General

  • Target

    283553a8e878f0e3786e3f2d0fd550d5_JaffaCakes118

  • Size

    159KB

  • Sample

    240706-mepa8aycnf

  • MD5

    283553a8e878f0e3786e3f2d0fd550d5

  • SHA1

    478f16f1dac871ab18768d5801701c56abec5f1e

  • SHA256

    ab1ec8875a1f1bbe143e1dbf40cf980ffe05db347c4937be87c2f0100df68b13

  • SHA512

    3d0a7ffd625f438f200054f31b9ae449a92c6814ac3bc2dc174aaab6a2a80e64cbe7825f950a74499b22fff6e7c7d2c1b2e85600c2cf2ddb7967a623ff218fa1

  • SSDEEP

    1536:KKPE6GbCrQtPVAMUHp4ar7jmH422EThBme15fSYDt5NIO2+dcAOosP13YiJnAU60:Kh6Gb0OVAJ7qGylt955NIO2+dhMVZN60

Malware Config

Extracted

Family

pony

C2

http://etsiunjour.fr:81/pony/gate.php

http://akamaifilms.com:81/pony/gate.php

Attributes
  • payload_url

    http://acarkent24.com/agX.exe

    http://archstone.ro/yuzFyjAw.exe

Targets

    • Target

      283553a8e878f0e3786e3f2d0fd550d5_JaffaCakes118

    • Size

      159KB

    • MD5

      283553a8e878f0e3786e3f2d0fd550d5

    • SHA1

      478f16f1dac871ab18768d5801701c56abec5f1e

    • SHA256

      ab1ec8875a1f1bbe143e1dbf40cf980ffe05db347c4937be87c2f0100df68b13

    • SHA512

      3d0a7ffd625f438f200054f31b9ae449a92c6814ac3bc2dc174aaab6a2a80e64cbe7825f950a74499b22fff6e7c7d2c1b2e85600c2cf2ddb7967a623ff218fa1

    • SSDEEP

      1536:KKPE6GbCrQtPVAMUHp4ar7jmH422EThBme15fSYDt5NIO2+dcAOosP13YiJnAU60:Kh6Gb0OVAJ7qGylt955NIO2+dhMVZN60

    • Pony,Fareit

      Pony is a Remote Access Trojan application that steals information.

    • Reads data files stored by FTP clients

      Tries to access configuration files associated with programs like FileZilla.

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Accesses Microsoft Outlook accounts

    • Accesses Microsoft Outlook profiles

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

MITRE ATT&CK Matrix ATT&CK v13

Credential Access

Unsecured Credentials

2
T1552

Credentials In Files

2
T1552.001

Discovery

Query Registry

1
T1012

Collection

Data from Local System

2
T1005

Email Collection

2
T1114

Tasks