🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dd1144b76e60dfb5a6dbff70f3435ef3cfc0ef2a82dfe1aeb30d843baf2c0c4b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 11


Intelligence 11 IOCs YARA File information Comments

SHA256 hash: dd1144b76e60dfb5a6dbff70f3435ef3cfc0ef2a82dfe1aeb30d843baf2c0c4b
SHA3-384 hash: 80496fb4c155b31780d96f30bd1d75146f25b1ec4464a1541319c20205df201d6f52d369ff3b9168a350ba12fb77db3e
SHA1 hash: 5c4c1b5d07f98508b118b96585ee53b0ff0c0b32
MD5 hash: 5d3eb94e6e62c60eb176fa0f7ed76646
humanhash: hawaii-violet-table-sierra
File name:infant.bat
Download: download sample
File size:8'568 bytes
First seen:2026-03-06 11:33:44 UTC
Last seen:Never
File type:Batch (bat) bat
MIME type:text/x-msdos-batch
ssdeep 192:kP2S2R4FFG7NfwdEIoCNL4/TpnxXsYXOkj7l:UrMNAzAHsYekj7l
TLSH T145023CF3030A3F5877B8036BF9C9A838B69AD87B2314D4AC19719D4DD11691FEE65A03
Magika batch
Reporter JAMESWT_WT
Tags:94-158-245-153 bat ink-approval-com

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
IT IT
Vendor Threat Intelligence
Malware configuration found for:
BatchScript
Details
Malware family:
n/a
ID:
1
File name:
infant.bat
Verdict:
Suspicious activity
Analysis date:
2025-10-24 00:00:49 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
70.0%
Tags:
virus
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
lolbin powershell reg schtasks
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan.BAT.Obfus.gen
Threat name:
Text.Trojan.Generic
Status:
Suspicious
First seen:
2025-10-24 03:03:08 UTC
File Type:
Text (Batch)
AV detection:
5 of 24 (20.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
execution persistence
Behaviour
Modifies registry key
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Command and Scripting Interpreter: PowerShell
Registers new Windows logon scripts automatically executed at logon.
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments