logo

DBatLoader Distributed via CMD Files

ID: 1bd08d32-f9be-581e-b3ef-a562444e30c6

STIX ID: report--1bd08d32-f9be-581e-b3ef-a562444e30c6

Feed Name: ASEC

Threat Score
65/100

Date Published: 2024-06-27

Date Updated: 2026-04-26

Author: Vanish

...
...

AhnLab ASEC reports discovery of DBatLoader (ModiLoader) being distributed via compressed CMD files attached to phishing emails; attackers hide a Base64-encoded EXE inside a UTF-16LE CMD, leverage extrac32.exe and certutil -decodehex (with forced types) to produce and execute a .pif, and then load a Delphi-based EXE that loads a DLL and retrieves additional payloads. The report includes detection names, MD5 hashes, and mitigation recommendations (email caution, AV updates, OS/browser patches).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.