YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash db175e6e4de27d93bd2c49a61b41e92c9ec3e41e2c652d5fe5ebaf3031a9b839.

Scan Results


SHA256 hash: db175e6e4de27d93bd2c49a61b41e92c9ec3e41e2c652d5fe5ebaf3031a9b839
File size:210'703 bytes
File download: Original
MIME type:application/x-executable
MD5 hash: 003721faf979b6cb83aba4a0498d086c
SHA1 hash: a4a5ab777915cec1c3e0b9f25cc2364da0623683
SHA3-384 hash: 23c1b5c791b4079e8fce0430f94eafe5a15ec76f28259a72e3511b60de9575f16fd2ca4a042c43dc9f9554b709a4494e
First seen:2026-05-18 07:55:07 UTC
Last seen:2026-05-18 07:59:01 UTC
Sightings:6
imphash :n/a
ssdeep : 6144:sW973uoO4TquAPF8yJdPgSumFuLm5a7E8ykt2tACW:sW973uoxT2smFuLm5a7E8ykt2tACW
TLSH :n/a
telfhash : t13e710044983d09d9af631c2568b96be35993b42a32e5bf18ff16cdc0485e429f164e0f
gimphash :n/a
dhash icon :n/a

Tasks


There are 6 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:6eb72731-528f-11f1-badc-42010aa4000b
File name:db175e6e4de27d93bd2c49a61b41e92c9ec3e41e2c652d5fe5ebaf3031a9b839
Task parameters:ClamAV scan:True
Unpack:True
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Unix.Dropper.Mirai-7138857-0
Signature:Unix.Dropper.Mirai-7139232-0
Signature:Unix.Dropper.Mirai-7540662-0
Signature:Unix.Trojan.Gafgyt-111
Signature:Unix.Trojan.Gafgyt-6981154-0
Signature:Unix.Trojan.Gafgyt-7643791-0
Signature:Unix.Trojan.Gafgyt-9876192-0
Signature:YARA.MALPEDIA_Elf_Bashlite_Auto.UNOFFICIAL

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
TLP:TLP:WHITE
Repository:YARAify
Rule name:elf_bashlite_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects elf.bashlite.
TLP:TLP:WHITE
Repository:Malpedia
Rule name:ELF_Toriilike_persist
Author:4r4
Description:Detects Torii IoT Botnet (stealthier Mirai alternative)
Reference:Identified via researched data
TLP:TLP:WHITE
Repository:YARAify
Rule name:Linux_Gafgyt_Generic
Author:albertzsigovits
Description:Generic Approach to Mirai/Gafgyt samples
TLP:TLP:WHITE
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
TLP:TLP:WHITE
Repository:Stratosphere
Rule name:Linux_Trojan_Gafgyt_09c3070e
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_0cd591cd
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_148b91a2
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_32eb0c81
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_33b4111a
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_620087b9
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_656bf077
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_779e142f
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_807911a2
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_821173df
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_9e9530a7
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_a0a4de11
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_a10161ce
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_a33a8363
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_a6a2adb9
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_cf84c9f2
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_d0c57a2e
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_d4227dbf
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_d996d335
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_dd0d6173
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_e0673a90
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_f3d83a74
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_fb14e81f
Author:Elastic Security
Reference:0fd07e6068a721774716eb4940e2c19faef02d5bdacf3b018bf5995fa98a3a27
TLP:TLP:WHITE
Repository:elastic
Rule name:NET
Author:malware-lu
TLP:TLP:WHITE
Repository:
Rule name:classified
TLP :TLP:AMBER
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
TLP:TLP:WHITE
Repository:YARAify
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags
TLP:TLP:WHITE
Repository:MalwareBazaar

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.

Task Information


Task ID:4cfa6496-528f-11f1-badc-42010aa4000b
File name:db175e6e4de27d93bd2c49a61b41e92c9ec3e41e2c652d5fe5ebaf3031a9b839
Task parameters:ClamAV scan:True
Unpack:True
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Unix.Dropper.Mirai-7138857-0
Signature:Unix.Dropper.Mirai-7139232-0
Signature:Unix.Dropper.Mirai-7540662-0
Signature:Unix.Trojan.Gafgyt-111
Signature:Unix.Trojan.Gafgyt-6981154-0
Signature:Unix.Trojan.Gafgyt-7643791-0
Signature:Unix.Trojan.Gafgyt-9876192-0
Signature:YARA.MALPEDIA_Elf_Bashlite_Auto.UNOFFICIAL

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
TLP:TLP:WHITE
Repository:YARAify
Rule name:elf_bashlite_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects elf.bashlite.
TLP:TLP:WHITE
Repository:Malpedia
Rule name:ELF_Toriilike_persist
Author:4r4
Description:Detects Torii IoT Botnet (stealthier Mirai alternative)
Reference:Identified via researched data
TLP:TLP:WHITE
Repository:YARAify
Rule name:Linux_Gafgyt_Generic
Author:albertzsigovits
Description:Generic Approach to Mirai/Gafgyt samples
TLP:TLP:WHITE
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
TLP:TLP:WHITE
Repository:Stratosphere
Rule name:Linux_Trojan_Gafgyt_09c3070e
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_0cd591cd
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_148b91a2
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_32eb0c81
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_33b4111a
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_620087b9
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_656bf077
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_779e142f
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_807911a2
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_821173df
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_9e9530a7
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_a0a4de11
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_a10161ce
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_a33a8363
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_a6a2adb9
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_cf84c9f2
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_d0c57a2e
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_d4227dbf
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_d996d335
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_dd0d6173
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_e0673a90
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_f3d83a74
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_fb14e81f
Author:Elastic Security
Reference:0fd07e6068a721774716eb4940e2c19faef02d5bdacf3b018bf5995fa98a3a27
TLP:TLP:WHITE
Repository:elastic
Rule name:NET
Author:malware-lu
TLP:TLP:WHITE
Repository:
Rule name:classified
TLP :TLP:AMBER
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
TLP:TLP:WHITE
Repository:YARAify
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags
TLP:TLP:WHITE
Repository:MalwareBazaar

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.

Task Information


Task ID:4c83b2c8-528f-11f1-badc-42010aa4000b
File name:db175e6e4de27d93bd2c49a61b41e92c9ec3e41e2c652d5fe5ebaf3031a9b839.elf
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Unix.Dropper.Mirai-7138857-0
Signature:Unix.Dropper.Mirai-7139232-0
Signature:Unix.Dropper.Mirai-7540662-0
Signature:Unix.Trojan.Gafgyt-111
Signature:Unix.Trojan.Gafgyt-6981154-0
Signature:Unix.Trojan.Gafgyt-7643791-0
Signature:Unix.Trojan.Gafgyt-9876192-0
Signature:YARA.MALPEDIA_Elf_Bashlite_Auto.UNOFFICIAL

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
TLP:TLP:WHITE
Repository:YARAify
Rule name:elf_bashlite_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects elf.bashlite.
TLP:TLP:WHITE
Repository:Malpedia
Rule name:ELF_Toriilike_persist
Author:4r4
Description:Detects Torii IoT Botnet (stealthier Mirai alternative)
Reference:Identified via researched data
TLP:TLP:WHITE
Repository:YARAify
Rule name:Linux_Gafgyt_Generic
Author:albertzsigovits
Description:Generic Approach to Mirai/Gafgyt samples
TLP:TLP:WHITE
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
TLP:TLP:WHITE
Repository:Stratosphere
Rule name:Linux_Trojan_Gafgyt_09c3070e
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_0cd591cd
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_148b91a2
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_32eb0c81
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_33b4111a
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_620087b9
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_656bf077
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_779e142f
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_807911a2
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_821173df
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_9e9530a7
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_a0a4de11
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_a10161ce
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_a33a8363
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_a6a2adb9
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_cf84c9f2
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_d0c57a2e
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_d4227dbf
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_d996d335
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_dd0d6173
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_e0673a90
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_f3d83a74
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_fb14e81f
Author:Elastic Security
Reference:0fd07e6068a721774716eb4940e2c19faef02d5bdacf3b018bf5995fa98a3a27
TLP:TLP:WHITE
Repository:elastic
Rule name:NET
Author:malware-lu
TLP:TLP:WHITE
Repository:
Rule name:classified
TLP :TLP:AMBER
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
TLP:TLP:WHITE
Repository:YARAify
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags
TLP:TLP:WHITE
Repository:MalwareBazaar

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.

Task Information


Task ID:297199ef-528f-11f1-badc-42010aa4000b
File name:db175e6e4de27d93bd2c49a61b41e92c9ec3e41e2c652d5fe5ebaf3031a9b839
Task parameters:ClamAV scan:True
Unpack:True
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Unix.Dropper.Mirai-7138857-0
Signature:Unix.Dropper.Mirai-7139232-0
Signature:Unix.Dropper.Mirai-7540662-0
Signature:Unix.Trojan.Gafgyt-111
Signature:Unix.Trojan.Gafgyt-6981154-0
Signature:Unix.Trojan.Gafgyt-7643791-0
Signature:Unix.Trojan.Gafgyt-9876192-0
Signature:YARA.MALPEDIA_Elf_Bashlite_Auto.UNOFFICIAL

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
TLP:TLP:WHITE
Repository:YARAify
Rule name:elf_bashlite_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects elf.bashlite.
TLP:TLP:WHITE
Repository:Malpedia
Rule name:ELF_Toriilike_persist
Author:4r4
Description:Detects Torii IoT Botnet (stealthier Mirai alternative)
Reference:Identified via researched data
TLP:TLP:WHITE
Repository:YARAify
Rule name:Linux_Gafgyt_Generic
Author:albertzsigovits
Description:Generic Approach to Mirai/Gafgyt samples
TLP:TLP:WHITE
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
TLP:TLP:WHITE
Repository:Stratosphere
Rule name:Linux_Trojan_Gafgyt_09c3070e
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_0cd591cd
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_148b91a2
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_32eb0c81
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_33b4111a
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_620087b9
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_656bf077
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_779e142f
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_807911a2
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_821173df
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_9e9530a7
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_a0a4de11
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_a10161ce
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_a33a8363
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_a6a2adb9
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_cf84c9f2
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_d0c57a2e
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_d4227dbf
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_d996d335
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_dd0d6173
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_e0673a90
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_f3d83a74
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_fb14e81f
Author:Elastic Security
Reference:0fd07e6068a721774716eb4940e2c19faef02d5bdacf3b018bf5995fa98a3a27
TLP:TLP:WHITE
Repository:elastic
Rule name:NET
Author:malware-lu
TLP:TLP:WHITE
Repository:
Rule name:classified
TLP :TLP:AMBER
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
TLP:TLP:WHITE
Repository:YARAify
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags
TLP:TLP:WHITE
Repository:MalwareBazaar

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.

Task Information


Task ID:055fab48-528f-11f1-badc-42010aa4000b
File name:db175e6e4de27d93bd2c49a61b41e92c9ec3e41e2c652d5fe5ebaf3031a9b839
Task parameters:ClamAV scan:True
Unpack:True
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Unix.Dropper.Mirai-7138857-0
Signature:Unix.Dropper.Mirai-7139232-0
Signature:Unix.Dropper.Mirai-7540662-0
Signature:Unix.Trojan.Gafgyt-111
Signature:Unix.Trojan.Gafgyt-6981154-0
Signature:Unix.Trojan.Gafgyt-7643791-0
Signature:Unix.Trojan.Gafgyt-9876192-0
Signature:YARA.MALPEDIA_Elf_Bashlite_Auto.UNOFFICIAL

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
TLP:TLP:WHITE
Repository:YARAify
Rule name:elf_bashlite_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects elf.bashlite.
TLP:TLP:WHITE
Repository:Malpedia
Rule name:ELF_Toriilike_persist
Author:4r4
Description:Detects Torii IoT Botnet (stealthier Mirai alternative)
Reference:Identified via researched data
TLP:TLP:WHITE
Repository:YARAify
Rule name:Linux_Gafgyt_Generic
Author:albertzsigovits
Description:Generic Approach to Mirai/Gafgyt samples
TLP:TLP:WHITE
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
TLP:TLP:WHITE
Repository:Stratosphere
Rule name:Linux_Trojan_Gafgyt_09c3070e
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_0cd591cd
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_148b91a2
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_32eb0c81
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_33b4111a
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_620087b9
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_656bf077
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_779e142f
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_807911a2
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_821173df
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_9e9530a7
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_a0a4de11
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_a10161ce
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_a33a8363
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_a6a2adb9
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_cf84c9f2
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_d0c57a2e
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_d4227dbf
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_d996d335
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_dd0d6173
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_e0673a90
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_f3d83a74
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_fb14e81f
Author:Elastic Security
Reference:0fd07e6068a721774716eb4940e2c19faef02d5bdacf3b018bf5995fa98a3a27
TLP:TLP:WHITE
Repository:elastic
Rule name:NET
Author:malware-lu
TLP:TLP:WHITE
Repository:
Rule name:classified
TLP :TLP:AMBER
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
TLP:TLP:WHITE
Repository:YARAify
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags
TLP:TLP:WHITE
Repository:MalwareBazaar

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.

Task Information


Task ID:e34cb4a3-528e-11f1-badc-42010aa4000b
File name:db175e6e4de27d93bd2c49a61b41e92c9ec3e41e2c652d5fe5ebaf3031a9b839
Task parameters:ClamAV scan:True
Unpack:True
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

Signature:Unix.Dropper.Mirai-7138857-0
Signature:Unix.Dropper.Mirai-7139232-0
Signature:Unix.Dropper.Mirai-7540662-0
Signature:Unix.Trojan.Gafgyt-111
Signature:Unix.Trojan.Gafgyt-6981154-0
Signature:Unix.Trojan.Gafgyt-7643791-0
Signature:Unix.Trojan.Gafgyt-9876192-0
Signature:YARA.MALPEDIA_Elf_Bashlite_Auto.UNOFFICIAL

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
TLP:TLP:WHITE
Repository:YARAify
Rule name:elf_bashlite_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects elf.bashlite.
TLP:TLP:WHITE
Repository:Malpedia
Rule name:ELF_Toriilike_persist
Author:4r4
Description:Detects Torii IoT Botnet (stealthier Mirai alternative)
Reference:Identified via researched data
TLP:TLP:WHITE
Repository:YARAify
Rule name:Linux_Gafgyt_Generic
Author:albertzsigovits
Description:Generic Approach to Mirai/Gafgyt samples
TLP:TLP:WHITE
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
TLP:TLP:WHITE
Repository:Stratosphere
Rule name:Linux_Trojan_Gafgyt_09c3070e
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_0cd591cd
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_148b91a2
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_32eb0c81
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_33b4111a
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_620087b9
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_656bf077
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_779e142f
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_807911a2
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_821173df
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_9e9530a7
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_a0a4de11
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_a10161ce
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_a33a8363
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_a6a2adb9
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_cf84c9f2
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_d0c57a2e
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_d4227dbf
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_d996d335
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_dd0d6173
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_e0673a90
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_f3d83a74
Author:Elastic Security
TLP:TLP:WHITE
Repository:elastic
Rule name:Linux_Trojan_Gafgyt_fb14e81f
Author:Elastic Security
Reference:0fd07e6068a721774716eb4940e2c19faef02d5bdacf3b018bf5995fa98a3a27
TLP:TLP:WHITE
Repository:elastic
Rule name:NET
Author:malware-lu
TLP:TLP:WHITE
Repository:
Rule name:classified
TLP :TLP:AMBER
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
TLP:TLP:WHITE
Repository:YARAify
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags
TLP:TLP:WHITE
Repository:MalwareBazaar

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.