thebat32.exe

The Bat!

RITLABS S.R.L.

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘thebat_startup’.
Publisher:
Ritlabs, SRL  (signed by RITLABS S.R.L.)

Product:
The Bat!

Description:
The Bat! E-Mail Client by Ritlabs, SRL

Version:
7.1.14

MD5:
7eadba965917a6ebf88d203af4287063

SHA-1:
deb87eaaf2d748146a0b63751921f9cc54fd28a0

SHA-256:
2ffd06cf0cba67eb0da98189edc1fa4a2b2a4e59c3126037e1ed4d39883bdb07

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
8/6/2025 10:22:59 PM UTC  (today)

Scan engine
Detection
Engine version

Rising Antivirus
PE:Malware.Generic(Thunder)!1.A1C4 [F]
23.00.65.16313

File size:
22 MB (23,027,192 bytes)

Product version:
7.1.14

Copyright:
Copyright (C) 1998-2016 Ritlabs, SRL

Original file name:
The Bat! E-Mail Client by Ritlabs, SRL

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\the bat!\thebat32.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
6/26/2015 2:00:00 AM

Valid to:
6/26/2016 1:59:59 AM

Subject:
CN=RITLABS S.R.L., O=RITLABS S.R.L., L=Chisinau, S=Republic of Moldova, C=MD

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
11756D584184E9FAADE0D8E77D289B67

File PE Metadata
Compilation timestamp:
2/13/2016 10:45:14 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
393216:KrprGYnTHP9Y9vLsl5lCe1CLC4k12Vk0cjxYrvVp+h7lyMyGnSHeR:KlP10cF4pAZrR

Entry address:
0x104DE20

Entry point:
55, 8B, EC, 83, C4, F0, B8, C4, CE, 42, 01, E8, 70, 33, FC, FE, E8, F3, 90, FD, FF, E8, FE, D4, FB, FE, 8B, C0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
16.3 MB (17,091,072 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
thebat_startup

Command:
C:\Program Files\the bat!\thebat32.exe


Scan thebat32.exe - Powered by Reason Core Security