• Latest
  • Trending
  • All
  • cPanel

Fox stealer: another Pony Fork

September 26, 2016

Threat Spotlight: Malicious HTML attachments

June 28, 2022

How to Build a Website Using Patterns in WordPress FSE – InMotion Hosting Support Center

June 27, 2022

EmoCheck – Emotet Detection Tool For Windows OS

June 27, 2022

Quickpost: Cracking PDF Owner Passwords

June 27, 2022

Sealighter – Easy ETW Tracing for Security Research

June 26, 2022

10 Best Linux Games for Free 2022

June 26, 2022
Tutorial
  • cPanel
  • News
  • Technology
    • Coding
    • Hosting
    • Gadgets
  • Cyber Security
No Result
View All Result
Tutorial
  • cPanel
  • News
  • Technology
    • Coding
    • Hosting
    • Gadgets
  • Cyber Security
No Result
View All Result
Tutorial
No Result
View All Result
Home Cyber Security

Fox stealer: another Pony Fork

anchani by anchani
September 26, 2016
in Cyber Security
Reading Time: 4 mins read
277 15
A A
0
547
SHARES
3.6k
VIEWS
Share on FacebookShare on Twitter

Gift for SweetTail-Fox-mlp
 by Mad-N-Monstrous

Small data drop about another Pony fork : Fox stealer.
First sample of this malware I saw was at beginning of September 2016 thanks to Malc0de. After figuring out the panel name and to which advert it was tied we were referring to it as PonyForx.

Advert :
2016-08-11 – Sold underground by a user going with nickname “Cronbot”

——–
Стилер паролей и нетолько – Fox v1.0

Мы выпускаем продукт на продажу. Уже проходит финальная стадия тестирования данного продукта.

О продукте : 
1. Умеет все что умеет пони. + добавлен новый софт.
2. Актуален на 2016 год.
3. Написан на С++ без дополнительных библиотек.
4. Админка от пони.

Условия : 
1. Только аренда.
2. Распространяется в виде EXE и DLL.
3. Исходники продавать не будем.

Аренда 250$ в месяц.
Исходники 2000$ разово.

—-Translated by Jack Urban : —-
Password stealer and more – Fox v.1.0

We are releasing the product for general sale. Final stage of testing for this product is already underway.

About the product:

1. Is able to do everything that pony does. + new software has been added.

2. Relevant for 2016.

3. Written in C++ without additional libraries.

4. Admin from pony.

Conditions:

1. For rent only.

2. Distributed as an EXE and DLL.

3. We will not be selling the source.

Rent is $250 a month.

Originals are a 2000$ one time fee. 

——–

It’s being loaded (with Locky Affid 13) by the Godzilla from  (aka AfraidGate) group .

MISP taxonomy tags reflecting ScriptJS activity in the last months

(note : it’s not the first time this group is pushing a stealer, they were dropping Pony with their Necurs between August and December 2015 [1] )

2016-09-26 – ScriptJS infection chain into Neutrino into Godzilla loader into PonyForx and Locky Affid 13
Here we can see the browsing history of the VM being sent to PonyForx (Fox stealer) C2
Fox stealer (PonyForx) fingerprint in Cuckoo


Sample :

cca1f8ba0be872ec86755e3defbb23c8fe4a272a6b4f7ec651302c5cddc5e183
Associated C2:
blognetoo[.]com/find.php/hello
blognetoo[.]com/find.php/data
blognetoo[.]com|104.36.83.52
blognetoo[.]com|45.59.114.126
Caught by ET rule :
2821590 || ETPRO TROJAN Win32.Pony Variant Checkin

[1] ScriptJS’s Pony :
master.districtpomade[.]com|188.166.54.203 – 2015-08-15 Pony C2 from ScriptJS
​js.travelany[.]com[.]ve|185.80.53.18 – 2015-12-10 Pony C2 from ScriptJS

Read More : 

 few bits about ScriptJS
Inside Pony 1.7 / Fareit C&C – Botnet Control Panel – 2012-06-27
Pony 1.9 (Win32/Fareit) – 2013-05-23 – Xylitol





Source link

Previous Post

AMSI: How Windows 10 Plans to Stop Script-Based Attacks and How Well It Does It

Next Post

RIG evolves, Neutrino waves goodbye, Empire Pack appears

anchani

anchani

Related Posts

Cyber Security

Threat Spotlight: Malicious HTML attachments

June 28, 2022
Cyber Security

EmoCheck – Emotet Detection Tool For Windows OS

June 27, 2022
Cyber Security

Quickpost: Cracking PDF Owner Passwords

June 27, 2022
Next Post

RIG evolves, Neutrino waves goodbye, Empire Pack appears

Rotten Apples: Resurgence

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

You might also like

Threat Spotlight: Malicious HTML attachments

June 28, 2022

How to Build a Website Using Patterns in WordPress FSE – InMotion Hosting Support Center

June 27, 2022

EmoCheck – Emotet Detection Tool For Windows OS

June 27, 2022

Quickpost: Cracking PDF Owner Passwords

June 27, 2022

Sealighter – Easy ETW Tracing for Security Research

June 26, 2022

10 Best Linux Games for Free 2022

June 26, 2022
Host Help

We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Check our landing page for details.

  • Home
  • cPanel
  • Technology
  • Gadget
  • Design

© 2022 HostHelp.org -Tutorials for your hosting solutions HostHelp.org.

No Result
View All Result
  • cPanel
  • News
  • Technology
    • Coding
    • Hosting
    • Gadgets
  • Cyber Security

© 2022 HostHelp.org -Tutorials for your hosting solutions HostHelp.org.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In