🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e67783d0fc3ab50f19708e77f5eb3382442e39ad654a12c3e6ea96bada3b621e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: e67783d0fc3ab50f19708e77f5eb3382442e39ad654a12c3e6ea96bada3b621e
SHA3-384 hash: e7e3ef5cf62c29cfea0e7bd8f5c4e435c79ea75b92bbd560ab80cb5b06ada96be0c85972ce0307a800599284da380f3b
SHA1 hash: 55f3a23b7c7f2021fa1227c3f79c96888e736ae0
MD5 hash: f3810b1ebe5a5e0d9c7e87137521ff0a
humanhash: sad-enemy-ack-rugby
File name:Windows Update.bat
Download: download sample
File size:2'434 bytes
First seen:2025-11-30 12:48:04 UTC
Last seen:Never
File type:Batch (bat) bat
MIME type:text/x-msdos-batch
ssdeep 48:bqRgXD+hBJTPEE08XT4LR0iEbzhU2n44JuNeI9s4GptRz21gNUyH03+uYIW:bGgXD+hBpNKn7KB2SNUyH03HPW
TLSH T12A4166112CB137EA0F0B612E06C5EA225FEE96CB3564DD1CB41A00C46B6F4EB0699A7C
Magika batch
Reporter Anonymous
Tags:bat

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
US US
Vendor Threat Intelligence
Malware configuration found for:
BatchScript
Details
BatchScript
varying reportable information from embedded commands and any observed URLs
Malware family:
n/a
ID:
1
File name:
Windows Update.bat
Verdict:
No threats detected
Analysis date:
2025-11-30 12:49:53 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Suspicious
Maliciousness:

Behaviour
Launching a process
Launching a service
Creating a file in the %AppData% subdirectories
Sending a custom TCP request
Creating a file
Deleting a recently created file
Replacing files
Creating a file in the %temp% directory
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
persistence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-11-30T10:04:00Z UTC
Last seen:
2025-12-01T10:51:00Z UTC
Hits:
~10
Detections:
Trojan-PSW.Win32.Stealer.sb Trojan-PSW.Win32.Greedy.sb HEUR:Trojan-PSW.BAT.Stealer.gen
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2025-11-30 12:48:13 UTC
File Type:
Text (Batch)
AV detection:
5 of 24 (20.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
credential_access discovery spyware stealer
Behaviour
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Browser Information Discovery
Credentials from Password Stores: Windows Credential Manager
Drops startup file
Reads user/profile data of web browsers
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments