MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3f2ee0c351d69881093345327a161de9e896dcf2d70c6db2a1b5de594db37dff. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Pony


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 3f2ee0c351d69881093345327a161de9e896dcf2d70c6db2a1b5de594db37dff
SHA3-384 hash: 5f4c84b2d946756ba24053185b1ce4471232521861ef89fa29824ae50965fd946d0ed2954747a8c732486fc212342166
SHA1 hash: 5eb064c555545181d2db0e166ef63cf3d6453991
MD5 hash: a27ec6697bb04491e94af81246efa3be
humanhash: paris-stream-glucose-violet
File name:HSBC Beneficiary Payments.gz
Download: download sample
Signature Pony
File size:886'295 bytes
First seen:2020-08-04 10:17:05 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 24576:HRvJuZlkwd3fPLkFOnvtacNu5NHAur0Fsp/3hAfC:xvkZWXIdu7Aa0F8/j
TLSH F11523C6DD329FEE72697CEC411A92F080BD6415B233E2A55B14215FDEEF232259432E
Reporter abuse_ch
Tags:gz HSBC Pony


Avatar
abuse_ch
Malspam distributing Pony:

HELO: mxserver17-out4.masterweb.com
Sending IP: 103.25.223.154
From: HSBC BANK <advising.service.26040270.825605.2830646254@securemail-advising.hsbc.com>
Subject: HSBC Beneficiary Payments Advice
Attachment: HSBC Beneficiary Payments.gz (contains "HSBC Beneficiary Payments.exe")

Pony C2:
http://seabreezeapartments.co.uk/bb/panelnew/gate.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
737
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Kryptik
Status:
Malicious
First seen:
2020-07-29 12:28:37 UTC
AV detection:
24 of 48 (50.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Pony

gz 3f2ee0c351d69881093345327a161de9e896dcf2d70c6db2a1b5de594db37dff

(this sample)

  
Dropping
Pony
  
Delivery method
Distributed via e-mail attachment

Comments