Tag: Pony

37.9.53.121 (Pony Stealer hosted by pinspb.ru)

Uncategorized

Server:  37.9.53.121 Gate file:  //xSZ64Wiax/WiOzJe3G7u7ok3gOYqHdv2xk.php According to virustotal this is an affiliate program, with the pony file downloaded from the same site. Hosting infos: http://whois.domaintools.com/37.9.53.121 Related md5s (Search on malwr.com to download the sample) Pony: 37ae22ba2799ed146c47085268dd481b

zbraaadanstfesse.org (Pony loader hosted by chicagovps.net)

Uncategorized

Resolved zbraaadanstfesse.org to 172.245.5.137 Server:  zbraaadanstfesse.org Gate file:  /p/stats.php This is currently being downloaded by this citadel net. This is also a backup domain for a betabot, and is the domain currently used by it. Betabot login: hxxp://zbraaadanstfesse.org/~.poto/login.php Related md5s (Search on malwr.com for samples): 7ec71449228f4209b9df59bb68ec3a5f Hosting infos: http://whois.domaintools.com/172.245.5.137

64.85.233.8 (Citadel banking malware hosted by home ip?)

Uncategorized

Server:   64.85.233.8 Config file:  /hide/1355/file.php Gate file:  /hide/1355/enter.php According to whois, this is a home cable internet ip (United States Concord Astound Broadband). Also on the server, smoke loader and pony Smoke Server:  64.85.233.8 Gate file:  /smokeldr/index.php Pony Server:  64.85.233.8 Gate file:  /js/gate.php The moron running this has Pony downloading itself, creating a continuousRead more...

toxhoster.net (Pony loader hosted by ecatel.net)

Uncategorized

Resolved toxhoster.net to 80.82.79.35 Server:  toxhoster.net Gate file:  /forum/gate.php Some idiot set it to download itself from the server, so it will run in an endless loop of stealing passwords, sending logs, and then downloading and running itself. Hosting infos: http://whois.domaintools.com/80.82.79.35 Related md5s (search on malwr.com to download the samples): b22258989a5e93d4cb1c3960441c1c06

securityspecialiastinc.in(Pony hosted in Japan Tokyo Linode Llc)

Uncategorized

Resolved : [securityspecialiastinc.in] To [106.187.88.52] Gate: securityspecialiastinc.in/p/gate.php Admin:securityspecialiastinc.in/p/admin.php sample: hxxp://106.187.88.52/p/p.exe Online Crypter: hxxp://securityspecialiastinc.in/crypt.php hosting infos: http://whois.domaintools.com/106.187.88.52