MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f1fd75c04548bb1db08a7a628130de2366e0828bc5aea714143e5ca1245d1426. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: f1fd75c04548bb1db08a7a628130de2366e0828bc5aea714143e5ca1245d1426
SHA3-384 hash: fa72be8fe5190aec0d8477db4ab200674252117051a52365f941291ddce9c1b1e222f4dcc71dfc3e35146e7281ad3f40
SHA1 hash: a6a5880dff4bfef1902424d2ff7db96a89224449
MD5 hash: 8b8ff942a44319c67f83c385dfb33942
humanhash: batman-jupiter-grey-nineteen
File name:menu.bat
Download: download sample
File size:1'358 bytes
First seen:2026-07-20 07:05:09 UTC
Last seen:Never
File type:Batch (bat) bat
MIME type:text/x-msdos-batch
ssdeep 24:2sUL15o0AOzBvnjs3RVt1A2zgJA2zVygA2zUt1APFVAlTyAeEt1A/HAlrWA1dmv:2VLYOzBfjsBVtzzMzVygzUt7TKEtXr7y
TLSH T17A218ECB715E168378B54594DF9D20C03535C1C7062729AFB2770A20B5EAFC8BE4A3A7
Magika batch
Reporter JAMESWT_WT
Tags:47-243-127-162 bat

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
IT IT
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
SPAM.zip
Verdict:
Malicious activity
Analysis date:
2026-07-20 06:58:04 UTC
Tags:
arch-exec powershell uac-bypass

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
cmd evasive fingerprint lolbin net netsh powershell rundll32
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-07-06T20:55:00Z UTC
Last seen:
2026-07-20T09:52:00Z UTC
Hits:
~10
Threat name:
Text.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-05 04:46:55 UTC
File Type:
Text (Batch)
AV detection:
5 of 24 (20.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments