🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d5132e01a34dcf20192df0db598ceb35216166140621bc1ba2dd5e441e27296f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Koadic


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: d5132e01a34dcf20192df0db598ceb35216166140621bc1ba2dd5e441e27296f
SHA3-384 hash: ad3ef0b95505edc2212bcd3d50abdc133de0121671235864362082a6204cdb49818f608ac65aedaaa6b09ae71fc67be9
SHA1 hash: 0225d41b5b0cd39a1a5a0841205f4a074089b848
MD5 hash: 7708a9c69ec846e42f4a05b1a469cfba
humanhash: uranus-berlin-potato-bravo
File name:GolfBooking_Request_April2026.bat
Download: download sample
Signature Koadic
File size:3'591'347 bytes
First seen:2026-04-17 20:39:55 UTC
Last seen:Never
File type:Batch (bat) bat
MIME type:text/plain
ssdeep 384:hh2MnBQkLV56VAznSY2djpKTcr1idsZEVns1nREtAT5h2ABbwhTguV0YCdnUBx7X:h/nnLS6b4DbRM
TLSH T12DF53EB54B4B3EAE14EB1B1151125802F94FBBBE187D122103ED397EBB91E4CCA25D72
Magika txt
Reporter smica83
Tags:bat Koadic

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
HU HU
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
GolfBooking_Request_April2026.bat
Verdict:
Malicious activity
Analysis date:
2026-04-17 20:45:27 UTC
Tags:
github auto-startup python api-base64 stealer evasion telegram

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
90.2%
Tags:
obfuscated autorun shell sage
Result
Verdict:
Malware
Maliciousness:

Behaviour
Launching a process
Creating a file
Creating a file in the system32 directory
Running batch commands
Сreating synchronization primitives
Searching for synchronization primitives
DNS request
Connection attempt
Sending a custom TCP request
Sending an HTTP GET request
Creating a process from a recently created file
Moving a recently created file
Delayed reading of the file
Creating a process with a hidden window
Using the Windows Management Instrumentation requests
Reading critical registry keys
Searching for the window
Downloading the file
Launching a tool to kill processes
Launching a file downloaded from the Internet
Enabling autorun by creating a file
Gathering data
Verdict:
Clean
File Type:
unknown
First seen:
2026-04-16T04:55:00Z UTC
Last seen:
2026-04-17T18:08:00Z UTC
Hits:
~10
Result
Threat name:
Koadic, Abobus Obfuscator
Detection:
malicious
Classification:
troj.expl.evad
Score:
100 / 100
Signature
Drops script or batch files to the startup folder
Excessive usage of taskkill to terminate processes
Found large BAT file
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Powershell drops PE file
Sigma detected: Curl Download And Execute Combination
Sigma detected: Drops script at startup location
Sigma detected: Execution from Suspicious Folder
Sigma detected: Invoke-Obfuscation CLIP+ Launcher
Sigma detected: Invoke-Obfuscation VAR+ Launcher
Sigma detected: Parent in Public Folder Suspicious Process
Sigma detected: PowerShell DownloadFile
Sigma detected: Suspicious Program Location with Network Connections
Sigma detected: Windows Shell/Scripting Application File Write to Suspicious Folder
Suspicious execution chain found
Suspicious powershell command line found
Tries to download and execute files (via powershell)
Uses the Telegram API (likely for C&C communication)
Writes to foreign memory regions
Yara detected Abobus Obfuscator
Yara detected Koadic BAT payload
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1900474 Sample: GolfBooking_Request_April2026.bat Startdate: 17/04/2026 Architecture: WINDOWS Score: 100 167 api.telegram.org 2->167 169 shed.dual-low.part-0012.t-0009.t-msedge.net 2->169 171 7 other IPs or domains 2->171 185 Malicious sample detected (through community Yara rule) 2->185 187 Yara detected Abobus Obfuscator 2->187 189 Sigma detected: Drops script at startup location 2->189 193 11 other signatures 2->193 13 cmd.exe 3 2->13         started        16 cmd.exe 1 2->16         started        signatures3 191 Uses the Telegram API (likely for C&C communication) 167->191 process4 signatures5 209 Suspicious powershell command line found 13->209 211 Tries to download and execute files (via powershell) 13->211 18 powershell.exe 14 1006 13->18         started        22 powershell.exe 21 13->22         started        25 find.exe 1 13->25         started        33 9 other processes 13->33 27 powershell.exe 3 10 16->27         started        29 powershell.exe 16->29         started        31 net.exe 1 16->31         started        35 4 other processes 16->35 process6 dnsIp7 173 raw.githubusercontent.com 185.199.111.133, 443, 49692, 49693 FASTLYUS Netherlands 18->173 143 C:\Users\Public\Desktops\vcruntime140_1.dll, PE32+ 18->143 dropped 145 C:\Users\Public\Desktops\vcruntime140.dll, PE32+ 18->145 dropped 147 C:\Users\Public\Desktops\python312.dll, PE32+ 18->147 dropped 151 862 other files (96 malicious) 18->151 dropped 37 python.exe 18->37         started        41 conhost.exe 18->41         started        175 github.com 140.82.113.4, 443, 49689, 49690 GITHUBUS United States 22->175 149 C:\Users\user\AppData\...\WindowSecuryt.bat, Unicode 22->149 dropped 195 Drops script or batch files to the startup folder 22->195 197 Suspicious execution chain found 22->197 199 Powershell drops PE file 22->199 43 conhost.exe 22->43         started        45 svchost.exe 25->45 injected 47 cmd.exe 27->47         started        49 cmd.exe 29->49         started        51 net1.exe 1 31->51         started        53 curl.exe 35->53         started        file8 signatures9 process10 dnsIp11 177 script.google.com 142.250.72.14, 443, 49774, 49775 GOOGLEUS United States 37->177 179 ipinfo.io 34.117.59.81, 443, 49713, 49714 GOOGLE-AS-APGoogleAsiaPacificPteLtdSG United States 37->179 153 C:\Users\user\...\6OFZUU5P34cX42VT.dll, PE32+ 37->153 dropped 155 C:\Users\user\...\4bROtKpOyPj6HbmS.dll, PE32+ 37->155 dropped 55 cmd.exe 37->55         started        58 cmd.exe 37->58         started        60 cmd.exe 37->60         started        68 12 other processes 37->68 62 consent.exe 45->62         started        64 cmd.exe 47->64         started        70 2 other processes 47->70 66 cmd.exe 49->66         started        72 2 other processes 49->72 file12 process13 signatures14 201 Excessive usage of taskkill to terminate processes 55->201 74 taskkill.exe 55->74         started        76 taskkill.exe 58->76         started        78 taskkill.exe 60->78         started        203 Writes to foreign memory regions 62->203 205 Suspicious powershell command line found 64->205 80 powershell.exe 64->80         started        86 2 other processes 64->86 90 3 other processes 66->90 92 9 other processes 68->92 82 net1.exe 70->82         started        84 net1.exe 72->84         started        process15 dnsIp16 94 python.exe 80->94         started        98 conhost.exe 80->98         started        181 127.0.0.1 unknown unknown 86->181 157 C:\Users\user\AppData\Local\Temp\u-t2.bat, Unicode 86->157 dropped 100 net1.exe 86->100         started        102 python.exe 90->102         started        104 net1.exe 90->104         started        106 conhost.exe 90->106         started        file17 process18 dnsIp19 183 api.telegram.org 149.154.166.110, 443, 49716, 49717 TELEGRAMRU United Kingdom 94->183 159 C:\Users\user\...\cDBMPNjUHNCoVNnY.dll, PE32+ 94->159 dropped 161 C:\Users\user\...\i091TNhr9Wd60npi.dll, PE32+ 94->161 dropped 108 cmd.exe 94->108         started        111 cmd.exe 94->111         started        113 cmd.exe 94->113         started        121 12 other processes 94->121 163 C:\Users\user\...\eJ5bU7ZovNHdiY40.dll, PE32+ 102->163 dropped 165 C:\Users\user\...\u2sq93sm2nj8h1Dv.dll, PE32+ 102->165 dropped 115 cmd.exe 102->115         started        117 cmd.exe 102->117         started        119 cmd.exe 102->119         started        123 13 other processes 102->123 file20 process21 signatures22 207 Excessive usage of taskkill to terminate processes 108->207 125 taskkill.exe 108->125         started        127 taskkill.exe 111->127         started        129 taskkill.exe 113->129         started        131 taskkill.exe 115->131         started        133 taskkill.exe 117->133         started        135 taskkill.exe 119->135         started        139 9 other processes 121->139 137 taskkill.exe 123->137         started        141 8 other processes 123->141 process23
Threat name:
Win32.Trojan.Qwexlafiba
Status:
Malicious
First seen:
2026-04-13 09:38:08 UTC
AV detection:
6 of 38 (15.79%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
defense_evasion execution spyware stealer
Behaviour
Kills process with taskkill
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Contacts third-party web service commonly abused for C2
Looks up external IP address via web service
Drops startup file
Executes dropped EXE
Loads dropped DLL
Reads user/profile data of web browsers
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Malware Config
Dropper Extraction:
https://github.com/d7-te/vtn/raw/main/T2.zip
https://github.com/ud-7-te/ud-vtn/raw/main/up-t2.png
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments