🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ee26e23429e2a93a9ec1a83a7dd490deb2035fa3a3b5ee8feea16d8612441272. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Koadic


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: ee26e23429e2a93a9ec1a83a7dd490deb2035fa3a3b5ee8feea16d8612441272
SHA3-384 hash: 31c8e88208649c0547bdba78a621963081a860b06082b012c17d160460bc5b5557a952134883409da238969eed5b9957
SHA1 hash: 17e7e9825336c4da743c6e41c9a9847ebade1867
MD5 hash: 6d184529b130e94ab606897aa21a1622
humanhash: fish-colorado-edward-montana
File name:Photo XRay Ultrasound Medical Records C1203.bat
Download: download sample
Signature Koadic
File size:3'507'007 bytes
First seen:2026-03-13 11:08:18 UTC
Last seen:Never
File type:Batch (bat) bat
MIME type:text/plain
ssdeep 768:tCnYjqCRXw9N+Eth2PyPctYl6MnzfXsogmy+KqJZ5otBhl0vbejTtm46WjxgK02b:jV0o
TLSH T1D8F5EEF01BE65E6D20C7E92482790E0BAB6F773E01691D66B9FD3D6DEE9408D0139039
Magika txt
Reporter smica83
Tags:bat Koadic

Intelligence


File Origin
# of uploads :
1
# of downloads :
100
Origin country :
HU HU
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
Photo XRay Ultrasound Medical Records C1203.bat
Verdict:
Malicious activity
Analysis date:
2026-03-13 11:09:36 UTC
Tags:
auto-startup github python stealer evasion telegram ims-api generic api-base64

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
90.2%
Tags:
obfuscated autorun shell sage
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
cmd find findstr lolbin
Result
Threat name:
Koadic, Abobus Obfuscator
Detection:
malicious
Classification:
troj.expl.evad
Score:
100 / 100
Signature
Drops script or batch files to the startup folder
Found large BAT file
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Powershell drops PE file
Sigma detected: Curl Download And Execute Combination
Sigma detected: Drops script at startup location
Sigma detected: Execution from Suspicious Folder
Sigma detected: Invoke-Obfuscation CLIP+ Launcher
Sigma detected: Invoke-Obfuscation VAR+ Launcher
Sigma detected: PowerShell DownloadFile
Sigma detected: Suspicious Program Location with Network Connections
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: Windows Shell/Scripting Application File Write to Suspicious Folder
Suspicious execution chain found
Suspicious powershell command line found
Tries to download and execute files (via powershell)
Uses the Telegram API (likely for C&C communication)
Yara detected Abobus Obfuscator
Yara detected Koadic BAT payload
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1883214 Sample: Photo XRay Ultrasound Medic... Startdate: 13/03/2026 Architecture: WINDOWS Score: 100 134 api.telegram.org 2->134 136 script.google.com 2->136 138 3 other IPs or domains 2->138 146 Malicious sample detected (through community Yara rule) 2->146 148 Yara detected Abobus Obfuscator 2->148 150 Sigma detected: Drops script at startup location 2->150 154 11 other signatures 2->154 11 cmd.exe 3 2->11         started        14 cmd.exe 1 2->14         started        16 svchost.exe 1 1 2->16         started        signatures3 152 Uses the Telegram API (likely for C&C communication) 134->152 process4 dnsIp5 166 Suspicious powershell command line found 11->166 168 Tries to download and execute files (via powershell) 11->168 19 powershell.exe 14 1006 11->19         started        23 powershell.exe 21 11->23         started        26 conhost.exe 11->26         started        34 9 other processes 11->34 28 powershell.exe 3 10 14->28         started        30 powershell.exe 14->30         started        32 cmd.exe 14->32         started        36 4 other processes 14->36 128 127.0.0.1 unknown unknown 16->128 signatures6 process7 dnsIp8 140 raw.githubusercontent.com 185.199.110.133, 443, 49683, 49684 FASTLYUS Netherlands 19->140 114 C:\Users\Public\Documemt\vcruntime140_1.dll, PE32+ 19->114 dropped 116 C:\Users\Public\Documemt\vcruntime140.dll, PE32+ 19->116 dropped 118 C:\Users\Public\Documemt\python312.dll, PE32+ 19->118 dropped 122 865 other files (96 malicious) 19->122 dropped 38 python.exe 19->38         started        42 conhost.exe 19->42         started        142 github.com 140.82.113.3, 443, 49681, 49682 GITHUBUS United States 23->142 120 C:\Users\user\AppData\...\WindowSecurytm.bat, Unicode 23->120 dropped 156 Drops script or batch files to the startup folder 23->156 158 Suspicious execution chain found 23->158 160 Powershell drops PE file 23->160 44 conhost.exe 23->44         started        46 cmd.exe 28->46         started        48 cmd.exe 30->48         started        162 Suspicious powershell command line found 32->162 50 powershell.exe 32->50         started        52 net.exe 32->52         started        56 3 other processes 32->56 54 net1.exe 1 36->54         started        file9 signatures10 process11 dnsIp12 144 script.google.com 142.250.65.78, 443, 49795, 49816 GOOGLEUS United States 38->144 124 C:\Users\user\...\yXwYuxYYoGr5bu6t.dll, PE32+ 38->124 dropped 58 cmd.exe 46->58         started        61 net.exe 46->61         started        63 conhost.exe 46->63         started        65 cmd.exe 48->65         started        67 net.exe 48->67         started        69 conhost.exe 48->69         started        71 cmd.exe 50->71         started        73 net1.exe 52->73         started        75 conhost.exe 56->75         started        file13 process14 signatures15 164 Suspicious powershell command line found 58->164 77 curl.exe 58->77         started        80 powershell.exe 58->80         started        82 net.exe 58->82         started        84 net1.exe 61->84         started        86 powershell.exe 65->86         started        88 net.exe 65->88         started        90 curl.exe 65->90         started        92 net1.exe 67->92         started        94 conhost.exe 71->94         started        process16 file17 126 C:\Users\user\AppData\Local\Temp\um.bat, Unicode 77->126 dropped 96 python.exe 80->96         started        100 conhost.exe 80->100         started        102 net1.exe 82->102         started        104 python.exe 86->104         started        106 conhost.exe 86->106         started        108 net1.exe 88->108         started        process18 dnsIp19 130 ipinfo.io 34.117.59.81, 443, 49710, 49711 GOOGLE-AS-APGoogleAsiaPacificPteLtdSG United States 96->130 110 C:\Users\user\...\bR00OO9muZQaEx6a.dll, PE32+ 96->110 dropped 132 api.telegram.org 149.154.166.110, 443, 49716, 49717 TELEGRAMRU United Kingdom 104->132 112 C:\Users\user\...\1VktV6WhwAaO4vRH.dll, PE32+ 104->112 dropped file20
Threat name:
Text.Trojan.Generic
Status:
Suspicious
First seen:
2026-03-07 07:56:13 UTC
File Type:
Text (Batch)
AV detection:
4 of 24 (16.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
defense_evasion execution spyware stealer
Behaviour
Kills process with taskkill
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Contacts third-party web service commonly abused for C2
Looks up external IP address via web service
Drops startup file
Executes dropped EXE
Loads dropped DLL
Reads user/profile data of web browsers
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Malware Config
Dropper Extraction:
https://github.com/m1-nc/roukii/raw/main/up.png
https://github.com/m1-nc/roukii/raw/main/m1-nc.zip
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments