MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 6a581c0c07ceb888ea418fccffd5efba33b9fd6561be1bcf90b0d6ba4deefd05. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Pony
Vendor detections: 16
| SHA256 hash: | 6a581c0c07ceb888ea418fccffd5efba33b9fd6561be1bcf90b0d6ba4deefd05 |
|---|---|
| SHA3-384 hash: | 78ec37b29d93e42238fc3822b8707043e37b7d782c88bc3591bc135f6501fb2ab7173abea7bb2de26acb1a71ff19cb88 |
| SHA1 hash: | f87e895764af09a96ce7b44cd7a0cc17eb5986e2 |
| MD5 hash: | 0365bbbde06f465f860a73f5fd7b38da |
| humanhash: | tennessee-nebraska-bluebird-blossom |
| File name: | 0365bbbde06f465f860a73f5fd7b38da.exe |
| Download: | download sample |
| Signature | Pony |
| File size: | 193'552 bytes |
| First seen: | 2023-12-18 17:45:07 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 60fd1f8a4d62b3c300aa0a0b884a4c8f (3 x Pony) |
| ssdeep | 3072:9orjHktzHeO/3wBP/n61FAMMnVv4L1LW6xfp:yr4Hv5MVv4xL7v |
| TLSH | T12614DF61B7831893F611C077C25F4FA0DAA1ADB40F99BF8762F4E93C2CD6850AE50729 |
| TrID | 29.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 22.7% (.EXE) Win16 NE executable (generic) (5038/12/1) 20.3% (.EXE) Win32 Executable (generic) (4505/5/1) 9.1% (.EXE) OS/2 Executable (generic) (2029/13) 9.0% (.EXE) Generic Win/DOS Executable (2002/3) |
| Reporter | |
| Tags: | exe Pony |
Intelligence
File Origin
# of uploads :
1
# of downloads :
345
Origin country :
NLVendor Threat Intelligence
Detection:
Pony
Detection(s):
Result
Verdict:
Malware
Maliciousness:
Behaviour
Reading critical registry keys
Stealing user critical data
Verdict:
Malicious
Threat level:
10/10
Confidence:
100%
Tags:
overlay xpack
Verdict:
Malicious
Labled as:
Fugrafa.Generic
Malware family:
Pony
Verdict:
Malicious
Result
Threat name:
Pony
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Detected unpacking (changes PE section rights)
Detected unpacking (creates a PE file in dynamic memory)
Detected unpacking (overwrites its own PE header)
Found malware configuration
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Tries to steal Mail credentials (via file registry)
Yara detected aPLib compressed binary
Yara detected Pony
Behaviour
Behavior Graph:
Score:
100%
Verdict:
Malware
File Type:
PE
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2023-12-17 06:04:00 UTC
File Type:
PE (Exe)
AV detection:
35 of 37 (94.59%)
Threat level:
5/5
Detection(s):
Malicious file
Verdict:
malicious
Label(s):
pony
Result
Malware family:
pony
Score:
10/10
Tags:
family:pony collection discovery rat spyware stealer
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of UnmapMainImage
outlook_win_path
Accesses Microsoft Outlook accounts
Accesses Microsoft Outlook profiles
Checks installed software on the system
Reads data files stored by FTP clients
Reads user/profile data of web browsers
Pony,Fareit
Malware Config
C2 Extraction:
http://209.59.216.75/pony/gate.php
http://66.175.212.25/pony/gate.php
http://66.175.212.25/pony/gate.php
Unpacked files
SH256 hash:
5b3b33dc65e7d0f6bdc6db589b113188a0f74b15bfa4fc35213da92d2bed6ff1
MD5 hash:
c1acea4f952c16ba7d0ba1fcbcb87c92
SHA1 hash:
14767e074221e28ac5ddbf095b41c7d9ce178f2f
Detections:
win_pony_auto
win_pony_g0
SH256 hash:
6a581c0c07ceb888ea418fccffd5efba33b9fd6561be1bcf90b0d6ba4deefd05
MD5 hash:
0365bbbde06f465f860a73f5fd7b38da
SHA1 hash:
f87e895764af09a96ce7b44cd7a0cc17eb5986e2
Malware family:
Pony
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Farheyt
Score:
0.80
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.