MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b9622cc44be9b2902beb1c399bcb15b6ee711d6d72ca1a9e82e96e957c231fe2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Pony


Vendor detections: 17


Intelligence 17 IOCs 1 YARA 20 File information Comments

SHA256 hash: b9622cc44be9b2902beb1c399bcb15b6ee711d6d72ca1a9e82e96e957c231fe2
SHA3-384 hash: ecea18df0dbaef9ecda25471982df9d3ca96c11ce57a3e330b6eb6c7e1a543116b9ca22d3cdc0725f560dfab6715be4c
SHA1 hash: e9a2dc6b6d60ea448e7b570bd2893f6efc0523fb
MD5 hash: 23bfaff7aff7af5807bac2244b7219e1
humanhash: princess-black-stairway-delta
File name:23bfaff7aff7af5807bac2244b7219e1.exe
Download: download sample
Signature Pony
File size:299'008 bytes
First seen:2026-07-20 18:35:35 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'125 x AgentTesla, 20'150 x Formbook, 12'362 x SnakeKeylogger)
ssdeep 3072:w9hnBRU+3Aclfnphf/9fZkBY8hk4KFNLtbYfuTJOH:wzBu+Qclrf/9fmBY8hkbFNLtkml
TLSH T1BA54ECC62A72DE2FF84C70F1D028B8629E1CBEA50DA7F6439CF6759D0479A124B541E3
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
dhash icon 308a8a8c888a8a30 (5 x SnakeKeylogger, 5 x CobaltStrike, 3 x DBatLoader)
Reporter abuse_ch
Tags:exe Pony


Avatar
abuse_ch
Pony C2:
http://giftorcharden.comxa.com/Panel/gate.php

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
http://giftorcharden.comxa.com/Panel/gate.php https://threatfox.abuse.ch/ioc/1854477/

Intelligence


File Origin
# of uploads :
1
# of downloads :
220
Origin country :
NL NL
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.1%
Tags:
phishing fareit lien zeus
Result
Verdict:
Malware
Maliciousness:

Behaviour
Launching a process
Searching for synchronization primitives
Сreating synchronization primitives
Creating a window
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
confuser confuserex confuserex confuserex corrupted evasive masquerade obfuscated obfuscated packed packed stealer
Verdict:
Malicious
File Type:
exe x32
First seen:
2015-07-09T04:51:00Z UTC
Last seen:
2026-07-22T00:12:00Z UTC
Hits:
~100
Result
Threat name:
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
.NET source code references suspicious native API functions
Antivirus detection for dropped file
C2 URLs / IPs found in malware configuration
Drops / launches Pony Loader self-deletion script - malware possibly based on Pony Loader leaked source code
Found malware configuration
Hides that the sample has been downloaded from the Internet (zone.identifier)
Icon mismatch, binary includes an icon from a different legit application in order to fool users
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Pony trojan / infostealer detected
Suricata IDS alerts for network traffic
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Tries to steal Mail credentials (via file registry)
Unusual module load detection (module proxying)
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected aPLib compressed binary
Yara detected Pony
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1945420 Sample: 9kkjW5O2S4.exe Startdate: 20/07/2026 Architecture: WINDOWS Score: 100 44 giftorcharden.comxa.com 2->44 56 Suricata IDS alerts for network traffic 2->56 58 Found malware configuration 2->58 60 Malicious sample detected (through community Yara rule) 2->60 62 9 other signatures 2->62 9 9kkjW5O2S4.exe 9 2->9         started        13 security.exe 3 2->13         started        signatures3 process4 file5 38 C:\Users\user\AppData\Roaming\security.exe, PE32 9->38 dropped 40 C:\Users\user\AppData\Roaming\hrxtg.xml, XML 9->40 dropped 42 C:\Users\user\AppData\...\9kkjW5O2S4.exe.log, ASCII 9->42 dropped 64 Drops / launches Pony Loader self-deletion script - malware possibly based on Pony Loader leaked source code 9->64 66 Tries to steal Mail credentials (via file registry) 9->66 68 Uses schtasks.exe or at.exe to add and modify task schedules 9->68 15 9kkjW5O2S4.exe 1 14 9->15         started        20 schtasks.exe 1 9->20         started        70 Hides that the sample has been downloaded from the Internet (zone.identifier) 13->70 72 Injects a PE file into a foreign processes 13->72 74 Unusual module load detection (module proxying) 13->74 22 security.exe 14 13->22         started        signatures6 process7 dnsIp8 46 giftorcharden.comxa.com 2.57.91.93, 49766, 49767, 80 AS-HOSTINGERCY Lithuania 15->46 34 C:\Users\user\AppData\Local\...\3885968.bat, ASCII 15->34 dropped 24 cmd.exe 1 15->24         started        26 conhost.exe 20->26         started        36 C:\Users\user\AppData\Local\...\3889546.bat, ASCII 22->36 dropped 48 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 22->48 50 Tries to steal Mail credentials (via file / registry access) 22->50 52 Tries to harvest and steal ftp login credentials 22->52 54 Tries to harvest and steal browser information (history, passwords, etc) 22->54 28 cmd.exe 1 22->28         started        file9 signatures10 process11 process12 30 conhost.exe 24->30         started        32 conhost.exe 28->32         started       
Verdict:
inconclusive
YARA:
12 match(es)
Tags:
.Net Executable Managed .NET PE (Portable Executable) PE File Layout SOS: 0.80 Win 32 Exe x86
Threat name:
ByteCode-MSIL.Trojan.Nagoot
Status:
Malicious
First seen:
2015-07-10 19:09:17 UTC
File Type:
PE (.Net Exe)
Extracted files:
61
AV detection:
26 of 36 (72.22%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:pony collection credential_access discovery execution persistence rat spyware stealer upx
Behaviour
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_win_path
Enumerates physical storage devices
Executes a command shell one-liner
System Location Discovery: System Language Discovery
ConfuserEx .NET packer
Suspicious use of SetThreadContext
UPX packed file
Accesses Microsoft Outlook accounts
Accesses Microsoft Outlook profiles
Checks installed software on the system
Checks computer location settings
Executes dropped EXE
Reads data files stored by FTP clients
Reads user/profile data of web browsers
Unsecured Credentials: Credentials In Files
Family: Pony,Fareit
Malware Config
C2 Extraction:
http://giftorcharden.comxa.com/Panel/gate.php
Unpacked files
SH256 hash:
b9622cc44be9b2902beb1c399bcb15b6ee711d6d72ca1a9e82e96e957c231fe2
MD5 hash:
23bfaff7aff7af5807bac2244b7219e1
SHA1 hash:
e9a2dc6b6d60ea448e7b570bd2893f6efc0523fb
SH256 hash:
f68512c9ba6a0a0e39218aeee9242039ceb3cf97058bdcc432ad6f76fa8153a5
MD5 hash:
a2c206b8b1c55e59c79f23475e47efde
SHA1 hash:
23c3c9a3f685cb14b1ac2d42e91a35ed930194c3
SH256 hash:
b9622cc44be9b2902beb1c399bcb15b6ee711d6d72ca1a9e82e96e957c231fe2
MD5 hash:
23bfaff7aff7af5807bac2244b7219e1
SHA1 hash:
e9a2dc6b6d60ea448e7b570bd2893f6efc0523fb
SH256 hash:
5903342dd817a658a9e3fe48e54c923122f04420bbde613a18ee9743aafe0347
MD5 hash:
16ffe2fdfeacfabb844a77cb30dbe803
SHA1 hash:
fbd5116d7460ec37beb6eb2291544445d87d830e
SH256 hash:
c1be4c71dfd5be13233d20c7bab32ee4aff40b05f0d2d18896b30fcc4e2bc58d
MD5 hash:
4eadc67ccec335a2c7651cc1a19dbdcf
SHA1 hash:
08356fe16778da5be822bf62a2ec1bb3d8ebf919
Detections:
win_pony_g0 win_pony_auto
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:dependsonpythonailib
Author:Tim Brown
Description:Hunts for dependencies on Python AI libraries
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:Fareit
Author:kevoreilly
Description:Fareit Payload
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:INDICATOR_EXE_Packed_ConfuserEx
Author:ditekSHen
Description:Detects executables packed with ConfuserEx Mod
Rule name:INDICATOR_SUSPICIOUS_EXE_Referenfces_File_Transfer_Clients
Author:ditekSHen
Description:Detects executables referencing many file transfer clients. Observed in information stealers
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:pe_imphash
Rule name:pony
Author:Brian Wallace @botnet_hunter
Description:Identify Pony
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:UPX
Author:kevoreilly
Description:UPX Unpacker: dump on OEP (original entry point)
Rule name:UPX20030XMarkusOberhumerLaszloMolnarJohnReiser
Author:malware-lu
Rule name:UPXV200V290MarkusOberhumerLaszloMolnarJohnReiser
Author:malware-lu
Rule name:UPXv20MarkusLaszloReiser
Author:malware-lu
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.
Rule name:Windows_Trojan_Pony_d5516fe8
Author:Elastic Security
Rule name:win_pony_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.pony.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments