MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0d1de7409f5d91b199b669e067151bcc5789ede5f80daa3e961b43e21609901f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Pony


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 0d1de7409f5d91b199b669e067151bcc5789ede5f80daa3e961b43e21609901f
SHA3-384 hash: 04c86c0e60c4f26793301a299e9e913b34dcc14b86cb90f9b377859d1910c0a8ecde16f84fa95eb492f33b6a70f593af
SHA1 hash: 9d4880d4715c826d9b0f74cc6b8e265784c4f746
MD5 hash: a049d28541fd2d12eb22cde4df9cb4f9
humanhash: golf-alaska-quiet-romeo
File name:0d1de7409f5d91b199b669e067151bcc5789ede5f80daa3e961b43e21609901f
Download: download sample
Signature Pony
File size:588'288 bytes
First seen:2020-11-12 14:07:13 UTC
Last seen:2024-07-24 11:10:40 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash ae39f2e1fd8e138e6db0871a4edbc740 (4 x Pony)
ssdeep 12288:YEVnfYRfMSsAsR/2q1NLqxsA0qPCb1M/+BbXuDU:YsMMl/nTqxsA0qPQeI
TLSH 49C49F26B2B09437C1226A7D880B5BAC6435FE213E1D7A866FF51D0C9F397413D1A29F
Reporter seifreed
Tags:Pony

Intelligence


File Origin
# of uploads :
2
# of downloads :
383
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Unauthorized injection to a recently created process
Reading critical registry keys
DNS request
Sending an HTTP POST request
Sending an HTTP GET request
Creating a file in the %temp% directory
Running batch commands
Creating a process with a hidden window
Stealing user critical data
Brute forcing passwords of local accounts
Deleting of the original file
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.LokiBot
Status:
Malicious
First seen:
2020-11-12 14:08:57 UTC
AV detection:
28 of 29 (96.55%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
0d1de7409f5d91b199b669e067151bcc5789ede5f80daa3e961b43e21609901f
MD5 hash:
a049d28541fd2d12eb22cde4df9cb4f9
SHA1 hash:
9d4880d4715c826d9b0f74cc6b8e265784c4f746
SH256 hash:
778160c69455ae5dd5388ec57e2c3388eec81a24a9537e8076f343294d6acb8a
MD5 hash:
8090481e4789f3f361388dc80f327312
SHA1 hash:
156f278c61abe310f2b8234c01ebc508950fe314
Detections:
win_pony_g0 win_pony_auto
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments