MalwareBazaar Database

This page shows some basic information the YARA rule deepfield_potassium_mirai_variant including corresponding malware samples.

Database Entry


YARA Rule:deepfield_potassium_mirai_variant
Author:Nokia Deepfield ERT
Description:Detects Potassium Mirai variant (ChaCha20 table, HTTP C2 with token/guid, .woof dropper). Also known as Woof (internal) and Dichter (related variant with Dutch C2 domains, same key material).
Firstseen:2026-09-17 21:17:52 UTC
Lastseen:2026-09-17 23:31:16 UTC
Sightings:14

Malware Samples


The table below shows all malware samples that matching this particular YARA rule (max 1000).

Firstseen (UTC)SHA256 hashTagsSignatureReporter