MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 35e37eca2a6905bac4d62a387d52a5b032fac52e28992ff29e1bfbf1e7d73c37. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 10
| SHA256 hash: | 35e37eca2a6905bac4d62a387d52a5b032fac52e28992ff29e1bfbf1e7d73c37 |
|---|---|
| SHA3-384 hash: | b6e586402a8b61ecdb7c1c217b68f048cacdc3a9eee5b1a2a55e0936c427d16150aec2754e2013a4d74abc6860c5ab30 |
| SHA1 hash: | e279460e253c692bc9590235a186878171d27ba8 |
| MD5 hash: | 9944d3c0f5f625911bc445a5b0b4c2bc |
| humanhash: | north-edward-freddie-purple |
| File name: | wupd.bat |
| Download: | download sample |
| File size: | 1'373 bytes |
| First seen: | 2026-08-20 07:52:19 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | text/x-msdos-batch |
| ssdeep | 24:AWuVjLuVMoLGHxBlV3gLVF2k8vC7zPxjuD5lbjwgrmFuysDbNQ5iZpyZjoXJ13O:nuRudGHxbVO2ktzPKNZhIsbg |
| TLSH | T1472122618C5094B3CAEE8ED37E52AD16330FD4F60E66C7C620254C6EE807C2BD26C2D2 |
| Magika | batch |
| Reporter | |
| Tags: | bat RAT |
Intelligence
File Origin
# of uploads :
1
# of downloads :
53
Origin country :
SEVendor Threat Intelligence
Malware configuration found for:
BatchScript
Details
Malware family:
n/a
ID:
1
File name:
https://bm.ncwsqnk.com/d.php?s=general&h=tnn08toi
Verdict:
Malicious activity
Analysis date:
2026-08-18 02:19:32 UTC
Tags:
arch-exec neptunerat rat powershell xworm remote
Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Detection:
n/a
Detection(s):
Result
Verdict:
Suspicious
Maliciousness:
Behaviour
Running batch commands
Launching a process
Searching for the window
Using the Windows Management Instrumentation requests
Searching for synchronization primitives
DNS request
Connection attempt
Sending an HTTP GET request
Creating a file
Creating a process from a recently created file
Creating a window
Verdict:
Suspicious
Threat level:
5/10
Confidence:
100%
Tags:
cmd lolbin wscript
Result
Threat name:
n/a
Detection:
malicious
Classification:
troj.evad
Score:
56 / 100
Signature
Sigma detected: Suspicious Program Names
Sigma detected: WScript or CScript Dropper
Uses ping.exe to check the status of other devices and networks
Uses ping.exe to sleep
Behaviour
Behavior Graph:
Score:
34%
Verdict:
Susipicious
File Type:
SCRIPT
Threat name:
Text.Trojan.Generic
Status:
Suspicious
First seen:
2026-08-19 12:17:27 UTC
File Type:
Text (Batch)
AV detection:
3 of 24 (12.50%)
Threat level:
5/5
Detection(s):
Suspicious file
Result
Malware family:
n/a
Score:
5/10
Tags:
discovery execution
Behaviour
Runs ping.exe
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
cURL User-Agent
Executes a command shell one-liner
System Network Configuration Discovery: Internet Connection Discovery
Discovers running processes
Executes a VBScript file via the Windows Script Host.
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
bat 35e37eca2a6905bac4d62a387d52a5b032fac52e28992ff29e1bfbf1e7d73c37
(this sample)
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.