Is ChemicalFlood.bat safe?
No antivirus engine detected this established batch file, and one sandbox found no malware-exclusive techniques, though ten direct IP contacts remain reputation-unverified.
All 76 antivirus engines produced no detection, including 17 tier-1 engines, and the completed sandbox run issued no malicious verdict. The direct-IP heuristic warrants some caution because ten contacted addresses were not reputation-checked, but no offensive technique, malicious child, family label, or external-intelligence hit corroborates it.
e0d75967904fd8833a…39117c6614e3e1Recommended next actions
Before running
Run it only when it came from the developer's official site or another source you independently trust.
If you already ran it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
All 76 antivirus engines produced no detection, including 17 tier-1 engines, and the completed sandbox run issued no malicious verdict. The direct-IP heuristic warrants some caution because ten contacted addresses were not reputation-checked, but no offensive technique, malicious child, family label, or external-intelligence hit corroborates it.
The strongest evidence is broad static agreement: 0 of 76 engines flagged the 37-byte batch file, including no tier-1 detections. One completed sandbox run recorded T1064 and T1082, but no malware-exclusive techniques and no malicious sandbox verdict. A medium-severity heuristic highlighted ten direct IP contacts, yet that rule explicitly requires corroboration and no complete host-reputation result is available. No malicious dropped child, persistence indicator, family consensus, YARA rule, or external-intelligence hit supports a threat attribution. Its 899-day observation history and submissions from 54 sources further reduce concern that this is an unseen emerging sample.
What We Detected
No detections were returned by 76 antivirus engines, including 17 tier-1 engines. The file is a 37-byte DOS batch script observed for 899 days and submitted by 54 distinct sources. External checks produced no MalwareBazaar match, CIRCL hit, or YARAify rule.
Threat Behavior
One sandbox run recorded two ambient techniques, T1064 and T1082, with no malware-exclusive technique and no malicious sandbox verdict. A heuristic noted direct communication with ten IP addresses and no domains. Because contactedHosts is unavailable, those addresses did not receive a complete saved reputation cross-check; the network signal therefore remains unresolved rather than confirmed benign. No persistence indicator or malicious dropped child was identified.
What To Do Now
Normal caution remains appropriate for batch scripts because they execute commands directly. Keep endpoint protection enabled, inspect the script contents before running it, and avoid execution if its source or intended purpose is unfamiliar.
Where this verdict could be wrong2 caveats
- MalwareTips.Synth.DirectIpC2 fired after behaviour.contactedIps recorded 10 direct IP contacts without domains; complete host-reputation results are unavailable because contactedHosts=null.
- behaviour.filesWritten includes a Windows scheduled-task path and a Downloads .exe path, although no persistence indicator, dropped hash, or malicious sandbox verdict corroborates harmful activity.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/76 engines reported malicious or suspicious findings.
- tier1Malicious=0 and tier1ReportedClean=17.
- behaviour.offensiveCount=0 and behaviour.hasMaliciousSandboxVerdict=false.
- externalIntel.yaraify.ruleCount=0, externalIntel.circl.hit=false, and externalIntel.malwareBazaar.hit=false.
- file.ageDays=899 and prevalence.uniqueSources=54 show an established observation history.
- triggeredHeuristics[0].rule=MalwareTips.Synth.DirectIpC2 fired for 10 direct IP contacts.
- contactedHosts=null, so complete reputation coverage for behaviour.contactedIps is unavailable.
- behaviour.filesWritten lists a Windows scheduled-task path and a Downloads .exe path without corroborating malicious verdicts.
Keep endpoint protection enabled and review the batch commands before execution. If the file came from an unexpected source, do not run it until the ten contacted IP addresses can be reputation-checked.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 76 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial10 runtime contacts were observed without a completed reputation cross-check.
YARA
Complete1 signature or behavior rule matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 2MITRE ATT&CK techniques
- 4spawned processes
- 10network contacts
- 3filesystem & mutex artifacts
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
ChemicalFlood.bat
e0d75967904fd8833a7dbb57841d43cb3c3da0c17b93d7a78239117c6614e3e1
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Windows\system32\cmd.exe" /c start /wait "" "C:\Users\<USER>\AppData\Local\Temp\ChemicalFlood.bat"
02Isolated runtime analysis - ProcessObserved
Observed process
C:\Windows\system32\cmd.exe /K "C:\Users\<USER>\AppData\Local\Temp\ChemicalFlood.bat"
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
Microsoft Compatibility Appraiser
C:\Windows\System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser
04Isolated runtime analysis - Written fileObserved
.exe
C:\Users\<USER>\Downloads\.exe
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
23.56.3.75
Contact observed during runtime.
06Isolated runtime analysis - Contacted hostObserved
204.79.197.203
Contact observed during runtime.
07Isolated runtime analysis - +1 more recorded observation in Analyst mode
7 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 23.56.3.75
- 204.79.197.203
- 138.91.171.81
- 40.126.29.9
- 40.83.247.108
- 40.127.169.103
- 23.56.3.24
- 20.106.86.13
- 104.81.49.225
- 20.114.59.183
- C:\Windows\System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser
- C:\Users\<USER>\Downloads\.exe
- \Device\ConDrv\\Connect
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 1rule hit recorded
- 0 / 76engines flagged
- 54sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 76 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has been submitted 55 times from 54 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 03
Scanned file: ChemicalFlood.bat — e0d75967904fd8833a7dbb57841d43cb3c3da0c17b93d7a78239117c6614e3e1
ProvenanceObservedSourceUploaded fileObserved at - 04
Observed process — "C:\Windows\system32\cmd.exe" /c start /wait "" "C:\Users\<USER>\AppData\Local\Temp\ChemicalFlood.bat"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 05
Observed process — C:\Windows\system32\cmd.exe /K "C:\Users\<USER>\AppData\Local\Temp\ChemicalFlood.bat"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
File written: Microsoft Compatibility Appraiser — C:\Windows\System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: .exe — C:\Users\<USER>\Downloads\.exe
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
Contacted host: 23.56.3.75 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: 204.79.197.203 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
Behavioral heuristics matched patterns associated with malware. Corroborating evidence determines how much weight they carry.
The sample contacted an external IP address directly and no application domain was recorded. Direct-IP traffic also occurs in legitimate installers and infrastructure, so this is supporting context only and requires corroboration from host reputation and other runtime evidence.
Evidence23.56.3.75 · 204.79.197.203 · 138.91.171.81
0 of 76 engines flagged this file
View all 76 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- ChemicalFlood.bat
- Format
- DOS batch file
- Code signing
- Not applicable to this file type
- Size
- 37 B
- Last analyzed
- Sep 19, 2026, 11:44 PM UTC
e0d75967904fd8833a7dbb57841d43cb3c3da0c17b93d7a78239117c6614e3e1Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Run it only when it came from the developer's official site or another source you independently trust.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is ChemicalFlood.bat safe?
What is ChemicalFlood.bat?
How many antivirus engines detected ChemicalFlood.bat?
What is the SHA-256 hash of ChemicalFlood.bat?
Is it safe to run ChemicalFlood.bat?
How up to date is this analysis of ChemicalFlood.bat?
Community
Member reviews and reports for this exact file hash.