MalwareBazaar Database

This page shows some basic information the YARA rule deepfield_potassium_mirai_variant including corresponding malware samples.

Database Entry


YARA Rule:deepfield_potassium_mirai_variant
Author:Nokia Deepfield ERT
Description:Detects Potassium Mirai variant (ChaCha20 table, HTTP C2 with token/guid, .woof dropper). Also known as Woof (internal) and Dichter (related variant with Dutch C2 domains, same key material).
Firstseen:2026-08-18 19:59:46 UTC
Lastseen:2026-10-04 05:55:22 UTC
Sightings:257

Malware Samples


The table below shows all malware samples that matching this particular YARA rule (max 1000).

Firstseen (UTC)SHA256 hashTagsSignatureReporter