🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

YARAify Scan Results

You are viewing the YARAify database entry for the file with the SHA256 hash f729df914abbfdcbcfe6efa95f811c5cee80f8983ad8acc9d1ee87bf5eb8d924.

Scan Results


SHA256 hash: f729df914abbfdcbcfe6efa95f811c5cee80f8983ad8acc9d1ee87bf5eb8d924
File size:93'448 bytes
File download: Original
MIME type:application/x-executable
MD5 hash: 7ac59b68b151be24004788e4ad353cbd
SHA1 hash: 03d0c506336ed6b0e26c0a18c0683cb5908c190b
SHA3-384 hash: ddebe161e5c808c67627f1c9b454a4e884a070a4f752a16f0fe5c6549fcc7cf6ec997636d6eca760e33153457a4b8697
First seen:2026-09-19 10:54:18 UTC
Last seen:Never
Sightings:1
imphash :n/a
ssdeep : 1536:LsEh1x4XYIDpemBVocBNTx5npAyKpVvekSpaa/KlbuhT9KTufAOm7MCI:hKHLBnBNTx5ngGIa/KoRivI
TLSH :n/a
telfhash : tnull
gimphash :n/a
dhash icon :n/a

Tasks


There are 2 tasks on YARAify for this particular file. The 10 most recent ones are shown below.

Task Information


Task ID:76b3c522-b418-11f1-a0cd-42010aa4000b
File name:f729df914abbfdcbcfe6efa95f811c5cee80f8983ad8acc9d1ee87bf5eb8d924.elf
Task parameters:ClamAV scan:True
Unpack:False
Share file:True

ClamAV Results


The file matched the following open source and commercial ClamAV rules.

YARA Results


Static Analysis

The following YARA rules matched on the file (static analysis).

Rule name:ELF_IoT_DVR_Botnet_Hama_UPX
Author:Serhii Kocherhan
Description:Detects packed and unpacked ELF IoT/DVR botnet variants targeting UPX compression structures and uncompressed code
TLP:TLP:WHITE
Repository:YARAify
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
TLP:TLP:WHITE
Repository:Stratosphere
Rule name:SUSP_ELF_LNX_UPX_Compressed_File
Author:Florian Roth (Nextron Systems)
Description:Detects a suspicious ELF binary with UPX compression
Reference:Internal Research
TLP:TLP:WHITE
Repository:Neo23x0
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
TLP:TLP:WHITE
Repository:YARAify
Rule name:upx_packed_elf_v1
Author:RandomMalware
TLP:TLP:WHITE
Repository:YARAify

Unpacker

The following YARA rules matched on the unpacked file.

Unpacked Files


The following files could be unpacked from this sample.