MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a0a2d1fc3ad4683f8cdd5ab29312f5c515e8543404926a94db641022c9ab40f8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Pony


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a0a2d1fc3ad4683f8cdd5ab29312f5c515e8543404926a94db641022c9ab40f8
SHA3-384 hash: 32b5aecef1f81f53f3df421b5e43c059ca4c3b6dd1062322b214b2f8b5c1fdda3e147b5860309133e461397f49239df0
SHA1 hash: 06f925678d81713afc4b98f6ccb79ee577022133
MD5 hash: aaadb684ed709d76869a3f281cc0df46
humanhash: music-arizona-william-grey
File name:Dokumenty, sverka za ves aprel.001
Download: download sample
Signature Pony
File size:135'995 bytes
First seen:2020-05-21 09:53:13 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 3072:FpiKFe5nixvI40s7kTUlfU29ro/O8fbODi0FxPfVAmdn:FpTFZQ402UBfEDFRfVRn
TLSH 26D3137CC7A073AB49F164ECB11BD5A1E9FA87A2606BC6346757A4A453873C340907CC
Reporter abuse_ch
Tags:001 Pony


Avatar
abuse_ch
Malspam distributing Pony:

HELO: mail.letuin.ru
Sending IP: 5.8.179.65
From: Валентина Рыбакова <hrm1-spb-sz@letuin.ru>
Subject: =?utf-8?B?0JTQvtC60YPQvNC10L3RgtGLINC60L7QvdC10YYg0L/R?==?utf-8?B?gNC+0YjQu9C+0LPQviDQvNC10YHRj9GG0LA=?=
Attachment: Dokumenty, sverka za ves aprel.001 (contains "Dokumenty, sverka za ves' aprel'.exe")

Pony C2:
http://142.202.188.254/p/z05857687.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
457
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Rtm
Status:
Malicious
First seen:
2020-05-21 10:37:05 UTC
AV detection:
17 of 48 (35.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Pony

rar a0a2d1fc3ad4683f8cdd5ab29312f5c515e8543404926a94db641022c9ab40f8

(this sample)

  
Dropping
Pony
  
Delivery method
Distributed via e-mail attachment

Comments