MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f3c2d287c23bc90e0185b416d9e3d0469f4c4eaa21aecd1835061f3677bee67f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Pony


Vendor detections: 16


Intelligence 16 IOCs YARA 19 File information Comments

SHA256 hash: f3c2d287c23bc90e0185b416d9e3d0469f4c4eaa21aecd1835061f3677bee67f
SHA3-384 hash: 91d8d46310cdfffe2497d0f2ed767e8d26f89cbfb96f334f98b8c3f5ab4f4a811f4fe404a21e2e6f09a04f0824432301
SHA1 hash: e05b520607df4d450913c2f8396770a91c4eb445
MD5 hash: 0a5965181377de2927d50038c02276d1
humanhash: harry-mike-july-florida
File name:0A5965181377DE2927D50038C02276D1.exe
Download: download sample
Signature Pony
File size:155'648 bytes
First seen:2024-01-19 09:05:22 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'070 x AgentTesla, 20'026 x Formbook, 12'352 x SnakeKeylogger)
ssdeep 1536:KxMDC/9LdBERbOLRAtl6ObtRyWr5Z/i8It2N09nmZcdNO9GrClrbpX4oV8KwL0DH:KxF/RW6ix1Nw8+U9GrgLw4DTXJN80
TLSH T1DEE3A3252AEF006DF3B7AEB52FD4F8EF895AE373151971BA216107064B22E40CD92735
TrID 41.0% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
15.2% (.EXE) UPX compressed Win32 Executable (27066/9/6)
14.9% (.EXE) Win32 EXE Yoda's Crypter (26569/9/4)
9.2% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
5.9% (.EXE) Win64 Executable (generic) (10523/12/4)
Reporter abuse_ch
Tags:exe Pony


Avatar
abuse_ch
Pony C2:
http://nsslawcollege.org/look/gate.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
406
Origin country :
NL NL
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Launching a process
Creating a file
Reading critical registry keys
DNS request
Sending an HTTP POST request
Creating a file in the %temp% directory
Running batch commands
Creating a process with a hidden window
Stealing user critical data
Unauthorized injection to a system process
Brute forcing passwords of local accounts
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
fareit lolbin msbuild overlay packed packed regasm replace
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
92 / 100
Signature
.NET source code contains potential unpacker
.NET source code contains very large strings
.NET source code references suspicious native API functions
Allocates memory in foreign processes
Antivirus / Scanner detection for submitted sample
Injects a PE file into a foreign processes
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Writes to foreign memory regions
Yara detected AntiVM3
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Generic
Status:
Malicious
First seen:
2024-01-16 10:10:00 UTC
File Type:
PE (.Net Exe)
Extracted files:
8
AV detection:
32 of 38 (84.21%)
Threat level:
  2/5
Verdict:
malicious
Label(s):
Result
Malware family:
Score:
  10/10
Tags:
family:pony collection rat spyware stealer upx
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_win_path
Suspicious use of SetThreadContext
Accesses Microsoft Outlook accounts
Accesses Microsoft Outlook profiles
UPX packed file
Pony,Fareit
Malware Config
C2 Extraction:
http://nsslawcollege.org/look/gate.php
Unpacked files
SH256 hash:
88acfa762621581447939abb92c82f5ad12baf0e819f5f76e92b6c1d9d65148b
MD5 hash:
4e56723e181827eb369b7433b67669fc
SHA1 hash:
657fb3e455aa54e315070e155777e4422caa49b1
Detections:
win_pony_auto win_pony_g0 INDICATOR_SUSPICIOUS_EXE_Referenfces_File_Transfer_Clients malware_windows_pony_stealer
SH256 hash:
7e9db2c53352030d679f81a0f56b2a9cc121263a0bfbbaea23bad000a1b741ac
MD5 hash:
26e3b34e67eccc4a30b1b1a53fbaf2e8
SHA1 hash:
b2496213c2285270695d24be663396be48742f41
Detections:
Gen_Base64_EXE
SH256 hash:
f3c2d287c23bc90e0185b416d9e3d0469f4c4eaa21aecd1835061f3677bee67f
MD5 hash:
0a5965181377de2927d50038c02276d1
SHA1 hash:
e05b520607df4d450913c2f8396770a91c4eb445
Detections:
Gen_Base64_EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Disable_Defender
Author:iam-py-test
Description:Detect files disabling or modifying Windows Defender, Windows Firewall, or Microsoft Smartscreen
Rule name:Fareit
Author:kevoreilly
Description:Fareit Payload
Rule name:INDICATOR_SUSPICIOUS_EXE_Referenfces_File_Transfer_Clients
Author:ditekSHen
Description:Detects executables referencing many file transfer clients. Observed in information stealers
Rule name:maldoc_find_kernel32_base_method_1
Author:Didier Stevens (https://DidierStevens.com)
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:Multifamily_RAT_Detection
Author:Lucas Acha (http://www.lukeacha.com)
Description:Generic Detection for multiple RAT families, PUPs, Packers and suspicious executables
Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:pony
Author:Brian Wallace @botnet_hunter
Description:Identify Pony
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:UPX20030XMarkusOberhumerLaszloMolnarJohnReiser
Author:malware-lu
Rule name:UPXV200V290MarkusOberhumerLaszloMolnarJohnReiser
Author:malware-lu
Rule name:UPXv20MarkusLaszloReiser
Author:malware-lu
Rule name:Windows_Trojan_Pony_d5516fe8
Author:Elastic Security
Rule name:win_pony_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.pony.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments