Concrete signature match: Trojan - Appears legitimate but performs malicious actions for Linux platform, family Mirai
This is a concrete detection of Trojan:Linux/Mirai.HAF, a confirmed variant of the notorious Mirai botnet family. This malware targets Linux-based IoT devices, transforming them into bots to launch distributed denial-of-service (DDoS) attacks. The detection leverages machine learning behavioral analysis (!MTB) for high confidence and low false positive risk.
No detailed analysis available from definition files.
dfc2b462b12a6f87dd8880222a8eff713317ace50b7f393923b3b44f7c2a26ea11996f5499d3475503751677e10b20902f26c7ee6cdc85e3c0c545f1e7168d147f0d96315473eae2fae7991959b70098d6480ee503e8353b187df7688874a2f84e2f9e081b75afb452538cc2ceee30fe59d80dd5ce0bc43dc2f90d05b21e2f385a8a25364db29883f35f9921a0cb84c472a354016851498ac64409cadd450446Immediately isolate the identified Linux device from the network. Thoroughly scan and remove the detected malware using a robust security solution. Apply all available security patches, disable unnecessary services (e.g., Telnet), change all default credentials, and implement strong, unique passwords for all administrative interfaces to prevent re-infection and secure the device.