🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9d05854c95c6afa68911bd28af12282185e0fe34f2e58fddbc503ab22d1508d7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



LotusWiper


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 9d05854c95c6afa68911bd28af12282185e0fe34f2e58fddbc503ab22d1508d7
SHA3-384 hash: 44b45593178cdc8229991cf8ff4aa530cd8e0492f1940772119b9cb3fd86f095542bd410d5bb0664c8aeaaea25d12013
SHA1 hash: 6b2bb5287f6c7a217ad3263926603b50fd7f9662
MD5 hash: c6d0f67db6a7dbf1f9394d98c1e13670
humanhash: asparagus-river-vegan-march
File name:9d05854c95c6afa68911bd28af12282185e0fe34f2e58fddbc503ab22d1508d7.bin
Download: download sample
Signature LotusWiper
File size:5'679 bytes
First seen:2026-04-22 12:16:13 UTC
Last seen:Never
File type:Batch (bat) bat
MIME type:text/x-msdos-batch
ssdeep 96:Pcvhwi1QLYsvkPwGiN3xL3XAOg8+9jnO/hWiKrMyz6ab64bA14bF4biGwW/TiSNT:9iCkSkPwfDLV1yvGwW/TiAIfPDc
TLSH T1B6C19E241D4605E64546C95DCB8AB1DF3D65FACFC301EE68F89D64C9AF810CB8E629F0
Magika batch
Reporter KodaDr
Tags:bat LotusWiper Wiper

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
RU RU
Vendor Threat Intelligence
Malware configuration found for:
BatchScript
Details
Malware family:
n/a
ID:
1
File name:
lotus.zip
Verdict:
Malicious activity
Analysis date:
2026-01-10 03:31:21 UTC
Tags:
arch-exec psexec

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Launching cmd.exe command interpreter
Running batch commands
Launching the process to interact with network services
Launching a process
Launching many processes
Searching for synchronization primitives
Creating a file
Windows shutdown
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-14T19:20:00Z UTC
Last seen:
2026-04-23T21:15:00Z UTC
Hits:
~10
Gathering data
Threat name:
Script-BAT.Trojan.Wiper
Status:
Malicious
First seen:
2025-12-15 00:04:39 UTC
File Type:
Text (Batch)
AV detection:
10 of 37 (27.03%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments