MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c65dea4696ecbba6b4c5a4c4e1da762e727e1878e169d811100b4ee4aedd7313. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Pony


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: c65dea4696ecbba6b4c5a4c4e1da762e727e1878e169d811100b4ee4aedd7313
SHA3-384 hash: 5ada58862822633007654805df0531858cb48150806511419c2b437493a8a9d2459c4db41307d6a13cf2d28f44789d92
SHA1 hash: 60952e9157251d9a09b7cb4a7cc229c16b91c988
MD5 hash: 968c90cf1dc04ec7dc895d59b4a331b0
humanhash: friend-king-crazy-ohio
File name:TT-mt103-20-05-20.tar.eml.zip
Download: download sample
Signature Pony
File size:161'251 bytes
First seen:2020-05-22 07:04:43 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 3072:h9wWexv7sbtYB1cJJnYs6RROjsrMWHl2y1uXYzf4tZJ:vwWexzwqIqs8RO20t/
TLSH A5F323018CDBA35CAD8A4E3D0B04BF65767D584A6DC7CB2C40218252D66BFBDBABCC15
Reporter abuse_ch
Tags:Pony zip


Avatar
abuse_ch
Malspam distributing Pony:

HELO: zvit.net
Sending IP: 199.96.83.18
From: Angela <test@zvit.net>
Subject: Payment notification
Attachment: TT-mt103-20-05-20.tar.eml.zip (contains "TT-mt103-20-05-20.exe")

Pony C2:
http://tradeslushpool.com/wp-admin/panel/gate.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
449
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-22 07:36:53 UTC
File Type:
Binary (Archive)
Extracted files:
9
AV detection:
5 of 48 (10.42%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Pony

zip c65dea4696ecbba6b4c5a4c4e1da762e727e1878e169d811100b4ee4aedd7313

(this sample)

  
Dropping
Pony
  
Delivery method
Distributed via e-mail attachment

Comments