s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

VT-2c32e46a570f8b87609f6a2073bc9cde87cd6934e0262511dddfdd72bb7cc875 medium

📛 Threat Title

File hash (SHA256): 2c32e46a570f8b87609f6a2073bc9cde87cd6934e0262511dddfdd72bb7cc875

Category: malware-hash Published: Source updated: First seen: Last updated:

Description

Hash IOC ingested from threat-intel feed 'Abuse.ch'. See VirusTotal for vendor verdicts, file metadata, sandbox behaviour, and relationships (contacted IPs / domains / URLs, dropped files, etc.). Feed description: SHA256 hashes: Recent additions

Indicators of Compromise (2)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain abuse.ch VT 0 / 91 UrlVoid 1 / 35

IOC database

Type
domain
Value
abuse.ch
First seen
Last seen
Attached to this threat
Appears in
4019 threats
Description
Extracted from Threat VT-0bc58e58275d6ecca05335aac681a0352173e19d8718230c1902c2bf99d8782f

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

Basic Properties
TLDch
History
Last analysis2026-05-24 09:28 UTC
Last modified on VirusTotal2026-05-24 16:38 UTC
WHOIS record date2026-03-29 11:09 UTC
hash_sha256 2c32e46a570f8b87609f6a2073bc9cde87cd6934e0262511dddfdd72bb7cc875 VT 34 / 75 1 feed

IOC database

Type
hash_sha256
Value
2c32e46a570f8b87609f6a2073bc9cde87cd6934e0262511dddfdd72bb7cc875
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Flagged by 34 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious Trojan:Win/Obfuscated.AV
ALYac malicious Trojan.Generic.39962992
Antiy-AVL malicious Trojan/BAT.Obfus
Arcabit malicious Trojan.Generic.D261C970
Avast malicious Other:Malware-gen [Trj]
AVG malicious Other:Malware-gen [Trj]
Avira malicious TR/Malware
BitDefender malicious Trojan.Generic.39962992
CAT-QuickHeal malicious Script.Trojan.A25536251
CTX malicious txt.trojan.obfus
Cynet malicious Malicious (score: 99)
DrWeb malicious BAT.Starter.741
Emsisoft malicious Trojan.Generic.39962992 (B)
ESET-NOD32 malicious BAT/Obfuscated.AR trojan
F-Secure malicious Trojan.TR/Malware
Fortinet malicious BAT/Formbook.AA!tr
GData malicious Trojan.Generic.39962992
Google malicious Detected
Ikarus malicious Trojan.Batch
Kaspersky malicious HEUR:Trojan.BAT.Obfus.gen
Lionic malicious Trojan.Script.Obfus.4!c
McAfeeD malicious Trojan:Script/BatLoader.AS
Microsoft malicious Trojan:BAT/XWorm.PV!MTB
MicroWorld-eScan malicious Trojan.Generic.39962992
Rising malicious Trojan.Obfuscated/BAT!9.708FB (XSE:WFNFX0JBVDrM+UdKZyi6qHAn58mmpfFG)
Symantec malicious CL.Downloader!gen55
Tencent malicious Bat.Trojan.Obfus.Twhl
TrendMicro malicious Trojan.BAT.BATLOADER.D
TrendMicro-HouseCall malicious Trojan.BAT.BATLOADER.D
Varist malicious BAT/Agent.BPS
VIPRE malicious Trojan.Generic.39962992
VirIT malicious Trojan.BAT.Agent.JQP
Xcitium malicious Malware@#3lbvf91bir2x7
Yandex malicious Trojan.Etecer.b6xc1Y.3

Details From VirusTotal

Basic Properties
MD5fa487e78d5bf33bca1a4dde6c42758db
SHA-1b26bd746b74422dfedc48b242c5d972badc5c8ec
SHA-2562c32e46a570f8b87609f6a2073bc9cde87cd6934e0262511dddfdd72bb7cc875
SSDEEP12288:/RNb2aioEq5JAWbOiWnXMCOCZeLdD5FHqJ6nH6HXm:3b2SEubO/MCOel8Hq2
TLSHT1299423E61ACA448941F44167DB56A412B749D2FBEB3DF445A1EF008F0039BDFFB9181A
File typeDOS batch file
File type tagbat
File extensionbat
MagicDOS batch file, ASCII text, with very long lines (41335u), with CRLF line terminators
File size422.7 KB
History
First seen on VirusTotal2026-05-15 08:45 UTC
Last submission2026-05-15 08:48 UTC
Last analysis2026-05-20 14:58 UTC
Last modified on VirusTotal2026-05-20 16:59 UTC
Known Names
  • 2c32e46a570f8b87609f6a2073bc9cde87cd6934e0262511dddfdd72bb7cc875.bat
  • PI-INQ-3001 & 3002.bat
  • _2c32e46a570f8b87609f6a2073bc9cde87cd6934e0262511dddfdd72bb7cc875.txt

References (1)

  • VirusTotal report

    Vendor verdicts, file metadata, sandbox behaviour, and relationships (contacted IPs / domains / URLs, execution parents, dropped files).

Remediations (10)

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.