MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5592f091a845c7e32d8c66d5efa561fa9d0ce09c88a54927f8f43ca31373cf93. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Pony


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 5592f091a845c7e32d8c66d5efa561fa9d0ce09c88a54927f8f43ca31373cf93
SHA3-384 hash: 28e4499919712aeb49954ef175f0be002d2308a11848d24d861f346e23eb3ebad0f99336ff435c4d91b17e17b71f2553
SHA1 hash: 92f38f2619294de002798d641e0729c69ee60d97
MD5 hash: 855461d7cf19eba28b8c896b6c03470d
humanhash: kansas-seventeen-pennsylvania-pip
File name:5592f091a845c7e32d8c66d5efa561fa9d0ce09c88a54927f8f43ca31373cf93
Download: download sample
Signature Pony
File size:588'288 bytes
First seen:2020-11-11 10:53:31 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash ae39f2e1fd8e138e6db0871a4edbc740 (4 x Pony)
ssdeep 12288:ZzoFnOngcUlsPssmHK6Ar8WEsu0qPCb1M/+BbXuDU:ZzbgrsItHWEsu0qPQeI
Threatray 129 similar samples on MalwareBazaar
TLSH 8DC49E26B2B09437C1222A7D881B5BAC6435FE213E1D7A866FF51D0C9F397413D1A29F
Reporter seifreed
Tags:Pony

Intelligence


File Origin
# of uploads :
1
# of downloads :
372
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Unauthorized injection to a recently created process
Reading critical registry keys
DNS request
Sending an HTTP POST request
Sending an HTTP GET request
Creating a file in the %temp% directory
Running batch commands
Creating a process with a hidden window
Stealing user critical data
Brute forcing passwords of local accounts
Deleting of the original file
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.LokiBot
Status:
Malicious
First seen:
2020-11-11 10:54:26 UTC
AV detection:
28 of 29 (96.55%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
5592f091a845c7e32d8c66d5efa561fa9d0ce09c88a54927f8f43ca31373cf93
MD5 hash:
855461d7cf19eba28b8c896b6c03470d
SHA1 hash:
92f38f2619294de002798d641e0729c69ee60d97
SH256 hash:
778160c69455ae5dd5388ec57e2c3388eec81a24a9537e8076f343294d6acb8a
MD5 hash:
8090481e4789f3f361388dc80f327312
SHA1 hash:
156f278c61abe310f2b8234c01ebc508950fe314
Detections:
win_pony_g0 win_pony_auto
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments