Classification: Malicious
Startupppppppppp.bat is a malicious file sample. Linked to Koadic malware. Reported by 2 threat sources, last seen 2025-10-13.
Detection summary
- 6 antivirus detections
- 0 IDS alerts
- 5 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Koadic |
MalwareBazaar Abuse.ch |
2025-10-13 07:00:44 |
2025-10-13 07:00:44 |
malicious-activity
|
S0250 Koadic
|
| Generic Malware |
Hybrid-Analysis |
2025-09-04 02:00:04 |
2025-09-04 03:45:14 |
|
|
Sample information
- Filenames
- Startupppppppppp.bat, Startupppppp.bat
- File type
- Unicode text, UTF-16, little-endian text, with ver ...
- Size
- 20007 bytes
- MD5
63c739127ec52d2235a66ff44d47f432
- SHA-1
27ebd898b6e67c7b9ddce96f40f812288046b3a8
- SHA-256
ce3e4ee359acdc3c95f1264864faaa199facbeac03ed393a6c3c51ce75541d9d
- First indexed
- 2025-09-04 01:48:09
- Last updated
- 2026-04-13 05:16:22
Antivirus detections
| Engine | Detection |
| AVG | Other:Malware-gen [Trj] |
| Avast | Other:Malware-gen [Trj] |
| GData | BAT.Malware.InvalidBOM.A |
| Kaspersky | HEUR:Trojan.BAT.Generic |
| TrendMicro | Trojan.BAT.BATFUSCATOR.SMTH |
| TrendMicro-HouseCall | Trojan.BAT.BATFUSCATOR.SMTH |
Process list
| Name | Command line |
| cmd.exe | /c ""C:\Startupppppp.bat" " |
| powershell.exe | powershell -WindowStyle Hidden -Command "Start-Process -FilePath 'C:\Startupppppp.bat' -ArgumentList 'hidden' -WindowStyle Hidden" |
| cmd.exe | /c ""C:\Startupppppp.bat" hidden " |
| python.exe | putty.py |
| python.exe | work.py |