🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash ef549f315d3af072ff7db4c7f65cdf1e7a9b30bb3a0143a6f9ef7b2d2dc2ffec.

Scan Results


SHA256 hash: ef549f315d3af072ff7db4c7f65cdf1e7a9b30bb3a0143a6f9ef7b2d2dc2ffec
File size:130'040 bytes
File download: Original
MIME type:application/x-executable
MD5 hash: cc819168f01c2089dfd03d5a1279bf77
SHA1 hash: dd8181724c41ad61bbc221a9259ff4e4f39c1960
SHA3-384 hash: 25026b64da69b9461e4c26e2d785ff320891ad8db220691d587ca573bb8ab89ad2e666b96a783870466ba69365b39532
First seen:2026-10-09 23:16:16 UTC
Last seen:Never
Sightings:1
imphash :n/a
ssdeep : 3072:YdZtnvckwIItkstqH0rZfvnTd3WghgXLbvuLZc8CoOCBp39:Y9nvckutks4H0NHTUg0LbW68CGBp39
TLSH :n/a
telfhash : t179510fb12b993d6432c7671a7345ee32e8720a9404e9b1d99e7364d4de327840ef10e2
gimphash :n/a
dhash icon :n/a

Tasks


There are 1 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:6d800df0-c437-11f1-b2b6-42010aa4000b
File name:ef549f315d3af072ff7db4c7f65cdf1e7a9b30bb3a0143a6f9ef7b2d2dc2ffec.elf
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:dependsonpythonailib
Author:Tim Brown
Description:Hunts for dependencies on Python AI libraries
TLP:TLP:WHITE
Repository:YARAify
Rule name:ELF_IoT_Persistence_Hunt
Author:4r4
Description:Hunts for ELF files with persistence and download capabilities
TLP:TLP:WHITE
Repository:YARAify
Rule name:ELF_Mirai
Author:NDA0E
Description:Detects multiple Mirai variants
TLP:TLP:WHITE
Repository:YARAify
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:test_rule_vldslv
Author:
TLP:TLP:WHITE
Repository:YARAify
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
TLP:TLP:WHITE
Repository:YARAify
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags
TLP:TLP:WHITE
Repository:MalwareBazaar
Rule name:virustotal
Author:Tracel
TLP:TLP:WHITE
Repository:MalwareBazaar

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.