🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3268b11bbde0c9c34672f53764bc9aa80a68cb697ebaab9f102965129d3a8c5a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Koadic


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 3268b11bbde0c9c34672f53764bc9aa80a68cb697ebaab9f102965129d3a8c5a
SHA3-384 hash: b590b181d9fbe56447707237d35821bc7f99f3b4abf750f92a253ef3ee869325601049a583e69bfc63ba04bc050db0eb
SHA1 hash: 516a6f2cbfb2f9113742a584a66725ac57338ee2
MD5 hash: d8db0727eeda4b40272cc779c87cf93f
humanhash: oregon-burger-december-enemy
File name:Banco BPM_Bonifico Bancario.pdf.7z
Download: download sample
Signature Koadic
File size:1'727 bytes
First seen:2026-05-20 15:50:10 UTC
Last seen:Never
File type: 7z
MIME type:application/x-7z-compressed
ssdeep 48:juRUmhzDuVwnvltStFZ8p7fUV7Fkxv0yS6ZDS4/+xkBAzw+:iRUmhbvf+F8MV7CbpT/+kB4w+
TLSH T11B316D3D50030CB5F7EADA37531B6CD000B5994D3E384604647A9341DD367735E01A9E
TrID 57.1% (.7Z) 7-Zip compressed archive (v0.4) (8000/1)
42.8% (.7Z) 7-Zip compressed archive (gen) (6000/1)
Magika sevenzip
Reporter ShadowOpCode
Tags:151-243-109-130 7z Koadic

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
IT IT
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Banco BPM_Bonifico Bancario.pdf.bat
File size:17'554 bytes
SHA256 hash: 125cc565e77c6db7dd998a8c7752c4087e2cf86bff5da96bced74640a042f6a1
MD5 hash: 3c75ef5928a2eecdfba69f5e70351a13
MIME type:text/x-msdos-batch
Signature Koadic
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
91.7%
Tags:
obfuscated shell sage
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
masquerade obfuscated powershell
Verdict:
Malicious
File Type:
7z
First seen:
2026-05-20T07:36:00Z UTC
Last seen:
2026-05-21T08:44:00Z UTC
Hits:
~10
Gathering data
Threat name:
Win32.Trojan.Malgent
Status:
Malicious
First seen:
2026-05-20 15:50:49 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments