MALICIOUS — d4d359cef880e6c7cda1b3fdf559f6d474d261ef1521e261d4f8f506fef7cc74
MALICIOUS — d4d359cef880e6c7cda1b3fdf559f6d474d261ef1521e261d4f8f506fef7cc74 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (87/100), attributed to the Ponystealer family. 5 of 52 detection engines flagged it.
Identification
- SHA-256:
d4d359cef880e6c7cda1b3fdf559f6d474d261ef1521e261d4f8f506fef7cc74 - SHA-1:
5267a94393d0c69403120531f2c35361ac344998 - MD5:
093c6719393979caf25222e2f56accae - imphash:
e946d0c3ee68a7484b853d46db7d8281 - ssdeep:
3072:M6RrEikYA0QdTh532O8QXJlx3er+jL7ScA96TElZIajM/naFhNlUw4WOXZS:Md0Ih532Kd3zjL7S1kEl7jyaFJm - TLSH:
T134408C9D0182D13BDCBB4269E192452C98F39861047F30C461A678AE7646FDF18BD8BF - Submitted as: d4d359cef880e6c7cda1b3fdf559f6d474d261ef1521e261d4f8f506fef7cc74
- File type: pe · Size: 176128 bytes
- Verdict: malicious (87/100) · Family: Ponystealer
Detections (5 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- ClamAV (daily): Win.Malware.Ponystealer-10037604-0
- Microsoft Defender: Trojan:Win32/Multiverze!rfn
- Emsisoft (Emergency Kit): Gen:Heur.PonyStealer.km0@d0G1n1ob
- Kaspersky (KVRT): Trojan.Win32.Autoit.abiqv
Why this verdict
The malicious score of 87/100 is the fusion of 2 weighted signals:
- ClamAV (daily) flagged Win.Malware.Ponystealer-10037604-0 (rule
Win.Malware.Ponystealer-10037604-0) - engine signal, weight 0.90, confidence 0.95 - Packing/obfuscation: high-entropy-sections:.text - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
File paths
- C:\Program
- C:\Users\BIGGS\AppData\Roaming
- C:\Windows\system32\cmd.exe
- C:\Users\BIGGS\AppData\Local
- C:\ProgramData\Oracle\Java\javapath;C:\Program
- C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program
- C:\P
More Ponystealer samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report