MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 08e77caeac969a8b821faba7751935211a94dae64df33269c1aa9f147368341e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Pony


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 08e77caeac969a8b821faba7751935211a94dae64df33269c1aa9f147368341e
SHA3-384 hash: d1c2fdbbc3dc9f86379d0d97e67e3edb1e5a0c47bbf6e99b6e9ace519a5cdcb547acce219ea4ac31ff78d580942507c9
SHA1 hash: 2b1919a05516af5b5d50bcebd1114c19e6c94df9
MD5 hash: 827f0a8acd2d4921f3f406a37d50c57f
humanhash: black-utah-grey-speaker
File name:BL Draft Original Shipping Document.zip
Download: download sample
Signature Pony
File size:126'687 bytes
First seen:2020-06-24 06:31:30 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 3072:2iYwnZ5gfiYf7KTQzl8W/PVHbXsblfqX4Gk9q:26ZDYfmT8yc9buE4Gj
TLSH 76C312AFC5130FFFBA1F63223E84AE147AA5B9F8D107AD34E51D24E94C98A4E2452D04
Reporter abuse_ch
Tags:DHL Downloader.Pony Pony zip


Avatar
abuse_ch
Malspam distributing Downloader.Pony:

HELO: chi-node5.websitehostserver.net
Sending IP: 99.198.97.170
From: DHL EXPRESS<boutiquefiorella@hotmail.com>
Subject: DHL AWB Express Shipment No: 2058917206
Attachment: BL Draft Original Shipping Document.zip (contains "BL Draft & Original Shipping Document.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
700
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-24 06:33:03 UTC
AV detection:
28 of 48 (58.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Pony

zip 08e77caeac969a8b821faba7751935211a94dae64df33269c1aa9f147368341e

(this sample)

  
Dropping
Downloader.Pony
  
Delivery method
Distributed via e-mail attachment

Comments