🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e69007a9004cb14a621b44be45ce6b30ce68dc1a40243a4e06c29e1b0be7a7a4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Koadic


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: e69007a9004cb14a621b44be45ce6b30ce68dc1a40243a4e06c29e1b0be7a7a4
SHA3-384 hash: 7a023cfc6529e84270994ff9a3cb75dfabffdade73503a5c2a37335cdb1a3aef964186f201fd54e646fb6c88e0244d5c
SHA1 hash: 3356991e6fe8dbb821ea29f9f3f67079302679d0
MD5 hash: ccd7c9da6bc9914fcd89d63ea06d0c38
humanhash: kansas-georgia-kentucky-pennsylvania
File name:PPZTuAsEUYpajFq.bat
Download: download sample
Signature Koadic
File size:14'021'160 bytes
First seen:2026-02-07 10:25:28 UTC
Last seen:Never
File type:Batch (bat) bat
MIME type:text/plain
ssdeep 393216:G99iBtmYxR2HkPMTFoLVES1Wq4F6rIeU3/Kn:NBtmIIHkLEfqh0X/c
TLSH T1ABE623644EBDAB2D3308C59CD297939F208BF47DA27CE18FD89BF6A31D872169452530
TrID 45.4% (.MP3) MP3 audio (ID3 v1.x tag) (2500/1/1)
36.3% (.TXT) Text - UTF-16 (LE) encoded (2000/1)
18.1% (.MP3) MP3 audio (1000/1)
Magika gzip
Reporter smica83
Tags:bat Koadic

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
HU HU
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
PPZTuAsEUYpajFq.bat
Verdict:
No threats detected
Analysis date:
2026-02-07 10:28:27 UTC
Tags:
lua

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
cmd lolbin obfuscated
Result
Threat name:
Detection:
malicious
Classification:
evad
Score:
48 / 100
Signature
Found large BAT file
Yara detected Koadic BAT payload
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1865155 Sample: PPZTuAsEUYpajFq.bat Startdate: 07/02/2026 Architecture: WINDOWS Score: 48 10 Found large BAT file 2->10 12 Yara detected Koadic BAT payload 2->12 6 cmd.exe 2 2->6         started        process3 process4 8 conhost.exe 6->8         started       
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments