General

  • Target

    286b49270364a6a8d80accf993029c14_JaffaCakes118

  • Size

    114KB

  • Sample

    240706-rdq6mszcnp

  • MD5

    286b49270364a6a8d80accf993029c14

  • SHA1

    cfacd84ca421a208f51fa9ea033f52d999e499c4

  • SHA256

    6f0ee3ea2e0e103a1b7d96ffbe051cbb5a5b164b7539d5f23d2a398b11f38bfd

  • SHA512

    0c95526242d3963c5f6ee4e02c403420f61b710bdc1ab6c9f61ed75454726e2559dcc054ad735617ed6011b4377db16e595f68ceb5b6277c296fc757526919a9

  • SSDEEP

    3072:/XAtWYKBlV6EsGMBwJl7VMFmEn6mot6NxsyUH9:fAoYKXV63Byl7Jie

Malware Config

Extracted

Family

pony

C2

http://etsiunjour.fr:81/pony/gate.php

Attributes
  • payload_url

    http://alcaponecigarillos.com/RdKtpaU.exe

    http://artseo.abetka.kiev.ua/urS1R.exe

    http://hunterland.com.ua/MTgQrd.exe

Targets

    • Target

      286b49270364a6a8d80accf993029c14_JaffaCakes118

    • Size

      114KB

    • MD5

      286b49270364a6a8d80accf993029c14

    • SHA1

      cfacd84ca421a208f51fa9ea033f52d999e499c4

    • SHA256

      6f0ee3ea2e0e103a1b7d96ffbe051cbb5a5b164b7539d5f23d2a398b11f38bfd

    • SHA512

      0c95526242d3963c5f6ee4e02c403420f61b710bdc1ab6c9f61ed75454726e2559dcc054ad735617ed6011b4377db16e595f68ceb5b6277c296fc757526919a9

    • SSDEEP

      3072:/XAtWYKBlV6EsGMBwJl7VMFmEn6mot6NxsyUH9:fAoYKXV63Byl7Jie

    • Pony,Fareit

      Pony is a Remote Access Trojan application that steals information.

    • Reads data files stored by FTP clients

      Tries to access configuration files associated with programs like FileZilla.

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Accesses Microsoft Outlook accounts

    • Accesses Microsoft Outlook profiles

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Credential Access

Unsecured Credentials

2
T1552

Credentials In Files

2
T1552.001

Discovery

Query Registry

1
T1012

Collection

Data from Local System

2
T1005

Email Collection

2
T1114

Tasks