Open-source atomic malware analysis

Analyze another

d0947eae56860259ab301c62cfdcd0f8c77a59edadd82880b7fd743cf95a8e7a.bat

BATCH
Verdict: HOSTILE
Mal-ecule
O(As₂)H(Po)Md
Size 278.0 KB download
First seen 93 days ago
Analyzed 70 days ago

Objectives

suspicious severity, 97% confident.
anti-static/obfuscation/string Batch fragmentation and junk-padding profile
baseline severity, 85% confident.
anti-static/obfuscation/code-metrics Multiple long lines (>1000 chars)
component severity, 95% confident.
command-and-control/dropper/execution Regex component marker
component severity, 90% confident.
command-and-control/dropper/staging PowerShell archive extraction command marker
component severity, 88% confident.
execution/interpreter/script Short ExecutionPolicy bypass flag
component severity, 100% confident.
impact/ransom Start launcher per host

Micro-behaviors

suspicious severity, 82% confident.
process/create Windows start minimized flag

Metadata

notable severity, 90% confident.
encoded-payload Encoded payload detected: base64
baseline severity, 100% confident.
file Batch script extension
component severity, 90% confident.
file/text Very long line

Identity

SHA-256 d0947eae56860259ab301c62cfdcd0f8c77a59edadd82880b7fd743cf95a8e7a
Filename d0947eae56860259ab301c62cfdcd0f8c77a59edadd82880b7fd743cf95a8e7a.bat

Origin

Source harvest

Timeline

First seen 15 May 2026 12:15 UTC
First analyzed 7 Jun 2026 11:31 UTC
Last analyzed 7 Jun 2026 11:31 UTC
Last updated 7 Jun 2026 11:31 UTC

Labeling

Label bad
Label source harvest
Traits version 318d5