MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d733390fa16a0835b88818e808a9bcfe02cd54ef798575dd75a0064df8d6d93c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: d733390fa16a0835b88818e808a9bcfe02cd54ef798575dd75a0064df8d6d93c
SHA3-384 hash: 174d96a02cea734c4450b6893d18acbe828985cf9e4b74ad08d3ad7824254a2e9df4997b43f0a600a7cde5e520eb1e7c
SHA1 hash: 6537ea1128f8b7d7785e5bd6394ed4cc40a37116
MD5 hash: 3a96437104cde299b3b6030dde0c7b62
humanhash: ceiling-cat-cardinal-golf
File name:sensi_tbk.sh
Download: download sample
File size:1'689 bytes
First seen:2026-08-13 20:50:10 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:kLCwLkgj0rkxjSjPjHyC5MDAXbe7X0ux+u7xS:kfwgjnxjSjPjHygMDAXbT
TLSH T1D331F2D975D74D33AA196C3912E46B4A71C2153B00612BE9B34C96776F0C954A06BE22
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://L/dn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
32
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
busybox
Status:
terminated
Behavior Graph:
%3 guuid=e1edc826-1900-0000-08b8-5bf907060000 pid=1543 /usr/bin/sudo guuid=910db929-1900-0000-08b8-5bf90e060000 pid=1550 /tmp/sample.bin guuid=e1edc826-1900-0000-08b8-5bf907060000 pid=1543->guuid=910db929-1900-0000-08b8-5bf90e060000 pid=1550 execve guuid=10391f2a-1900-0000-08b8-5bf910060000 pid=1552 /usr/bin/wget net send-data guuid=910db929-1900-0000-08b8-5bf90e060000 pid=1550->guuid=10391f2a-1900-0000-08b8-5bf910060000 pid=1552 execve guuid=f34db66a-1900-0000-08b8-5bf97e060000 pid=1662 /usr/bin/busybox guuid=910db929-1900-0000-08b8-5bf90e060000 pid=1550->guuid=f34db66a-1900-0000-08b8-5bf97e060000 pid=1662 execve guuid=1095f46d-1900-0000-08b8-5bf983060000 pid=1667 /usr/bin/dash guuid=910db929-1900-0000-08b8-5bf90e060000 pid=1550->guuid=1095f46d-1900-0000-08b8-5bf983060000 pid=1667 clone guuid=49b04a6e-1900-0000-08b8-5bf988060000 pid=1672 /usr/bin/rm guuid=910db929-1900-0000-08b8-5bf90e060000 pid=1550->guuid=49b04a6e-1900-0000-08b8-5bf988060000 pid=1672 execve guuid=c9949a6e-1900-0000-08b8-5bf989060000 pid=1673 /usr/bin/wget net send-data write-file guuid=910db929-1900-0000-08b8-5bf90e060000 pid=1550->guuid=c9949a6e-1900-0000-08b8-5bf989060000 pid=1673 execve guuid=1b0da975-1900-0000-08b8-5bf996060000 pid=1686 /usr/bin/dash guuid=910db929-1900-0000-08b8-5bf90e060000 pid=1550->guuid=1b0da975-1900-0000-08b8-5bf996060000 pid=1686 clone guuid=68c24f76-1900-0000-08b8-5bf999060000 pid=1689 /usr/bin/chmod guuid=910db929-1900-0000-08b8-5bf90e060000 pid=1550->guuid=68c24f76-1900-0000-08b8-5bf999060000 pid=1689 execve guuid=b2b2bb76-1900-0000-08b8-5bf99b060000 pid=1691 /tmp/b guuid=910db929-1900-0000-08b8-5bf90e060000 pid=1550->guuid=b2b2bb76-1900-0000-08b8-5bf99b060000 pid=1691 execve guuid=c84e1279-1900-0000-08b8-5bf9a2060000 pid=1698 /usr/bin/rm delete-file guuid=910db929-1900-0000-08b8-5bf90e060000 pid=1550->guuid=c84e1279-1900-0000-08b8-5bf9a2060000 pid=1698 execve guuid=ea7d5779-1900-0000-08b8-5bf9a3060000 pid=1699 /usr/bin/rm guuid=910db929-1900-0000-08b8-5bf90e060000 pid=1550->guuid=ea7d5779-1900-0000-08b8-5bf9a3060000 pid=1699 execve guuid=25779079-1900-0000-08b8-5bf9a5060000 pid=1701 /usr/bin/wget net send-data write-file guuid=910db929-1900-0000-08b8-5bf90e060000 pid=1550->guuid=25779079-1900-0000-08b8-5bf9a5060000 pid=1701 execve guuid=5703f5bb-1900-0000-08b8-5bf914070000 pid=1812 /usr/bin/dash guuid=910db929-1900-0000-08b8-5bf90e060000 pid=1550->guuid=5703f5bb-1900-0000-08b8-5bf914070000 pid=1812 clone guuid=210971bc-1900-0000-08b8-5bf916070000 pid=1814 /usr/bin/chmod guuid=910db929-1900-0000-08b8-5bf90e060000 pid=1550->guuid=210971bc-1900-0000-08b8-5bf916070000 pid=1814 execve guuid=0d6ebcbc-1900-0000-08b8-5bf917070000 pid=1815 /tmp/b delete-file net guuid=910db929-1900-0000-08b8-5bf90e060000 pid=1550->guuid=0d6ebcbc-1900-0000-08b8-5bf917070000 pid=1815 execve 19a01213-d2eb-537d-9ee7-c6c02a59e30a 95.155.151.113:80 guuid=10391f2a-1900-0000-08b8-5bf910060000 pid=1552->19a01213-d2eb-537d-9ee7-c6c02a59e30a send: 136B guuid=667cfd6d-1900-0000-08b8-5bf984060000 pid=1668 /usr/bin/uname guuid=1095f46d-1900-0000-08b8-5bf983060000 pid=1667->guuid=667cfd6d-1900-0000-08b8-5bf984060000 pid=1668 execve guuid=c9949a6e-1900-0000-08b8-5bf989060000 pid=1673->19a01213-d2eb-537d-9ee7-c6c02a59e30a send: 137B guuid=eefcb775-1900-0000-08b8-5bf997060000 pid=1687 /usr/bin/wc guuid=1b0da975-1900-0000-08b8-5bf996060000 pid=1686->guuid=eefcb775-1900-0000-08b8-5bf997060000 pid=1687 execve guuid=25779079-1900-0000-08b8-5bf9a5060000 pid=1701->19a01213-d2eb-537d-9ee7-c6c02a59e30a send: 139B guuid=25b604bc-1900-0000-08b8-5bf915070000 pid=1813 /usr/bin/wc guuid=5703f5bb-1900-0000-08b8-5bf914070000 pid=1812->guuid=25b604bc-1900-0000-08b8-5bf915070000 pid=1813 execve 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=0d6ebcbc-1900-0000-08b8-5bf917070000 pid=1815->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=681dd1bc-1900-0000-08b8-5bf918070000 pid=1816 /tmp/b net send-data zombie guuid=0d6ebcbc-1900-0000-08b8-5bf917070000 pid=1815->guuid=681dd1bc-1900-0000-08b8-5bf918070000 pid=1816 clone guuid=681dd1bc-1900-0000-08b8-5bf918070000 pid=1816->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 4499fbd0-1235-52bd-a47b-0da69ce9f232 95.155.151.113:9506 guuid=681dd1bc-1900-0000-08b8-5bf918070000 pid=1816->4499fbd0-1235-52bd-a47b-0da69ce9f232 send: 10B guuid=1034e0bc-1900-0000-08b8-5bf91a070000 pid=1818 /tmp/b guuid=681dd1bc-1900-0000-08b8-5bf918070000 pid=1816->guuid=1034e0bc-1900-0000-08b8-5bf91a070000 pid=1818 clone
Result
Malware family:
n/a
Score:
  9/10
Tags:
defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Reads CPU attributes
Reads system network configuration
Creates/modifies Cron job
Enumerates active TCP sockets
Enumerates running processes
Modifies init.d
Modifies rc script
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Modifies Watchdog functionality
Traces itself
Contacts a large (111615) amount of remote hosts
Creates a large amount of network flows
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh d733390fa16a0835b88818e808a9bcfe02cd54ef798575dd75a0064df8d6d93c

(this sample)

  
Delivery method
Distributed via web download

Comments