🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 01593287286f40bf5305f2d54962fdbcb8a4b6c4a5c0912b6f2e5826bea9c741. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Koadic


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 01593287286f40bf5305f2d54962fdbcb8a4b6c4a5c0912b6f2e5826bea9c741
SHA3-384 hash: 86651c10463c964c24e04ed906213d74bb54d2ae01340c103ca2c5ec28be72754c3875f2440dc5aedbc9323a369afd7d
SHA1 hash: ffc96640e5ba9c5ed126abf671e4ce6108ed8fdb
MD5 hash: fe537d6afd83f8e9e7f0402209c98a08
humanhash: golf-bulldog-pluto-pennsylvania
File name:Villa_Interior_Design_Construction_Request.bat
Download: download sample
Signature Koadic
File size:3'595'299 bytes
First seen:2026-05-15 09:26:16 UTC
Last seen:Never
File type:Batch (bat) bat
MIME type:text/plain
ssdeep 3072:baf6YTfB0wzB4ikSef5HG8C0IsAH39Yo+2JUcRh1WaXEUuEyTdseZrVm3K2HYB5A:0
TLSH T127F521511A922BEB21658624D1264568FBE7B53D40FF4A2BDABC7D3ECFE0648813D331
Magika txt
Reporter smica83
Tags:bat Koadic

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
HU HU
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
bat
Verdict:
No threats detected
Analysis date:
2026-05-15 09:27:13 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
90.2%
Tags:
obfuscate autorun shell sage
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
cmd find findstr lolbin
Result
Threat name:
Koadic, Abobus Obfuscator
Detection:
malicious
Classification:
troj.expl.evad
Score:
100 / 100
Signature
Drops script or batch files to the startup folder
Found large BAT file
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Powershell drops PE file
Sigma detected: Curl Download And Execute Combination
Sigma detected: Drops script at startup location
Sigma detected: Execution from Suspicious Folder
Sigma detected: Invoke-Obfuscation CLIP+ Launcher
Sigma detected: Invoke-Obfuscation VAR+ Launcher
Sigma detected: PowerShell DownloadFile
Sigma detected: Suspicious Program Location with Network Connections
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: Windows Shell/Scripting Application File Write to Suspicious Folder
Suspicious execution chain found
Suspicious powershell command line found
Tries to download and execute files (via powershell)
Uses the Telegram API (likely for C&C communication)
Yara detected Abobus Obfuscator
Yara detected Koadic BAT payload
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1913924 Sample: Villa_Interior_Design_Const... Startdate: 15/05/2026 Architecture: WINDOWS Score: 100 121 api.telegram.org 2->121 123 script.google.com 2->123 125 3 other IPs or domains 2->125 135 Malicious sample detected (through community Yara rule) 2->135 137 Yara detected Abobus Obfuscator 2->137 139 Sigma detected: Drops script at startup location 2->139 143 11 other signatures 2->143 11 cmd.exe 3 2->11         started        14 cmd.exe 1 2->14         started        signatures3 141 Uses the Telegram API (likely for C&C communication) 121->141 process4 signatures5 155 Suspicious powershell command line found 11->155 157 Tries to download and execute files (via powershell) 11->157 16 powershell.exe 14 1007 11->16         started        20 powershell.exe 20 11->20         started        23 conhost.exe 11->23         started        31 9 other processes 11->31 25 powershell.exe 3 10 14->25         started        27 powershell.exe 14->27         started        29 cmd.exe 14->29         started        33 4 other processes 14->33 process6 dnsIp7 117 raw.githubusercontent.com 185.199.111.133, 443, 49724, 49725 FASTLYUS Netherlands 16->117 105 C:\Users\Public\Desktops\vcruntime140_1.dll, PE32+ 16->105 dropped 107 C:\Users\Public\Desktops\vcruntime140.dll, PE32+ 16->107 dropped 109 C:\Users\Public\Desktops\python312.dll, PE32+ 16->109 dropped 113 855 other files (84 malicious) 16->113 dropped 35 python.exe 16->35         started        38 conhost.exe 16->38         started        119 github.com 140.82.114.3, 443, 49721, 49722 GITHUBUS United States 20->119 111 C:\Users\user\AppData\...\WindowSecuryt.bat, Unicode 20->111 dropped 145 Drops script or batch files to the startup folder 20->145 147 Suspicious execution chain found 20->147 149 Powershell drops PE file 20->149 40 conhost.exe 20->40         started        42 cmd.exe 25->42         started        44 cmd.exe 27->44         started        151 Suspicious powershell command line found 29->151 46 powershell.exe 29->46         started        48 powershell.exe 29->48         started        52 3 other processes 29->52 50 net1.exe 1 33->50         started        file8 signatures9 process10 dnsIp11 127 api.telegram.org 149.154.166.110, 443, 49749, 49750 TELEGRAMRU United Kingdom 35->127 129 script.google.com 142.251.45.206, 443, 49802, 49843 GOOGLEUS United States 35->129 131 ipinfo.io 34.117.59.81, 443, 49739, 49745 GOOGLE-AS-APGoogleAsiaPacificPteLtdSG United States 35->131 54 cmd.exe 42->54         started        57 net.exe 42->57         started        59 conhost.exe 42->59         started        61 cmd.exe 44->61         started        63 net.exe 44->63         started        65 conhost.exe 44->65         started        67 cmd.exe 46->67         started        71 2 other processes 48->71 69 net1.exe 52->69         started        process12 signatures13 153 Suspicious powershell command line found 54->153 73 curl.exe 54->73         started        77 powershell.exe 54->77         started        79 net.exe 54->79         started        81 net1.exe 57->81         started        83 powershell.exe 61->83         started        85 net.exe 61->85         started        87 curl.exe 61->87         started        89 net1.exe 63->89         started        91 conhost.exe 67->91         started        process14 dnsIp15 133 127.0.0.1 unknown unknown 73->133 115 C:\Users\user\AppData\Local\Temp\ut.bat, Unicode 73->115 dropped 93 conhost.exe 77->93         started        95 python.exe 77->95         started        97 net1.exe 79->97         started        99 conhost.exe 83->99         started        101 python.exe 83->101         started        103 net1.exe 85->103         started        file16 process17
Threat name:
Text.Trojan.Generic
Status:
Suspicious
First seen:
2026-05-14 14:53:50 UTC
File Type:
Text (Batch)
AV detection:
3 of 38 (7.89%)
Threat level:
  5/5
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments