MB-bff96189e03c5c8f59e5932054c76c39423b290b11682603628ff696342e2ac3
high
📛 Threat Title
Unknown: rADVPAYMNT_34ef.bat
Description
File type: bat. Size: 163252 bytes. Tags: bat. Reporter: fabiodemartin. First seen: 2026-05-14 07:30:07.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
bff96189e03c5c8f59e5932054c76c39423b290b11682603628ff696342e2ac3
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/bff96189e03c5c8f59e5932054c76c39423b290b11682603628ff696342e2ac3
1 feed
IOC database
- Type
- hash_sha256
- Value
bff96189e03c5c8f59e5932054c76c39423b290b11682603628ff696342e2ac3- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Unknown
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/bff96189e03c5c8f59e5932054c76c39423b290b11682603628ff696342e2ac3
hash_sha1
23e6cbef658f140dd260d7e994c15a0c9ece5411
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/23e6cbef658f140dd260d7e994c15a0c9ece5411
2 feeds
IOC database
- Type
- hash_sha1
- Value
23e6cbef658f140dd260d7e994c15a0c9ece5411- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/23e6cbef658f140dd260d7e994c15a0c9ece5411
hash_md5
a919c672635f9bbc4a30e67c87e07dda
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/a919c672635f9bbc4a30e67c87e07dda
2 feeds
IOC database
- Type
- hash_md5
- Value
a919c672635f9bbc4a30e67c87e07dda- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/a919c672635f9bbc4a30e67c87e07dda
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: bat. Size: 163252 bytes. Tags: bat. Reporter: fabiodemartin. First seen: 2026-05-14 07:30:07.
Remediations (10)
-
web:community.broadcom.com
Hello, i am new to our environment and have a quick question. I am seeing a blue ? on all host and it states. Remediation status unknown (never checked) what does this mean? when i click on remediation Pre-check i see the following.
-
web:community.spiceworks.com
This is for the remediation status column. I can't find anything on the interwebs about this. I know the scripts should work b/c I used other scripts that worked and only changed the registry key and value within each script, and the scripts are UTF-8. Detection status of course shows 'With issues' b/c the registry key value is wrong, the remediation script sets to correct value. DETECT ...
-
web:github.com
The Intune Remediations collection is a set of script packages designed to detect and fix common support issues on user endpoints. Each script package includes a detection script, a remediation script, and metadata. By deploying these packages through Intune, you can proactively address issues before end-users even notice them, potentially reducing support calls.
-
web:github.com
Script to make changes on registry to fix CVE-2013-3900. It comes with an option to undo in case it breaks something on your environment. - CVE-2013-3900_Remediation_PowerShell/tool.ps1 at main · piranhap/CVE-2013-3900_Remediation_PowerShell
-
web:learn.microsoft.com
The most common cause is a detected threat in a downloaded file, but it can also be an installed program. Click on the Windows Security icon in the system tray. Click on Virus & threat protection > Protection history to see the Remediation incomplete detection and location of the file.
-
web:learn.microsoft.com
Learn more about Remediations in Microsoft Intune, including what Remediations are and view any prerequisites and licensing requirements. Also, learn how to deploy built-in and custom remediation scripts, and learn how to monitor your scripts.
-
web:scloud.work
When a proactive remediation script fails to work as expected, it's much faster to test it locally than wait for the next sync from Intune. In this post, I'll show you how I troubleshoot Intune remediation scripts directly on a Windows device. This includes script locations, relevant logs, and registry entries that help verify what […]
-
web:windowsforum.com
Alright, Windows fans and warriors, grab your coffee—or your cyber-awareness cap—because it's time to dissect a particularly intriguing vulnerability story. Today we're diving into CVE-2013-3900, a vulnerability that concerns the WinVerifyTrust function in Windows. Let's dissect the issue, clarify the technical fixes, and explore how it impacts you and your system security.
-
web:www.reddit.com
The remediation script below runs DISM, checks/corrects various registry values, checks for update blocks, and finally checks for Windows Updates. I mostly put together different pieces that I've found online, wrote of my own and definitely did not write any of the modules in here.
-
web:www.reddit.com
If you don't have the in house staff to perform the threat analysis or threat hunting, you need a SOC. You could look at black point cyber since your are a PAX 8 customer. You currently have the detection portion of EDR, but not the analysis and remediation piece. You can't compare Symantec to Sentinel One, they aren't the same. Sentinel One IMO, is a far superior product, and in the years we ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.