🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d469ed578f2c6cb7523034b80617c8f3cee0cf548079d4499ff0ec6ff35453e0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



BlankGrabber


Vendor detections: 13


Intelligence 13 IOCs YARA 3 File information Comments

SHA256 hash: d469ed578f2c6cb7523034b80617c8f3cee0cf548079d4499ff0ec6ff35453e0
SHA3-384 hash: 66d66fb90efff9150a6ce1e724e4c604713f6935180e4911208f648463a489f0e0d0885761545912870bbcdf0a710ac8
SHA1 hash: 2a0f332352064124a5e251f09aa14951062b94ca
MD5 hash: 801c7fa665d06f2b82b414f0b6f29e05
humanhash: magazine-shade-speaker-wisconsin
File name:SystemUpdate_3180.bat
Download: download sample
Signature BlankGrabber
File size:2'438 bytes
First seen:2025-11-03 21:28:17 UTC
Last seen:2025-11-03 21:28:18 UTC
File type:Batch (bat) bat
MIME type:text/x-msdos-batch
ssdeep 48:P4DY777x/Jw1KnSteiu5gXdm4jE8zkXNfkrrXT63FegnDAtLzutuAtkja:P4D6nSteiu5gXgTXXpknXqdnDeLzIuez
TLSH T175413DBA71D39B2045202C70A87EED5143C5E5DBCFB90907F4E096C29E7A348CFA49E2
Magika batch
Reporter smica83
Tags:bat

Intelligence


File Origin
# of uploads :
2
# of downloads :
83
Origin country :
HU HU
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
SystemUpdate_3180.bat
Verdict:
Malicious activity
Analysis date:
2025-11-03 21:29:48 UTC
Tags:
github blankgrabber anti-evasion stealer auto-startup screenshot evasion discord pyinstaller susp-powershell generic ims-api

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
92.5%
Tags:
autorun dropper shell sage
Result
Verdict:
Malware
Maliciousness:

Behaviour
Launching a process
Creating a file
Running batch commands
Creating a file in the %temp% directory
Creating a window
Сreating synchronization primitives
DNS request
Connection attempt
Sending a custom TCP request
Creating a file in the Windows subdirectories
Creating a process from a recently created file
Creating a process with a hidden window
Reading critical registry keys
Launching the process to change network settings
Loading a suspicious library
Using the Windows Management Instrumentation requests
Searching for synchronization primitives
Stealing user critical data
Launching a file downloaded from the Internet
Adding an exclusion to Microsoft Defender
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
certutil certutil lolbin obfuscated
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-11-03T18:44:00Z UTC
Last seen:
2025-11-03T19:29:00Z UTC
Hits:
~10
Detections:
PDM:Trojan.Win32.Generic Trojan-PSW.Python.Blank.sb Trojan.Win32.Agent.sb Trojan-PSW.MSIL.Stealer.sb Trojan-Spy.Win32.Agent.dffz Trojan-Downloader.PowerShell.Agent.sb Trojan.VBS.Runner.sb HEUR:Trojan-PSW.Python.Blank.gen HEUR:Trojan.BAT.Agent.gen Trojan.Win32.Dizemp.sb Trojan.Win32.Agent.sba Trojan.Python.Agent.gen
Result
Threat name:
Blank Grabber
Detection:
malicious
Classification:
rans.troj.spyw.expl.evad
Score:
100 / 100
Signature
Adds a directory exclusion to Windows Defender
Bypasses PowerShell execution policy
Changes security center settings (notifications, updates, antivirus, firewall)
Encrypted powershell cmdline option found
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Modifies existing user documents (likely ransomware behavior)
Modifies Windows Defender protection settings
Powershell drops PE file
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Removes signatures from Windows Defender
Sigma detected: Capture Wi-Fi password
Sigma detected: Dot net compiler compiles file from suspicious location
Sigma detected: Legitimate Application Dropped Script
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Powershell Defender Disable Scan Feature
Sigma detected: Powershell download and execute file
Sigma detected: PowerShell DownloadFile
Sigma detected: Rar Usage with Password and Compression Level
Sigma detected: Rare Remote Thread Creation By Uncommon Source Image
Sigma detected: Suspicious Encoded PowerShell Command Line
Sigma detected: Suspicious PowerShell Encoded Command Patterns
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: Suspicious Startup Folder Persistence
Suspicious powershell command line found
Tries to download and execute files (via powershell)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal WLAN passwords
Tries to steal Crypto Currency Wallets
Uses netsh to modify the Windows network and firewall settings
Uses WMIC command to query system information (often done to detect virtual machines)
Writes or reads registry keys via WMI
Yara detected Blank Grabber
Yara detected Powershell download and execute
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1807285 Sample: SystemUpdate_3180.bat Startdate: 03/11/2025 Architecture: WINDOWS Score: 100 96 release-assets.githubusercontent.com 2->96 98 ip-api.com 2->98 100 2 other IPs or domains 2->100 110 Sigma detected: Capture Wi-Fi password 2->110 112 Sigma detected: Powershell download and execute file 2->112 114 Yara detected Blank Grabber 2->114 116 13 other signatures 2->116 13 cmd.exe 2 2->13         started        16 svchost.exe 2->16         started        signatures3 process4 dnsIp5 142 Suspicious powershell command line found 13->142 144 Encrypted powershell cmdline option found 13->144 146 Tries to download and execute files (via powershell) 13->146 148 7 other signatures 13->148 19 powershell.exe 14 17 13->19         started        24 certutil.exe 3 2 13->24         started        26 conhost.exe 13->26         started        28 2 other processes 13->28 94 127.0.0.1 unknown unknown 16->94 signatures6 process7 dnsIp8 106 github.com 140.82.112.3, 443, 49692 GITHUBUS United States 19->106 108 release-assets.githubusercontent.com 185.199.111.133, 443, 49693 FASTLYUS Netherlands 19->108 80 C:\Windows\Temp\sysupd.exe, PE32+ 19->80 dropped 126 Powershell drops PE file 19->126 30 sysupd.exe 41 19->30         started        82 C:\Users\user\AppData\Local\Temp\~var_1.bat, DOS 24->82 dropped file9 signatures10 process11 file12 86 C:\Users\user\AppData\Local\Temp\...\rar.exe, PE32+ 30->86 dropped 88 C:\Users\user\AppData\Local\...\rarreg.key, ASCII 30->88 dropped 90 C:\Users\user\AppData\...\unicodedata.pyd, PE32+ 30->90 dropped 92 22 other files (none is malicious) 30->92 dropped 150 Modifies Windows Defender protection settings 30->150 152 Adds a directory exclusion to Windows Defender 30->152 154 Tries to harvest and steal WLAN passwords 30->154 156 2 other signatures 30->156 34 sysupd.exe 1 105 30->34         started        signatures13 process14 dnsIp15 102 ip-api.com 208.95.112.1, 49705, 80 TUT-ASUS United States 34->102 104 discord.com 162.159.135.232, 443, 49706 CLOUDFLARENETUS United States 34->104 118 Tries to harvest and steal browser information (history, passwords, etc) 34->118 120 Modifies Windows Defender protection settings 34->120 122 Adds a directory exclusion to Windows Defender 34->122 124 5 other signatures 34->124 38 cmd.exe 1 34->38         started        41 cmd.exe 1 34->41         started        43 cmd.exe 34->43         started        45 25 other processes 34->45 signatures16 process17 signatures18 128 Modifies Windows Defender protection settings 38->128 130 Removes signatures from Windows Defender 38->130 47 powershell.exe 38->47         started        62 2 other processes 38->62 132 Adds a directory exclusion to Windows Defender 41->132 50 powershell.exe 23 41->50         started        52 conhost.exe 41->52         started        54 powershell.exe 43->54         started        56 conhost.exe 43->56         started        134 Suspicious powershell command line found 45->134 136 Changes security center settings (notifications, updates, antivirus, firewall) 45->136 138 Encrypted powershell cmdline option found 45->138 140 2 other signatures 45->140 58 getmac.exe 45->58         started        60 WMIC.exe 45->60         started        64 47 other processes 45->64 process19 file20 158 Loading BitLocker PowerShell Module 50->158 67 WmiPrvSE.exe 50->67         started        160 Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines) 58->160 162 Writes or reads registry keys via WMI 58->162 164 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 60->164 76 C:\Users\user\AppData\...\dy3wavuc.cmdline, Unicode 64->76 dropped 78 C:\Users\user\AppData\Local\Temp\V7HMn.zip, RAR 64->78 dropped 69 csc.exe 64->69         started        72 conhost.exe 64->72         started        signatures21 process22 file23 84 C:\Users\user\AppData\Local\...\dy3wavuc.dll, PE32 69->84 dropped 74 cvtres.exe 69->74         started        process24
Threat name:
Script-BAT.Trojan.Malgent
Status:
Malicious
First seen:
2025-11-03 16:03:38 UTC
File Type:
Text (Batch)
AV detection:
5 of 38 (13.16%)
Threat level:
  5/5
Result
Malware family:
blankgrabber
Score:
  10/10
Tags:
family:blankgrabber collection credential_access defense_evasion discovery execution persistence privilege_escalation spyware stealer upx
Behaviour
Detects videocard installed
Gathers system information
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Browser Information Discovery
Enumerates physical storage devices
Event Triggered Execution: Netsh Helper DLL
System Network Configuration Discovery: Wi-Fi Discovery
Enumerates processes with tasklist
UPX packed file
Accesses cryptocurrency files/wallets, possible credential harvesting
Deobfuscate/Decode Files or Information
Legitimate hosting services abused for malware hosting/C2
Looks up external IP address via web service
Obfuscated Files or Information: Command Obfuscation
Clipboard Data
Executes dropped EXE
Loads dropped DLL
Reads user/profile data of web browsers
Unsecured Credentials: Credentials In Files
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Disables one or more Microsoft Defender components
Downloads MZ/PE file
A stealer written in Python and packaged with Pyinstaller
Blankgrabber family
blankgrabber
Malware Config
Dropper Extraction:
https://github.com/ertag1-pixel/kdfkjdfkf/releases/download/sdfsdfewewewesdfsder/sysupd.exe
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Base64_Encoded_Powershell_Directives
Rule name:Certutil_Decode_OR_Download
Author:Florian Roth (Nextron Systems)
Description:Certutil Decode
Reference:Internal Research
Rule name:obfuscated_BAT
Author:@warz_s
Description:Identifies obfuscated BAT files
Reference:https://github.com/secwarz/YaraRules

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BlankGrabber

Batch (bat) bat d469ed578f2c6cb7523034b80617c8f3cee0cf548079d4499ff0ec6ff35453e0

(this sample)

Comments