Unidentified 105
Malware⚠️ Overview
Unidentified 105 is a designation used in certain internal threat intelligence databases for a malware family that, as of April 2025, has no publicly documented discovery date, known operator, or confirmed category. Searches of MITRE ATT&CK (accessed March 2025) found no entry for “Unidentified 105”; no CVE identifiers from the NVD or vendors such as Microsoft or Trend Micro reference this name. VirusTotal queries return zero samples directly tagged “Unidentified 105”, and academic publications indexed by Google Scholar show no peer-reviewed analysis. The lack of attribution means its classification remains unknown—it may be a placeholder for an uncategorized sample, a spurious hash, or a designation from a private intelligence feed not publicly released.
🔧 Technical Capabilities
No publicly verifiable technical capabilities have been published for Unidentified 105. Reverse‑engineering reports from sources like Mandiant or CrowdStrike do not mention this name; therefore propagation methods, attack vectors, C2 infrastructure, persistence mechanisms, and evasion techniques cannot be described from open‑source evidence. A search of VirusTotal’s community comments and Hybrid‑Analysis sandbox reports yielded no behavioral profiles. The absence of any vendor security advisory (e.g., from Cisco Talos, Palo Alto Networks Unit 42, or Symantec) means no IoCs or technical indicators are available. MITRE ATT&CK IDs often linked to generic malware families (e.g., T1059 for command‑line execution) cannot be applied without analysis. Until a verified sample is studied and published, any discussion of capabilities would be speculative and thus violates the requirement for verifiable facts.
📜 History & Notable Incidents
No first appearance date, major campaigns, high‑profile victims, or law enforcement actions are publicly associated with Unidentified 105. Searches of the BleepingComputer forums, The Hacker News, and FireEye’s Mandiant reports (through March 2025) return zero references. Similarly, the CVE database (via NVD NIST) contains no entries referencing this malware family. It may be an internal identifier used by a single organization or a misattributed hash from an automated analysis pipeline. Without confirmed incident reports from sources like Kaspersky Securelist or the UK NCSC, no historical timeline can be constructed. The only verifiable fact is that no verified incidents have been publicly reported under this name.
🔍 Detection Indicators
No file hashes (MD5, SHA‑1, SHA‑256), behavioral signatures, network IoCs (IPs, domains, URLs), registry keys, mutex names, or User‑Agent strings have been published for Unidentified 105. A scan of the AlienVault OTX pulse database and IBM X‑Force Exchange reveals zero correlated indicators. The absence of any Snort or YARA rule using the string “Unidentified_105” confirms no detection signatures are publicly available. Security teams encountering a sample labeled thus must treat it as unknown and run generic sandboxing and memory analysis to develop IoCs. Without official vendor attribution, all detection is hypothetical.
☠️ Risk & Impact
Because no public information exists on Unidentified 105, the damage it causes—data exfiltration, financial losses, or targeted sectors—cannot be assessed. Affected industries remain unknown. The only verifiable risk is the uncertainty itself: an unclassified malware sample may pose a latent threat that standard defensive measures might not counteract. No reports from the FBI’s IC3 or Europol’s EC3 mention this family, so no empirical impact data exists. Organizations should apply standard risk‑based analysis to any unknown binary bearing this label until further intelligence emerges.
🛡️ Mitigation
Given the absence of specific mitigations, recommended defensive measures follow general best practices: enable application whitelisting, employ endpoint detection and response (EDR) tools with behavioral analysis, and maintain up‑to‑date antivirus signatures from multiple vendors. No patches or dedicated detection rules exist because no CVEs or vendor advisories reference Unidentified 105. Security teams should treat any such sample as suspicious and submit it to sandbox services (e.g., ANY.RUN, Joe Sandbox) for automated analysis. Until public documentation appears, mitigation must be generic and based on the principle of least privilege.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.