🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2a20d78642d3c155f5820606bf5bfd66f0c1f7264b79bf96fa80ee2f13debde2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 2a20d78642d3c155f5820606bf5bfd66f0c1f7264b79bf96fa80ee2f13debde2
SHA3-384 hash: e8bdba2f07b9dc0e7dcf2cde8a46c4ae51407fb1088a1d16f2a155ec1b35c01073024af0799e02ea3785b168459b86ad
SHA1 hash: 1d6b7096cd90b85459a5ca39a2ef56bee13f8c5f
MD5 hash: c454027b25b92e06d085101fc54cf490
humanhash: hot-arizona-xray-cold
File name:2a20d78642d3c155f5820606bf5bfd66f0c1f7264b79bf96fa80ee2f13debde2.bat
Download: download sample
File size:213 bytes
First seen:2026-03-06 11:44:35 UTC
Last seen:Never
File type:Batch (bat) bat
MIME type:text/plain
ssdeep 6:3JZFSgHYwLqBDudZLFNEuuwLqBDarFTXQEcIIVEwLqBDoPWdpIv:3JZFpY+qwFg+qkFNIS+qMe8v
TLSH T13CD0C99BF16A903917450FC5C305B81DC94701DB38C6C586D039CA8B703243A37C6A73
Magika batch
Reporter JAMESWT_WT
Tags:bat moonzonet-com

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
IT IT
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
malware.bat
Verdict:
No threats detected
Analysis date:
2026-03-03 02:44:02 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Verdict:
Malicious
File Type:
unix shell
Detections:
Trojan.APosT.UDP.C&C HEUR:Trojan.BAT.Alien.gen
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Executes dropped EXE
Downloads MZ/PE file
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments