YARAhub

You are currently viewing the YARAhub entry of the YARA rule Loader_SH_1. Depending on the TLP classification of this YARA rule chosen by the author, further information about this YARA rule is available below.

YARA Rule Details: Loader_SH_1


Rule name:Loader_SH_1
Author:Nikos 'n0t' Totosis - @casperinous
Description:Detects SH-1 Loader utilised to drop Solaris.
Reference MD5: fc4628f35acf2b7766c9a01284f4fffb
Likes: 0
Reference Link :n/a
Malpedia Family :n/a
Date added:2026-06-22
Rule Matching TLP :TLP:WHITE
Rule Sharing TLP :TLP:RED
License : https://creativecommons.org/licenses/by-nc/4.0/
UUID: 7e530251-ada9-47a9-b0e1-a95dc8360259
Static hits:0
Unpacker hits:0

YARA Rule Content


The content of the YARA rule is shown below.

YARA Rule Matches


The following table shows the most recent files matching this particular YARA rule.

First seen (UTC)SHA256 hashStatic matchesUnpacker matches