🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 862e9f6287d828ccd2e2f4de1162e159b95353deadff001e499d4bae7b724690. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Koadic


Vendor detections: 12


Intelligence 12 IOCs YARA File information Comments

SHA256 hash: 862e9f6287d828ccd2e2f4de1162e159b95353deadff001e499d4bae7b724690
SHA3-384 hash: d55c40fb7c1ed5116f85f130ca5cb8d44396e4bf22759bf31f99bff642de056e4209e77d21156f80f312b32ab4245e4f
SHA1 hash: 899c7a1e17da7a32fceb1a402d569cc3a0152667
MD5 hash: b29d019335a00d7a4cbc0cddf31f961f
humanhash: video-speaker-comet-video
File name:HSBC_Bank_Payment_Advice09238740008.bat
Download: download sample
Signature Koadic
File size:7'223 bytes
First seen:2026-04-23 07:35:38 UTC
Last seen:Never
File type:Batch (bat) bat
MIME type:text/x-msdos-batch
ssdeep 192:b3NQwW5sEQ40OjSUIEuFkmsMgofQXfaFiSyo:b3NQwW5sEQ40OjSUIEuFkmsMgofQXfaT
TLSH T183E16D6089820AC7F2E780EE6BA5A3257697ACBF162C91DBC57933545DDE20F7FE0410
Magika batch
Reporter lowmal3
Tags:bat Koadic

Intelligence


File Origin
# of uploads :
1
# of downloads :
57
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
PURCHASE_ORDER0293456.bat
Verdict:
No threats detected
Analysis date:
2026-04-20 09:47:44 UTC
Tags:
loader

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.1%
Tags:
obfuscated virus shell
Result
Verdict:
Malware
Maliciousness:

Behaviour
Launching a process
Сreating synchronization primitives
Connection attempt to an infection source
Query of malicious DNS domain
Sending a TCP request to an infection source
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
batch masquerade obfuscated powershell powershell soft-404
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-04-14T02:07:00Z UTC
Last seen:
2026-04-25T05:23:00Z UTC
Hits:
~10000
Detections:
Trojan.PowerShell.Cobalt.sb Trojan-Downloader.Win32.Gomal.sb Backdoor.MSIL.Cardinal.sb HEUR:Trojan.BAT.Generic Trojan.Win64.Agent.sb
Result
Threat name:
Detection:
malicious
Classification:
evad
Score:
68 / 100
Signature
Antivirus detection for URL or domain
Joe Sandbox ML detected suspicious sample
Multi AV Scanner detection for submitted file
Sample has a suspicious name (potential lure to open the executable)
Yara detected Koadic BAT payload
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1903244 Sample: HSBC_Bank_Payment_Advice092... Startdate: 23/04/2026 Architecture: WINDOWS Score: 68 17 dump.win 2->17 21 Antivirus detection for URL or domain 2->21 23 Multi AV Scanner detection for submitted file 2->23 25 Sample has a suspicious name (potential lure to open the executable) 2->25 27 2 other signatures 2->27 8 cmd.exe 1 2->8         started        signatures3 process4 process5 10 powershell.exe 14 19 8->10         started        13 conhost.exe 8->13         started        dnsIp6 19 dump.win 172.67.215.99, 443, 49693 CLOUDFLARENETUS United States 10->19 15 conhost.exe 10->15         started        process7
Verdict:
Malicious
Threat:
Trojan.PowerShell.Cardinal
Threat name:
Script-BAT.Trojan.Pantera
Status:
Malicious
First seen:
2026-04-14 05:29:37 UTC
File Type:
Text (Batch)
AV detection:
12 of 24 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Badlisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Koadic

Batch (bat) bat 862e9f6287d828ccd2e2f4de1162e159b95353deadff001e499d4bae7b724690

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments