MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 144d82a7c955f7c6bae4eea628145cb2dcc3c7a82e9edc175dffb0aca1e4ce3b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 144d82a7c955f7c6bae4eea628145cb2dcc3c7a82e9edc175dffb0aca1e4ce3b
SHA3-384 hash: 458e369137a0c772a6ca5ac49a1016a879d5cc83f73e3063a542d323bcabfda591ba4b841b5fda30e6a512fad3ab6848
SHA1 hash: 74ce17bfc34550ee48a6361af624cf0009aa6853
MD5 hash: 579666fb7d1c99673dcf3a0729e593b6
humanhash: speaker-shade-asparagus-autumn
File name:sensi_tbk
Download: download sample
File size:1'659 bytes
First seen:2026-08-13 14:53:42 UTC
Last seen:2026-08-14 06:06:12 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:kLCwLJuevue0rk3BjSjPjHyC5MDAXbe7X0ux+u7xS:kftDnRjSjPjHygMDAXbT
TLSH T16E3122DA75C74D33EA09AC3912E47F4A71C2113B00612BDAB34856776F0C964F16BE32
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://L/dn/an/an/a

Intelligence


File Origin
# of uploads :
2
# of downloads :
28
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
busybox
Status:
terminated
Behavior Graph:
%3 guuid=b05197be-1800-0000-a1bf-c23efb0b0000 pid=3067 /usr/bin/sudo guuid=f9c976c0-1800-0000-a1bf-c23e030c0000 pid=3075 /tmp/sample.bin guuid=b05197be-1800-0000-a1bf-c23efb0b0000 pid=3067->guuid=f9c976c0-1800-0000-a1bf-c23e030c0000 pid=3075 execve guuid=1052acc0-1800-0000-a1bf-c23e050c0000 pid=3077 /usr/bin/wget net send-data guuid=f9c976c0-1800-0000-a1bf-c23e030c0000 pid=3075->guuid=1052acc0-1800-0000-a1bf-c23e050c0000 pid=3077 execve guuid=9106e4c4-1800-0000-a1bf-c23e0c0c0000 pid=3084 /usr/bin/busybox guuid=f9c976c0-1800-0000-a1bf-c23e030c0000 pid=3075->guuid=9106e4c4-1800-0000-a1bf-c23e0c0c0000 pid=3084 execve guuid=eca287c8-1800-0000-a1bf-c23e120c0000 pid=3090 /usr/bin/dash guuid=f9c976c0-1800-0000-a1bf-c23e030c0000 pid=3075->guuid=eca287c8-1800-0000-a1bf-c23e120c0000 pid=3090 clone guuid=381fd3c8-1800-0000-a1bf-c23e140c0000 pid=3092 /usr/bin/rm guuid=f9c976c0-1800-0000-a1bf-c23e030c0000 pid=3075->guuid=381fd3c8-1800-0000-a1bf-c23e140c0000 pid=3092 execve guuid=465c12c9-1800-0000-a1bf-c23e150c0000 pid=3093 /usr/bin/wget net send-data write-file guuid=f9c976c0-1800-0000-a1bf-c23e030c0000 pid=3075->guuid=465c12c9-1800-0000-a1bf-c23e150c0000 pid=3093 execve guuid=567b7ed4-1800-0000-a1bf-c23e1c0c0000 pid=3100 /usr/bin/dash guuid=f9c976c0-1800-0000-a1bf-c23e030c0000 pid=3075->guuid=567b7ed4-1800-0000-a1bf-c23e1c0c0000 pid=3100 clone guuid=5503dfd5-1800-0000-a1bf-c23e1e0c0000 pid=3102 /usr/bin/chmod guuid=f9c976c0-1800-0000-a1bf-c23e030c0000 pid=3075->guuid=5503dfd5-1800-0000-a1bf-c23e1e0c0000 pid=3102 execve guuid=27b268d6-1800-0000-a1bf-c23e1f0c0000 pid=3103 /tmp/b guuid=f9c976c0-1800-0000-a1bf-c23e030c0000 pid=3075->guuid=27b268d6-1800-0000-a1bf-c23e1f0c0000 pid=3103 execve guuid=5d120dd9-1800-0000-a1bf-c23e200c0000 pid=3104 /usr/bin/rm delete-file guuid=f9c976c0-1800-0000-a1bf-c23e030c0000 pid=3075->guuid=5d120dd9-1800-0000-a1bf-c23e200c0000 pid=3104 execve guuid=d80d0fda-1800-0000-a1bf-c23e210c0000 pid=3105 /usr/bin/rm guuid=f9c976c0-1800-0000-a1bf-c23e030c0000 pid=3075->guuid=d80d0fda-1800-0000-a1bf-c23e210c0000 pid=3105 execve guuid=6ae39eda-1800-0000-a1bf-c23e220c0000 pid=3106 /usr/bin/wget net send-data write-file guuid=f9c976c0-1800-0000-a1bf-c23e030c0000 pid=3075->guuid=6ae39eda-1800-0000-a1bf-c23e220c0000 pid=3106 execve guuid=ec481be0-1800-0000-a1bf-c23e230c0000 pid=3107 /usr/bin/dash guuid=f9c976c0-1800-0000-a1bf-c23e030c0000 pid=3075->guuid=ec481be0-1800-0000-a1bf-c23e230c0000 pid=3107 clone guuid=3e87c3e0-1800-0000-a1bf-c23e250c0000 pid=3109 /usr/bin/chmod guuid=f9c976c0-1800-0000-a1bf-c23e030c0000 pid=3075->guuid=3e87c3e0-1800-0000-a1bf-c23e250c0000 pid=3109 execve guuid=eb2e15e1-1800-0000-a1bf-c23e260c0000 pid=3110 /tmp/b delete-file net guuid=f9c976c0-1800-0000-a1bf-c23e030c0000 pid=3075->guuid=eb2e15e1-1800-0000-a1bf-c23e260c0000 pid=3110 execve 19a01213-d2eb-537d-9ee7-c6c02a59e30a 95.155.151.113:80 guuid=1052acc0-1800-0000-a1bf-c23e050c0000 pid=3077->19a01213-d2eb-537d-9ee7-c6c02a59e30a send: 136B guuid=42e48dc8-1800-0000-a1bf-c23e130c0000 pid=3091 /usr/bin/uname guuid=eca287c8-1800-0000-a1bf-c23e120c0000 pid=3090->guuid=42e48dc8-1800-0000-a1bf-c23e130c0000 pid=3091 execve guuid=465c12c9-1800-0000-a1bf-c23e150c0000 pid=3093->19a01213-d2eb-537d-9ee7-c6c02a59e30a send: 137B guuid=4c5d8bd4-1800-0000-a1bf-c23e1d0c0000 pid=3101 /usr/bin/wc guuid=567b7ed4-1800-0000-a1bf-c23e1c0c0000 pid=3100->guuid=4c5d8bd4-1800-0000-a1bf-c23e1d0c0000 pid=3101 execve guuid=6ae39eda-1800-0000-a1bf-c23e220c0000 pid=3106->19a01213-d2eb-537d-9ee7-c6c02a59e30a send: 139B guuid=6c3128e0-1800-0000-a1bf-c23e240c0000 pid=3108 /usr/bin/wc guuid=ec481be0-1800-0000-a1bf-c23e230c0000 pid=3107->guuid=6c3128e0-1800-0000-a1bf-c23e240c0000 pid=3108 execve 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=eb2e15e1-1800-0000-a1bf-c23e260c0000 pid=3110->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=de0030e1-1800-0000-a1bf-c23e270c0000 pid=3111 /tmp/b net send-data zombie guuid=eb2e15e1-1800-0000-a1bf-c23e260c0000 pid=3110->guuid=de0030e1-1800-0000-a1bf-c23e270c0000 pid=3111 clone guuid=de0030e1-1800-0000-a1bf-c23e270c0000 pid=3111->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 4499fbd0-1235-52bd-a47b-0da69ce9f232 95.155.151.113:9506 guuid=de0030e1-1800-0000-a1bf-c23e270c0000 pid=3111->4499fbd0-1235-52bd-a47b-0da69ce9f232 send: 10B guuid=e26e3de2-1800-0000-a1bf-c23e280c0000 pid=3112 /tmp/b guuid=de0030e1-1800-0000-a1bf-c23e270c0000 pid=3111->guuid=e26e3de2-1800-0000-a1bf-c23e280c0000 pid=3112 clone
Result
Malware family:
n/a
Score:
  9/10
Tags:
defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Reads CPU attributes
Reads system network configuration
Creates a large amount of network flows
Creates/modifies Cron job
Enumerates active TCP sockets
Enumerates running processes
Modifies init.d
Modifies rc script
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Modifies Watchdog functionality
Traces itself
Contacts a large (10753) amount of remote hosts
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 144d82a7c955f7c6bae4eea628145cb2dcc3c7a82e9edc175dffb0aca1e4ce3b

(this sample)

  
Delivery method
Distributed via web download

Comments