🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 509090e9d5e98b9445ee3783c37cd5e59cecdc92e683e2329627cbc29ca73ccd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 509090e9d5e98b9445ee3783c37cd5e59cecdc92e683e2329627cbc29ca73ccd
SHA3-384 hash: 9ea765f5d6bec042c07abea4e3f161dd4f1afd22517f862f2485cac9f9c4d82d5af17283044989ce8a44ab0b6be3eb23
SHA1 hash: a72e59704058c54d930cf7cae234d1b5509466ae
MD5 hash: ff707ba5d0fd4e73e3ad5b1e6157dccd
humanhash: nevada-mockingbird-minnesota-king
File name:2950428276197768463.bat
Download: download sample
File size:15'180 bytes
First seen:2026-05-21 14:17:53 UTC
Last seen:Never
File type:Batch (bat) bat
MIME type:text/plain
ssdeep 384:+gpLVBoQu4HWrfCHfAzpddhddn7a8JetVZB+Ml:Dtu4HW5zpddhddnLeFsMl
TLSH T184625C35F586354B2D83419BF40213E3DA6DE0345B0B5260A4DEC35DBA8F06D966EA3F
Magika batch
Reporter TomU
Tags:bat

Intelligence


File Origin
# of uploads :
1
# of downloads :
36
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
Launching a service
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
expand fingerprint lolbin net powershell regsvr32 webdav
Verdict:
Malicious
File Type:
text
First seen:
2026-05-21T13:25:00Z UTC
Last seen:
2026-05-21T13:33:00Z UTC
Hits:
~10
Threat name:
Script-BAT.Trojan.Strelastealer
Status:
Malicious
First seen:
2026-05-22 17:39:00 UTC
File Type:
Text
AV detection:
12 of 24 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
execution
Behaviour
Runs net.exe
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_BAT_OBFUSC_Jul24_3
Author:Florian Roth
Description:Detects indicators of obfuscation in Windows Batch files
Reference:https://x.com/0xToxin/status/1811656147943752045

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Batch (bat) bat 509090e9d5e98b9445ee3783c37cd5e59cecdc92e683e2329627cbc29ca73ccd

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments