MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6df218a5efe3aafc25210e07cc376237ec8224bad9ed4488cc4ec33dc0c07751. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 13


Intelligence 13 IOCs YARA 5 File information Comments

SHA256 hash: 6df218a5efe3aafc25210e07cc376237ec8224bad9ed4488cc4ec33dc0c07751
SHA3-384 hash: 3e6c2a6a8ae382eadecb3a9522bb6ec64c5c31f79dfff1b0a2bc7f239e1251428affccdd5ad844eb911fe7655e58c5a4
SHA1 hash: ad3a4b497fe169824224ee3c37135168cb6406e6
MD5 hash: 38b776288330ff8abb19ccd6a5f842c6
humanhash: leopard-oklahoma-arizona-harry
File name:z1CCL26046-LABEL.bat
Download: download sample
File size:15'375'848 bytes
First seen:2026-06-09 01:00:11 UTC
Last seen:Never
File type:Batch (bat) bat
MIME type:text/x-msdos-batch
ssdeep 49152:Cvbc26AnsmMixOttc/Luu8lxW4LQmSzrrVFK3SYtoUwi24FUixgdf34pvxkM7vaw:b
TLSH T12AF65C720697BDFD3B6D3D85A0056E445C5C3B4B1269824ABBC830BA63ED5B48F2CD78
Magika batch
Reporter FXOLabs
Tags:bat

Intelligence


File Origin
# of uploads :
1
# of downloads :
54
Origin country :
US US
Vendor Threat Intelligence
Malware configuration found for:
BatchScript
Details
Malware family:
n/a
ID:
1
File name:
_6df218a5efe3aafc25210e07cc376237ec8224bad9ed4488cc4ec33dc0c07751.txt
Verdict:
No threats detected
Analysis date:
2026-06-09 01:03:48 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
97.4%
Tags:
autorun emotet
Result
Verdict:
Malware
Maliciousness:

Behaviour
Launching a process
Creating a file in the %temp% directory
Creating a process from a recently created file
Сreating synchronization primitives
Connection attempt
Sending a custom TCP request
Enabling autorun by creating a file
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
base64 masquerade obfuscated powershell
Verdict:
Malicious
Labled as:
Dropper.Generic.PWSH.Downloader.D
Verdict:
Malicious
File Type:
text
First seen:
2026-06-08T14:45:00Z UTC
Last seen:
2026-06-09T21:55:00Z UTC
Hits:
~1000
Detections:
Trojan-Spy.Win64.Overlord.sb HEUR:Trojan-Spy.Win32.KeyLogger.gen not-a-virus:HEUR:NetTool.Win32.Convagent.pefng
Verdict:
Malicious
Threat:
Trojan-Spy.Win32.KeyLogger
Threat name:
Script-PowerShell.Trojan.Heuristic
Status:
Malicious
First seen:
2026-06-09 00:34:25 UTC
File Type:
Text
AV detection:
6 of 36 (16.67%)
Threat level:
  2/5
Verdict:
malicious
Label(s):
unc_rat_008
Similar samples:
Result
Malware family:
n/a
Score:
  7/10
Tags:
execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: PowerShell
Drops startup file
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:APT1_WEBC2_Y21K
Author:AlienVault Labs
Rule name:ClamAV_Emotet_String_Aggregate
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Batch (bat) bat 6df218a5efe3aafc25210e07cc376237ec8224bad9ed4488cc4ec33dc0c07751

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments