MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 60dbd25b16ab3e850b59d57cb96eb19f557cae3cef5c7e2fdd8919c70a5ab81e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Pony


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 60dbd25b16ab3e850b59d57cb96eb19f557cae3cef5c7e2fdd8919c70a5ab81e
SHA3-384 hash: b6b6dbb72383ac9073aaf75cdb1d148f360e3c30b5d968180a0ce36d28a57c9a63bc577fe6178dc76e34cdf7ad1f7312
SHA1 hash: 05cde74ae6c50d0ae5f0dfaa0bf4fedbc34a58c5
MD5 hash: 35056b1cb2f552320c8564e8f735b391
humanhash: don-alanine-happy-london
File name:855461d7cf19eba28b8c896b6c03470d
Download: download sample
Signature Pony
File size:588'288 bytes
First seen:2020-11-17 11:30:50 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash ae39f2e1fd8e138e6db0871a4edbc740 (4 x Pony)
ssdeep 12288:eK9Dn0RR7gZ8YMrsIBRX8IFIsF0qPCb1M/+BbXuDU:eKuRi8fvTFIsF0qPQeI
TLSH 2FC49E26B2A09437C1126A7D880B5BAC6435FE213E1D7A866FF52D0C9F397413D1A39F
Reporter seifreed
Tags:Pony

Intelligence


File Origin
# of uploads :
1
# of downloads :
455
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Unauthorized injection to a recently created process
Reading critical registry keys
DNS request
Sending an HTTP POST request
Sending an HTTP GET request
Creating a file in the %temp% directory
Running batch commands
Creating a process with a hidden window
Stealing user critical data
Brute forcing passwords of local accounts
Deleting of the original file
Result
Verdict:
0
Threat name:
Win32.Trojan.LokiBot
Status:
Malicious
First seen:
2020-11-17 11:31:45 UTC
AV detection:
26 of 28 (92.86%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
60dbd25b16ab3e850b59d57cb96eb19f557cae3cef5c7e2fdd8919c70a5ab81e
MD5 hash:
35056b1cb2f552320c8564e8f735b391
SHA1 hash:
05cde74ae6c50d0ae5f0dfaa0bf4fedbc34a58c5
SH256 hash:
778160c69455ae5dd5388ec57e2c3388eec81a24a9537e8076f343294d6acb8a
MD5 hash:
8090481e4789f3f361388dc80f327312
SHA1 hash:
156f278c61abe310f2b8234c01ebc508950fe314
Detections:
win_pony_g0 win_pony_auto
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments