logo

How to Create F.L.I.R.T Signature Using Yara Rules for Static Analysis of ELF Malware

ID: 9ea14d9a-a75f-548b-80c8-cf755e3a66f9

STIX ID: report--9ea14d9a-a75f-548b-80c8-cf755e3a66f9

Feed Name: JPCERT Blog

Date Published: 2023-06-06

Date Updated: 2026-04-19

Author: 増渕 維摩(Yuma Masubuchi)

...
...

This article explains a technique for improving static analysis of stripped ELF malware by generating YARA rules from a target sample, using VirusTotal Retrohunt to find symbol-rich binaries, and creating matching FLIRT signatures, aided by the AutoYara4FLIRT IDA plugin and CLI. It provides a YARA condition for detecting binaries with .symtab/.strtab, discusses workflow and automation, and reports evaluation results (roughly 60% function match on x86 and ~30% on ARM, with some x86 samples >90%), noting VT Retrohunt requirements and broader applicability across architectures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.