Trojan

Should I remove “TrojanDownloader:Linux/Morila.F!MTB”?

Malware Removal

The TrojanDownloader:Linux/Morila.F!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Linux/Morila.F!MTB virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs

How to determine TrojanDownloader:Linux/Morila.F!MTB?


File Info:

crc32: F1837D17
md5: 6719418281513dffc789f1ec26ccbc54
name: upload_file
sha1: ecdad996c8a0b40ccdd5b9ae20adb40a6b02dcb3
sha256: 3807990d1963451143b6b1c264d9a887f337c228eea8d6c282d27ab29327eb65
sha512: f68747df982dbee69cd8bbcc1f596040e924067113eb8f3433849b45f733b21cec49a47df34bcfebaac912351ac7cc87ca12cb3b2aacf2cc0302337220591cea
ssdeep: 24:vlG4+lG3lG5Ic4klGGOaslG/lGKslGOz+lG1EslGnlGNJlG3lGg:vlKlelIJ4klfOblGlilD+lOl+lgJlmlV
type: Bourne-Again shell script, ASCII text executable

Version Info:

0: [No Data]

TrojanDownloader:Linux/Morila.F!MTB also known as:

MicroWorld-eScanGeneric.Bash.MiraiA.0E7C82E8
FireEyeGeneric.Bash.MiraiA.0E7C82E8
McAfeeLinux/Downloader.k
SymantecDownloader.Trojan
ESET-NOD32Linux/TrojanDownloader.SH.S
TrendMicro-HouseCallELF_MIRAILOD.SM
AvastBV:Downloader-AAN [Drp]
GDataGeneric.Bash.MiraiA.0E7C82E8
KasperskyHEUR:Trojan-Downloader.Shell.Agent.p
BitDefenderGeneric.Bash.MiraiA.0E7C82E8
NANO-AntivirusTrojan.Script.Downloader.hjbjdt
RisingMalware.Shell!1.C8A3 (CLASSIC)
Ad-AwareGeneric.Bash.MiraiA.0E7C82E8
EmsisoftGeneric.Bash.MiraiA.0E7C82E8 (B)
ComodoTrojWare.Script.TrojanDownloader.Agent.SH@7q1bln
F-SecureMalware.HTML/ExpKit.Gen2
DrWebLinux.DownLoader.664
SophosMal/ShellDl-A
IkarusTrojan-Downloader.Linux.Sh
CyrenSH/Mirai.A.gen!Camelot
AviraHTML/ExpKit.Gen2
ArcabitGeneric.Bash.MiraiA.0E7C82E8
ZoneAlarmHEUR:Trojan-Downloader.Shell.Agent.p
MicrosoftTrojanDownloader:Linux/Morila.F!MTB
CynetMalicious (score: 85)
AhnLab-V3Shell/ElfDownloader.S1
ALYacGeneric.Bash.MiraiA.0E7C82E8
TencentHeur:Trojan.Linux.Downloader.e
MAXmalware (ai score=86)
FortinetLinux/ShellDLoader.RMF!tr
AVGBV:Downloader-AAN [Drp]
Qihoo-360virus.script.bash.000002

How to remove TrojanDownloader:Linux/Morila.F!MTB?

TrojanDownloader:Linux/Morila.F!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment