🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d691b19f562b8f33b2ce91ca0aefdc2f84377e0a6a8f05223f4264185f0c0421. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Koadic


Vendor detections: 12


Intelligence 12 IOCs YARA File information Comments

SHA256 hash: d691b19f562b8f33b2ce91ca0aefdc2f84377e0a6a8f05223f4264185f0c0421
SHA3-384 hash: 547dea932ad414036b551107e3230868e1ee8af8cb7058221460d95a76fee9fb0880cb0cdc4a379c7e0400c783740fed
SHA1 hash: e268db2cb06dd54b572a94b835ee997a24cad1b0
MD5 hash: c8afbf6ad24394ad955784a218c23a0c
humanhash: oscar-delaware-angel-lemon
File name:CTM_DENOMINATION_25000_USD_BREAKDOWN.bat
Download: download sample
Signature Koadic
File size:5'689 bytes
First seen:2026-04-23 07:31:44 UTC
Last seen:Never
File type:Batch (bat) bat
MIME type:text/x-msdos-batch
ssdeep 96:8XEJ+met9m2KHBIP+2xL+Y9gFVnf2bM4SFHRXi2o7b1t9XugnK:T9Ffamd6SD7
TLSH T1B0C19E2FFAE7338B6736C8D650B7CB24B28FBE7F5C2558669080212E19D6C5D2889740
Magika batch
Reporter lowmal3
Tags:bat Koadic

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
DE DE
Vendor Threat Intelligence
Malware configuration found for:
BatchScript
Details
Malware family:
n/a
ID:
1
File name:
_d691b19f562b8f33b2ce91ca0aefdc2f84377e0a6a8f05223f4264185f0c0421.txt
Verdict:
No threats detected
Analysis date:
2026-04-23 07:55:36 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
93.3%
Tags:
obfuscated shell sage
Result
Verdict:
Malware
Maliciousness:

Behaviour
Launching a process
Сreating synchronization primitives
Connection attempt to an infection source
Query of malicious DNS domain
Sending a TCP request to an infection source
Gathering data
Verdict:
Malicious
File Type:
text
First seen:
2026-04-06T03:44:00Z UTC
Last seen:
2026-04-24T17:44:00Z UTC
Hits:
~10000
Detections:
Trojan-Downloader.Win32.Gomal.sb Backdoor.MSIL.Cardinal.sb HEUR:Trojan.BAT.Generic Trojan.Win64.Agent.sb Trojan.PowerShell.Cobalt.sb
Result
Threat name:
Detection:
malicious
Classification:
evad
Score:
64 / 100
Signature
Antivirus detection for URL or domain
Joe Sandbox ML detected suspicious sample
Multi AV Scanner detection for submitted file
Yara detected Koadic BAT payload
Behaviour
Behavior Graph:
Verdict:
Malicious
Threat:
Trojan.PowerShell.Cardinal
Threat name:
Win32.Trojan.Leonem
Status:
Malicious
First seen:
2026-04-06 06:56:11 UTC
File Type:
Text
AV detection:
13 of 36 (36.11%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Badlisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Koadic

Batch (bat) bat d691b19f562b8f33b2ce91ca0aefdc2f84377e0a6a8f05223f4264185f0c0421

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments