VDB
GCVE-110-OSM-2026-10275
GCVE-110-OSM-2026-10275
Advisory PublishedCVSS 5.4/10
Repository created 2026-07-21 by throwaway account dcm1-6626 hosting a heavily obfuscated malicious batch dropper (udm.bat). Shared in the same threat actor
cluster as dm1-21726/space and reported by @suyog41 on Twitter/X.
udm.bat (MD5: faa7c59292d14c19f3446c26c08b0a57, 2.61 MB) is a Windows batch file obfuscated with Rouki-OBFUSCATOR using Unicode emoji characters
(ヾ(⌐■_■)ノ, ┌( ಠ_ಠ)┘, (◕‿◕)) as variable names across 23 very long lines to defeat static analysis. The extreme file size (2.6 MB for a batch file) is
consistent with an embedded base64-encoded payload. Functions as a dropper/launcher for the Python stealer bundle hosted in dm1-21726/space.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | all (affected) | — |
References
Browse GCVE Records
867 records in the GCVE database · Updated September 2, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.