🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ca194119f7a51d264abb63b7fa605437ad2108a5c49b13ea55413a3be43c352f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 13 File information Comments

SHA256 hash: ca194119f7a51d264abb63b7fa605437ad2108a5c49b13ea55413a3be43c352f
SHA3-384 hash: f5c5ffc76ccd68b8a8081419c8c42c28e39218e04a1715d0fd2b7a5a247fd4b87e8288666fe5b68d72ecc1872400afcc
SHA1 hash: d5719c29505bdf5f1a168f8a47deaec071ac40a5
MD5 hash: 255d3c1ed96f3f47ba1e10850963cf85
humanhash: twelve-tennis-may-sweet
File name:ca194119f7a51d264abb63b7fa605437ad2108a5c49b13ea55413a3be43c352f.bin
Download: download sample
File size:11'181'739 bytes
First seen:2026-10-03 07:04:57 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 196608:8C915y7touuhH//rbTrbh6rMQhuH2vbRlCWDKnQukGcHL9JWSjXh:8ue7tbud/DbTvhoMQSCRBDKnQ5
TLSH T1DCB633472A7371863EE2DF0291281D308172FEA299074B6F6DF9236833F3B7549255B5
TrID 66.6% (.XPI) Mozilla Firefox browser extension (8000/1/1)
33.3% (.ZIP) ZIP compressed archive (4000/1)
Magika Tuxxin
Reporter whack_sh
Tags:zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
142
Origin country :
US US
File Archive Information

This file archive contains 10 file(s), sorted by their relevance:

File name:install.cmd
File size:276 bytes
SHA256 hash: 686dcbbc1180f83da0b081491c13ada752dda287fc682049efbdafa4f380e1f2
MD5 hash: 5fdb591d6fc959da965d891363130536
MIME type:text/x-msdos-batch
File name:ABISPAY_Agent.exe
File size:9'260'339 bytes
SHA256 hash: 95b2ee6152ee5c5548c186eb37b93ed41964a22bf7648c6be19ee8175856cb57
MD5 hash: 944490cea65c71f0181587d32f0218aa
MIME type:application/x-dosexec
File name:uninstall.cmd
File size:242 bytes
SHA256 hash: 1ae7fd038f82e53dae4ad11b6c2ff63ea265abe7c0b58432fe1b7a0fb71eb1c9
MD5 hash: 59bb864a046718308658512d02f66dea
MIME type:text/x-msdos-batch
File name:README.md
File size:5'923 bytes
SHA256 hash: baaa1274a893215736e9d0a68897113d4b220c0be4f82022f3e56d839959e774
MD5 hash: 895e627017a4e26e79265af83964f606
MIME type:text/plain
File name:Pretendard-Regular.otf
File size:1'574'352 bytes
SHA256 hash: 3ffbacde6ab8411f1d2db54bb9b1f0b3ee2a738932033722cf0388c06aed1c93
MD5 hash: 84c0ea9d65324c758c8bd9686207afea
MIME type:application/vnd.ms-opentype
File name:install_task.ps1
File size:1'506 bytes
SHA256 hash: 9ea65dca3004fe97808f94c9b1979edfa887b570dce6ded6a29cdd8729b3d635
MD5 hash: df10fa63b2c2162fde6cb7ee124f2c26
MIME type:text/plain
File name:Pretendard-Bold.otf
File size:1'576'660 bytes
SHA256 hash: 2e91915fab54df71cc9598ebf608b2bdb54c6fe3c066ac61dff0bc44fca71cc7
MD5 hash: f8a9b84216af5155ffe0e8661203f36f
MIME type:application/vnd.ms-opentype
File name:uninstall_task.ps1
File size:394 bytes
SHA256 hash: e85b7ebf7e6dae8e71a5aa3ee50f3bbc80014097a6452764db557832e9cda59a
MD5 hash: 5df106998f0f7915caa5a6590446b492
MIME type:text/plain
File name:config.sample.json
File size:960 bytes
SHA256 hash: 6ca885d279a8b6cf4e9116df44c2f68ebbe6b2fb4a2c7044d867a80ec2958f94
MD5 hash: f6d19b80db359f7300eec7011a58f18d
MIME type:application/json
File name:OFL-Pretendard.txt
File size:4'418 bytes
SHA256 hash: d31ddd9f2bed32fd7e302a205cf2380ba0de6529152d239ef99cfb6f261bfc04
MD5 hash: 87daebf900acc60034b603264ed71d8e
MIME type:text/plain
Vendor Threat Intelligence
Verdict:
Malware
YARA:
3 match(es)
Tags:
DeObfuscated Executable PDB Path PE (Portable Executable) PE File Layout PowerShell T1027 T1059.001 Zip Archive
Threat name:
Binary.Trojan.Generic
Status:
Suspicious
First seen:
2026-10-03 07:14:24 UTC
File Type:
Binary (Archive)
Extracted files:
714
AV detection:
3 of 24 (12.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
execution pyinstaller ransomware
Behaviour
Suspicious use of WriteProcessMemory
Loads dropped DLL
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:detect_powershell
Author:daniyyell
Description:Detects suspicious PowerShell activity related to malware execution
Rule name:Detect_PyInstaller
Author:Obscurity Labs LLC
Description:Detects PyInstaller compiled executables across platforms
Rule name:Detect_Zoom_Invite_malware_RAT_C2
Author:daniyyell
Description:Detects Zoom Invite Call Leading to Malware Hosted in Telegram C2
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:PyInstaller
Author:@bartblaze
Description:Identifies executable converted using PyInstaller. This rule by itself does NOT necessarily mean the detected file is malicious.
Rule name:SCRIPT_Dropper_Unknown_ForgeAuto_aaa464f7
Author:Marjoriefort
Description:Detects Unknown (script_js, etat binaire)
Rule name:SUSP_Scheduled_Tasks_Create_From_Susp_Dir
Author:SECUINFRA Falcon Team
Description:Detects a PowerShell Script that creates a Scheduled Task that runs from an suspicious directory
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:upxHook
Author:@r3dbU7z
Description:Detect artifacts from 'upxHook' - modification of UPX packer
Reference:https://bazaar.abuse.ch/sample/6352be8aa5d8063673aa428c3807228c40505004320232a23d99ebd9ef48478a/
Rule name:WIN_Sample_Unique_69354b41
Author:Marjoriefort
Description:Specimen unique (soumission Bazaar) - strings distinctifs propres au sample
Reference:69354b41e10daf03d3f3af881b32d5c0fec56b1cfe96629fd4c5263413a42854.exe

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

zip ca194119f7a51d264abb63b7fa605437ad2108a5c49b13ea55413a3be43c352f

(this sample)

  
Delivery method
Distributed via web download

Comments