MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 18909faad7553046953dca1e904e782fda4cfdda2a35a02414c2d6eb44e1d61e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 18909faad7553046953dca1e904e782fda4cfdda2a35a02414c2d6eb44e1d61e
SHA3-384 hash: 3c63c8d22f87d810ff6eea4df8faae9eb5fdeb6342da2d189f752c9389cc277c1f164d710d59b70b3cacd7481552f36b
SHA1 hash: 354547ae5f0c8e543b382f90e4c96ee4c877c5da
MD5 hash: 8a7aa793fb303b70a814ecaf274587c8
humanhash: floor-william-colorado-massachusetts
File name:sensi_tbk.sh
Download: download sample
File size:1'694 bytes
First seen:2026-08-14 02:58:48 UTC
Last seen:2026-08-14 17:51:41 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:kLC/rNLk91jpkxjSjPjHyC5MDAXbe7X0ux+u7xS:kuo91jGxjSjPjHygMDAXbT
TLSH T1763106DA75D74D339E196C3912E46B4A75C1113F00512BE9B34C96779F0C964E06BD32
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://L/dn/an/an/a

Intelligence


File Origin
# of uploads :
2
# of downloads :
36
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
busybox
Status:
terminated
Behavior Graph:
%3 guuid=210bfa07-1700-0000-4ae9-ce65d40d0000 pid=3540 /usr/bin/sudo guuid=c466510c-1700-0000-4ae9-ce65d50d0000 pid=3541 /tmp/sample.bin guuid=210bfa07-1700-0000-4ae9-ce65d40d0000 pid=3540->guuid=c466510c-1700-0000-4ae9-ce65d50d0000 pid=3541 execve guuid=ebe9f10c-1700-0000-4ae9-ce65d70d0000 pid=3543 /usr/bin/wget net send-data guuid=c466510c-1700-0000-4ae9-ce65d50d0000 pid=3541->guuid=ebe9f10c-1700-0000-4ae9-ce65d70d0000 pid=3543 execve guuid=a823f710-1700-0000-4ae9-ce65e30d0000 pid=3555 /usr/bin/rm delete-file guuid=c466510c-1700-0000-4ae9-ce65d50d0000 pid=3541->guuid=a823f710-1700-0000-4ae9-ce65e30d0000 pid=3555 execve guuid=340b4d11-1700-0000-4ae9-ce65e70d0000 pid=3559 /usr/bin/busybox guuid=c466510c-1700-0000-4ae9-ce65d50d0000 pid=3541->guuid=340b4d11-1700-0000-4ae9-ce65e70d0000 pid=3559 execve guuid=901efe14-1700-0000-4ae9-ce65f30d0000 pid=3571 /usr/bin/dash guuid=c466510c-1700-0000-4ae9-ce65d50d0000 pid=3541->guuid=901efe14-1700-0000-4ae9-ce65f30d0000 pid=3571 clone guuid=33145c15-1700-0000-4ae9-ce65f60d0000 pid=3574 /usr/bin/rm guuid=c466510c-1700-0000-4ae9-ce65d50d0000 pid=3541->guuid=33145c15-1700-0000-4ae9-ce65f60d0000 pid=3574 execve guuid=4994a415-1700-0000-4ae9-ce65f80d0000 pid=3576 /usr/bin/wget net send-data write-file guuid=c466510c-1700-0000-4ae9-ce65d50d0000 pid=3541->guuid=4994a415-1700-0000-4ae9-ce65f80d0000 pid=3576 execve guuid=af25a41d-1700-0000-4ae9-ce65140e0000 pid=3604 /usr/bin/dash guuid=c466510c-1700-0000-4ae9-ce65d50d0000 pid=3541->guuid=af25a41d-1700-0000-4ae9-ce65140e0000 pid=3604 clone guuid=5ae02a1e-1700-0000-4ae9-ce65180e0000 pid=3608 /usr/bin/chmod guuid=c466510c-1700-0000-4ae9-ce65d50d0000 pid=3541->guuid=5ae02a1e-1700-0000-4ae9-ce65180e0000 pid=3608 execve guuid=2f88711e-1700-0000-4ae9-ce651c0e0000 pid=3612 /tmp/b guuid=c466510c-1700-0000-4ae9-ce65d50d0000 pid=3541->guuid=2f88711e-1700-0000-4ae9-ce651c0e0000 pid=3612 execve guuid=f1c3cc20-1700-0000-4ae9-ce65280e0000 pid=3624 /usr/bin/rm delete-file guuid=c466510c-1700-0000-4ae9-ce65d50d0000 pid=3541->guuid=f1c3cc20-1700-0000-4ae9-ce65280e0000 pid=3624 execve guuid=74b31d21-1700-0000-4ae9-ce652a0e0000 pid=3626 /usr/bin/rm guuid=c466510c-1700-0000-4ae9-ce65d50d0000 pid=3541->guuid=74b31d21-1700-0000-4ae9-ce652a0e0000 pid=3626 execve guuid=ff5d6721-1700-0000-4ae9-ce652c0e0000 pid=3628 /usr/bin/wget net send-data write-file guuid=c466510c-1700-0000-4ae9-ce65d50d0000 pid=3541->guuid=ff5d6721-1700-0000-4ae9-ce652c0e0000 pid=3628 execve guuid=548b0525-1700-0000-4ae9-ce653b0e0000 pid=3643 /usr/bin/dash guuid=c466510c-1700-0000-4ae9-ce65d50d0000 pid=3541->guuid=548b0525-1700-0000-4ae9-ce653b0e0000 pid=3643 clone guuid=46514e25-1700-0000-4ae9-ce653e0e0000 pid=3646 /usr/bin/chmod guuid=c466510c-1700-0000-4ae9-ce65d50d0000 pid=3541->guuid=46514e25-1700-0000-4ae9-ce653e0e0000 pid=3646 execve guuid=ec14ea25-1700-0000-4ae9-ce65410e0000 pid=3649 /tmp/b delete-file net guuid=c466510c-1700-0000-4ae9-ce65d50d0000 pid=3541->guuid=ec14ea25-1700-0000-4ae9-ce65410e0000 pid=3649 execve 19a01213-d2eb-537d-9ee7-c6c02a59e30a 95.155.151.113:80 guuid=ebe9f10c-1700-0000-4ae9-ce65d70d0000 pid=3543->19a01213-d2eb-537d-9ee7-c6c02a59e30a send: 136B guuid=0eaa0615-1700-0000-4ae9-ce65f40d0000 pid=3572 /usr/bin/uname guuid=901efe14-1700-0000-4ae9-ce65f30d0000 pid=3571->guuid=0eaa0615-1700-0000-4ae9-ce65f40d0000 pid=3572 execve guuid=4994a415-1700-0000-4ae9-ce65f80d0000 pid=3576->19a01213-d2eb-537d-9ee7-c6c02a59e30a send: 137B guuid=d72eaf1d-1700-0000-4ae9-ce65160e0000 pid=3606 /usr/bin/wc guuid=af25a41d-1700-0000-4ae9-ce65140e0000 pid=3604->guuid=d72eaf1d-1700-0000-4ae9-ce65160e0000 pid=3606 execve guuid=ff5d6721-1700-0000-4ae9-ce652c0e0000 pid=3628->19a01213-d2eb-537d-9ee7-c6c02a59e30a send: 139B guuid=8d3c0f25-1700-0000-4ae9-ce653c0e0000 pid=3644 /usr/bin/wc guuid=548b0525-1700-0000-4ae9-ce653b0e0000 pid=3643->guuid=8d3c0f25-1700-0000-4ae9-ce653c0e0000 pid=3644 execve 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=ec14ea25-1700-0000-4ae9-ce65410e0000 pid=3649->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1099ac26-1700-0000-4ae9-ce65440e0000 pid=3652 /tmp/b net send-data zombie guuid=ec14ea25-1700-0000-4ae9-ce65410e0000 pid=3649->guuid=1099ac26-1700-0000-4ae9-ce65440e0000 pid=3652 clone guuid=1099ac26-1700-0000-4ae9-ce65440e0000 pid=3652->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 4499fbd0-1235-52bd-a47b-0da69ce9f232 95.155.151.113:9506 guuid=1099ac26-1700-0000-4ae9-ce65440e0000 pid=3652->4499fbd0-1235-52bd-a47b-0da69ce9f232 send: 10B guuid=83bcb826-1700-0000-4ae9-ce65450e0000 pid=3653 /tmp/b guuid=1099ac26-1700-0000-4ae9-ce65440e0000 pid=3652->guuid=83bcb826-1700-0000-4ae9-ce65450e0000 pid=3653 clone
Gathering data
Result
Malware family:
n/a
Score:
  9/10
Tags:
defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Reads CPU attributes
Reads system network configuration
Creates/modifies Cron job
Enumerates active TCP sockets
Enumerates running processes
Modifies init.d
Modifies rc script
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Modifies Watchdog functionality
Traces itself
Contacts a large (140327) amount of remote hosts
Creates a large amount of network flows
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 18909faad7553046953dca1e904e782fda4cfdda2a35a02414c2d6eb44e1d61e

(this sample)

  
Delivery method
Distributed via web download

Comments