Is install.bat safe?
No antivirus engine detected the long-established batch installer, while its completed sandbox run showed no offensive behavior, malicious contacts, persistence, or dropped payloads.
None of 74 antivirus engines flagged this 139-byte batch installer, including all 17 tier-1 engines. It has circulated since 2020 across more than 1,000 sources, and the completed sandbox run produced no malicious outcome, offensive behavior, persistence, or harmful child file.
7c5f19bc6d71305299…422a04156c2671Recommended next actions
Before running
Run it only when it came from the developer's official site or another source you independently trust.
If you already ran it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
None of 74 antivirus engines flagged this 139-byte batch installer, including all 17 tier-1 engines. It has circulated since 2020 across more than 1,000 sources, and the completed sandbox run produced no malicious outcome, offensive behavior, persistence, or harmful child file.
The strongest signal is complete detection silence: 0 of 74 engines flagged the sample, including all 17 tier-1 engines. One completed sandbox run found no malicious outcome and no techniques restricted to malware or offensive tools. The three observed domains were all inspected, and none was known as malicious or suspicious, although the run also recorded IP contacts that were not represented in the host-inspection block. No dropped hashes, persistence indicators, malicious child files, or external intelligence matches were recorded. Its age and broad prevalence—1,041 sources and 1,216 submissions since 2020—further reduce the likelihood of an active threat.
What We Detected
The file is a 139-byte DOS batch installer first submitted in November 2020. None of 74 antivirus engines detected it, including Avast, BitDefender, ESET-NOD32, Kaspersky, and Microsoft. It is also well established, with 1,041 unique sources and 1,216 submissions.
Threat Behavior
One completed sandbox run produced no malicious verdict and no offensive-only MITRE techniques. The script imported a registry file and copied a directory, but the run recorded no persistence indicators, registry keys set, dropped hashes, or malicious child files. All three observed domains were inspected and had no known-malicious or known-suspicious matches; the separate observed IP addresses were not fully covered by that domain-oriented reputation result. The long-sleep and direct-clock-access tags are weak cautions without corroborating detections or harmful behavior.
What To Do Now
The evidence supports ordinary use when the file came from the expected package or vendor. Keep endpoint protection enabled and obtain a fresh copy from the official source if the script appeared unexpectedly or its companion files are unavailable for inspection.
Where this verdict could be wrong2 caveats
- file.tags includes long-sleeps and direct-cpu-clock-access, but no engine detection, offensive technique, or malicious sandbox outcome corroborates those tags.
- The batch script invokes "reg import spine.reg" and copies a directory, but behaviour.registryKeysSet is empty and droppedFileHashes is empty in the completed run.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/74 engines reported a malicious or suspicious result.
- All 17 tier-1 engines reported no detection.
- behaviour.hasMaliciousSandboxVerdict=false and behaviour.offensiveCount=0.
- No persistence indicators, dropped hashes, or malicious child files were found.
- The file has 1,041 unique sources and 1,216 submissions dating to 2020.
- The batch file imports an external registry file named spine.reg.
- Tags include long-sleeps and direct-cpu-clock-access.
- Observed IP contacts were not fully represented in contactedHosts.inspected.
Use it only as part of the expected software package and keep endpoint protection enabled. If received unexpectedly, verify the source and inspect the companion spine.reg and Spine directory before running it.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 74 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial3 of 16 contacted hosts were cross-checked; coverage is incomplete.
YARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 7MITRE ATT&CK techniques
- 15spawned processes
- 16network contacts
- 8filesystem & mutex artifacts
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- gateway.fe.apple-dns.net
- fp2e7a.wpc.phicdn.net
- fp2e7a.wpc.2be4.phicdn.net
- 17.57.144.116
- 17.248.185.18
- 17.253.27.205
- 17.179.252.2
- 17.248.203.64
- 35.170.158.185
- 23.40.99.7
- 50.17.244.20
- 23.202.92.242
- 23.202.92.31
- /Users/user1/.bash_history
- /Users/user1/.bash_sessions/FBF81F94-0682-4BB5-B9ED-96EBED009BA0.history
- /Users/user1/.bash_sessions/FBF81F94-0682-4BB5-B9ED-96EBED009BA0.historynew
- /Users/user1/.bash_sessions/FBF81F94-0682-4BB5-B9ED-96EBED009BA0.session
- /dev/ttys000
- \Sessions\1\BaseNamedObjects\DBWinMutex
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 0 / 74engines flagged
- 1,041sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 74 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has a long, established submission history across 1,041 sources.
Verdict inputView chapterProvenanceDerivedSourceSubmission historyObserved at - 03
The hash has been submitted 1,216 times from 1,041 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: install.bat — 7c5f19bc6d713052997b4a5ccf4b2f7dccfb47179fc54c9b23422a04156c2671
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Windows\system32\cmd.exe" /c start /wait "" "C:\Users\<USER>\Desktop\install.bat"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — C:\Windows\system32\cmd.exe /K "C:\Users\<USER>\Desktop\install.bat"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: .bash_history — /Users/user1/.bash_history
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: FBF81F94-0682-4BB5-B9ED-96EBED009BA0.history — /Users/user1/.bash_sessions/FBF81F94-0682-4BB5-B9ED-96EBED009BA0.history
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: gateway.fe.apple-dns.net — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 10
Contacted host: fp2e7a.wpc.phicdn.net — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
0 of 74 engines flagged this file
View all 74 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Fingerprint and provenance
- File name
- install.bat
- Format
- DOS batch file
- Code signing
- Not applicable to this file type
- Size
- 139 B
- Last analyzed
- Sep 28, 2026, 11:54 PM UTC
7c5f19bc6d713052997b4a5ccf4b2f7dccfb47179fc54c9b23422a04156c2671Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Run it only when it came from the developer's official site or another source you independently trust.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is install.bat safe?
What is install.bat?
How many antivirus engines detected install.bat?
What is the SHA-256 hash of install.bat?
Is it safe to run install.bat?
How up to date is this analysis of install.bat?
Community
Member reviews and reports for this exact file hash.