Malware

What is “Linux/Mirai.BAK”?

Malware Removal

The Linux/Mirai.BAK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Linux/Mirai.BAK virus can do?

  • Injection (inter-process)
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • A potential decoy document was displayed to the user
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Linux/Mirai.BAK?


File Info:

crc32: 2C41BADA
md5: 9ca2c0ff1282e782c40f064e5aba9a64
name: upload_file
sha1: d8f1440b97e3865bb4be1aecffd3222fac0c47cb
sha256: 3c2ad268a199ff477665e96cccc61d23cfd74a64eb72ec89d28efd520f3289f8
sha512: 37714e4e5112c5cdbaf1620fad6dc136aa9ac224bf81e8c8793416074bd0f448a3f9eb5e9205aa2fb3a971a71f9c7b1afb5d862b8bf34579d60d378349eab45c
ssdeep: 3072:Nc4i0agsmw3Py5CP5HM8EVLUuYtgB5H6oVqqwPa5POdOQ33Q:Nc/0aNPy54EVAhOaIqqfPqOJ
type: ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped

Version Info:

0: [No Data]

Linux/Mirai.BAK also known as:

MicroWorld-eScanTrojan.GenericKD.43826634
FireEyeTrojan.GenericKD.43826634
CAT-QuickHealElf.Trojan.A1019390
McAfeeGenericRXLY-NZ!9CA2C0FF1282
SangforMalware
SymantecLinux.Mirai
AvastELF:Hajime-R [Trj]
ClamAVUnix.Dropper.Botnet-6566040-0
KasperskyHEUR:Backdoor.Linux.Mirai.b
BitDefenderTrojan.GenericKD.43826634
NANO-AntivirusTrojan.Mirai.hwnnhe
TencentBackdoor.Linux.Mirai.wz
Ad-AwareTrojan.GenericKD.43826634
SophosMal/Generic-S
ComodoMalware@#1tq7zhvgp80a1
F-SecureMalware.LINUX/Mirai.pfohw
DrWebLinux.Mirai.4898
ZillyaTrojan.Mirai.Linux.78039
TrendMicroBackdoor.Linux.ZYX.USELVIF20
McAfee-GW-EditionGenericRXLY-NZ!9CA2C0FF1282
EmsisoftTrojan.GenericKD.43826634 (B)
GDataTrojan.GenericKD.43826634
JiangminBackdoor.Linux.fkyl
AviraLINUX/Mirai.pfohw
Antiy-AVLTrojan[Backdoor]/Linux.Mirai.b
MicrosoftTrojan:Linux/Mirai.AH!MTB
ArcabitTrojan.Generic.D29CBDCA
ZoneAlarmHEUR:Backdoor.Linux.Mirai.b
Avast-MobileELF:Mirai-UM [Trj]
CynetMalicious (score: 85)
ALYacTrojan.GenericKD.43826634
MAXmalware (ai score=100)
ESET-NOD32Linux/Mirai.BAK
RisingBackdoor.Mozi!1.C55A (CLASSIC)
IkarusTrojan.Linux.Mirai
FortinetELF/Mirai.YVMI!tr
AVGELF:Hajime-R [Trj]
Qihoo-360Linux/Backdoor.6f4

How to remove Linux/Mirai.BAK?

Linux/Mirai.BAK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment