MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d9fc385e5b0754b45923042e167cd4ff5d495678596cef74aecfd3ad8c237882. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: d9fc385e5b0754b45923042e167cd4ff5d495678596cef74aecfd3ad8c237882
SHA3-384 hash: 5d0f84528e0c271f45c52348fd3f4f275d0e286bec0e860f7276c0a39216c0080391505b69dbea689e3cad68f21ca40d
SHA1 hash: 8d698921d0b60444ff79c34a5d48f0eaf822a5b6
MD5 hash: ad240ca5aa03cc8d0969fc4416d001e5
humanhash: zulu-bakerloo-mountain-florida
File name:ad240ca5aa03cc8d0969fc4416d001e5.bat
Download: download sample
File size:556'519 bytes
First seen:2025-02-11 07:20:55 UTC
Last seen:Never
File type:Batch (bat) bat
MIME type:text/x-msdos-batch
ssdeep 12288:BTFhw7YqYXf3P4CJgAdS5jKkGWFKbqqp/oo/:tfJ7XvDgAs/Gtl/
TLSH T1C7C4D0624AD0A7F1FD7A314E39B2B465548DA568F42C6F8139014BBF9CE99284D2CCCF
Magika txt
Reporter abuse_ch
Tags:bat

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
NL NL
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
http://45.88.186.152:55553/folder/Bitvice.bat
Verdict:
Malicious activity
Analysis date:
2025-02-10 17:04:57 UTC
Tags:
opendir loader evasion xworm rat remote fody

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
97.4%
Tags:
shell virus sage
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
obfuscated
Result
Threat name:
n/a
Detection:
malicious
Classification:
expl.evad
Score:
100 / 100
Signature
.NET source code contains a sample name check
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
.NET source code contains very large array initializations
.NET source code references suspicious native API functions
Adds a directory exclusion to Windows Defender
Bypasses PowerShell execution policy
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Multi AV Scanner detection for submitted file
Sigma detected: HackTool - CrackMapExec PowerShell Obfuscation
Sigma detected: Potential PowerShell Obfuscation Via Reversed Commands
Sigma detected: Potentially Suspicious PowerShell Child Processes
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Powerup Write Hijack DLL
Sigma detected: Suspicious PowerShell Parameter Substring
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Wscript starts Powershell (via cmd or directly)
Yara detected Costura Assembly Loader
Yara detected Powershell decode and execute
Yara detected Powershell decrypt and execute
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1611845 Sample: sZJOgGfDbO.bat Startdate: 11/02/2025 Architecture: WINDOWS Score: 100 68 18.31.95.13.in-addr.arpa 2->68 80 Multi AV Scanner detection for submitted file 2->80 82 Yara detected Powershell decrypt and execute 2->82 84 Yara detected Powershell decode and execute 2->84 86 14 other signatures 2->86 12 cmd.exe 1 2->12         started        15 wscript.exe 2->15         started        signatures3 process4 signatures5 94 Suspicious powershell command line found 12->94 96 Wscript starts Powershell (via cmd or directly) 12->96 98 Bypasses PowerShell execution policy 12->98 17 powershell.exe 3 21 12->17         started        21 conhost.exe 12->21         started        100 Windows Scripting host queries suspicious COM object (likely to drop second stage) 15->100 102 Suspicious execution chain found 15->102 23 conhost.exe 15->23         started        process6 file7 64 C:\Users\user\AppData\...\bppfjqx53yl4.vbs, ASCII 17->64 dropped 66 C:\Users\user\AppData\...\bppfjqx53yl4.bat, DOS 17->66 dropped 72 Suspicious powershell command line found 17->72 74 Adds a directory exclusion to Windows Defender 17->74 25 wscript.exe 17->25         started        28 powershell.exe 37 17->28         started        30 powershell.exe 23 17->30         started        32 2 other processes 17->32 signatures8 process9 signatures10 90 Wscript starts Powershell (via cmd or directly) 25->90 34 cmd.exe 25->34         started        92 Loading BitLocker PowerShell Module 28->92 37 conhost.exe 28->37         started        39 conhost.exe 30->39         started        41 conhost.exe 32->41         started        43 conhost.exe 32->43         started        process11 signatures12 76 Suspicious powershell command line found 34->76 78 Wscript starts Powershell (via cmd or directly) 34->78 45 powershell.exe 34->45         started        49 conhost.exe 34->49         started        process13 dnsIp14 70 45.88.186.152, 53, 62792, 62894 ANONYMIZEEpikNetworkCH Netherlands 45->70 104 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 45->104 106 Adds a directory exclusion to Windows Defender 45->106 51 powershell.exe 45->51         started        54 powershell.exe 45->54         started        56 ReAgentc.exe 45->56         started        signatures15 process16 signatures17 88 Loading BitLocker PowerShell Module 51->88 58 conhost.exe 51->58         started        60 conhost.exe 54->60         started        62 conhost.exe 56->62         started        process18
Threat name:
Script-BAT.Trojan.Heuristic
Status:
Malicious
First seen:
2025-02-10 17:47:51 UTC
File Type:
Text (PowerShell)
AV detection:
5 of 24 (20.83%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
System Network Configuration Discovery: Internet Connection Discovery
Drops file in Windows directory
Drops file in System32 directory
Unexpected DNS network traffic destination
Blocklisted process makes network request
Command and Scripting Interpreter: PowerShell
Downloads MZ/PE file
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Batch (bat) bat d9fc385e5b0754b45923042e167cd4ff5d495678596cef74aecfd3ad8c237882

(this sample)

  
Delivery method
Distributed via web download

Comments