MalwareBazaar Database
This page shows some basic information the YARA rule ELF_Packer_Dropper_Fileless_Armhf including corresponding malware samples.
Database Entry
| YARA Rule: | ELF_Packer_Dropper_Fileless_Armhf |
|---|---|
| Author: | Serhii Kocherhan |
| Description: | Detects obfuscated Linux ELF packers/droppers featuring ChaCha20/RC4 decryption, memfd_create/execveat fileless execution capabilities, and unique binary artifacts. |
| Firstseen: | 2026-09-23 04:04:51 UTC |
| Lastseen: | 2026-09-25 06:31:38 UTC |
| Sightings: | 44 |
Malware Samples
The table below shows all malware samples that matching this particular YARA rule (max 1000).
| Firstseen (UTC) | SHA256 hash | Tags | Signature | Reporter |
|---|