MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6a581c0c07ceb888ea418fccffd5efba33b9fd6561be1bcf90b0d6ba4deefd05. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Pony


Vendor detections: 16


Intelligence 16 IOCs YARA File information Comments

SHA256 hash: 6a581c0c07ceb888ea418fccffd5efba33b9fd6561be1bcf90b0d6ba4deefd05
SHA3-384 hash: 78ec37b29d93e42238fc3822b8707043e37b7d782c88bc3591bc135f6501fb2ab7173abea7bb2de26acb1a71ff19cb88
SHA1 hash: f87e895764af09a96ce7b44cd7a0cc17eb5986e2
MD5 hash: 0365bbbde06f465f860a73f5fd7b38da
humanhash: tennessee-nebraska-bluebird-blossom
File name:0365bbbde06f465f860a73f5fd7b38da.exe
Download: download sample
Signature Pony
File size:193'552 bytes
First seen:2023-12-18 17:45:07 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 60fd1f8a4d62b3c300aa0a0b884a4c8f (3 x Pony)
ssdeep 3072:9orjHktzHeO/3wBP/n61FAMMnVv4L1LW6xfp:yr4Hv5MVv4xL7v
TLSH T12614DF61B7831893F611C077C25F4FA0DAA1ADB40F99BF8762F4E93C2CD6850AE50729
TrID 29.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
22.7% (.EXE) Win16 NE executable (generic) (5038/12/1)
20.3% (.EXE) Win32 Executable (generic) (4505/5/1)
9.1% (.EXE) OS/2 Executable (generic) (2029/13)
9.0% (.EXE) Generic Win/DOS Executable (2002/3)
Reporter abuse_ch
Tags:exe Pony


Avatar
abuse_ch
Pony C2:
http://66.175.212.25/pony/gate.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
345
Origin country :
NL NL
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Reading critical registry keys
Stealing user critical data
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
overlay xpack
Result
Threat name:
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Detected unpacking (changes PE section rights)
Detected unpacking (creates a PE file in dynamic memory)
Detected unpacking (overwrites its own PE header)
Found malware configuration
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Tries to steal Mail credentials (via file registry)
Yara detected aPLib compressed binary
Yara detected Pony
Behaviour
Behavior Graph:
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2023-12-17 06:04:00 UTC
File Type:
PE (Exe)
AV detection:
35 of 37 (94.59%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
Result
Malware family:
Score:
  10/10
Tags:
family:pony collection discovery rat spyware stealer
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of UnmapMainImage
outlook_win_path
Accesses Microsoft Outlook accounts
Accesses Microsoft Outlook profiles
Checks installed software on the system
Reads data files stored by FTP clients
Reads user/profile data of web browsers
Pony,Fareit
Malware Config
C2 Extraction:
http://209.59.216.75/pony/gate.php
http://66.175.212.25/pony/gate.php
Unpacked files
SH256 hash:
5b3b33dc65e7d0f6bdc6db589b113188a0f74b15bfa4fc35213da92d2bed6ff1
MD5 hash:
c1acea4f952c16ba7d0ba1fcbcb87c92
SHA1 hash:
14767e074221e28ac5ddbf095b41c7d9ce178f2f
Detections:
win_pony_auto win_pony_g0
SH256 hash:
6a581c0c07ceb888ea418fccffd5efba33b9fd6561be1bcf90b0d6ba4deefd05
MD5 hash:
0365bbbde06f465f860a73f5fd7b38da
SHA1 hash:
f87e895764af09a96ce7b44cd7a0cc17eb5986e2
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments