MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ca87cae4178948ec9ae47c09a34a78e89ec84287dceadceac4543ae905c63e42. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Pony


Vendor detections: 13


Intelligence 13 IOCs 1 YARA 3 File information Comments

SHA256 hash: ca87cae4178948ec9ae47c09a34a78e89ec84287dceadceac4543ae905c63e42
SHA3-384 hash: a1cc9bc5eff6a0308cdea277fc0970f761bbbc50a4aed46a19e02d71e3a7208cf25ab8f6ca7975a8f5af47522d9396e0
SHA1 hash: 8db895f793b75337b1eb4b846fa93d78275261f0
MD5 hash: 1d39caf49956b39411099339914ccffc
humanhash: happy-king-moon-yankee
File name:8db895f793b75337b1eb4b846fa93d78275261f0.exe
Download: download sample
Signature Pony
File size:1'274'200 bytes
First seen:2021-08-07 15:45:21 UTC
Last seen:2021-08-07 16:28:27 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash ea299e240e03c9175414089d9c26dfc8 (1 x Pony)
ssdeep 12288:85wLRwO+kyheb8El82ijWVhdePIix7qTvk8BIUJ4q6H:856RwO+KHijWGx7qTvCUJsH
Threatray 306 similar samples on MalwareBazaar
TLSH T1D34523408980E786F55B05BD1455B5AE312AB806A36B1FB9123BC79DFB3E2CBEF50704
dhash icon 0f792d128b494334 (1 x Pony)
Reporter abuse_ch
Tags:exe Pony


Avatar
abuse_ch
Pony C2:
http://electrolaser.pt/tech/panel/gate.php

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
http://electrolaser.pt/tech/panel/gate.php https://threatfox.abuse.ch/ioc/166006/

Intelligence


File Origin
# of uploads :
2
# of downloads :
669
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
u.exe
Verdict:
No threats detected
Analysis date:
2018-07-03 09:36:23 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Launching a service
Sending a UDP request
Launching a process
Creating a file in the %temp% directory
Deleting a recently created file
Result
Threat name:
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Drops / launches Pony Loader self-deletion script - malware possibly based on Pony Loader leaked source code
Found malware configuration
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Mail credentials (via file registry)
Yara detected aPLib compressed binary
Yara detected Pony
Behaviour
Behavior Graph:
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2018-07-03 06:45:56 UTC
File Type:
PE (Exe)
Extracted files:
25
AV detection:
27 of 31 (87.10%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:pony discovery rat spyware stealer upx
Behaviour
Checks SCSI registry key(s)
Modifies data under HKEY_USERS
Suspicious behavior: LoadsDriver
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Drops file in Windows directory
Checks installed software on the system
Enumerates connected drives
Deletes itself
Reads data files stored by FTP clients
Reads user/profile data of web browsers
Pony,Fareit
Malware Config
C2 Extraction:
http://electrolaser.pt/tech/panel/gate.php
Unpacked files
SH256 hash:
90e9c2e98285d827b507803b3f1ee02bc6db4c4115a7adf514dae9a92e535483
MD5 hash:
cf32f8b9f64ca2c5f6be1c7ba989d864
SHA1 hash:
08b88b7b1fac42455eda4bc70417b2e5f4127fc6
Detections:
win_pony_g0 win_pony_auto
SH256 hash:
3723715d03f5648863287ec751a0b6211fb3fadb8040bc66d05f8360144b3be4
MD5 hash:
12660460aedd5976aa3164b596f1ba88
SHA1 hash:
758cd18fa18e1a67506a7af0c337964f9c98f0e3
SH256 hash:
c8da28e4a5e65e64f83bac760268f2a08d379a7065f1ec00b10d569b32158dad
MD5 hash:
a8bfb3d7d0577baa4c57328f814fc222
SHA1 hash:
b175690760fea65f7c209d4ea5c5fc7d8053c322
SH256 hash:
ae40469fd48e4a2eaf57798dc4c78cb58ae00640eb03925f7932e17df4ea1ab3
MD5 hash:
61efc9d7378d477ddec1ff33907a0e38
SHA1 hash:
3c80c1bcb336e089a1c3e06cefb72f8402d7ab70
SH256 hash:
72108b4a4adb742f063e8c75fc6ea2f94f61a6fce27f9a6b2e7465a7a4817203
MD5 hash:
9f2af5de0981aa7abef4788b3b2063f1
SHA1 hash:
3bd50ece4f54c5c3dce66fa8b2d121fb85d9c27b
SH256 hash:
6b3f9021ddf5b88a28b9e53bfe8d617a40d1437f28cf7f71045de09ba8764d8c
MD5 hash:
db6b70db288a78d954514606f8e99d61
SHA1 hash:
1a08586dc8bce175c88941091ad292e9814ed7d0
SH256 hash:
32e5abe46fa0b68957838163f80e3765644ace16de8e64ab23db0bcf2d8b137a
MD5 hash:
a544d4527d2801b2229a92dc95c93e02
SHA1 hash:
17f58d38ad20dcd93f966dfd7b2d6ab30c80023d
SH256 hash:
ca87cae4178948ec9ae47c09a34a78e89ec84287dceadceac4543ae905c63e42
MD5 hash:
1d39caf49956b39411099339914ccffc
SHA1 hash:
8db895f793b75337b1eb4b846fa93d78275261f0
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Fareit
Author:kevoreilly
Description:Fareit Payload
Rule name:INDICATOR_SUSPICIOUS_EXE_Referenfces_File_Transfer_Clients
Author:ditekSHen
Description:Detects executables referencing many file transfer clients. Observed in information stealers
Rule name:win_pony_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.pony.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments