MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 35e37eca2a6905bac4d62a387d52a5b032fac52e28992ff29e1bfbf1e7d73c37. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: 35e37eca2a6905bac4d62a387d52a5b032fac52e28992ff29e1bfbf1e7d73c37
SHA3-384 hash: b6e586402a8b61ecdb7c1c217b68f048cacdc3a9eee5b1a2a55e0936c427d16150aec2754e2013a4d74abc6860c5ab30
SHA1 hash: e279460e253c692bc9590235a186878171d27ba8
MD5 hash: 9944d3c0f5f625911bc445a5b0b4c2bc
humanhash: north-edward-freddie-purple
File name:wupd.bat
Download: download sample
File size:1'373 bytes
First seen:2026-08-20 07:52:19 UTC
Last seen:Never
File type:Batch (bat) bat
MIME type:text/x-msdos-batch
ssdeep 24:AWuVjLuVMoLGHxBlV3gLVF2k8vC7zPxjuD5lbjwgrmFuysDbNQ5iZpyZjoXJ13O:nuRudGHxbVO2ktzPKNZhIsbg
TLSH T1472122618C5094B3CAEE8ED37E52AD16330FD4F60E66C7C620254C6EE807C2BD26C2D2
Magika batch
Reporter abuse_ch
Tags:bat RAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
53
Origin country :
SE SE
Vendor Threat Intelligence
Malware configuration found for:
BatchScript
Details
Malware family:
n/a
ID:
1
File name:
https://bm.ncwsqnk.com/d.php?s=general&h=tnn08toi
Verdict:
Malicious activity
Analysis date:
2026-08-18 02:19:32 UTC
Tags:
arch-exec neptunerat rat powershell xworm remote

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Suspicious
Maliciousness:

Behaviour
Running batch commands
Launching a process
Searching for the window
Using the Windows Management Instrumentation requests
Searching for synchronization primitives
DNS request
Connection attempt
Sending an HTTP GET request
Creating a file
Creating a process from a recently created file
Creating a window
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
cmd lolbin wscript
Result
Threat name:
n/a
Detection:
malicious
Classification:
troj.evad
Score:
56 / 100
Signature
Sigma detected: Suspicious Program Names
Sigma detected: WScript or CScript Dropper
Uses ping.exe to check the status of other devices and networks
Uses ping.exe to sleep
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1961023 Sample: wupd.bat Startdate: 20/08/2026 Architecture: WINDOWS Score: 56 32 dl.nn.ccztfc.net 2->32 34 mr-b01.tm-azurefd.net 2->34 36 3 other IPs or domains 2->36 42 Sigma detected: WScript or CScript Dropper 2->42 44 Sigma detected: Suspicious Program Names 2->44 8 cmd.exe 2 2->8         started        signatures3 process4 signatures5 46 Uses ping.exe to sleep 8->46 48 Uses ping.exe to check the status of other devices and networks 8->48 11 cmd.exe 1 8->11         started        14 curl.exe 2 8->14         started        17 curl.exe 2 8->17         started        20 7 other processes 8->20 process6 dnsIp7 50 Uses ping.exe to sleep 11->50 22 PING.EXE 1 11->22         started        38 dl.nn.ccztfc.net 104.234.4.12, 49731, 49734, 49737 ASYMPTOTE-ASYMPTOTENETWORKLLCUS United States 14->38 40 127.0.0.1 unknown unknown 14->40 28 C:\Users\user\AppData\Local\...\inject.ps1, ASCII 17->28 dropped 30 C:\Users\user\AppData\Local\...\launch.vbs, ASCII 20->30 dropped 24 tasklist.exe 1 20->24         started        26 find.exe 1 20->26         started        file8 signatures9 process10
Threat name:
Text.Trojan.Generic
Status:
Suspicious
First seen:
2026-08-19 12:17:27 UTC
File Type:
Text (Batch)
AV detection:
3 of 24 (12.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
discovery execution
Behaviour
Runs ping.exe
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
cURL User-Agent
Executes a command shell one-liner
System Network Configuration Discovery: Internet Connection Discovery
Discovers running processes
Executes a VBScript file via the Windows Script Host.
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Batch (bat) bat 35e37eca2a6905bac4d62a387d52a5b032fac52e28992ff29e1bfbf1e7d73c37

(this sample)

  
Delivery method
Distributed via web download

Comments