🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 aed14a29a45cec329420ea8d570aca068fa8a64fd5c6c64d582af3b2858b34fc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: aed14a29a45cec329420ea8d570aca068fa8a64fd5c6c64d582af3b2858b34fc
SHA3-384 hash: 99ca7aff4e92bfb6b0548405b46728fd6fec278502d073e7aca54a83979edc291eb36ecd9bbac691b5b44dfa98a51687
SHA1 hash: bac6d6a4792ecb2860440f179d18e6fc80d0d095
MD5 hash: 1c0caeed9b5e86a4b07a9664f807c139
humanhash: edward-fanta-green-william
File name:Contracts.bat
Download: download sample
File size:591 bytes
First seen:2026-05-20 18:05:51 UTC
Last seen:Never
File type:Batch (bat) bat
MIME type:text/x-msdos-batch
ssdeep 12:i7X7HzApbfNJknpeBS81HoCJIQHL/CvjFxJT280RwKNcvhLV:i7+qJGra3owycJV
TLSH T1CEF0AC51340612E41A2DC4D8561A295BF68D62CFB24EDDB8B152D2F25F762EFCCE8CC2
Magika batch
Reporter TomU
Tags:bat

Intelligence


File Origin
# of uploads :
1
# of downloads :
34
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
bat
Verdict:
Malicious activity
Analysis date:
2026-05-21 03:29:13 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
92.5%
Tags:
shell sage hype
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a file in the Windows subdirectories
Creating a process from a recently created file
Launching a process
Creating a file
Creating a window
DNS request
Connecting to a non-recommended domain
Connection attempt
Sending an HTTP GET request
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
evasive lolbin timeout wscript
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-05-12T23:27:00Z UTC
Last seen:
2026-05-21T18:38:00Z UTC
Hits:
~10000
Threat name:
Script-BAT.Trojan.Heuristic
Status:
Malicious
First seen:
2025-05-13 02:21:42 UTC
File Type:
Text (Batch)
AV detection:
13 of 36 (36.11%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
defense_evasion
Behaviour
Delays execution with timeout.exe
Script User-Agent
Suspicious use of WriteProcessMemory
Badlisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Batch (bat) bat aed14a29a45cec329420ea8d570aca068fa8a64fd5c6c64d582af3b2858b34fc

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments