MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2beab06a68f9fe2dbe40ae26497b0226293b67acc89d496b6863594dfd023597. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Pony


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 2beab06a68f9fe2dbe40ae26497b0226293b67acc89d496b6863594dfd023597
SHA3-384 hash: d11a5086bd3e42695f3148c5171f76dd69174068ce76222bf91be8c88a43d209490d41122c2fdc785c52a38e5b8666ee
SHA1 hash: 9d0a4749ab597a746d88ee1cfde4d6cb11a20940
MD5 hash: 8c4c1918414c907d3543762c26f66bc4
humanhash: happy-hydrogen-pennsylvania-fanta
File name:Akt sverki nachalo iyulya.001
Download: download sample
Signature Pony
File size:105'456 bytes
First seen:2020-07-03 08:30:12 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 3072:+W6DPXnNdv4RmRatEWrDoWR2mcHX8io2scUI7faS:16/nrv4RmRkNyHXM2s7S
TLSH FEA31252D6D27036B08DD521FC9187D14A3A03E2048E6387FA917B5D4F5422A7CEE9FE
Reporter abuse_ch
Tags:001 Downloader.Pony


Avatar
abuse_ch
Malspam distributing Downloader.Pony:

HELO: szugan.ru
Sending IP: 84.17.13.118
From: Жанна Медведева <turkova@szugan.ru>
Reply-To: Жанна Медведева <tarasovaek55@rambler.ru>
Subject: Сверка 3е июля
Attachment: Akt sverki nachalo iyulya.001 (contains "Akt sverki nachalo iyulya.exe")

Pony C2:
http://139.180.214.192/p/z05857687.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
99
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-07-03 08:32:05 UTC
AV detection:
18 of 48 (37.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Pony

rar 2beab06a68f9fe2dbe40ae26497b0226293b67acc89d496b6863594dfd023597

(this sample)

  
Dropping
Downloader.Pony
  
Delivery method
Distributed via e-mail attachment

Comments