🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 eab7651a0fec6c7fe5deca87a6a0cfddb4d7ac655c2f3bd1182126588501e30c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Koadic


Vendor detections: 12


Intelligence 12 IOCs YARA File information Comments

SHA256 hash: eab7651a0fec6c7fe5deca87a6a0cfddb4d7ac655c2f3bd1182126588501e30c
SHA3-384 hash: f45af90107471e6871038cbd01f7611773fc6a4368596a33316ba2f5638c3f9ed27df404112252d7c828fc0066cd973a
SHA1 hash: 4246ec86fbba21c7f39c3906445b53fb09a2a3fe
MD5 hash: ed25e3eae50e1a2968fcfdb545908124
humanhash: spring-illinois-diet-connecticut
File name:AMAN_SENDAI_VESSEL_INFORMATIONS.bat
Download: download sample
Signature Koadic
File size:6'485 bytes
First seen:2026-04-23 07:30:24 UTC
Last seen:2026-04-23 08:09:26 UTC
File type:Batch (bat) bat
MIME type:text/x-msdos-batch
ssdeep 48:mC+xB02+hzt9M49+f4xkZGqAS21rAMzRtnEXjmhZo0WrJ2CJG3uRcWtfyCvPmM6r:FDdETvpMaNmVSkayTYfiR
TLSH T1CFD195A6D6EB1B1B20A74955E983F826D845403F913F1AE7C3442E3EFD518BEA04F6C4
Magika batch
Reporter lowmal3
Tags:bat Koadic

Intelligence


File Origin
# of uploads :
2
# of downloads :
58
Origin country :
DE DE
Vendor Threat Intelligence
Malware configuration found for:
BatchScript
Details
Malware family:
n/a
ID:
1
File name:
bat
Verdict:
No threats detected
Analysis date:
2026-04-23 07:44:50 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
93.3%
Tags:
obfuscated shell sage
Result
Verdict:
Malware
Maliciousness:

Behaviour
Launching a process
Сreating synchronization primitives
Connection attempt to an infection source
Sending a custom TCP request
Query of malicious DNS domain
Sending a TCP request to an infection source
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-04-02T14:27:00Z UTC
Last seen:
2026-04-24T17:44:00Z UTC
Hits:
~10000
Detections:
HEUR:Trojan.BAT.Generic Trojan.Win32.Strab.sb Trojan.Win32.Agent.sb Trojan.PowerShell.Cobalt.sb Trojan-PSW.Win32.Stealer.sb Trojan-PSW.Win32.Disco.sb Trojan-PSW.MSIL.Agensla.sb HEUR:HackTool.Multi.AmsiETWPatch.gen
Result
Threat name:
Detection:
malicious
Classification:
evad
Score:
64 / 100
Signature
Antivirus detection for URL or domain
Joe Sandbox ML detected suspicious sample
Multi AV Scanner detection for submitted file
Yara detected Koadic BAT payload
Behaviour
Behavior Graph:
Threat name:
Script-BAT.Trojan.AgentTesla
Status:
Malicious
First seen:
2026-04-02 17:47:37 UTC
File Type:
Text (Batch)
AV detection:
14 of 36 (38.89%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Badlisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Koadic

Batch (bat) bat eab7651a0fec6c7fe5deca87a6a0cfddb4d7ac655c2f3bd1182126588501e30c

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments