MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 3f2ee0c351d69881093345327a161de9e896dcf2d70c6db2a1b5de594db37dff. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Pony
Vendor detections: 4
| SHA256 hash: | 3f2ee0c351d69881093345327a161de9e896dcf2d70c6db2a1b5de594db37dff |
|---|---|
| SHA3-384 hash: | 5f4c84b2d946756ba24053185b1ce4471232521861ef89fa29824ae50965fd946d0ed2954747a8c732486fc212342166 |
| SHA1 hash: | 5eb064c555545181d2db0e166ef63cf3d6453991 |
| MD5 hash: | a27ec6697bb04491e94af81246efa3be |
| humanhash: | paris-stream-glucose-violet |
| File name: | HSBC Beneficiary Payments.gz |
| Download: | download sample |
| Signature | Pony |
| File size: | 886'295 bytes |
| First seen: | 2020-08-04 10:17:05 UTC |
| Last seen: | Never |
| File type: | gz |
| MIME type: | application/gzip |
| ssdeep | 24576:HRvJuZlkwd3fPLkFOnvtacNu5NHAur0Fsp/3hAfC:xvkZWXIdu7Aa0F8/j |
| TLSH | F11523C6DD329FEE72697CEC411A92F080BD6415B233E2A55B14215FDEEF232259432E |
| Reporter | |
| Tags: | gz HSBC Pony |
abuse_ch
Malspam distributing Pony:HELO: mxserver17-out4.masterweb.com
Sending IP: 103.25.223.154
From: HSBC BANK <advising.service.26040270.825605.2830646254@securemail-advising.hsbc.com>
Subject: HSBC Beneficiary Payments Advice
Attachment: HSBC Beneficiary Payments.gz (contains "HSBC Beneficiary Payments.exe")
Pony C2:
http://seabreezeapartments.co.uk/bb/panelnew/gate.php
Intelligence
File Origin
# of uploads :
1
# of downloads :
737
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Kryptik
Status:
Malicious
First seen:
2020-07-29 12:28:37 UTC
AV detection:
24 of 48 (50.00%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Gamarue
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
Pony
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.