MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 71c3a953b7da40683ba95bcefeb914aee4f85f32967c78fb910b28078ac1f06d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 71c3a953b7da40683ba95bcefeb914aee4f85f32967c78fb910b28078ac1f06d
SHA3-384 hash: 3554032c57404c21af8d86a9a00610bdb3a4428aada12d8d15608696d13f94680968e6087719d739ffe0e1aca1926182
SHA1 hash: 4025be44e1a15edee555b7b9d9a858f88fbf668e
MD5 hash: 063ff668d01f0ad63a302a3d06df0ddf
humanhash: august-wyoming-blue-india
File name:lg
Download: download sample
File size:2'464 bytes
First seen:2025-01-27 12:06:47 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:vDA/zF7GwIHBmXDf9gw2L5LfFk5xSfXbvDTd:vsh7Gl4bUtr6qvnR
TLSH T15151829B375687302E66F4D3B5B5486473DAF4F690CCDEDA47E8B4A9084DE1CA0C0AD2
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://193.143.1.66/hold.x86n/an/an/a
http://193.143.1.66/hold.mipsn/an/an/a
http://193.143.1.66/hold.mpsln/an/an/a
http://193.143.1.66/hold.armn/an/an/a
http://193.143.1.66/hold.arm5n/an/an/a
http://193.143.1.66/hold.arm6n/an/an/a
http://193.143.1.66/hold.arm7n/an/an/a
http://193.143.1.66/hold.ppcn/an/an/a
http://193.143.1.66/hold.m68kn/an/an/a
http://193.143.1.66/hold.spcn/an/an/a
http://193.143.1.66/hold.i686n/an/an/a
http://193.143.1.66/hold.sh4n/an/an/a
http://193.143.1.66/hold.arcn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
45
Origin country :
DE DE
Vendor Threat Intelligence
Gathering data
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Result
Verdict:
MALICIOUS
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-01-27 12:07:07 UTC
File Type:
Text (Shell)
AV detection:
16 of 24 (66.67%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 71c3a953b7da40683ba95bcefeb914aee4f85f32967c78fb910b28078ac1f06d

(this sample)

  
Delivery method
Distributed via web download

Comments