MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3690c82ee5cd4896e05585a9b871541b545631dab62f5de0abd48054c93bdc09. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Pony


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 3690c82ee5cd4896e05585a9b871541b545631dab62f5de0abd48054c93bdc09
SHA3-384 hash: f16aa4327925440b63cb48aa3e645b7a1cddbc698f7b9fb5d8f32e49a28f6040de911037e69e335a9eab7045e54ae23e
SHA1 hash: 9325a3085d30a18db01fbe429062bc2d87ac9ec2
MD5 hash: bcbe822e4f2b748f772301cc59030fd7
humanhash: queen-carbon-sodium-mirror
File name:Rincian Perbankan dan Transfer Formulir Aplikasi_pdf.gz
Download: download sample
Signature Pony
File size:322'307 bytes
First seen:2020-05-06 10:45:19 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 6144:5Dx2veDgkSmC4ac7xR8DodY2S3QlJx1CgzuI+7b3NFKAk:z2ve04RrK2S3kv1B5
TLSH FA642375B413348E2F645229E099DD277FB6AC99422568D71DA062218CCCFC131FEEF6
Reporter abuse_ch
Tags:Citibank Downloader.Pony gz Pony


Avatar
abuse_ch
Malspam distributing Downloader.Pony:

HELO: mail-gate5.qwords.net
Sending IP: 43.252.136.13
From: Citibank <janto.huang@beton.co.id>
Subject: ٹی ٹی ٹرانزیکشن کی ادائیگی کے بارے میں اطلاع سے انکار - "واپسی دفتر کو دوبارہ رد" کیا گیا - BATK16xxxxxxxxxxxx
Attachment: Rincian Perbankan dan Transfer Formulir Aplikasi_pdf.gz (contains "Rincian Perbankan dan Transfer Formulir Aplikasi_pdf.exe")

Pony C2:
http://imaad-international.org/miracle/panelnew/gate.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
457
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-06 11:35:49 UTC
File Type:
Binary (Archive)
Extracted files:
40
AV detection:
24 of 31 (77.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Pony

gz 3690c82ee5cd4896e05585a9b871541b545631dab62f5de0abd48054c93bdc09

(this sample)

  
Dropping
Downloader.Pony
  
Delivery method
Distributed via e-mail attachment

Comments