🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c2c78096de99d7d3c088aaaa8b51db754a2e3ca76b3464498158d94c047da8d5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ConnectWise


Vendor detections: 9


Intelligence 9 IOCs YARA 6 File information Comments

SHA256 hash: c2c78096de99d7d3c088aaaa8b51db754a2e3ca76b3464498158d94c047da8d5
SHA3-384 hash: b01790c8d52e726bc6ff01c048afbaa7fa6b8959bb01722288f373c9d49a6e657adab27fbfd722ffffd5546db454abfc
SHA1 hash: 42618f6455c5fde970688e8c6be73e7f953d1a46
MD5 hash: 8951771c650faf9e2e9f66cb7e88478c
humanhash: friend-eighteen-mississippi-fix
File name:c2c78096de99d7d3c088aaaa8b51db754a2e3ca76b3464498158d94c047da8d5.bin
Download: download sample
Signature ConnectWise
File size:11'339'843 bytes
First seen:2026-09-18 14:15:16 UTC
Last seen:Never
File type:Batch (bat) bat
MIME type:text/x-msdos-batch
ssdeep 49152:92lsUEuvgrbdvM7iGQ1pHf1B5WcR9hy02Rtij7BAbOs9ngYwmXgXELOPokWbuXVG:o
TLSH T187B62338895E3BDE0501A1FAB726B8893DDD23C74C42135783ACC6A131F94B49E67CB6
Magika batch
Reporter whack_sh
Tags:bat ConnectWise

Intelligence


File Origin
# of uploads :
1
# of downloads :
17
Origin country :
US US
Vendor Threat Intelligence
Malware configuration found for:
BatchScript
Details
Result
Verdict:
Malware
Maliciousness:

Behaviour
Launching a process
Creating a file in the %temp% directory
Creating a process from a recently created file
Creating a window
Сreating synchronization primitives
DNS request
Connection attempt
Sending a custom TCP request
Modifying a system file
Sending an HTTP GET request
Loading a suspicious library
Creating a file in the Windows subdirectories
Deleting a recently created file
Creating a file
Creating a file in the Program Files subdirectories
Creating a service
Launching a service
Searching for synchronization primitives
Moving a file to the Windows subdirectory
Possible injection to a system process
Enabling autorun with the shell\open\command registry branches
Enabling autorun
Enabling autorun for a service
Unauthorized injection to a recently created process
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
anti-vm base64 dropper masquerade obfuscated powershell
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-09-18T09:40:00Z UTC
Last seen:
2026-09-18T11:47:00Z UTC
Hits:
~10
Result
Threat name:
ScreenConnect Tool
Detection:
malicious
Classification:
evad
Score:
100 / 100
Signature
Bypasses PowerShell execution policy
Changes security center settings (notifications, updates, antivirus, firewall)
Contains functionality to hide user accounts
Creates files in the system32 config directory
Creates HTA files
Detected unpacking (creates a PE file in dynamic memory)
Enables network access during safeboot for specific services
Found large BAT file
Found suspicious powershell code related to unpacking or dynamic code loading
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Modifies security policies related information
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Powershell drops PE file
Reads the Security eventlog
Reads the System eventlog
Sigma detected: Base64 Encoded PowerShell Command Detected
Sigma detected: PowerShell Base64 Encoded FromBase64String Cmdlet
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious Script Execution From Temp Folder
Suspicious powershell command line found
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1974943 Sample: M1xvap1kYd.bat Startdate: 18/09/2026 Architecture: WINDOWS Score: 100 118 eip-terr-na.cdp1.digicert.com.akahost.net 2->118 120 companieslogo.com 2->120 122 churchoflife.io 2->122 124 Malicious sample detected (through community Yara rule) 2->124 126 Multi AV Scanner detection for submitted file 2->126 128 Detected unpacking (creates a PE file in dynamic memory) 2->128 130 6 other signatures 2->130 10 msiexec.exe 156 151 2->10         started        14 cmd.exe 1 2->14         started        16 ScreenConnect.ClientService.exe 2->16         started        19 11 other processes 2->19 signatures3 process4 dnsIp5 88 C:\Windows\Installer\MSIF1C.tmp, PE32 10->88 dropped 90 C:\Windows\Installer\MSID985.tmp, PE32+ 10->90 dropped 92 C:\Windows\Installer\MSICF91.tmp, PE32 10->92 dropped 94 38 other files (36 malicious) 10->94 dropped 146 Enables network access during safeboot for specific services 10->146 148 Modifies security policies related information 10->148 21 msiexec.exe 10->21         started        23 msiexec.exe 10->23         started        35 6 other processes 10->35 150 Suspicious powershell command line found 14->150 152 Bypasses PowerShell execution policy 14->152 25 FeedbackTool_6.exe 13 14->25         started        29 powershell.exe 12 14->29         started        31 conhost.exe 14->31         started        112 churchoflife.io 155.254.99.109, 49712, 8041 HYONIX-HyonixSG United States 16->112 154 Reads the Security eventlog 16->154 156 Reads the System eventlog 16->156 37 2 other processes 16->37 114 127.0.0.1 unknown unknown 19->114 158 Changes security center settings (notifications, updates, antivirus, firewall) 19->158 33 drvinst.exe 19->33         started        39 2 other processes 19->39 file6 signatures7 process8 file9 41 rundll32.exe 11 21->41         started        45 rundll32.exe 23->45         started        64 C:\...\DocusignPrintDriver3.6.3.xps.x64_3.exe, PE32 25->64 dropped 66 C:\Users\user\AppData\Local\...\progress.hta, HTML 25->66 dropped 132 Multi AV Scanner detection for dropped file 25->132 134 Creates HTA files 25->134 47 DocusignPrintDriver3.6.3.xps.x64_3.exe 25->47         started        49 mshta.exe 21 25->49         started        52 msiexec.exe 25->52         started        68 C:\Users\user\AppData\...\FeedbackTool_6.exe, PE32 29->68 dropped 136 Found suspicious powershell code related to unpacking or dynamic code loading 29->136 138 Powershell drops PE file 29->138 70 C:\Windows\System32\...\SETDBCF.tmp, PE32+ 33->70 dropped 72 DocuSignPrintDrive...erFilter.dll (copy), PE32+ 33->72 dropped 54 rundll32.exe 33->54         started        140 Contains functionality to hide user accounts 37->140 56 conhost.exe 39->56         started        signatures10 process11 dnsIp12 74 C:\Windows\...\ScreenConnect.Windows.dll, PE32 41->74 dropped 76 C:\...\ScreenConnect.InstallerActions.dll, PE32 41->76 dropped 78 C:\Windows\...\ScreenConnect.Core.dll, PE32 41->78 dropped 86 4 other malicious files 41->86 dropped 142 Contains functionality to hide user accounts 41->142 80 Microsoft.Deployme...indowsInstaller.dll, PE32 45->80 dropped 82 C:\...\DocuSign.Installer.CustomActions.dll, PE32+ 45->82 dropped 84 C:\...\DocusignPrintDriver3.6.3.xps.x64_3.exe, PE32 47->84 dropped 58 DocusignPrintDriver3.6.3.xps.x64_3.exe 47->58         started        116 companieslogo.com 104.26.8.218, 443, 49710 CLOUDFLARENET-CloudflareIncUS Canada 49->116 144 Creates files in the system32 config directory 54->144 file13 signatures14 process15 file16 96 C:\Windows\...\Docusign Print Driver x64.exe, PE32 58->96 dropped 98 DocuSign.Bootstrap...ation.resources.dll, PE32 58->98 dropped 100 DocuSign.Bootstrap...ation.resources.dll, PE32 58->100 dropped 102 14 other malicious files 58->102 dropped 61 Docusign Print Driver x64.exe 58->61         started        process17 file18 104 C:\Users\user\AppData\Local\...\MSIB336.tmp, PE32 61->104 dropped 106 C:\Users\user\AppData\Local\...\MSI8D0F.tmp, PE32 61->106 dropped 108 C:\Users\user\AppData\Local\...\MSI803D.tmp, PE32+ 61->108 dropped 110 C:\...\Docusign Print Driver x64.exe, PE32 61->110 dropped
Result
Malware family:
n/a
Score:
  8/10
Tags:
adware backdoor defense_evasion discovery execution persistence privilege_escalation ransomware rat revoked_codesign spyware trojan
Behaviour
Uses Volume Shadow Copy service COM API
Uses Task Scheduler COM API
Suspicious use of WriteProcessMemory
Suspicious use of SetWindowsHookEx
Suspicious use of FindShellTrayWindow
Suspicious use of AdjustPrivilegeToken
Suspicious behavior: EnumeratesProcesses
Runs net.exe
Modifies system certificate store
Modifies registry class
Modifies data under HKEY_USERS
Modifies Internet Explorer settings
Checks processor information in registry
Checks SCSI registry key(s)
System Location Discovery: System Language Discovery
Executes a command shell one-liner
Enumerates physical storage devices
Drops file in Windows directory
Drops file in Program Files directory
Drops file in System32 directory
Boot or Logon Autostart Execution: Authentication Package
Enumerates connected drives
Command and Scripting Interpreter: PowerShell
Checks installed software on the system
Adds Run key to start application
Loads dropped DLL
Executes dropped EXE
Event Triggered Execution: Component Object Model Hijacking
ConnectWise ScreenConnect remote access tool
Checks computer location settings
Signed with revoked ConnectWise certificate
Sets service image path in registry
Manipulates Digital Signatures
Boot or Logon Autostart Execution: Port Monitors
Badlisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:telebot_framework
Author:vietdx.mb
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques
Rule name:Warp
Author:Seth Hardy
Description:Warp
Rule name:WarpStrings
Author:Seth Hardy
Description:Warp Identifying Strings

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ConnectWise

Batch (bat) bat c2c78096de99d7d3c088aaaa8b51db754a2e3ca76b3464498158d94c047da8d5

(this sample)

  
Delivery method
Distributed via web download

Comments