Backdoor

What is “Backdoor.Linux.Mirai.h”?

Malware Removal

The Backdoor.Linux.Mirai.h is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Linux.Mirai.h virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • A potential decoy document was displayed to the user

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Linux.Mirai.h?


File Info:

crc32: 50A28FFF
md5: 545b6967baf360c5a288613076c860fc
name: tmpojbllo8o
sha1: 36f8ae7e7cf052fc88fef5817aceffa9c680bd70
sha256: 20ce5e16c3d3ce83ceed37fd3d4c6e65d9439988c4998dc1639307d1dff09c27
sha512: 77e9f719ac65b40826bebb2bd59b0aeb1fbe934fc2683f2002bbf07a9096896e99499a47da6382183e85272558b7a2f2140e15ea069133d5936ac6b0b42531d0
ssdeep: 384:MmMEQQOuY9AgHwbU/VFSWCPb2nuJsSiQRkSzw/mTxOftJ1ughN2u:lMEQ9FSgHwQVkKnuJBiQM+FiDN2u
type: ELF 32-bit LSB executable, Intel 80386, version 1 (GNU/Linux), statically linked, stripped

Version Info:

0: [No Data]

Backdoor.Linux.Mirai.h also known as:

ClamAVUnix.Trojan.DarkNexus-7679166-0
FireEyeTrojan.GenericKD.43339031
McAfeeRDN/Generic.dx
ESET-NOD32a variant of Linux/Mirai.XL
TrendMicro-HouseCallTrojan.Linux.MIRAI.USELVFD20
CynetMalicious (score: 85)
GDataTrojan.GenericKD.43339031
KasperskyHEUR:Backdoor.Linux.Mirai.h
BitDefenderTrojan.GenericKD.43339031
MicroWorld-eScanTrojan.GenericKD.43339031
TencentLinux.Backdoor.Mirai.Sued
Ad-AwareTrojan.GenericKD.43339031
EmsisoftTrojan.GenericKD.43339031 (B)
ComodoMalware@#2j7ls4a2byduy
F-SecureMalware.LINUX/Mirai.yhjnr
TrendMicroTrojan.Linux.MIRAI.USELVFD20
McAfee-GW-EditionRDN/Generic.dx
SophosMal/Generic-S
IkarusWin32.Outbreak
JiangminBackdoor.Linux.ckwj
AviraLINUX/Mirai.yhjnr
ArcabitTrojan.Generic.D2954D17
ZoneAlarmHEUR:Backdoor.Linux.Mirai.h
ALYacTrojan.GenericKD.43339031
MAXmalware (ai score=99)
SentinelOneDFI – Malicious ELF
FortinetELF/Mirai.H!tr.bdr
Qihoo-360Linux/Backdoor.428

How to remove Backdoor.Linux.Mirai.h?

Backdoor.Linux.Mirai.h removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment