s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-fcd8aa174ce96564e96dd65f447dca2612fe942b80f4b59d088bea516ded1a71 high

📛 Threat Title

Unknown: rSH_F26041602.bat

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: bat. Size: 1088783 bytes. Tags: bat. Reporter: fabiodemartin. First seen: 2026-05-14 06:00:07.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 fcd8aa174ce96564e96dd65f447dca2612fe942b80f4b59d088bea516ded1a71 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/fcd8aa174ce96564e96dd65f447dca2612fe942b80f4b59d088bea516ded1a71
1 feed

IOC database

Type
hash_sha256
Value
fcd8aa174ce96564e96dd65f447dca2612fe942b80f4b59d088bea516ded1a71
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/fcd8aa174ce96564e96dd65f447dca2612fe942b80f4b59d088bea516ded1a71

hash_sha1 1e38d2450deee221a1d16eaa11f4aa0068087874 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/1e38d2450deee221a1d16eaa11f4aa0068087874
2 feeds

IOC database

Type
hash_sha1
Value
1e38d2450deee221a1d16eaa11f4aa0068087874
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/1e38d2450deee221a1d16eaa11f4aa0068087874

hash_md5 d80ad8209a97ea825fefdc1cef9a93d4 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/d80ad8209a97ea825fefdc1cef9a93d4
2 feeds

IOC database

Type
hash_md5
Value
d80ad8209a97ea825fefdc1cef9a93d4
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/d80ad8209a97ea825fefdc1cef9a93d4

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: bat. Size: 1088783 bytes. Tags: bat. Reporter: fabiodemartin. First seen: 2026-05-14 06:00:07.

Remediations (10)

  • web:blog.stormitservices.com

    Let's go step-by-step on how to create a PowerShell remediation script in Microsoft Intune to fix non-compliant devices due to Windows Update issues. Step 1: Understand Proactive Remediation In Intune:

  • web:console.sweetspotgov.com

    The document addresses additional questions regarding a Bat Guano Remediation project, clarifying the scope of work and technical specifications. The project is limited to guano removal, cleaning, and disinfection, explicitly excluding bat entry point sealing.

  • web:getvisibility.atlassian.net

    The Forcepoint DLP remediation tool (RRemediate.exe) applies classification tags to files identified in DLP incidents. This executable replaces the previously used remediation .bat script and serves as an Endpoint Remediation script for Forcepoint FSM (Forcepoint Security Manager).

  • web:patchmypc.com

    Clients stuck in unknown ? Use these steps to troubleshoot and validate update state in SCCM.

  • web:scloud.work

    When a proactive remediation script fails to work as expected, it's much faster to test it locally than wait for the next sync from Intune. In this post, I'll show you how I troubleshoot Intune remediation scripts directly on a Windows device. This includes script locations, relevant logs, and registry entries that help verify what […]

  • web:support.microsoft.com

    When will the removal happen? PowerShell 2.0 will be removed in a later release starting in August 2025 for Windows 11, version 24H2 and a September 2025 release for Windows Server 2025. All later releases for Windows 11 and Windows Server 2025 will not include PowerShell 2.0.

  • web:woshub.com

    The Encryption Oracle Remediation policy provides 3 levels of mitigation for the CredSSP vulnerability: Force Updated Clients - the most secure mode, which blocks vulnerable computer connections. If this option is enabled on the RDP host, it will block RDP connections from client computers with a vulnerable version of CredSSP.

  • web:www.dell.com

    The laptop is getting BSOD and from the WinDiag and we found out it is the dell support assist remediation from the dell command update, after we uninstall it that's all good until dell command update push it back into the system because it was marked as critical update.

  • web:www.majorgeeks.com

    Windows Defender may try to remove a virus, trojan, or other malware and return a message stating Remediation incomplete. Remediation incomplete leads one to assume that a virus, trojan or malware was found, but not removed.

  • web:www.reddit.com

    The remediation script below runs DISM, checks/corrects various registry values, checks for update blocks, and finally checks for Windows Updates. I mostly put together different pieces that I've found online, wrote of my own and definitely did not write any of the modules in here.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.