MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 986462b76b2e496caa135b897e0329909bc2547dfbd4cbec97ee0c344e3df4df. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Pony


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 986462b76b2e496caa135b897e0329909bc2547dfbd4cbec97ee0c344e3df4df
SHA3-384 hash: e7bf1e151e8122163eb5deaf4420814866d4e06a1e729643e7cee8639ade008b0fda4145ad3170d5288fadd8de6b5060
SHA1 hash: 3d4af64ba0f8c7dd62db9f3f74dfaeafb1696b0f
MD5 hash: 2f9945befaa4a7d58a5efd17e812dc2d
humanhash: floor-pip-leopard-bluebird
File name:Tovar na vozvrat za etot mesyac.001
Download: download sample
Signature Pony
File size:131'168 bytes
First seen:2020-07-09 14:46:54 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 3072:o5jXhYz9lbKj7pqbmAMfir+fY/wVDBYX31UOF1VRensvl:6jXc9187pImnfaohBzi1/uU
TLSH 62D312A5493424D1BA9E53BB993300696D0ED10FC6F7A21B47893E3CEBCFA08456F4C2
Reporter abuse_ch
Tags:001 Downloader.Pony geo RUS


Avatar
abuse_ch
Malspam distributing Downloader.Pony:

HELO: smtp.ugramail.ru
Sending IP: 217.20.80.59
From: Полина Мамонтова <analitika@ugramail.ru>
Reply-To: Полина Мамонтова <tarasovaek59@rambler.ru>
Subject: Заявка, возврат июль
Attachment: Tovar na vozvrat za etot mesyac.001 (contains "Tovar na vozvrat za etot mesyac.exe")

Pony C2:
http://172.105.48.152/p/z05857687.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
115
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-07-09 14:48:08 UTC
AV detection:
14 of 29 (48.28%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Pony

rar 986462b76b2e496caa135b897e0329909bc2547dfbd4cbec97ee0c344e3df4df

(this sample)

  
Dropping
Downloader.Pony
  
Delivery method
Distributed via e-mail attachment

Comments