General

  • Target

    1c4e740ac96b1274029384dc152101fc_JaffaCakes118

  • Size

    179KB

  • Sample

    240701-ypdg9azgmr

  • MD5

    1c4e740ac96b1274029384dc152101fc

  • SHA1

    a03c0b30567e8388c1df43cc46cac9a941a80547

  • SHA256

    0e6d900559c5c615a2f38fe823bce10228589513e04c7f20b32a28e15679d6df

  • SHA512

    433cd9c98000fbc2e79de9979c94ad0fd295e65ad110caffdf05fd58cba17ce7c0feba6141e233454cd0282ac1e448326eca55190d896e60b20a4dd7f52e60c9

  • SSDEEP

    3072:f7UKBs+k+l8IGMqUt03XIC4SHP7pUR5/Jc15DYyF:TUl+k+u4II6HPVcmbDYQ

Malware Config

Extracted

Family

pony

C2

http://108.178.59.26/forum/viewtopic.php

http://206.72.197.13/forum/viewtopic.php

Attributes
  • payload_url

    http://91.184.22.164/apaS9np.exe

    http://sousuoku.com/ehRqcK55.exe

    http://www.vivaidiportanova.it/pU5.exe

Targets

    • Target

      1c4e740ac96b1274029384dc152101fc_JaffaCakes118

    • Size

      179KB

    • MD5

      1c4e740ac96b1274029384dc152101fc

    • SHA1

      a03c0b30567e8388c1df43cc46cac9a941a80547

    • SHA256

      0e6d900559c5c615a2f38fe823bce10228589513e04c7f20b32a28e15679d6df

    • SHA512

      433cd9c98000fbc2e79de9979c94ad0fd295e65ad110caffdf05fd58cba17ce7c0feba6141e233454cd0282ac1e448326eca55190d896e60b20a4dd7f52e60c9

    • SSDEEP

      3072:f7UKBs+k+l8IGMqUt03XIC4SHP7pUR5/Jc15DYyF:TUl+k+u4II6HPVcmbDYQ

    • Pony,Fareit

      Pony is a Remote Access Trojan application that steals information.

    • Reads data files stored by FTP clients

      Tries to access configuration files associated with programs like FileZilla.

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Accesses Microsoft Outlook accounts

    • Accesses Microsoft Outlook profiles

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

MITRE ATT&CK Matrix ATT&CK v13

Credential Access

Unsecured Credentials

2
T1552

Credentials In Files

2
T1552.001

Discovery

Query Registry

1
T1012

Collection

Data from Local System

2
T1005

Email Collection

2
T1114

Tasks