Classification: Malicious
register.cmd is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02. Detected by 1 antivirus engines.
Detection summary
- 1 antivirus detections
- 0 IDS alerts
- 16 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Suspicious Sample |
Triage |
2026-09-02 15:13:39 |
2026-09-02 15:13:39 |
anomalous-activity
|
|
| Generic Malware |
Triage |
2026-02-22 06:18:52 |
2026-05-08 19:06:55 |
malicious-activity
|
|
| Generic Malware |
Hybrid-Analysis |
2024-03-16 18:29:58 |
2024-07-23 14:35:39 |
|
|
Tags
defense_evasion
persistence
ransomware
adware
spyware
execution
Sample information
- Filenames
- register.cmd
- File type
- DOS batch file, ASCII text, with very long lines, ...
- Size
- 1081 bytes
- MD5
69d7c77da0c817b911e7fcbfeb1dd271
- SHA-1
1db8578ea39bb51aaca5d545d0f2f8524c52e8f0
- SHA-256
a171d3ae6b224d7c2ab8b778aa66311e2a91c91540dab6606623b36c02f548ca
- SHA-512
99909932af6298a916aeceb35d9f3938bb4fd1e942725564149324af8d1b241799415c52c2fa74bc44820fc845d631b89cfc92e02df29b9e7d1fce5832389050
- First indexed
- 2024-03-16 18:15:38
- Last updated
- 2026-09-02 15:59:00
Antivirus detections
| Engine | Detection |
| Sangfor | Trojan.Win32-Script.Save.76941d43 |
Process list
| Name | Command line |
| cmd.exe | /c ""C:\register.cmd" " |
| mode.com | mode CON COLS=37 LINES=3 |
| fsutil.exe | fsutil dirty query C: |
| fsutil.exe | fsutil dirty query C: |
| regsvr32.exe | regsvr32 "C:\ExplorerBlurMica.dll" |
| taskkill.exe | taskkill /F /IM explorer.exe |
| explorer.exe | |
| timeout.exe | timeout /t 5 |
| cmd.exe | /c ""C:\register.cmd" " |
| mode.com | mode CON COLS=37 LINES=3 |
| fsutil.exe | fsutil dirty query C: |
| fsutil.exe | fsutil dirty query C: |
| regsvr32.exe | regsvr32 "C:\ExplorerBlurMica.dll" |
| taskkill.exe | taskkill /F /IM explorer.exe |
| explorer.exe | |
| timeout.exe | timeout /t 5 |