hash: 56ba71e217d13c871fc4a4e491a1f147da88bfc32acd7d8da204e14295208eb0
File size:219'264 bytes
File download: Original
MIME type:application/x-executable
MD5 hash: 4b63684e726f86f1ea115479d31b7523
SHA1 hash: 40cdb37f350e914c5d14fb5547e8d6ea19deea6b
SHA3-384 hash: 5985e020cbca617b30ad78426fb3e57ebba0091d7f2d531e8ccb68a5ad81dd75894b1fb8af579073d5427e510591689a
First seen:2026-09-19 10:41:04 UTC
Last seen:2026-09-19 10:44:02 UTC
Sightings:5
imphash :n/a
ssdeep : 6144:bcjno/vF5GOc1rDCKSo0iqCs4ZYW8IhpMTedc:bcjnU5Gxlb1FqxOYPeMV
TLSH :n/a
telfhash : tnull
gimphash :n/a
dhash icon :n/a

Tasks


There are 5 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:07853fef-b417-11f1-a0cd-42010aa4000b
File name:sever1078.arm
Task parameters:ClamAV scan:True
Unpack:True
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Unix.Trojan.Mirai-9935286-0

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:ELF_IoT_DVR_Botnet_Hama_UPX
Author:Serhii Kocherhan
Description:Detects packed and unpacked ELF IoT/DVR botnet variants targeting UPX compression structures and uncompressed code
TLP:TLP:WHITE
Repository:YARAify
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
TLP:TLP:WHITE
Repository:Stratosphere
Rule name:SUSP_ELF_LNX_UPX_Compressed_File
Author:Florian Roth (Nextron Systems)
Description:Detects a suspicious ELF binary with UPX compression
Reference:Internal Research
TLP:TLP:WHITE
Repository:Neo23x0
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
TLP:TLP:WHITE
Repository:YARAify
Rule name:upx_packed_elf_v1
Author:RandomMalware
TLP:TLP:WHITE
Repository:YARAify

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.

Task Information


Task ID:eb9e2b3c-b416-11f1-a0cd-42010aa4000b
File name:56ba71e217d13c871fc4a4e491a1f147da88bfc32acd7d8da204e14295208eb0.elf
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Unix.Trojan.Mirai-9935286-0

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:ELF_IoT_DVR_Botnet_Hama_UPX
Author:Serhii Kocherhan
Description:Detects packed and unpacked ELF IoT/DVR botnet variants targeting UPX compression structures and uncompressed code
TLP:TLP:WHITE
Repository:YARAify
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
TLP:TLP:WHITE
Repository:Stratosphere
Rule name:SUSP_ELF_LNX_UPX_Compressed_File
Author:Florian Roth (Nextron Systems)
Description:Detects a suspicious ELF binary with UPX compression
Reference:Internal Research
TLP:TLP:WHITE
Repository:Neo23x0
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
TLP:TLP:WHITE
Repository:YARAify
Rule name:upx_packed_elf_v1
Author:RandomMalware
TLP:TLP:WHITE
Repository:YARAify

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.

Task Information


Task ID:e437b964-b416-11f1-a0cd-42010aa4000b
File name:sever1078.arm
Task parameters:ClamAV scan:True
Unpack:True
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Unix.Trojan.Mirai-9935286-0

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:ELF_IoT_DVR_Botnet_Hama_UPX
Author:Serhii Kocherhan
Description:Detects packed and unpacked ELF IoT/DVR botnet variants targeting UPX compression structures and uncompressed code
TLP:TLP:WHITE
Repository:YARAify
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
TLP:TLP:WHITE
Repository:Stratosphere
Rule name:SUSP_ELF_LNX_UPX_Compressed_File
Author:Florian Roth (Nextron Systems)
Description:Detects a suspicious ELF binary with UPX compression
Reference:Internal Research
TLP:TLP:WHITE
Repository:Neo23x0
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
TLP:TLP:WHITE
Repository:YARAify
Rule name:upx_packed_elf_v1
Author:RandomMalware
TLP:TLP:WHITE
Repository:YARAify

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.

Task Information


Task ID:c0d05f28-b416-11f1-a0cd-42010aa4000b
File name:sever1078.arm
Task parameters:ClamAV scan:True
Unpack:True
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Unix.Trojan.Mirai-9935286-0

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:ELF_IoT_DVR_Botnet_Hama_UPX
Author:Serhii Kocherhan
Description:Detects packed and unpacked ELF IoT/DVR botnet variants targeting UPX compression structures and uncompressed code
TLP:TLP:WHITE
Repository:YARAify
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
TLP:TLP:WHITE
Repository:Stratosphere
Rule name:SUSP_ELF_LNX_UPX_Compressed_File
Author:Florian Roth (Nextron Systems)
Description:Detects a suspicious ELF binary with UPX compression
Reference:Internal Research
TLP:TLP:WHITE
Repository:Neo23x0
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
TLP:TLP:WHITE
Repository:YARAify
Rule name:upx_packed_elf_v1
Author:RandomMalware
TLP:TLP:WHITE
Repository:YARAify

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.

Task Information


Task ID:9d90f580-b416-11f1-a0cd-42010aa4000b
File name:sever1078.arm
Task parameters:ClamAV scan:True
Unpack:True
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Unix.Trojan.Mirai-9935286-0

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:ELF_IoT_DVR_Botnet_Hama_UPX
Author:Serhii Kocherhan
Description:Detects packed and unpacked ELF IoT/DVR botnet variants targeting UPX compression structures and uncompressed code
TLP:TLP:WHITE
Repository:YARAify
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
TLP:TLP:WHITE
Repository:Stratosphere
Rule name:SUSP_ELF_LNX_UPX_Compressed_File
Author:Florian Roth (Nextron Systems)
Description:Detects a suspicious ELF binary with UPX compression
Reference:Internal Research
TLP:TLP:WHITE
Repository:Neo23x0
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
TLP:TLP:WHITE
Repository:YARAify
Rule name:upx_packed_elf_v1
Author:RandomMalware
TLP:TLP:WHITE
Repository:YARAify

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.