Is Oneclick-V8.3.bat safe?
No antivirus engine detected this established batch file, while one sandbox showed an administrative command and a version check that warrant ordinary caution.
The sample drew no detections from 75 antivirus engines, including 17 tier-1 engines, and no malicious sandbox decision or known-malicious host was recorded. Its use of an administrative command and contact with a suspicious-rated code-hosting endpoint are cautionary, but they are not independently corroborated as malware activity.
e12c12287f56d3fbc5…2a6b397f553d11Recommended next actions
Before running
Run it only when it came from the developer's official site or another source you independently trust.
If you already ran it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
The sample drew no detections from 75 antivirus engines, including 17 tier-1 engines, and no malicious sandbox decision or known-malicious host was recorded. Its use of an administrative command and contact with a suspicious-rated code-hosting endpoint are cautionary, but they are not independently corroborated as malware activity.
All 75 antivirus engines were silent, including the 17 tier-1 engines, which strongly weighs against a recognized threat. One completed sandbox observed fltmc and mapped an offensive service-related technique, but it produced no malicious sandbox decision, persistence indicator, or registry modification. The only network request fetched version metadata from a code-hosting endpoint whose cached rating was suspicious, not malicious. The sample is established across 136 sources and 158 submissions, and no MalwareBazaar, CIRCL, or YARAify corroboration was found. Negative reputation and conflicting community allegations lower confidence, while six dropped items remain individually unresolved.
What We Detected
None of 75 antivirus engines flagged the batch file, including all 17 tier-1 engines. The file is also well established, with 136 sources and 158 submissions, and no matching family was identified by MalwareBazaar, CIRCL, or YARAify.
Threat Behavior
One sandbox run observed the administrative command fltmc and mapped T1543.003, causing a UAC-bypass heuristic to fire. However, the run produced no malicious sandbox decision, persistence indicators, or registry changes. It also fetched a Version.md file from raw.githubusercontent.com; that fully covered host check rated the host suspicious rather than malicious. Six written child files were inspected without a malicious result, but their individual verdicts remain unknown.
What To Do Now
Use the script only if it came from the expected project or distributor, and inspect its batch commands before granting administrator privileges. Keep endpoint protection enabled and avoid running it on a production system if its origin cannot be verified.
Where this verdict could be wrong4 caveats
- The MalwareTips.Synth.UacBypass heuristic fired, but its cited evidence is fltmc alone and the completed sandbox recorded no registry changes, persistence indicators, or malicious sandbox verdict.
- raw.githubusercontent.com received a suspicious cached-host result, although the observed URL requested Version.md and no host was marked malicious.
- file.reputation=-11 and several communityComments allege malware or Matrix, but those annotations are inconsistent and lack corroboration from engines or curated external intelligence.
- All six dropped children have unknown individual verdicts, so droppedChildren.hasMaliciousChild=false does not establish that each child was independently cleared.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/75 antivirus engines reported a detection.
- All 17 tier-1 engines reported no detection.
- behaviour.hasMaliciousSandboxVerdict=false.
- contactedHosts.maliciousHosts is empty with complete coverage of the sole distinct host.
- No MalwareBazaar, CIRCL, or YARAify hit was found.
- MalwareTips.Synth.UacBypass fired on an administrative fltmc invocation.
- T1543.003 was observed during the single sandbox run.
- raw.githubusercontent.com was rated suspicious with score 79 in the contacted-host cache.
- file.reputation is -11.
- Six dropped children have unknown individual verdicts.
- Community annotations contain uncorroborated and conflicting threat claims.
Run it only when obtained from the expected source and after reviewing the batch commands, especially anything requiring elevation. Keep antivirus and endpoint protection enabled.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial1 of 2 contacted hosts were cross-checked; coverage is incomplete.
YARA
Complete2 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 9MITRE ATT&CK techniques
- 15spawned processes
- 2network contacts
- 7filesystem & mutex artifacts
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
Oneclick-V8.3.bat
e12c12287f56d3fbc525be1a6c5ab7bf3ada3a6272c077dab92a6b397f553d11
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Windows\system32\cmd.exe" /c start /wait "" "C:\Users\<USER>\Desktop\Oneclick-V8.3.bat"
02Isolated runtime analysis - ProcessObserved
Observed process
C:\Windows\system32\cmd.exe /K "C:\Users\<USER>\Desktop\Oneclick-V8.3.bat"
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
Oneclick Log.txt
C:\Oneclick Logs\Oneclick Log.txt
04Isolated runtime analysis - Written fileObserved
WinVersion.txt
C:\Oneclick Logs\Extra\WinVersion.txt
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostDerived
raw.githubusercontent.com
Saved reputation verdict: suspicious.
06Contacted-host cross-check - Contacted hostObserved
185.199.111.133
Contact observed during runtime.
07Isolated runtime analysis - +1 more recorded observation in Analyst mode
7 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 185.199.111.133
- https://raw.githubusercontent.com/QuakedK/Oneclick/main/Version.md
- C:\Oneclick Logs\Oneclick Log.txt
- C:\Oneclick Logs\Extra\WinVersion.txt
- C:\Oneclick Logs
- C:\Oneclick Logs\Extra
- \Device\ConDrv\\Connect
Files this sample writes at runtime
This file drops 6 children at runtime. None are currently flagged malicious in our cache.
- 9f9c3e129204cf802582…959e34Never scannednever seen before
- 7d95fc7dde08020ce0e0…5f1d3eNever scannednever seen before
- 298d73fb42e04320704a…46798dNever scannednever seen before
- 20bcb6707f18bf26982d…2ad45dNever scannednever seen before
- f6580d567c6265897ea0…ff5907Never scannednever seen before
- 1a00549ed7f2bdaeef7b…e973aaNever scannednever seen before
Servers this file contacts
This file contacts 1 host we've flagged suspicious in our own URL scanner.
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 2rule hits recorded
- 0 / 75engines flagged
- 136sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 75 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has a long, established submission history across 136 sources.
Verdict inputView chapterProvenanceDerivedSourceSubmission historyObserved at - 03
1 high-confidence signature or behavior rule matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 04
Scanned file: Oneclick-V8.3.bat — e12c12287f56d3fbc525be1a6c5ab7bf3ada3a6272c077dab92a6b397f553d11
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Windows\system32\cmd.exe" /c start /wait "" "C:\Users\<USER>\Desktop\Oneclick-V8.3.bat"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — C:\Windows\system32\cmd.exe /K "C:\Users\<USER>\Desktop\Oneclick-V8.3.bat"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: Oneclick Log.txt — C:\Oneclick Logs\Oneclick Log.txt
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: WinVersion.txt — C:\Oneclick Logs\Extra\WinVersion.txt
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: raw.githubusercontent.com — Saved reputation verdict: suspicious.
ProvenanceDerivedSourceContacted-host cross-checkObserved at - 10
Contacted host: 185.199.111.133 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
Sample invoked a known UAC auto-elevation helper (fodhelper / eventvwr / sdclt / wsreset / cmstp / etc.) with custom arguments. These binaries are abused via registry-hijack UAC bypasses; legitimate software never calls them with arguments.
EvidenceC:\Windows\System32\fltMC.exe fltmcThe sample contacted an external IP address directly and no application domain was recorded. Direct-IP traffic also occurs in legitimate installers and infrastructure, so this is supporting context only and requires corroboration from host reputation and other runtime evidence.
Evidence185.199.111.133
0 of 75 engines flagged this file
View all 75 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Fingerprint and provenance
- File name
- Oneclick-V8.3.bat
- Format
- DOS batch file
- Code signing
- Not applicable to this file type
- Size
- 271.0 KB
- Last analyzed
- Sep 21, 2026, 12:24 AM UTC
e12c12287f56d3fbc525be1a6c5ab7bf3ada3a6272c077dab92a6b397f553d11Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Run it only when it came from the developer's official site or another source you independently trust.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is Oneclick-V8.3.bat safe?
What is Oneclick-V8.3.bat?
How many antivirus engines detected Oneclick-V8.3.bat?
What is the SHA-256 hash of Oneclick-V8.3.bat?
Is it safe to run Oneclick-V8.3.bat?
How up to date is this analysis of Oneclick-V8.3.bat?
Community
Member reviews and reports for this exact file hash.