MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a8a98322ac04825ae3dac08e12ed29383d966fec2033a8002e9d75e71b57d406. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Pony


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a8a98322ac04825ae3dac08e12ed29383d966fec2033a8002e9d75e71b57d406
SHA3-384 hash: 7774d7349356b6fc7060414940236744a621b1ce50a321fe9efac25fb66289568b71419300c97cc51bf535bf0c49f1ad
SHA1 hash: 8daed3fd2a32abc1b6e31f79e3c9279e801274d1
MD5 hash: bd750f258dcb1715d244a8a712649d02
humanhash: spaghetti-network-moon-salami
File name:a8a98322ac04825ae3dac08e12ed29383d966fec2033a8002e9d75e71b57d406
Download: download sample
Signature Pony
File size:471'040 bytes
First seen:2020-03-24 07:30:37 UTC
Last seen:2020-03-24 09:50:55 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 49d3391c6a1655a57f48db5bb00eb76e (1 x Pony)
ssdeep 6144:Jz2pgPKO9/CYGKigun3B78PTc5lIW2MB8+mWRwhvhkPjwyKDN/:wgiO9/LGh7R7gTcIWxB8+mjwja
Threatray 3'648 similar samples on MalwareBazaar
TLSH 84A44CA595D2001DEAA2A5763AAC1097D99CCD7B2DD851FC0313803BBD3BE576F420EB
Reporter Marco_Ramilli
Tags:exe Pony

Intelligence


File Origin
# of uploads :
2
# of downloads :
104
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Pony

Executable exe a8a98322ac04825ae3dac08e12ed29383d966fec2033a8002e9d75e71b57d406

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::EVENT_SINK_AddRef

Comments