Malicious
Malicious

255d3c1ed96f3f47ba1e10850963cf85

ZIP Archive
MD5: 255d3c1ed96f3f47ba1e10850963cf85
Size: 11.18 MB
application/zip
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 255d3c1ed96f3f47ba1e10850963cf85
Sha1 d5719c29505bdf5f1a168f8a47deaec071ac40a5
Sha256 ca194119f7a51d264abb63b7fa605437ad2108a5c49b13ea55413a3be43c352f
Sha384 78f4bc1c5bb2d05e00f8f732c6fbe0adc6a3bac589a829741c4022f68b1ee73aa88eb6b3bd4f2555534d65dd4005610b
Sha512 6acf8c4c06ec4e4cfe63cb74d2bf756d91fb56a7cba07e6661fdb66985b404919c7c7f61034a977f45889e352be3f2fabc754f9d571eece43ab2c919956c7a97
SSDeep 196608:8C915y7touuhH//rbTrbh6rMQhuH2vbRlCWDKnQukGcHL9JWSjXh:8ue7tbud/DbTvhoMQSCRBDKnQ5
TLSH DCB633472A7371863EE2DF0291281D308172FEA299074B6F6DF9236833F3B7549255B5
ABISPAY_Agent
Malicious
Overlay_ba7d973d.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0-preview.png
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
install_task.ps1
uninstall_task.ps1
config.sample.json
README.md
fonts
Pretendard-Bold.otf
Pretendard-Regular.otf
OFL-Pretendard.txt
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 5 STICH kept: 1secondary ignored: 4
bin 3img 1

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path arc:zip>scr:ps1~T1027~T1059.001
Shape arc:zip>scr:ps1
malicious 2 nodes
Deobfuscated PowerShell UNKNWOWNmalicious
"Starthuhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
"Starthuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
ABISPAY_Agent
Malicious
Overlay_ba7d973d.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0-preview.png
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
[PowerShell Command]
Malicious
install_task.ps1
uninstall_task.ps1
config.sample.json
README.md
fonts
Pretendard-Bold.otf
Pretendard-Regular.otf
OFL-Pretendard.txt
No malware configuration was found at this point.
Deobfuscated PowerShell UNKNWOWNmalicious
"Starthuhuhuhuhuhuhuhuhuhuhu
255d3c1ed96f3f47ba1e10850963cf85 › ABISPAY_Agent › install.cmd › [PowerShell Command]
Deobfuscated PowerShell UNKNWOWNmalicious
"Starthuhuhuhuhuhuhuhuhuhuhu
255d3c1ed96f3f47ba1e10850963cf85 › ABISPAY_Agent › uninstall.cmd › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙